May 2026

    Cyber Oversight under pressure event at RSAC, some takeaways

    NACD: Northern California's Cyber Oversight Under Pressure event during RSAC —

    Written by Alok Nandan5 min read
    Cyber Oversight under pressure event at RSAC, some takeaways

    NACD: Northern California's Cyber Oversight Under Pressure event during RSAC — https://www.nacdonline.org/northern-california/northern-california-events/cyber-oversight-under-pressure/

    Key Takeaways

    Early Incident Awareness and Escalation: CISO Actions

    Inform the board early, initially via informal channels (e.g., CISO to audit committee chair), as soon as an incident is credible, even if facts are incomplete. Be transparent and avoid surprises, while maintaining a non-alarmist tone.

    Distinguish clearly between an "incident," a "breach," and a "material breach," with escalation thresholds pre-defined and understood in advance by the management team and board.

    Engage cross-functional leadership (e.g., general counsel, engineering) immediately to validate unauthorized access, attribution, and scope, recognizing early signals may evolve or prove incorrect.

    Initiate regulatory clocks as needed and consider early government notification where appropriate.

    Board's Immediate Oversight Priorities: Board Actions

    Focus on the core questions: what happened, who was responsible, and how it occurred; who is leading the response; and whether containment measures and external expertise have been effectively deployed.

    Ensure management has engaged external counsel and forensics early to preserve privilege and support regulatory decision-making.

    Assess whether containment is underway and what critical unknowns remain before further decisions are taken.

    Watch for red flags: unclear ownership, delayed escalation, lack of external support, or overconfidence from leadership.

    Periods of leadership transition require heightened board oversight, as control gaps and execution risks are more likely to emerge during these times.

    Materiality and Disclosure Decisions

    Determining materiality is complex and must involve external legal counsel; once established, SEC disclosure is required within four days.

    Evaluate materiality beyond financial impact (e.g., access to IP, customer data, or critical systems may be equally consequential).

    Account for jurisdictional differences (e.g., GDPR 72-hour window, India 6-hour window).

    Balance risks of premature disclosure versus delayed reporting; boards should generally bias toward transparency while avoiding incomplete or misleading statements.

    Board vs. Management Decision Boundaries

    Management leads operational response; the board weighs in on high-stakes decisions such as ransom payments, disclosure timing, and major operational trade-offs.

    Define clear triggers for when issues escalate from management to audit/risk committee or full board.

    Maintain disciplined briefing cadence, frequent enough for oversight, but structured to avoid operational disruption.

    Confidence in Management Response

    Confidence is driven by clarity of process, prioritization, escalation process, and evidence of practiced incident response plans (e.g. through regular tabletop exercise preparation). Plans should be updated regularly, especially after lessons learned from incidents.

    Strong leaders demonstrate cross-functional coordination, humility, and willingness to seek external help.

    Red flags include lack of preparation, unclear triage priorities, or a CISO operating in isolation.

    Boards should ensure continuity planning (e.g., backup decision-makers) is embedded in response frameworks.

    Post-Incident Review and Strategic Implications

    Conduct both immediate ("hot wash") and delayed ("cold wash") reviews to identify root causes across technology, processes, and third parties, not just to mitigate risk in the moment, but over the long term.

    Reassess risk tolerance, cyber strategy, and investment priorities, avoiding reactive overspending without clear long-term need.

    Evaluate gaps in areas such as third-party risk, M&A integration, identity/access management, and cyber insurance coverage.

    Treat retrospectives as "no-blame" environments to improve organizational learning and resilience.

    Audit Committee Oversight and CISO Engagement

    Cyber risk is increasingly overseen by the audit committee (≈79% of S&P 500, up from 71% in 2024 — source: Zscaler), making it the primary governance forum.

    Effective briefings tie cybersecurity posture directly to business risk, financial impact, and strategic priorities, not just technical metrics.

    Committees should leave each session able to assess risk acceptability, resource allocation, and leadership effectiveness.

    Encourage ongoing dialogue between the CISO and audit chair, including agenda-setting and escalation protocols between meetings.

    Common Failure Modes in Board Oversight

    Overly technical reporting from CISO that lacks linkage to enterprise risk, customers, or financial outcomes that the board are interested in.

    Excessive metrics without prioritization, obscuring what truly matters for decision-making.

    Insufficient direct access between CISO and board, often filtered through management layers like CEO.

    Misalignment between board expectations and CISO communication style or business fluency.

    Board-Level Best Practices

    Ensure directors receive cyber training and maintain fluency in evolving threats (e.g., AI-driven attacks, quantum risks).

    Regularly review and test incident response plans, including board participation in tabletop exercises. Plans should be used regularly to ensure they are most useful and relevant.

    Commission periodic independent security assessments to benchmark posture against peers and have a comparison for future years.

    Establish clear, structured dialogue with the CISO around risk strategy, roadmap, and resource allocation.

    Provide support to CISO on how best to communicate with the board and what should be shared.

    Agenda Time and Priority Setting

    Cyber oversight remains concentrated in audit committees, which risk becoming overburdened "catch-all" forums.

    Cyber time on the audit committee agenda is variable and often constrained by competing priorities; depth depends more on relevance than duration.

    Cyber earns more time when clearly tied to business impact, financial reporting, or active incidents rather than standalone technical updates.

    Committees should not be learning about issues for the first time in formal meetings. Ongoing dialogue between meetings is expected.

    Increasing agenda pressure is prompting consideration of dedicated risk or technology committees for deeper focus.

    Expected Outcomes from Each Briefing

    Directors should leave each session able to determine whether cyber risks are acceptable within the organization's risk appetite.

    Briefings should enable decisions on resource allocation, investment priorities, and leadership effectiveness (including CISO performance).

    Updates should cover what has changed since the last meeting, including incident developments and mitigation actions.

    Content That Drives Effective Oversight

    Emerging threat landscape updates should be contextualized (e.g., how external breaches or geopolitical risks specifically affect the company).

    Security posture discussions should include third-party risk, talent, and organizational culture, not just technology controls.

    Periodic topics (e.g., cyber insurance, regulatory developments) should be incorporated as part of a structured roadmap.

    Independent third-party assessments can provide benchmarking and improve board confidence in relative security posture.

    Demonstrate intellectual honesty: clearly articulate what is working, what is not, and where support is needed.

    Align messaging with peers (e.g., internal audit, IT) and co-develop forward-looking agendas with the audit chair.

    Structure updates to enable decisions, not just provide information.