Cybersecurity Board Reporting: How to Make the Board Actually Want Your Update

From the Cybersecurity Ecosystem Show conversation with Christopher Hetner, Chief Cyber Advisor at World Wide Technology

Watch on: Spotify, Apple, YouTube

Here is the math that should worry every security leader. In many companies, the CISO gets a 20 minute briefing with the audit committee once a year. Meanwhile, the reconnaissance phase of an attack, which used to give defenders three or four months of runway, has been compressed by AI to minutes.

Christopher Hetner has spent the last seven years on the boardroom side of that gap. He serves as Cyber Risk Advisor to the National Association of Corporate Directors, a community of roughly 25,000 members, and chairs the AI and Cyber Insights Council for the NASDAQ Center for Board Excellence. Behind that sits close to 30 years in cyber and technology: building data centers in New York City in the nineties, serving as global CISO at GE Capital, and spending four years at the Securities and Exchange Commission as senior policy advisor to two SEC chairs. Today he is Chief Cyber Advisor at World Wide Technology, and he estimates 60 percent of his time goes to advising corporate directors, CEOs, and general counsel.

On this episode of the Cybersecurity Ecosystem Show, he laid out what actually works in the boardroom: why most cyber reporting fails the people it is meant for, how to build an enterprise risk structure when no regulator is forcing you to, and a risk quantification approach that board members describe in the words every CISO wants to hear: "It's a language that we understand."

Why do boards still struggle with cybersecurity?

Not because they are not smart. Chris is direct about this: the directors in his community are former CFOs, general counsels, and CEOs who ran multi-billion dollar companies. The problem is translation, not talent.

"They're acclimated and adjusted more towards a business lens," he said. "They're not necessarily into the zeros and ones and the bits and bytes in cyber."

By his estimate, based on recent NACD surveys and his work with the NASDAQ Center for Board Excellence, roughly 70 percent of board members are still not in tune with how current threats, AI, and now post-quantum computing can materially impact their business. And the exposure is not abstract. Ransomware, business interruption, and loss of intellectual property land on the balance sheet in real dollars, whatever the currency.

His fix is a governance principle worth writing down: visibility for the entire board, not a designated tech director. Having one or two directors with a technology background is great, and he encourages it. But proper governance means the whole board is engaged on the topic, because the whole board has to pull the levers that manage the risk.

"It shouldn't be pigeonholed to a specific individual," he said.

The deeper issue is that most companies are still governing this risk the way they did when threats moved slowly. "We're still operating in a modality in terms of governing and managing this risk based on the threats we've seen 20 years ago," he said. "When I was a CISO, the reconnaissance period would take like three or four months. Now with AI, that's being compressed to minutes."

What happens when the CISO operates on an island

Ask Chris what the before picture looks like, and the word that keeps coming up is isolation. Limited touch points with the board. A once-a-year audit committee slot, or quarterly in the highly regulated world. And no structural connection to the rest of the business.

The costs of that isolation are concrete. His go-to example is M&A. Say the company plans to grow 20 percent year over year, and the growth strategy is acquisition. If the CISO has no visibility into that deal activity, the security picture becomes distributed and unmanageable. "You acquire an asset that's been compromised, and it's integrated into your network," he said. The program is reactive by construction, when the whole point is to get, in his phrase, left of boom.

The second cost is wasted money, and this is the part worth reading twice if you own a budget.

"You can spend hundreds of millions of dollars on cybersecurity, but without that layer, the CISO tends to operate in their own island and has very limited visibility in terms of the contours of the business," he said. His team's analytics work with boards, particularly around loss ratios, keeps surfacing the same finding: inflated budgets, and capital that could be reallocated to the risks that actually matter to the business.

Money does not equal protection. "You could be sitting on hundreds of millions of dollars and still an unprotected enterprise."

How do you build enterprise risk management without a regulator forcing you?

Chris built this structure repeatedly in financial services, where the regulatory mandate left no choice. His advice for everyone else is to build it anyway, and he gave a usable starting sequence.

First, identify the pillars of the business and put their owners in the room. Who runs M&A? Finance? Is there a chief risk officer? Who owns HR, legal, compliance? Those people form the enterprise risk management committee.

Second, define it through a well-documented charter: roles, responsibilities, meeting frequency, and which top risks are being identified.

Third, create a risk register that reflects what actually matters to your company. A healthcare organization holding large volumes of personal health data will put privacy at the top. A manufacturer will put operational uptime there, which means the people responsible for the factory floors belong in the discussion.

