By Ann Marie van den Hurk, Mind The Gap Advisory
There is a structural communication gap between boards and CISOs that no one is talking about directly. It is not a technology gap. It is not a budget gap. It is not even a knowledge gap, not really.
It is a framing gap. And it sits at the center of why organizations that believe they are prepared for a cyber crisis discover, during a live event, that they were not prepared for the part that matters most.
The board asks about readiness. The CISO answers with posture. Both parties leave the room believing the question was answered. Neither realizes they were responding to different versions of the same word.
What readiness means to a board
When a board member asks whether the organization is ready for a cyber crisis, they are operating from a governance frame. They have personal accountability for oversight. They are thinking about regulatory exposure, investor confidence, public narrative, and the speed at which they will be expected to demonstrate that leadership is in control.
They are asking, in effect: if something visible happens, will we know what to do, who decides, and how to hold the organization’s authority while the situation is still forming?
That is not a security question. It is a leadership governance question.
What readiness means to a CISO
When a CISO hears the same question, they typically answer from a security posture frame. They describe the threat landscape, the investment levels, the compliance status, the detection capabilities. All of that is accurate and relevant.
But it answers a different question. Security posture describes how well the organization is protected and monitored. It does not describe whether the leadership team can make good decisions in the first 20 minutes of a publicly visible incident, before verification is complete and before the facts are clear.
Those two things are related but they are not the same. An organization can have excellent security posture and deeply inadequate crisis decision governance. The posture determines whether an incident occurs or is contained early. The governance determines what happens to leadership authority, stakeholder confidence, and regulatory standing when an incident becomes visible despite the posture.
Why the gap persists
The framing gap persists for three reasons.
First, the vocabulary is shared but the meaning is not. Both sides use words like readiness, resilience, and preparedness to mean different things. The board means governance under pressure. The CISO means security capability. Neither party typically surfaces this distinction explicitly, so both leave the briefing believing alignment exists.
Second, the CISO is trained to speak in the language of security. That language is precise and technically accurate. It is also often opaque to board members who lack security backgrounds, which means boards tend to accept security briefings without probing the governance layer they actually care about.
Third, boards do not always know what question to ask. The governance questions that would surface the gap, who is authorized to decide, what triggers executive activation, what can leadership say before facts are confirmed, are not intuitive unless you have spent time thinking about crisis leadership at the decision level. Most board members have not. They ask the question they know how to ask and accept the answer they receive.
Where liability quietly accumulates
The consequence of the framing gap is not immediate. It accumulates quietly in the space between what the board believes the organization can do and what the organization can actually demonstrate under pressure.
That space only becomes visible when a crisis is already moving. At that point, a board that believed the organization was ready discovers that ready meant something different in the briefing than it means during the incident. The decision authority structure is unclear. The escalation threshold was never defined. The cross-functional operating picture does not exist. And the first 20 minutes, the window where board members, regulators, and the public form their initial judgment, pass without a coherent leadership response.
The liability is not only reputational. Regulators and plaintiffs will ask what the board knew about the organization’s readiness and when they knew it. A board that received technically accurate but governance-incomplete briefings is in a more difficult position than it realizes.
Closing the gap before it becomes a crisis
The framing gap is not difficult to close once it is named. It requires CISOs to add a governance layer to their briefings, and it requires boards to ask questions that go beyond security posture into decision structure.
It also requires both parties to understand that they are asking and answering different versions of the same question, and that neither version is wrong, but only one of them addresses the leadership accountability that cyber governance now requires.
The organizations that close this gap before an incident are the ones that build decision authority infrastructure: named decision owners, defined escalation thresholds, pre-authorized holding positions, and tested cross-functional alignment. They are the ones that do not discover the gap during a live event.
If your organization has not yet had a governance-framed conversation about what happens in the first 20 minutes of a visible cyber incident, the Crisis Decision Authority Diagnostic is where that conversation begins.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
