New data from IANS, Artico Search, and The CAP Group finds that while cyber security reporting to boards of directors is now commonplace, many boards and CISOs are more focused on compliance than on important strategic dialogue during those sessions. This could leave boards with a lack of visibility into important future issues and at risk of weak oversight amid an increasingly critical and complex set of threats.
The 2026 Benchmark Report: How Boards are Partnering with CISOs finds that 95% of CISOs deliver regular updates to their boards, signalling a mature reporting cadence. However, the depth of board engagement varies, mainly limited to ‘listening’ and ‘receiving’, without digging deeper into threats and business impacts.
The findings suggest that oversight effectiveness depends less on reporting cadence and more on the depth of the dialogue, and clarity around decision rights.
“Cybersecurity reporting to boards has matured structurally, with time allocated to CISOs becoming much more commonplace, but gaps still remain,” said Steve Martano, IANS Faculty and Partner in Artico Search’s cyber practice. “The best security presentations drive holistic discussions on cyber risk and business risk. These discussions are driven by a CISO who forms a concise data-driven narrative and fosters discussion and brainstorming around risk tolerance, risk strategy, and cyber/tech risk ROI.”
Key findings from the report include:
Cyber risk updates are more transactional than strategic
Boards report strong visibility into current-state risk, programme initiatives, and resourcing needs from the CISO. However, nearly half or more also indicate that reporting on the impact of evolving threats (53%) and AI-driven risk (47%) needs improvement, signalling demand for more forward-looking insight.
Most boards and CISOs have dialogues but remain ‘protocol-bound’
While boards increasingly recognise cyber security as a standing oversight responsibility, deep trust and partnership remain uneven and far from universal. Only 30% of boards describe their relationship with the CISO as strong and collaborative.
Updates are frequent, but ‘airtime’ is limited
Most boards and CISOs have established access. 95 % of CISOs provide regular updates to the board, with 60% engaging with the full board. But their time is short – roughly 30 minutes – and for 35% of boards, the CISO’s security updates are limited to committee discussions.
“What we’re seeing is that while boards are consistently informed, many are still working to translate cyber reporting into strategic decision-making,” said Nick Kakolowski, Senior Director CISO Research at IANS. “Directors want clearer insight into what’s coming next, particularly as AI reshapes both the threat landscape and enterprise risk.”