Fourth, align it to a framework. Chris points to COSO, which defines enterprise risk management and has a plugin for cybersecurity.

The payoff is that budget conversations change shape. Once the CISO can see the contours of the business, the top threats stop being generic. Business interruption has a known daily cost. The privacy team knows which data carries material fines. Finance moves tens of millions of dollars a day, so wire transfer fraud is critical. Now the cybersecurity budget aligns to true enterprise risk instead of to a tool wishlist.

And it changes who stands in front of the board. "It shouldn't be the CISO in isolation reporting to the board," Chris said. "It should be the CISO in tandem with heads of business, in tandem with the CFO, with the chief risk officer, so that this is represented as more of a broader view versus a tech issue."

How do you quantify cyber risk in a way boards trust?

This is where Chris's approach gets specific, and it starts from an argument about authority. Who gets to say what a risk is worth?

"The ultimate arbiter for any type of risk domain, whether it be your hurricane risk or flood risk or a fire, is the insurance markets," he said. He spent about three years working with some of the largest brokers and carriers in New York evaluating methods for sizing enterprise exposure, and he has engaged with Lloyd's and leaders across the brokering and carrier space.

The approach the NACD selected for its members is annual loss expectancy analysis, built on actuarial data and a large base of industry benchmarks, and made specific to your peer group. That specificity matters because context changes everything. Big pharma looks different from a hospital. An insurer looks different from a capital markets firm running a trading platform. Manufacturing's biggest exposure is business interruption. Banking's may be loss of personal and account data. A trading platform moving millions a day in equities cares most about availability and integrity.

The losses get expressed in the same distinct categories the insurance markets use: wire transfer fraud, business interruption, ransomware, loss of intellectual property, and now supply chain and AI risk.

From there, the model layers in your maturity. Chris is agnostic on frameworks; NIST, ISO, or MITRE all work as the measure of your capability to manage the risk. What comes out the other side is residual exposure, a number the board can do something with. Say it is 200 million dollars in unaddressed cyber risk, concentrated in ransomware, intellectual property theft, and business interruption because the company lacks immutable backups.

The step most models skip: telling you where to spend

Chris draws the line between his approach and traditional quantification models here.

"Traditional models like FAIR and all these other concepts projected potential loss, but we go a step further," he said. "We actually substantiate that loss based on your specific industry group and based on dynamics of the company. But we also help to inform, based on your exposure, here's where you should deploy capital."

Improve MFA. Expand endpoint detection. Deploy immutable backups across the systems that carry the business interruption exposure. Then trend it over time, and the company should watch the exposure come down. Sometimes it goes the other way: a zero day lands, or the business expands into regions with geopolitical exposure, and risk rises. That is not a failure of the model. That is a decision point, expressed in terms a board, a CFO, and an enterprise risk committee can act on.

Because that is the board's actual job here: deciding how much risk to accept, how much to transfer through insurance or other vehicles, and where to deploy the capital against what remains. Repeat month over month, quarter over quarter.

If you run a security program at a bank or credit union, this should sound familiar. It is the same philosophy Rivial's platform is built on: cyber risk quantified in dollars, tied to the systems that carry it, and rolled up into board reporting the audit committee can read without a translator. The insurance markets priced the risk long before the heat map did.

What changes when the board gets dollars instead of heat maps

The testimonial Chris hears from board members is the one that matters: "It's a language that we understand. I don't have to be fearful that I don't understand what's being reported."

Engagement spreads across the entire board instead of pooling with the one technical director. And capital allocation gets cleaner. Chris described a frustration every audit committee member will recognize: the CISO asked for 20 million dollars last quarter, now needs another 10, and nobody can say where the capital is going. Aligning budget to quantified business risk answers that question before it is asked.

His larger ambition is standardization, and his analogy lands. "If you sit on three publicly traded boards, you probably have three different cyber risk metrics," he said. Compare that to reading a financial statement, where GAAP means profit and loss look the same everywhere. "We need a very similar approach to reporting on cyber threats, including now with AI."

One more shift he sees coming: frequency. With AI platforms running exploitation at machine speed, the annual update is a relic. "If I'm just waiting for my annual update from the CISO, those days are over."

Why hasn't cyber risk quantification caught on everywhere?

Taylor put the uncomfortable stat on the table: adoption of cyber risk quantification remains low across the industry. Chris's answer had less to do with the models and more to do with the people presenting them.

