Site navigation

NCSC Guide: How To Bridge Cyber With The Boardroom

Graham Turner

,

Cybersecurity board
New guidance from the NCSC seeks to help cybersecurity leaders communicate cyber-risks effectively with Boards.

Cybersecurity is a critical risk for boards and executive teams, with cyber-leaders (such as CISOs) playing a crucial role in describing and mitigating the risks.

Doing this effectively, however, isn’t always easy. New guidance from the NCSC seeks to help those leaders to communicate effectively with Boards, and to better engage with their members.

It’s important to remember that Boards ultimately want you to be successful in defending the organisation against cybersecurity threats.

When the Board is behind your efforts, cybersecurity can be recognised as a positive thing that helps your organisation’s digital activity to flourish, and not just seen as a necessary evil or cost-centre.

The NCSC guidance stresses that most Board members do not have in-depth cyber security knowledge. That’s not their role. Cybersecurity leaders, on the other hand, do have detailed knowledge of the domain, but maybe less experience in communicating with Board or senior executive teams. As a cyber-professional, the NCSC state that it is part of your job to bridge this gap to provide better cybersecurity outcomes.

Cybersecurity is a strategic issue, which means you must engage with Boards on their terms and in their language to ensure the cyber-risk is understood, managed and mitigated.

This guidance describes how to communicate and engage more effectively with board members, to improve cybersecurity decision making within your organisation.

It will also help you to communicate with senior executives, who make recommendations to the Board and are responsible for executing the strategy. Executives will take most of the decisions relating to cybersecurity and will be answerable to the Board for those decisions.

Your CEO and CFO will likely be board members too.

Understanding Your Audience

As a cybersecurity expert, it’s easy to want to share detailed updates. However, it’s important to align your messaging with what the Board needs. Cyber security may take up 99% of your job, but it’s only a small part of the Board’s agenda.

Understanding their broader concerns and strategic goals is key. Ensure your communications are relevant to their goals and challenges, and always remember that time is limited during Board meetings.

How Boards Work

Boards are responsible for overseeing long-term strategy and governance. While most decisions are made by the executive team, the Board focuses on risk management, including cyber risks.

Cybersecurity professionals should ensure that cyber risks are evaluated and understood in terms of business impact. Building trust and demonstrating how cyber-risks affect strategy will make your contributions more valuable to the Board.

Understanding Your Board

Every Board is unique, made up of individuals with different skills and preferences. Learn how your specific Board operates – who the key members are, how often they meet, and what formats work best. This will help you tailor your communication style to be more effective.

Cyber as a Risk

Boards are familiar with risk management, so it’s essential to present cyber-risks in a way they understand. Explain cyber-risks as business risks, and use clear, simple language to outline the potential impact.

Avoid hyperbole and focus on realistic assessments of threats. Be transparent about your current position and avoid sugar-coating risks.

Engage Beyond the Boardroom

Board meetings are often short, so try to build relationships with key members outside of these formal sessions. This allows for deeper discussions and provides opportunities for Board members to ask questions they may hesitate to ask in meetings.

High-profile cyber incidents can also serve as useful opportunities to update the Board on relevant risks and mitigation strategies.

Answer Key Questions

Understand the Board’s priorities and be prepared to answer their critical questions.

These may include: What are the key risks? How are they being mitigated? What’s the status of our cybersecurity efforts? Provide concise, relevant data to support your answers, and consider using summary dashboards that align with the Board’s reporting style.

The Big Picture

Boards will likely ask broader questions to ensure that cybersecurity is aligned with the overall business strategy.

Be ready to answer questions about how cyber risks impact key objectives and how the company compares with others in its sector. Demonstrating a clear, strategic understanding of the big picture will help secure the Board’s confidence.

Strategic Engagement

Cybersecurity professionals need to elevate discussions to focus on the strategic implications of cyber-risks. This means connecting cybersecurity with the company’s broader business challenges. Presenting to senior leaders can be daunting, but focusing on the strategic relevance of cyber will help gain their trust and support.

Own the Problem

If you feel that the Board doesn’t fully grasp the cyber-risks, take responsibility for adjusting your approach. It’s your job to ensure they understand the risks and the progress being made. Work with your audience as they are, not as you wish they were.

Provide a Holistic View

From the Board’s perspective, cybersecurity should be seen as part of a cohesive risk management strategy, not in isolation. It’s your role to present a holistic view that ensures all aspects of cyber-risk are covered and that no gaps exist in your mitigation plans.

Advise, Don’t Educate

Your role is to advise the Board on cyber risks, not to educate them on the intricacies of your work. Present the information in a way that allows the Board to make informed decisions without needing to understand all the technical details. Use trusted third-party sources to back up your advice where possible.


Recommended reading


Be Prepared for Scrutiny

Boards will likely seek external validation of your assessments, especially on significant investments or critical risks. Be ready to have your work audited, just as other departments like finance or health and safety expect to be.

Effective Communication

To engage the Board, communicate clearly and concisely. Use simple language that avoids technical jargon and stick to a consistent structure. Brevity is key—use executive summaries, diagrams, and visuals to aid comprehension. Remember, it’s easier to add detail when requested than to simplify complex information later.

Final Tips

Rehearse your presentations, and don’t hesitate to partner with a Board champion who can help with content and fielding questions. Stay positive and solution-focused in your tone. Communicating the importance of cyber security effectively is crucial for securing the investment and resources needed to protect the business from emerging threats.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data