Engaging with the Board
Understanding the Board’s Perspective
Last Updated: March 9, 2026Boards do not govern information security in isolation from the broader strategic and commercial agenda they oversee. Cybersecurity sits alongside financial performance, regulatory compliance, operational...
Different Board Engagement Types
Last Updated: March 9, 2026The board represents the ISO’s most strategically significant audience. Engaging it effectively requires more than technical competence; it demands the ability to translate complex security...
Communicating with the Board
Last Updated: March 9, 2026While presenting to the board is a mark of respect, it requires rigorous preparation, relevant statistics and defendable metrics. Corporate boards have moved past paying...
Taking Threats and Risks to the Board
Last Updated: March 9, 2026The manner in which the ISO presents risks and threats to the board is one of the most consequential disciplines in board engagement. Done well,...
Expectations towards the Board
Last Updated: March 9, 2026Effective information security governance is not solely the ISO’s responsibility. The board carries its own set of obligations, and the quality of an organisation’s security...
Board Committee for Information Security Risk
Last Updated: March 9, 2026Boards are responsible for ensuring that cyber resilience and risk management are embedded throughout the organisation, across its people, processes, and technologies. Board members must...
Board’s Role in Cyber Incident Management
Last Updated: March 9, 2026Cybersecurity incidents carry profound consequences for organisations across multiple dimensions, including financial performance, operational continuity, regulatory standing, and reputational integrity. The board’s responsibility in this...
