Security leaders have gotten very good at showing up. They present quarterly, on schedule, deck in hand. They've learned the room. They've developed the vocabulary. By nearly every process measure, CISO-board engagement has never looked more mature.
New research from Pulse Security AI, released this week at Black Hat, documents what's happening underneath that cadence—and the picture is significantly less comfortable.
The CISO–Board Communication Gap (free download, no form), drawn from a 42-respondent survey, 20-plus in-depth interviews with sitting and former CISOs, and two moderated workshops with roughly 22 security executives— 80-plus senior practitioners in total—is one of the most specific examinations of the CISO-board relationship published to date. Its central finding can be stated plainly: security leaders are presenting more than ever, and boards are understanding less than both sides think.
"For a decade, the industry has told security leaders to communicate better with the board," said Mike Armistead, CEO and co-founder of Pulse Security AI. "Our data says the problem is upstream of that. You cannot report status against a baseline that was never set."
That sentence lands differently once you see the data behind it.
The most arresting number in the report: only 12.5% of security leaders are "very confident" their board accurately understands the true state of the program after a presentation; 41% are "somewhat confident"; and 38% are neutral or mixed.
Read those numbers from the other direction: nearly nine in 10 security leaders walk out of their board presentation without strong confidence that the people responsible for cybersecurity governance just received an accurate picture of the program.
The report's framing of this is precise: "Boards think they understand their security posture and what it means for the business. The CISOs presenting to them aren't so sure—and the cycle continues largely unchanged."
The conventional diagnosis here is that CISOs need better communication skills—sharper storytelling, fewer technical terms, more business framing. The Pulse Security data complicates that narrative directly. "Translating technical findings into business language" ranks as both a top time burden and a top desired improvement in the survey. But when respondents described what they actually wanted, they didn't ask for coaching. They asked for simpler data delivery, better frameworks, and clearer context. The communication problem is real. Its solution, the research argues, isn't coaching; it's structural.
[RELATED: How the BISO Role Translates Cybersecurity into Enterprise Resilience]
Here is the structural problem: 55% of boards have never formally defined their organization's cyber risk appetite. Another 27% have defined it only qualitatively. That means just 18% of boards have established anything resembling a quantitative baseline—and only 16% successfully use a quantified risk model like FAIR. A mere 3% present dollar-figure risk estimates.
Without an agreed baseline, the CISO has no fixed reference point against which to report status. "Good" and "bad" are relative terms. Relative to what? In the absence of an answer the organization has actually defined, something fills the vacuum—and the research documents exactly what that something is.
Roughly 70% of security leaders say board members bring external information into the room: third-party security ratings, press coverage of peer incidents, findings from vendors who have a financial interest in the board's conclusions. And 42% of leaders have had to defend a commercial security score in a board meeting in the past 12 months.
One CISO quoted in the report put the problem as sharply as it can be put: "That score I have to defend is decided by two product managers—usually junior—who have never held a serious security role."
The risk appetite vacuum isn't just a governance gap. It actively distorts the conversation. When there's no agreed baseline, the board imports one, and that imported baseline is often whatever score a vendor decided to assign, or whatever breach just made the news, or whatever a board member's friend at another company said over dinner. The CISO is then in the position of defending against external noise rather than reporting against an internal standard. That is not a communication problem. That is a governance design problem.
Seventy-one percent of security leaders spend 10 or more hours preparing for each board or audit-committee presentation—effectively one to two full working days, every quarter, on top of everything else the security function is managing. Twenty-nine percent spend 21 to 40 hours. Thirty-nine percent involve four or more contributors per presentation cycle.
When the research asked what actually consumes that time, the answers weren't about narrative craft. They were about raw material assembly: creating visualizations and slides, gathering data from multiple disconnected security tools, and translating technical findings into business language.
One CISO at a global technology firm made the operational cost explicit: "Every hour spent pulling, analyzing, and translating data from a dozen disconnected tools is an hour not spent on actual security work."
This is the preparation tax, and it compounds in two ways. First, it is a direct drain on security leadership capacity; time senior practitioners spend on slide assembly is time they aren't spending on threat analysis, program strategy, or team development. Second, fragmented preparation produces fragmented output. When board metrics are assembled by hand from disparate sources every quarter rather than drawn from a single, maintained source of truth, the presentation is structurally less likely to convey a coherent picture of business risk and program effectiveness. The preparation problem and the confidence problem are connected.
When the research asked what would most reduce the burden, leaders named three things: automated synthesis of threats and vulnerabilities, automated data aggregation, and better tools to translate findings into business impact. The theme across all three is the same: the manual labor of assembly needs to be solved at the system level, not at the individual CISO's level.
Beyond the three headline findings, the survey surfaced a cluster of governance dynamics that reinforce the same picture.
Half of boards are not making cyber risk decisions. Fifty percent of boards made no explicit decision to accept, mitigate, or transfer cyber risk in the past year. Risk governance is supposed to produce decisions. A board that convenes quarterly for security updates and never makes a formal risk disposition is a board that is being briefed, not one that is governing.
Nearly half of CISOs have no venue for candor. Forty-eight percent of security leaders have no private executive-session access to the board or audit committee—no forum where they can raise unresolved concerns, flag disagreements with management, or deliver an honest assessment that isn't filtered through a full room of stakeholders. The things most worth saying in a board conversation about security risk are often the things that require a smaller, more private setting to say.
