Skip to content

15 August, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • disclosure

      Cyber resilience is a test of leadership

      Cyber threat is moving fast, and boards need to step up now in order to...

      climate litigation

      Why climate transition is a governance imperative

      The ‘just transition’ to a sustainable, resilient economy means navigating systemic change fairly and successfully.

      board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

  • Comment
      • View all
    • climate litigation

      Why climate transition is a governance imperative

      The ‘just transition’ to a sustainable, resilient economy means navigating systemic change fairly and successfully.

      create value

      4 ways to help your CFO create value

      The chief financial officer has a vital contribution to make to the board’s strategy on...

      leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

      female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • FRC Annual Review of Audit Quality 2026

      This Financial Reporting Council report uses findings from its supervisory activities to assess audit quality...

      Governance Guide: How Boards Drive Growth

      This Board Agenda Governance Guide investigates how directors can evolve to drive performance and growth...

      Organizational Transformation in the Age of AI

      This World Economic Forum paper looks at how organisations must re-architect their workflows and operating...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

5 questions to ask chief information security officers

by Federico Charosky

Board involvement helps to not only defend an organisation from cybersecurity threats, but also strengthen its resilience.

information security

Image: YuganovKonstantin/Shutterstock.com

Favorite

For a long time, the chief information security officer (CISO) has had a hard time. Being singly responsible and accountable for the security of an entire organisation, across its geographical and virtual footprint, day and night, is a huge burden.

To achieve this during a time of increasingly frequent and ever more sophisticated cyber-attacks, while skills are in high demand and low supply, and while keeping within budget, is a tough job for even the most experienced industry professionals.

Unfortunately, when a company is breached, the stress of the moment often means finger-pointing can start immediately, with the CISO getting the lion’s share of the blame. It’s perhaps no surprise that the average time a CISO spends in the role is about two and half years.

A CISO simply cannot control everybody’s actions. Nobody should be blamed for innocently clicking on a malicious link in an email or other message. If the entire security posture of an organisation is dependent on someone not clicking a link, there are fundamental problems.

Yet, there are, of course, more serious issues in cybersecurity today than malicious links. For instance, due to ‘Citrix Bleed’—a vulnerability coming to light in October that has affected single-sign-on access across many organisations worldwide—we’ve seen disruptions to water utility companies, the bond market and financial transactions; it’s even meant ambulance services have been diverted from hospitals.

Not ‘if’, but ‘when’…

After several years of cyber incidents hitting the mainstream media headlines, and better education from security agencies such as the UK’s National Cyber Security Centre (NCSC), more senior decision-makers, company directors and board members are realising that it’s not ‘if’, but ‘when’ their organisation will be compromised.

But there remains a strong atmosphere of blame today. Although there are a lot of actions that organisations can proactively take to strengthen their cybersecurity posture, it’s really nobody’s fault if they are breached.

If it were a country, cybercrime would have the third largest economy after the US and China.

Cybercriminals have been working hard at their dark craft for years and they are extremely good at it. They do it full time, often in teams of people with different but complementary skills; they excel in one niche area of cybercrime and buy other services from specialist vendors. It’s now a well-oiled machine that’s forecast to cost the economy a staggering US$10.5tn a year by 2025 (meaning, if it were a country, cybercrime would have the third-largest economy after the US and China).

CISOs certainly have their work cut out, but they can’t guarantee the protection of the organisation on their own. (And no longer should cybersecurity fall to the responsibility of IT teams, who have enough to do, and don’t always have the right training or know-how to protect a company’s technology in addition to managing it.)

What can the board do?

So how can the board support a CISO to enable them to strengthen resilience organisation-wide? How can a CISO lean on the board without worrying about their own job security every time they read about another ransomware attack in the press?

Today, cybersecurity moves too fast and is too complex to sit with the CISO or IT department alone. It’s a subject that demands board-level attention and engagement and, ideally, someone on the board—or someone who advises the board—who understands the current threats, how to manage them and how to balance the financial and reputational costs of a cyber-attack with their own investment in cybersecurity.

At Quorum Cyber, we provide all this with our ARQCUS programme, advising and guiding company boards throughout the year.

Technical teams and non-technical senior managers and directors often speak two different languages.

Perhaps the first thing that needs to be addressed is the language of cybersecurity. Technical teams and non-technical senior managers and directors often speak two different languages. This is a big problem for both sides as CISOs try to articulate the benefits of a risk-based security strategy and request adequate funding, and board members attempt to understand the issues, prioritise resources and make informed decisions against other major concerns such as skills shortages, supply chain issues and investment in new technology.

Five fundamental questions

There are five key questions boards can ask CISOs in order to better support them:

1. How do they measure the maturity of the information and cybersecurity in the organisation? It should align to the UK’s NCSC Cyber Assessment Framework (CAF) or the US National Institute of Standards and Technology (NIST). And it’s best to focus on unifying language, not scoring themselves against each scale.

2. Have they tried to implement any controls for a while but are struggling to justify the budget? Then relate this to the maturity assessment for the area affected by the lack of control. At this stage, it might help to bring in a specialist external cybersecurity company to assess the organisation’s security posture and maturity.

3. Can they show statistics on cybersecurity incidents and cyber-attacks on the organisations? All organisations are under a near-constant attack from automated tools, and many from targeted or manual attacks. The CISO should be able to show how they are defending the organisation and learning how to do it better and more efficiently.

4. Would they benefit from a business-focused stakeholder? If yes, they could be assigned a business mentor from the board. This is to ensure that the CISO doesn’t merely try to defend the organisation but enables it to thrive.

5. Are they using the investment they’ve already made in products, services, and licences wisely and to the maximum extent? Many organisations only use a fraction of these.

It would also be valuable to allow the CISO to provide quarterly presentations to the board about security initiatives, risks and achievements.

Backed by the board, CISOs can achieve a whole lot more for the business, including setting out a security roadmap, embedding a security culture and mindset, building security into any new IT projects, ensuring resources are best used, and, over time, reducing the total cost of ownership. When boards and CISOs work together they can significantly improve any organisation’s resilience and liberate it to achieve its goals – whatever threats loom over the horizon.

Federico Charosky is chief executive officer of IT security specialists Quorum Cyber

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Cyber criminals chase ransomware insurance money
    April 18, 2023
    ransomware insurance

    Specialist ransomware criminals are investigating victims’ insurance capacity—sometimes by blatantly asking companies outright.

  • Are you serious about cybersecurity?
    October 3, 2023
    cybersecurity chatbot

    Artificial intelligence chatbot hackers are just the latest in a long list of cyber threats, which are not going away any time soon.

  • Technology, cyber risk and ESG top list of business leaders' concerns
    June 8, 2022
    Digital code on skycrapers

    Mazars survey reveals 82% of executives plan to increase investment in IT systems, while 75% plan to boost spending on sustainability.

  • Are cyber disclosure demands too high?
    August 15, 2022
    cyber disclosure

    Organisations increasingly struggle with cybersecurity as they balance fear of reputational damage against cyber disclosure requirements.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy