When the Board Speaks Like the Oracle of Delphi: Cybersecurity Turns into a Ritual, Not a Strategy

In ancient Greece, leaders journeyed to the Temple of Apollo at Delphi to seek divine guidance from the Pythia, the Oracle who delivered cryptic prophecies that shaped empires. Her words, often shrouded in mystery, required careful interpretation by priests and advisors before any real decision could be made.

Fast forward to the modern boardroom, and some CISOs might say little has changed. One recently remarked to me, “Talking to the board about how they want to have security for their business feels like talking to the Oracle of Delphi. The conversation and guidance from the board is so cryptic that it needs translation, and this challenge alone has gotten me nowhere since the last two years I have been here.”

The Communication Gap Between CISOs and Boards


Despite growing awareness of cyber risk as a business risk, communication between CISOs and boards often breaks down. It’s not due to lack of intent, but lack of clarity. Boards speak the language of business resilience, financial risk, and shareholder value. CISOs speak the language of controls, threat vectors, and incident response. Somewhere between these two dialects, the message becomes muddled. As a result:

  • Boards feel uncertain about whether cybersecurity is effectively managed.
  • CISOs struggle to secure budget and executive buy-in.
  • Both sides leave the conversation frustrated.

To move from mysticism to meaningful dialogue, both sides must adapt their communication styles.

3 Strategies for the Board to Articulate their Expectations


Boards must articulate their expectations to the CISO clearly to avoid ambiguity and misalignment. When the CISO is left to interpret priorities, it results in over-engineering controls in some areas and under-protecting others. Clear direction empowers the CISO to focus resources where they matter most, align cybersecurity strategy with business objectives, and provide assurance that board-level risk decisions are being operationalized effectively.

1. Resolve the disconnect between what question the Board asks and what they are truly prepared to act on

Boards need to tune their questions to the business model they actually operate, not the one they wish they had. This ensures that CISO responses are relevant, actionable, and aligned with the organization’s real decision-making structure.

If a board intends to keep compliance liability de-centralized, for example, at a regional or business-unit level, it should avoid asking the CISO for a unified maturity assessment or enterprise-wide posture statement. Doing so only creates tension between governance aspiration and operational reality.

2. Let the CISO Focus on Securing the Enterprise, Not Filling Governance Gaps

The board must allow the CISO to focus on securing the enterprise, not compensate for weaknesses in other governance functions. A CISO’s effectiveness depends on the maturity of other corporate functions including Compliance, Audit, Risk Management, IT, and Business Continuity. Expecting the CISO to bridge these gaps blurs accountability and undermines overall resilience.

For example, assigning the CISO to lead enterprise risk management simply because “cyber risk is business risk” often results in fragmented accountability and diluted focus. The CISO role drifts from a strategic enabler, spending more time patching governance voids than addressing real threats.

3. Invest time to articulate risk appetite and expectations

Boards often say, “We want to be secure,” without defining what secure means in measurable terms. Clarity around risk tolerance, prioritization, and investment boundaries gives CISOs actionable direction.

If the board’s true appetite is to accept moderate risk in non-critical regions to reduce spend, but enforce zero tolerance for downtime in core operations, the CISO can design a tiered control framework aligned to that reality, rather than wasting effort chasing blanket compliance.

How CISOs can in-turn Deliver to Meet Board Expectations


A CISO must read beyond the board’s words to understand their true intent, distinguishing between aspirational statements and actionable priorities. Interpreting board expectations is about aligning cybersecurity outcomes with the organization’s strategic and risk appetite boundaries, not just reacting to directives. A skilled CISO therefore listens for what the board values, e.g. resilience, reputation, and continuity, and translates those expectations into measurable security goals.

1. Translate technical risks into business impacts

Instead of explaining vulnerabilities or frameworks, frame discussions around how cyber risk affects operational continuity, brand trust, and compliance posture.

Rather than presenting a report on “unpatched critical CVEs,” a CISO might say: “A vulnerability in our payment gateway could disrupt online transactions for up to 48 hours, resulting in an estimated £3.5M in lost revenue and regulatory reporting obligations.” That shift from technical issue to business consequence immediately changes the quality of the discussion.

2. Establish a shared language of metrics

Meaningful, outcome-based metrics, such as time to detect/respond, percentage of critical assets with risk treatment plans, or alignment to business continuity objectives, bridge the gap between cyber operations and corporate performance.

Replacing “number of security incidents” with “percentage of incidents detected within SLA” reframes the conversation from counting problems to demonstrating operational efficiency and readiness.

3. Schedule education, not just reporting

Quarterly dashboards are valuable, but periodic deep dives help board members understand the why behind the numbers and build confidence in decision-making.

For instance, a dedicated annual session on threat trends and attack simulations allows the board to see not just metrics, but capability in action, transforming abstract data into tangible understanding of risk posture and response maturity.and compliance posture.


Clarity is power. To move beyond guesswork and truly build cyber resilience, boards must shift from offering cryptic guidance to delivering clear, strategic direction. In parallel, CISOs must evolve from interpreting vague intentions to acting as trusted advisors, translating that strategy into concrete, measurable business outcomes.

Newsletter Form

Subscribe to our newsletter

Curated insights on AI's impact on information security and cyber warfare - real-world use cases and the critical skills your organization needs to stay ahead.


Related Articles

Responses