"The CISO community are very tactical," he said. "They're getting thrusted into the boardroom from the data centers. They're getting thrusted into the boardroom from the engineering team, without having a deep understanding of the business, without having the relationships."

Under pressure, the tactical CISO defaults to the metrics they are most comfortable with: patching, penetration testing, mean time to detect and respond, phishing rates. Chris is careful not to dismiss them. "All important metrics, but they belong in the SOC and the security operations center and data center."

The fix he is working toward, through the NACD, the Cyber Future Foundation where he advises, and World Wide Technology's technology executive board programs, is professionalization of the CISO community: the discipline and structure that gives security leadership connective tissue with enterprise risk and the board. When a board lacks the expertise internally, outside help exists; Chris himself is pulled into roughly a dozen boards a year to sit as the interpretive layer between the CISO's metrics and the directors' questions.

There is also a plain culture component that no model replaces: tone from the top. A CEO who runs webinars and town halls on security hygiene moves the needle. A CEO transacting business on personal email teaches the opposite lesson, no matter what the awareness training says.

What should CISOs tell the board about AI and post-quantum?

Chris says the AI conversation with boards has two sides, and both belong in your reporting.

On the adoption side, his framing is the most quotable line of the episode: "These agents are no different than employees. Replace human with agents: as human error, we're going to have agent error." Human in the loop is table stakes, but the way to manage agents at scale is agentic monitoring, agents watching agents. Boards adopting AI to automate processes need to hear that the workforce they are adding requires supervision like any other.

On the defense side, AI is compressing both directions of the fight. Adversaries execute attacks faster. But a threat assessment report that took an analyst six to eight hours to produce and socialize ten years ago can now be done in minutes. The question for the board is whether your program is capturing that advantage or ceding it.

Post-quantum computing got the bluntest treatment of the episode. Q-day is on its way, and Chris works with leaders from the NSA and the cryptography community on pushing readiness out to critical infrastructure: banks, telecom, power.

"PQC is going to kind of flip everything on its head," he said. The work is a full survey of your encryption: which assets matter most, what encryption is embedded in your organization and its supply chain, and what your ability to swap it out looks like. "These are not trivial tasks, and these are going to cost companies hundreds of millions of dollars to pursue."

His timeline advice fits in three words: "I would start now."

Report risk in the board's language

Everything in this conversation converges on one discipline: expressing cyber exposure in the currency the board already governs in. If your board report still leads with patch counts and a red-yellow-green matrix, the Rivial platform does what Chris described, quantifying risk in dollars by category and generating board reports that read like the rest of the board book. And for a concrete picture of what belongs in the deck, read our guide to the 6-metric cybersecurity dashboard that gets board buy-in.

Then listen to the full conversation with Chris. Three decades that run from New York data centers to GE Capital's global CISO seat to advising both chairs of the SEC is a rare vantage point, and he is generous with it. You can connect with him on LinkedIn.

Here are the key takeaways from this blog:

  • The gap is speed: attack reconnaissance has compressed from months to minutes while many boards still get a 20 minute cyber briefing once a year, and roughly 70 percent of directors are not in tune with how these threats hit the business.

  • Isolation wastes money: without an enterprise risk layer, the CISO operates on an island, budgets inflate, and a company can spend hundreds of millions and remain unprotected.

  • Build the structure before a regulator makes you: an ERM committee of business pillar owners, a documented charter, a risk register ranked by what the business actually depends on, and a framework like COSO.

  • Price risk the way insurers do: annual loss expectancy analysis against your peer group, expressed in the insurance markets' categories, then netted against your maturity to produce residual exposure in dollars.

  • Go past quantification to allocation: the differentiator is telling the board where to deploy capital, then trending exposure down quarter over quarter.

  • Professionalize the presenter: operational metrics belong in the SOC, and the CISO who reports in tandem with the CFO and heads of business gets engagement instead of glazed eyes.

  • Get ahead of AI and PQC: treat agents like employees who need supervision, expect agentic-to-agentic monitoring, and start post-quantum readiness now, because the encryption survey alone is a massive lift.

Tags: Board Reporting, Cyber Risk Quantification, Enterprise Risk Management, AI, Podcast

The Cybersecurity Ecosystem Show connects practitioners, investors, vendors, regulators, and everyone in between. New episodes drop weekly. Subscribe so you don't miss one.

Reply

or to participate.