Personal liability shapes what gets said. Thirty-three percent of security leaders say their own legal exposure—a post-SolarWinds reality that the SEC's disclosure enforcement has only intensified—influences what they tell the board and how they tell it. This is not a character flaw; it is a rational response to a genuine legal environment. But it means that one in three CISOs is making editorial decisions about board communication based partly on personal legal risk, not purely on what the board needs to know.
Most risk characterization remains qualitative. Forty-nine percent of leaders characterize risk severity using qualitative categories—high, medium, low. Twenty-one percent use maturity levels, and 18% use risk scores or ratings. Only 3% present dollar-figure estimates. Given that boards operate in the language of financial exposure and business consequence, the predominance of qualitative risk characterization helps explain the persistent confidence gap. Qualitative labels require the board to supply the translation into business terms on their own—and they often supply it using whatever external information they bring into the room.
Board time is split evenly between past and future, which means half the meeting is spent on things that can't be changed. Forty-nine percent of board content looks backward at past events; 51% addresses future strategy. Nearly a quarter of leaders have no predefined threshold for board-level escalation. When an incident occurs, those leaders are negotiating in real time about what to tell the board and when.
There is a genuinely hopeful signal in the research, and it comes from an uncomfortable source. Among security leaders who have navigated a material security incident, 53% report that board trust in the security team increased afterward.
The report's explanation for this is important: "A real event forces a concrete, shared understanding of risk that quarterly decks rarely achieve." When an incident happens, the abstract becomes tangible. The board members who brought third-party scores and news coverage into the room now have a real event—one their organization experienced—against which to understand what security risk actually means in practice. The CISO who has been presenting qualitative categories now has a specific, concrete case to walk through. Credibility, built through crisis, that quarterly presentations rarely establish.
A corporate director at a Fortune 100 company made the point plainly in the research: "Performing a tabletop exercise with our security team established their credibility in a way a presentation never could."
That observation points toward the most actionable finding in the entire report: the conditions that build board trust after a breach—shared, concrete experience, visible decision-making under pressure, a common frame of reference for what risk actually looks like—can be created deliberately, before an incident, through tabletop exercises that include board communication as an explicit component.
The research closes with five practices drawn from the leaders who reported the highest board trust and the lowest preparation burden. They are worth quoting directly.
Define risk appetite before you report against it. With 55% of boards operating without a defined cyber risk appetite, status has no baseline. Agree on thresholds—even qualitative ones—so every update maps to a decision the board has already made.
Lead with business consequence, not control inventory. Frame each item as an effect on revenue, resilience, or obligation—then let the technical detail sit in an appendix.
Automate data aggregation so prep isn't a fire drill. Seventy-one percent spend 10-plus hours per cycle, most of it gathering and reconciling data by hand. Standardize a single source for board metrics so each cycle is a refresh, not a rebuild.
Agree on escalation thresholds while it's calm. Nearly a quarter of leaders have no predefined trigger for board-level escalation. Set clear disclosure thresholds in advance so an incident produces clarity, not confusion.
Secure a recurring private session with the board. Forty-eight percent have no executive-session access and thus no venue for candor. A standing private session gives leaders room to raise unresolved risk without a full audience.
The CISO quoted at the close of the research captures the spirit of all five: "The best board conversations I've had weren't about the tools. They were about what we'd decided to accept, and what we hadn't—agreed on long before the meeting."
The research was conducted across organizations ranging from less than 2,000 employees (38% of respondents) to more than 10,000 (44%), with industries spanning technology, financial services, healthcare, and manufacturing. The problems it documents are not scale-dependent. A small organization's CISO presenting to a three-person audit committee faces the same baseline-definition problem as a Fortune 500 CISO presenting to a full board—arguably a harder version of it, given fewer resources for dedicated board-prep support.
For enterprise security leaders, the report's most direct implication is that communication coaching and presentation training—the industry's conventional prescription for the CISO-board problem—address a symptom rather than the disease. Coaching helps a CISO articulate a message more clearly, but it does not solve the absence of an agreed risk appetite to report against. It does not reduce the 10-plus hours of manual data assembly that precede every presentation. It does not give the CISO a private room in which to say things that can't be said in a full meeting. The structural problems require structural solutions.
For mid-market and smaller organizations, the finding about external noise is particularly acute. When a board has no formal risk appetite and the CISO has no private executive-session access, the most influential input into board-level security perception is whatever information board members encounter between quarterly meetings: vendor marketing, news coverage of breaches at peer organizations, or a commercial security rating that was, as one CISO noted, decided by junior product managers. Small organizations with lean security functions are least equipped to push back against that noise and most exposed to its consequences.
For boards themselves—and for the growing number of board members who carry explicit cybersecurity oversight responsibilities under SEC disclosure rules—the research offers a specific and actionable challenge: the absence of a defined cyber risk appetite is not a neutral omission. It is the primary structural condition that makes meaningful security governance impossible. A board cannot evaluate whether its organization's security posture is adequate without having first defined what "adequate" means. Setting that baseline—even a qualitative one—is the governance decision that makes every subsequent presentation more informative and every CISO conversation more honest.
Armistead put the organizational challenge in operational terms: "You cannot assemble a clear picture of the business when the underlying information lives in a dozen disconnected places. Security leaders have earned the room. What they need now is the operating layer underneath it."