Key Takeaways
- Only 12.5 % of security leaders feel very confident that boards truly grasp the state of the cybersecurity program after a presentation.
- More than half of boards (55 %) have never formally defined the organization’s cyber risk appetite; another 27 % do so only qualitatively.
- Preparing for board meetings is a significant operational tax: 71 % of security leaders spend 10 + hours per cycle, often involving multiple contributors to build slides, gather data, and translate technical findings into business language.
- Governance frequently relies on instinct rather than instrumentation—half of boards made no explicit risk‑acceptance, mitigation, or transfer decision in the past year, and many CISOs lack private executive‑session access or predefined escalation thresholds.
- Trust can be rebuilt without waiting for a breach; 53 % of leaders reported increased board confidence after a material security incident, suggesting that shared, concrete experiences drive alignment.
- The report offers five evidence‑based practices from high‑trust CISOs to close the communication gap and establish a clear, agreed‑upon risk baseline.
Executive Summary
Pulse Security AI’s new research, The CISO‑Board Communication Gap, reveals a persistent disconnect between how security leaders present cyber risk and how boards interpret it. Drawing on survey data, in‑depth interviews, and workshops with senior practitioners, the study quantifies the confidence gap, highlights the absence of a formal risk‑appetite baseline, and measures the operational burden placed on security teams to prepare board updates. The findings underscore that improving communication alone is insufficient; boards must first establish a clear, agreed‑upon risk framework, and security leaders need better tools and governance structures to deliver consistent, business‑focused insights.
The Confidence Gap Is Measurable
Only 12.5 % of security leaders report being “very confident” that their board walks away with an accurate understanding of the cybersecurity program after a presentation. Another 41 % feel “somewhat confident,” while 38 % remain neutral or mixed. This measurable lack of confidence indicates that, despite regular reporting, boards often leave meetings with an incomplete or distorted view of risk. The gap persists across quarters, creating a cycle where security leaders repeatedly invest effort in presentations that fail to shift board perception in a meaningful way.
The Baseline Was Never Set
A striking 55 % of boards have never formally defined the company’s cyber risk appetite, and an additional 27 % define it only in vague, qualitative terms. Without an explicit baseline, boards tend to fill the void with external noise: roughly 70 % of security leaders say board members bring third‑party ratings, press coverage, or media headlines into discussions, and 42 % have had to defend a commercial security score within the last year. The absence of a quantifiable risk appetite undermines the ability to measure progress, prioritize investments, or hold the security function accountable.
Board Prep Is an Operational Tax
Preparing for each board cycle consumes substantial time and resources. Seventy‑one percent of security leaders spend ten or more hours—equivalent to one to two full working days—on preparation each quarter. Thirty‑nine percent involve four or more contributors per presentation. The primary time sinks include building slide decks, aggregating data from disparate security tools, and translating technical findings into language that resonates with business executives. This operational burden diverts focus from proactive security improvements and contributes to burnout among security teams.
Governance Runs on Instinct, Not Instrumentation
Half of the boards surveyed made no explicit decision to accept, mitigate, or transfer cyber risk in the past year. Moreover, 48 % of security leaders lack private executive‑session access, 23 % have no predefined threshold for board‑level escalation, and 33 % say their own legal exposure influences what they choose to disclose. These findings indicate that board oversight of cyber risk often relies on gut feeling or ad‑hoc judgments rather than structured, data‑driven processes. The lack of formal governance mechanisms hampers consistent risk management and limits the board’s ability to exercise fiduciary duty effectively.
Trust Is Recoverable, and a Breach Shouldn’t Be the Trigger
Interestingly, 53 % of security leaders observed an increase in board trust following a material security incident. A real‑world event forces a shared, concrete understanding of risk that quarterly updates rarely achieve. The report suggests that trust can be cultivated proactively by adopting practices used by high‑trust CISOs: establishing a clear risk‑appetite framework, delivering consistent metrics tied to business outcomes, scheduling regular private briefings, defining escalation thresholds, and leveraging incident‑driven learning sessions to align board and security perspectives without waiting for a crisis.
Recommendations and Practices for Alignment
Based on interviews with leaders who enjoy strong board confidence, the report outlines five actionable practices:
- Formalize Cyber Risk Appetite – Work with the board to define quantitative risk tolerance levels (e.g., acceptable loss thresholds, likelihood scales).
- Standardize Reporting Metrics – Adopt a small set of business‑oriented key risk indicators (KRIs) that are updated automatically and presented in a consistent format.
- Institutionalize Private Briefings – Secure regular, confidential executive‑session time to discuss sensitive findings without the pressure of public scrutiny.
- Define Clear Escalation Triggers – Establish predefined thresholds (e.g., severity scores, regulatory impacts) that automatically prompt board notification.
- Leverage Post‑Incident Reviews – Use lessons learned from security events as structured learning opportunities for the board, turning crises into trust‑building moments.
Implementing these practices can shift board discussions from reactive, perception‑based debates to proactive, risk‑managed decision‑making.
Methodology Overview
The insights stem from a mixed‑methods approach: a 42‑respondent survey of security leaders and corporate directors, more than 20 in‑depth interviews with sitting and former CISOs, and two moderated workshops involving roughly 22 CISOs. Seventy percent of survey participants hold CISO or head‑of‑security roles, with representation across technology/software (34 %), financial services (25 %), healthcare/life sciences (9 %), and manufacturing (9 %). While the sample is not nationally representative, its depth and seniority—drawn from individuals who regularly sit in audit‑committee meetings—provide valuable directional insights. Percentages are calculated per question, and the small director sub‑sample is treated as indicative only. All quotes have been anonymized per participant request.
About Pulse Security AI
Pulse Security AI is redefining how cybersecurity programs are operated. The platform combines security professionals with AI agents to execute procedures, capture decisions, and deliver real‑time program visibility without the manual overhead traditionally associated with security management. By providing an operational layer that integrates data from disparate tools, Pulse enables security leaders to run faster, reduce costs, and maintain clear confidence in the state of their programs. The solution aims to close the gap between technical security activities and board‑level risk oversight.
Contact
Carmen Angela Harris
Pulse Security
[email protected]
Join our LinkedIn group Information Security Community!
For the full report, visit:
The CISO‑Board Communication Gap

