The Board’s Blind Spot: Why Cyber Risk Is a Governance Failure, Not a Technology Problem

I have sat through enough board meetings to know how cybersecurity typically gets discussed. It surfaces once a quarter, usually sandwiched between the audit update and lunch. The CTO or CIO gives a briefing. There are a few acronyms. Someone asks whether we are "covered." The room nods. Everyone moves on.
Then a breach happens. And the first question from the chair is always the same: "Why didn’t we know?"
The honest answer, more often than not, is that the board never asked the right questions in the first place.
This is the first instalment of our Leadership and Cyber Governance series. It looks at why the boardroom, not the security operations centre, is where most organisations’ cyber resilience actually breaks down.
Board Oversight Is Shrinking. The Threat Landscape Is Not.
DSIT’s 2025 Cyber Security Breaches Survey tells a remarkable story. Only 27% of UK businesses now have a board member with explicit responsibility for cybersecurity. In 2021, that figure was 38%. Board ownership of cyber risk is declining at precisely the point when breach costs, regulatory penalties, and threat complexity are all moving sharply in the opposite direction.
Among larger organisations, the picture looks better on paper. But even there, "involvement" mostly amounts to passive oversight with no real accountability attached. Having a name next to the word "cyber" on an org chart does not mean you have a director who knows what a ransomware recovery looks like in practice, or what NIS2 actually requires of them as an individual.
The Conversation Happening Too Rarely, in the Wrong Language
Secureworks published research last year showing that only 69% of board members feel aligned with their CISO on risk posture. That means nearly a third of boards are operating with a fundamentally different understanding of their own exposure than the person responsible for managing it.
Part of the problem is frequency. The World Economic Forum found that only 60% of CISOs discuss their organisation’s security posture with the board three to four times a year. The rest engage less often than that. If you are briefing the board on cyber risk less frequently than you review the P&L, something has gone structurally wrong.
But the bigger issue is language. I have watched CISOs present to boards using terminology that means everything to them and nothing to the room. Most security leaders are technically excellent. Very few have ever been coached to talk about threat exposure the way a finance director talks about margin erosion, or to pitch a security investment as if it were a capital allocation decision competing for the same pot. That gap in translation is where governance falls apart. The board switches off because the briefing does not feel relevant to their commercial responsibilities. The CISO stops pushing because no one at the table seems to want the detail.
Everyone walks away thinking the other side has it handled. Nobody does.
Where the CISO Reports Tells You Everything
Heidrick and Struggles’ 2025 global survey captured a genuine structural shift. In 2024, 48% of CISOs reported to a CIO or CTO. By 2025, that had dropped to 30%, with 42% now reporting directly to the CEO. That is a threefold increase in a single year.
Three in five CISOs now present to the full board. Four in five present to at least a sub committee.
This matters more than most boards appreciate. Where the CISO sits in the hierarchy is not an HR question. It is a question of how fast a material threat reaches the people who can act on it. When a CISO reports through two or three layers before reaching the board, every escalation gets filtered, softened, or quietly deprioritised by someone who may not grasp what is at stake. I have seen it happen repeatedly. The organisations with the slowest incident response, the thinnest security budgets, and the widest disconnect between stated risk appetite and operational reality almost always share the same structural flaw: the security leader is too far removed from the decision makers.
The Numbers the Board Cannot Afford to Ignore
IBM’s 2025 Cost of a Data Breach report put the global average at $4.88 million per breach in 2024. The highest figure recorded since the pandemic. In the UK, DSIT estimates that a significant breach costs an organisation roughly £195,000 on average, and across the economy, the aggregate runs to approximately £14.7 billion a year.
What rarely makes it into the board pack is the market reaction. Research published this year in Information Systems Frontiers found that listed companies shed an average of $309 million in market capitalisation on the day a breach goes public. The share price does not drop because the firewall failed. It drops because investors read the disclosure and conclude the board was not paying attention.
On the other side of that equation, Gartner’s research shows that organisations running Continuous Threat Exposure Management programmes can reduce breaches by two thirds by 2026. Those programmes require board level sponsorship to work. The commercial return from getting governance right is considerable. But it will not happen while cyber sits as a standing agenda item that everyone politely endures.

