Cybersecurity has been a standing board agenda item for the better part of a decade, which is precisely the problem. The item gets checked, the deck gets presented, the board notes that it reviewed the quarterly security update, and the organization’s exposure goes largely undiscussed. Kris Boike, Head of Information Security at Dorsey & Whitney and a former chief information officer (CIO), has spent more than 25 years running cybersecurity, infrastructure, and risk programs inside Fortune 10 and Fortune 50 organizations, including the Federal Reserve System, and her read on the state of board oversight is blunt: most boards govern security the way they did ten years ago. The threats moved. The stakes climbed. The perspective in the room stayed put. That gap is not a technology failure. It is a governance failure, and it belongs to directors.
The Status Report Is Not Oversight
The default rhythm of board security oversight is retrospective. A chief information security officer (CISO) or CIO walks through what happened in the last quarter: how many incidents were logged, how many were contained, and how patching compliance trended. Directors nod. The report is filed. Nothing in that sequence tells the board whether the organization is carrying more risk than it can afford, because the report was never designed to answer that question. It was designed to demonstrate activity.
Boike’s alternative is to change what directors ask rather than what management presents. “A strong director doesn’t just review what happened last quarter,” she says. “They probe whether the security strategy fits the organization’s risk appetite, where the real exposure sits, and what leadership is choosing to accept.” The last clause carries the weight. Every security program is a series of deliberate decisions about what not to protect, what to defer, and what to live with, and those decisions are almost never surfaced in a status report. They are made quietly, inside budget cycles and roadmap trade-offs, by executives who may never have been asked to name them out loud. A director who asks what leadership is choosing to accept forces those choices into the open, where the board can either ratify them or refuse them. “Better questions surface the risks that dashboards tend to hide,” Boike says. Dashboards are built to be green. Accepted risk rarely shows up in a color.
Technology Risk Does Not Live Alone
The structural error in most boardrooms is categorical. Security is treated as a function with its own report, its own committee slot, its own vocabulary, and its own owner, which quarantines it from the enterprise risk conversation happening a few agenda items away. A board that governs technology risk in isolation is governing a fragment. The consequences of a security failure never stay inside the function: they surface as regulatory exposure, client attrition, contractual liability, delayed transactions, and reputational damage that lands on the whole organization.
“Technology risk shouldn’t live in its own silo,” Boike says. “When you show a board how security feeds the broader enterprise risk picture, you help them govern the whole organization instead of one function. That connection is where mature oversight begins.” The word mature is the one to watch. Immature oversight asks whether the security program is running well. Mature oversight asks what the security posture implies about the organization’s ability to absorb a shock, meet its obligations, and keep operating under pressure. The first question can be answered by a control owner. The second can only be answered by a board that has integrated technology risk into how it thinks about everything else. Making that connection is also, practically, the only way a board gets a defensible view of proportionality. Without it, directors have no basis for judging whether the security investment is adequate, excessive, or badly aimed, because they have nothing to measure it against.
Diversity Of Experience Is A Governance Control
Boards have a well-documented tendency to recruit in their own image, and the security seat is not exempt. The result is rooms where everyone shares a background, a set of reference points, and, critically, a set of blind spots. Adding a director who has run technology risk inside a heavily regulated institution is not a diversity gesture. It is a control, in the same sense that a second signature on a wire transfer is a control. It exists to catch what the first perspective misses.
“Boards make sharper decisions when someone offers a perspective they don’t already have,” Boike says. “Experience across highly regulated environments, transformation, and infrastructure gives directors a fuller view of what sound governance actually looks like.” Each of those three domains teaches something the others do not. Regulated environments teach what supervisors accept as evidence of control, which is usually stricter and less forgiving than internal standards. Transformation teaches where risk concentrates during change, which is where most organizations are least protected and most distracted. Infrastructure teaches the physical and architectural realities that determine whether a policy is enforceable or merely written. A director carrying all three is harder to reassure with a confident presentation, and that resistance is the point.
The through line in Boike’s argument is a shift in posture. “Move the conversation from reacting to incidents toward governing risk with intention, and the whole board gets stronger,” she says. Reactive oversight is oversight that arrives after the decision has already been made somewhere else in the organization. Intentional governance means the board sets the risk appetite before management spends against it, and then holds the strategy to that standard rather than to last quarter’s incident count. That is not a harder job than the one most boards are already doing. It is a different one, and the boards that make the switch will find they were never really overseeing security at all. They were reading about it.
Follow Kris Boike on LinkedIn for more insights on cybersecurity leadership, enterprise risk governance, and board-level security oversight.