Most boards believe they are overseeing cybersecurity well. Gartner's 2025 survey of non-executive directors found that 90 percent lack confidence that their organization has the right balance of protection and cost, even as those same boards approve budgets, sit through quarterly briefings, and sign off on risk appetite statements every year. The oversight machinery is running. It is just not producing the thing boards think it produces.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
The gap between activity and assurance
A year earlier, Gartner surveyed 328 non-executive directors and found 67 percent rated their board's current cyber oversight practices inadequate, while 93 percent said cyber risk threatens shareholder value. That is not a knowledge gap. Directors know the stakes. What they lack is a way to tell whether the organization is actually safer than it was last quarter, as opposed to merely more compliant.
The same survey showed where attention actually goes. Only 39 percent of directors ranked cyber-risk investment among their top five priorities for the next two years, compared with 63 percent for AI and 57 percent for general technology investment. Boards rate cyber risk as an existential threat and then under-resource its oversight relative to the things they find more exciting to talk about. That is a governance choice, not an accident, and it is worth naming plainly instead of dressing it up as a resourcing constraint.
Part of the problem is what boards are handed. A 2026 benchmark report from IANS, Artico Search, and the CAP Group, drawing on 17 board directors and a separate survey of 663 CISOs, found that 95 percent of CISOs deliver regular updates to the board, and 82 percent of directors rate the regulatory-reporting content of those updates as satisfactory or better. But only 47 percent of directors felt satisfied with the CISO's ability to articulate the impact of a given threat, and 53 percent identified specific gaps in reporting on how threats are evolving. Compliance reporting is solid. Forward-looking risk judgment is thin. Those are different skills, and most board reporting formats only exercise the first one.
Security updates in that same report got roughly 30 minutes of average board airtime, and 35 percent of boards restrict CISO engagement to a committee rather than the full board. Thirty minutes a quarter, filtered through a subcommittee, is not enough time to develop the kind of pattern recognition that lets a director ask a sharp follow-up question. It is enough time to nod through a dashboard.
What boards think oversight looks like
Ask most directors to describe good cyber oversight and they will describe a cadence, quarterly reports, an annual penetration test summary, a compliance attestation, maybe a tabletop exercise readout. All of that is legitimate input. None of it answers the question a board actually needs answered, which is whether the organization's risk exposure is trending up or down relative to what it is worth protecting, and whether management would tell them honestly if it were getting worse.
Here is a worked example from a mid-cap financial services board I advised this year. The board received a quarterly security scorecard with green, yellow, and red indicators across a dozen control categories. Every quarter for two years, the scorecard was mostly green. The board took comfort in that. When a third-party vendor breach exposed customer data, the post-incident review found the scorecard measured control existence, not control effectiveness. A firewall policy existed. It had not been tested against the attack pattern that was actually used. The board had been getting a status report on paperwork, not a status report on risk. That distinction, paperwork versus risk, is the whole article in miniature.
The three questions that actually change the answer
The fix is not a longer scorecard. It is a small number of questions that force a different kind of answer, asked consistently, quarter after quarter, until the answer format itself changes.
The first question is what the single biggest way we could be breached in the next twelve months looks like, and what is standing between us and that outcome today. This forces management to prioritize instead of enumerate, and it exposes whether they actually know their own weakest point or are reciting a generic threat list.
The second question is whether, if the answer to that first question were worse than it was last quarter, we would know, and how. This tests whether the organization has real detection and escalation capability or is relying on the absence of bad news as evidence of good security. Directors should expect a specific mechanism in response, not reassurance.
The third question is what we decided not to fix, and why. Every security program has a backlog of accepted risk. A board that never sees that backlog is not exercising oversight, it is receiving a highlight reel. Surfacing the deliberately unfixed items, with the reasoning, is where a board's judgment actually adds value, because prioritization under constraint is a board-level decision, not a technical one.
The strongest case against this framework
The honest counterargument is that boards are generalists meeting quarterly, and no amount of better questioning turns them into risk analysts capable of independently judging whether "standing between us and that outcome" is actually sufficient. A CISO can answer these three questions confidently and still be wrong, and a board with no technical depth has no way to catch it. Gartner's own data shows only 72 percent of boards plan to add cyber-risk expertise to the board within a year, which means more than a quarter do not, and questions alone do not substitute for expertise sitting in the room. There is real force to this. Better questions raise the floor on lazy reporting, but they do not replace the need for at least one director, or a standing technical advisor, who can independently stress-test the answer. Boards that adopt these three questions without also building or borrowing that expertise will get better-sounding answers, not necessarily better security.
Monday questions for leadership and the board
What is our single biggest breach path today, in plain language, not a control category. Who would know within how many hours if that risk got worse, and what would they do next. What have we consciously decided not to fix this year, and does the board actually see that list. Does our current CISO reporting format let a director ask a sharp follow-up, or does it end in a dashboard with no room for challenge. If our next incident happened to a vendor rather than to us, would our oversight process even surface it before a regulator does.
A board that can answer those five questions from memory is doing oversight. A board that needs to check the last scorecard is doing paperwork.