The Regulatory Ground Has Moved Beneath the Board’s Feet
If the commercial case were not sufficient, the regulatory environment has removed any remaining ambiguity.
NIS2, effective across the European Union since October 2024, embeds personal liability for every management body member of essential and important entities. Fines reach 10 million EUR or 2% of global turnover for essential entities. 7 million EUR or 1.4% for important entities. Sanctions include public censure, suspension, and disqualification by name. Board responsibilities under NIS2 cannot be delegated to committees or external advisors. Sign off responsibility sits with the management body individually.
DORA took effect in January 2025 across twenty categories of EU financial entity. It requires boards to approve ICT risk management frameworks, receive regular updates on incidents, complete cyber training, and accept personal accountability for operational resilience.
In the UK, DSIT and the NCSC published the Cyber Governance Code of Practice in April 2025. It is voluntary for now, covering five pillars: risk management, strategy, people, incident planning, and assurance. But DSIT has been explicit that if voluntary adoption proves insufficient, mandatory mechanisms will follow. The Cyber Security and Resilience Bill is already widening the scope of regulated entities.
The FCA, for its part, now treats cyber resilience as equivalent to financial risk for regulated firms. Boards must be able to demonstrate active, evidenced oversight.
The direction is the same everywhere you look. Personal accountability at board level is no longer aspirational. It is becoming the regulatory floor.
What the Boards Getting This Right Actually Do
Having worked with organisations at different stages of governance maturity, the pattern among the strongest boards is surprisingly similar.
They have brought the CISO into direct contact with the CEO or the board itself, removing layers that dilute urgency. They receive substantive cyber briefings at least quarterly, with clear escalation protocols for anything material in between. They have either appointed a director with genuine cybersecurity expertise or invested in structured training so that the existing board can engage meaningfully with the risk.
PwC’s research shows that 51% of Fortune 100 boards now assign cyber oversight to a dedicated audit or technology committee. Gartner expects 70% of boards to include at least one cybersecurity expert member by 2026. The majority are not there yet.
The returns are tangible. 57% of organisations with mature cyber investment cite customer trust as a primary commercial outcome. 49% cite brand integrity. McKinsey’s analysis of industrial boards frames this directly: the differentiating factor is not the quality of oversight alone, but the willingness to make strategic investment decisions from the top.
The Choice in Front of Every Board
The boards treating cyber governance with real rigour are spending less on breaches, standing on firmer ground with regulators, and holding up better when markets get nervous. Those that are not will find themselves exposed to personal liability under NIS2 and DORA, escalating financial penalties, and the kind of reputational fallout that no amount of crisis communications can repair once a breach goes public.
Whether the board should own cyber risk is no longer up for discussion. Regulation has closed that question. What remains open is whether your board is governing it with the competence, the investment, and the seriousness the environment now demands.
At Garzon Cyber Solutions, we work with boards and senior leadership teams to close the gap between cyber exposure and governance capability. From CISO advisory and board level risk translation to compliance readiness across NIS2, DORA, and the UK Cyber Governance Code, we provide the strategic intelligence that moves cybersecurity from a technology line item to a board level priority.
Cyber risk is a governance problem. The board is where it gets solved.
Sources: DSIT & NCSC, Cyber Security Breaches Survey 2025 · DSIT & NCSC, Cyber Governance Code of Practice 2025 · IBM, Cost of a Data Breach Report 2025 · WEF, Global Cybersecurity Outlook 2025 · Secureworks, Boardroom Cybersecurity Report 2024 · Heidrick & Struggles, Global CISO Compensation Survey 2025 · Gartner, Top Cybersecurity Predictions 2024 · PwC, Annual Corporate Directors Survey 2024 · McKinsey, Boards as the Final Cybersecurity Defence · DLA Piper, NIS2 Directors Personal Liability 2024 · Springer Nature, Stock Market Response to Cyber Attacks 2025 · Garzon Cyber Solutions, Governance Advisory Intelligence, 2026
Where does this sit on your own risk register?
A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.
Start the Conversation →