By Ann Marie van den Hurk, Mind The Gap Advisory
Most CISOs walk into a board briefing with the right information and leave the room having failed to answer the question the board was actually asking.
This is not a communication failure. It is a framing failure. And it is almost universal.
The CISO brings threat intelligence, security investment data, compliance posture, and a framework summary. The board hears numbers, acronyms, and a general sense that things are being managed. What the board wanted to know, and did not ask precisely enough to find out, is whether the organization is ready to make the right decisions when a cyber crisis becomes publicly visible.
Those are different questions. The first is about security posture. The second is about leadership governance. A briefing that only answers the first leaves the board with data but without the confidence that data was supposed to produce.
Why technical briefings fail the governance test
Boards in 2026 carry personal accountability for cyber governance in ways they did not three years ago. SEC disclosure rules, NIS2, DORA, and CIRCIA’s approaching 72-hour reporting window have shifted cyber from a risk category the board monitors to a governance obligation the board owns.
That shift changes what the board needs from a briefing. They do not need to understand the technical architecture of the threat. They need to understand whether the organization’s leadership structure is capable of responding in a way that protects the organization’s regulatory standing, stakeholder relationships, and operational continuity when an incident is already moving.
A briefing that leads with threat vectors and security tool investments is answering a question the board has already delegated. It is not answering the question they are now responsible for.
What a governance-framed briefing looks like
The most effective board briefings I have seen do not begin with threat data. They begin with decision structure.
Start with who. Before the board can assess readiness, they need to know who holds crisis decision authority, who the named individual is that can move before consensus, and how that person’s authority interacts with Legal, Communications, and the board itself during a live incident. If this cannot be explained clearly in two minutes, the governance infrastructure is not yet clear enough to survive a real event.
Move to threshold. Define what it takes to move an incident from a security matter to an executive crisis. The board should understand the specific conditions, not categories, that trigger escalation to leadership. That threshold is a governance decision, not a security one, and the board should have been involved in setting it.
Address the first 20 minutes explicitly. This is the window where board members, regulators, and the public form their initial judgment about how leadership is handling the situation. The briefing should describe what the organization is authorized to say and do before technical verification is complete. Pre-authorized holding positions, approved communication channels, and named spokespersons are governance artifacts the board should know exist.
Describe testing, not documentation. Most boards are shown crisis plans. Very few are told how those plans have been tested under actual pressure conditions. A briefing that describes what your organization did when a simulated crisis compressed the decision window to 20 minutes is more useful to a board than 40 pages of documented protocols.
Close with the gap, not the grade. The most trust-building thing a CISO can do in a board briefing is name what the organization does not yet have rather than defend what it does. A board that learns about a gap from the CISO briefing trusts the CISO. A board that discovers a gap during an incident questions whether they were ever told the truth.
The confidence that a good briefing actually produces
Boards do not need certainty. They need to know that the organization has thought clearly about what it will do when certainty is not available.
A board that leaves a briefing knowing who decides, what triggers escalation, what leadership can say in the first 20 minutes, and where the known gaps are has received a governance briefing. That board is positioned to ask better questions, provide better oversight, and make better decisions about risk investment.
A board that leaves with a compliance percentage and a framework name has received a technical update. That board will ask better questions next quarter, after they have read something that made them realize they did not ask the right ones this time.
The difference between those two outcomes is not how much information you brought into the room. It is whether you framed the briefing around the question the board is now accountable for answering.
If you are preparing for a board briefing and are not certain how to frame the decision authority layer, the Crisis Decision Authority Diagnostic is designed to give you the specific answers a governance-framed briefing requires.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
