Black Hat 2026: Improving CISO to Board Cyber Risk Reporting 

A Pulse Security report finds that effective board cyber risk reporting depends more on governance than presentations.

Written By
Ken Underhill
Ken Underhill
Aug 4, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Cybersecurity has become a standing agenda item in boardrooms, yet many chief information security officers (CISOs) still struggle to communicate cyber risk in a way that enables informed business decisions. 

According to Pulse Security’s The CISO-Board Communication Gap report, released during Black Hat 2026, the challenge is not simply improving presentations. 

Instead, the research suggests that unclear governance, undefined risk appetite, and fragmented reporting processes create structural barriers that prevent boards from fully understanding organizational cyber risk.

Key takeaways of the CISO report

  • More than half of organizations have not formally defined their cyber risk appetite.
  • Effective board communication depends more on governance than presentation skills.
  • Most CISOs spend over 10 hours preparing each board cyber risk report.
  • Boards need business-focused cyber risk reporting supported by clear governance and defined risk thresholds.
  • Automating reporting and establishing structured board engagement can improve cybersecurity oversight.

Undefined risk appetite creates a communication problem

The report is based on a 42-respondent survey, more than 20 in-depth interviews, two moderated workshops, and insights from over 80 senior security practitioners. 

While the findings are not intended to be statistically representative, they reflect the experiences of executives who regularly participate in board and audit committee meetings.

One of the report’s most significant findings is that 55% of organizations have not formally defined their cyber risk appetite. 

Without agreed-upon thresholds for acceptable risk, CISOs often lack a common business baseline against which security metrics can be evaluated. 

Only 16% of respondents reported successfully using a quantified cyber risk model such as FAIR when communicating with their boards.

Rather than asking security leaders to simplify technical language, respondents indicated they wanted clearer explanations of how security investments reduce business risk, improve resilience, and support organizational objectives. 

Advertisement

The report suggests that communication challenges are therefore rooted more in governance than presentation skills.

Board confidence remains low

The research also identified a confidence gap between CISOs and corporate boards. 

Only 12.5% of security leaders reported being “very confident” that their board fully understood the true state of the security program following board presentations. 

Most respondents described themselves as only somewhat confident or neutral regarding board understanding.

Interestingly, confidence improved following major cybersecurity incidents. 

Among respondents who experienced a material breach, 53% reported increased board trust afterward. 

According to the report, real-world incidents often provide the shared context needed for boards and security leaders to align on organizational risk in ways that routine quarterly presentations rarely achieve.

Board reporting requires operational effort

Preparing cybersecurity updates for the board remains a resource-intensive process. 

The report found that 71% of respondents spend more than 10 hours preparing for each board reporting cycle, while many organizations require multiple contributors to gather and reconcile information from numerous security tools

Creating executive presentations, aggregating data, and translating technical findings into business language accounted for much of that preparation time.

Respondents identified automated data aggregation, automated synthesis of security findings, and improved business-focused reporting tools as the most effective ways to reduce preparation burdens while improving consistency.

Advertisement

Governance improvements can strengthen board communication

Beyond reporting mechanics, the research highlights broader governance gaps affecting cybersecurity oversight. 

Nearly half of respondents indicated they lack a private executive session with the board for candid discussions, while 50% reported their boards had not made explicit decisions to accept, mitigate, or transfer cyber risk during the previous year. 

The report also found that qualitative descriptions remain the dominant method for communicating cyber risk, with quantified financial measures used far less frequently.

To help organizations strengthen board communication and cyber risk governance, the report recommends the following five practices:

  1. Define cyber risk appetite before reporting against it.
  2. Focus board discussions on business consequences rather than technical controls.
  3. Automate data aggregation to streamline board reporting.
  4. Establish cyber incident escalation thresholds before an incident occurs.
  5. Hold recurring private sessions between CISOs and board members to encourage candid risk discussions.

For CISOs, the findings reinforce that effective board communication depends on more than polished presentations. 

Establishing clear governance, defined risk thresholds, and business-focused reporting can help boards make more informed cybersecurity decisions while reducing reporting burdens.  

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.