The Conventional Wisdom
You've likely heard it before: cybersecurity is an enterprise risk, so boards must take ownership. The FTC and SEC are drafting rules emphasizing board oversight of cybersecurity. Senior management must implement policies, provide training, and report incidents. The proposed solution? Elevate cybersecurity to the boardroom, make it a standing agenda item, and give directors cybersecurity training. Build an ERM framework that treats cyber risk like financial or operational risk.
The message is clear: if your board isn't deeply engaged in cybersecurity governance, you're exposed.
Why We Disagree
The issue with this framing is that it confuses accountability with execution. Boards should understand cybersecurity risk and hold management accountable for managing it. But "board oversight" doesn't mean boards should own the risk or drive the technical program.
The regulatory push from the FTC and SEC isn't asking boards to become security practitioners. It's asking them to ensure management has a plan, resources are allocated, and controls are monitored. The responsibility of senior management to implement cybersecurity policies and procedures and provide training for information security staff isn't new governance territory. It's standard management accountability.
Treating cybersecurity as uniquely requiring board-level ownership creates two problems. First, you overload boards with technical details they can't act on. Second, you let management off the hook by pushing accountability upward instead of embedding it in operational roles.
The Evidence
Look at what the regulations actually require. The FTC's rules and the SEC's proposed changes reference ERM concepts, but ERM doesn't mean boards execute risk management. It means boards oversee it. In ISO/IEC 27014, which defines governance of information security, the board's role is to evaluate, direct, and monitor, not to design controls or respond to incidents.
Consider how boards handle other enterprise risks. Your board doesn't write the business continuity plan. They don't configure the financial controls in your ERP system. They ask: Do we have a plan? Who's accountable? What's our exposure? How do we know it's working?
Cybersecurity should work the same way. When you frame it as requiring special board ownership, you're implying that existing governance structures are inadequate. But the real issue isn't structure. It's that many organizations haven't applied their existing governance rigor to cybersecurity.
Here's what actually needs to happen:
- Senior management implements policies and procedures (this is already their job under ISO/IEC 27001 Clause 5.1 and SOC 2 Trust Services Criteria CC2.1)
- Information security staff receive training sufficient to address relevant security risks (required by ISO/IEC 27001 Clause 7.2 and SOC 2 CC1.4)
- The board reviews metrics, asks hard questions, and holds executives accountable (standard board function)
The gap isn't governance. It's execution.
What to Do Instead
Treat cybersecurity like any other operational risk that could materially impact the business. Integrate it into your existing ERM framework without creating a parallel governance structure.
For boards: Ask the same questions you'd ask about any enterprise risk. What's our risk appetite for cybersecurity incidents? What's the financial impact if our operations stop for 48 hours? Who owns this at the executive level? What metrics tell us the program is working? You don't need to understand Kerberos authentication or SIEM alert tuning. You need to understand business impact and management accountability.
For senior management: Stop treating cybersecurity as IT's problem. If you're responsible for implementing policies and procedures, then implement them. Assign clear ownership. Fund the program. Review performance. When the SEC says senior management must provide training for information security staff, that's not a new cybersecurity requirement. It's basic management competence applied to a technical domain.
For security teams: Build your program so it can be governed, not just operated. Translate technical risk into business risk. A vulnerability scan report doesn't help the board. A risk register that maps threats to business processes does. Your job isn't to make directors into security experts. It's to give management the information they need to make informed decisions.
The practical steps:
- Map cybersecurity risks to business objectives in your existing risk register
- Define clear ownership at the executive level (typically CISO or CIO, reporting to CEO or COO)
- Establish metrics that measure program effectiveness, not just activity (mean time to detect and respond, percentage of critical assets with current risk assessments)
- Report to the board quarterly using the same format you use for other operational risks
- Ensure your incident response plan includes communication protocols that match your existing crisis management framework
When the Conventional Wisdom Is Right
Board engagement does matter when cybersecurity risk could materially affect the business. If you're a financial services firm, a healthcare provider, or a critical infrastructure operator, cybersecurity incidents can bring operations to a standstill. In those cases, boards should ask tough questions and demand accountability.
The conventional wisdom is also right that regulatory expectations are changing. The FTC and SEC are drafting rules that make cybersecurity governance more explicit. Organizations may be required to report incidents and disclose cybersecurity policies and procedures. That's real pressure, and it requires a real response.
Where the conventional wisdom succeeds: it forces organizations to take cybersecurity seriously at the executive level. Before these regulatory changes, many boards treated cybersecurity as a technical issue that didn't require their attention. That was wrong, and the new emphasis corrects it.
But taking something seriously doesn't mean owning it. The board's job is governance. Management's job is execution. When you blur that line, you end up with boards trying to manage technical programs they don't understand and management deferring decisions they should own.
The goal isn't to make cybersecurity special. It's to make it manageable within the structures you already have. If your ERM framework works for financial risk, operational risk, and compliance risk, it can work for cybersecurity risk. You don't need a new governance model. You need to apply the one you have.



