Ninety-five percent of CISOs deliver regular updates to their board. Only 30 percent of boards describe the relationship with that CISO as strong and collaborative. Those two numbers, both from research by IANS, Artico Search, and the CAP Group surveying board directors alongside a separate pool of 663 CISOs, describe the same relationship from opposite sides of the table, and the gap between them is not about effort. CISOs are showing up. The format they are showing up with is not landing.

This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.

The report card looks fine and the relationship doesn't

The same research found 82 percent of directors rate their CISO's regulatory reporting as satisfactory or better. That number, on its own, would suggest the communication problem is solved. It is not. Only 47 percent of directors said they were satisfied with the CISO's ability to articulate the actual impact of a threat, and 53 percent identified specific gaps in how well the reporting captured where threats were heading, not just where they stood. Directors are not complaining about compliance content. They are complaining about judgment content, the part of a briefing that says what this means and what happens next, and that is a different writing and speaking skill than the one most security reporting formats are built around.

Part of the constraint is structural. Board security updates in the same research averaged roughly 30 minutes, and 35 percent of boards limit CISO engagement to a committee rather than bringing the CISO in front of the full board. Thirty minutes, filtered through a subcommittee, is enough time to walk through a slide deck. It is not enough time to build the kind of ongoing pattern recognition that lets a director ask a good follow-up question, which means the format has to do more work per minute than most CISOs are used to asking of it.

Translate risk into money, not into more technical detail

The instinct under time pressure is to compress, which usually means cutting detail rather than changing the unit of measurement. That is backwards. Deloitte's guidance on cybersecurity board reporting and separate research on effective board communication converge on the same fix, expressed by practitioners as needing to speak "boardish," which means translating technical findings into financial and operational terms before the meeting starts, not during it. A vulnerability count means nothing to a director. A dollar range tied to business interruption, informed by cyber risk quantification methods that estimate potential loss the way an actuary would, means something immediately, because it is denominated in the same currency as every other item on the board's agenda.

This is not about dumbing content down. It is about choosing the right abstraction layer for the audience. An engineering team needs to know which CVE is unpatched. A board needs to know what that unpatched CVE is worth in exposure, how that exposure compares to last quarter, and what it would cost to close it. Reporting that only speaks in the first register forces every director to do their own mental translation in real time, and most will not, which means the real message never lands.

Cadence matters as much as vocabulary. A CISO who only appears quarterly is asking the board to absorb three months of change in one sitting, which pushes every briefing toward summary and away from judgment because there simply is not time to do both. A short standing item at every board meeting, even five minutes, paired with a deeper quarterly session, gives directors continuity, so the deeper session can spend its time on what changed and why, instead of re-establishing baseline context every quarter from scratch.

A worked example

A CISO I advised was preparing for a board presentation after a moderately serious incident, a phishing campaign that had compromised several employee accounts but had been contained before any data left the environment. His draft deck opened with a timeline of the attack, a list of affected systems, and a description of the containment steps, fourteen slides of technical narrative before a single business consequence appeared. We rebuilt the deck to open with three numbers, the estimated dollar exposure if the campaign had not been caught in time, the actual cost of the response, and the change in projected annual loss exposure the incident triggered given what it revealed about email security gaps. The technical detail moved to an appendix, available on request. The presentation ran twelve minutes instead of thirty, and for the first time, board members asked forward-looking questions, about budget for the fix rather than about what had already happened. The content did not get simpler. The order and the units changed, and that changed which part of the board's brain the presentation reached.

The strongest case against reformatting for the board

The real objection to all of this is that translating risk into financial terms can smuggle in false precision. Cyber risk quantification models rest on assumptions, probability estimates, loss distributions, that are far less certain than the clean dollar figure on the slide makes them look, and a board that gets comfortable with a single number may stop asking about the uncertainty behind it. A CISO who reports "$4.2 million in annual loss exposure" risks the board treating that as a fact rather than a modeled estimate, which is arguably worse than a board that knows it does not fully understand the technical picture and asks more questions as a result. This is a fair criticism, and the discipline it demands is real, every quantified figure needs an explicit range and a one-line explanation of what could move it, not a bare number presented as precise. But the alternative, staying in purely technical language because financial language risks false confidence, has already been tested. It produced the 47 percent satisfaction number on articulating threat impact. Some loss of precision in service of being understood is a better trade than perfect technical accuracy that nobody in the room can act on.

Monday questions for leadership and the board

Does our board reporting open with financial and operational impact, or does it open with technical narrative that makes directors do their own translation. When we quantify risk in dollar terms, do we show the range and the assumptions behind it, or just the number. Is the CISO presenting to the full board, or only to a committee that then has to relay the message secondhand. How much airtime does security actually get on the board agenda, and does that match how much of the company's risk it represents. When a director asks a forward-looking question, does the CISO have room in the format to answer it, or is the meeting already over.

A board that cannot say what its cyber risk is worth in dollars is not being under-informed. It is being informed in the wrong language, and no amount of additional detail fixes a translation problem.