The translation gap: why board-level ownership doesn’t always equal resilience

Luke Stevenson, Cyber Security Product Portfolio Manager

Information security is seeing increasing recognition and representation at the most senior levels of today’s regulated organisations. 71% of respondents to the Corporate Governance Institute’s 2025 Boardroom Bellwether survey predicted that their cyber security threats would grow and two-thirds indicated increasing investment in cyber resilience. Despite this though, time after time, we see ownership failing to translate into palpable action. There are a few reasons why.

Boards lack expertise

Many senior leaders are experts in finance, operations and commercial strategy rather than information security. They lack perspective.

Historically, boards haven't been set up to own cyber security because it has been allowed to remain a technical problem handled within IT. Now, with regulatory change, geopolitical instability and increasing scrutiny of supply chains, boards must engage.

The challenge, however, is that many senior leaders are experts in finance, operations and commercial strategy rather than information security.

They lack perspective when it comes to information security and how to translate it into strategy.

Boards themselves understand this is a problem. In 2023, the Corporate Governance Institute found 60% of board members felt they’d received insufficient cyber-resilience training in the last 12 months. A third were worried that their lack of technology literacy reflects poorly upon them as board members.

There’s also a communication gap. Every function in an organisation has its own language. Finance talks about margin and risk. Operations talks about service delivery. Security teams talk about vulnerabilities, attack vectors and patching cycles. Everyone is discussing the same business, but they're often speaking different dialects.

Imagine the board wants to know whether the organisation is compliant. IT might reel off newly patched CVEs, relevant ISO controls, and new MFA systems - leaving the board unsure what these mean and how they impact the broader picture. If IT expresses frustration with technical debt, a board member might think that means developers have written poor-quality code, when the real problem is with long-term system management.

When cyber risks are presented in technical terms alone, it's difficult for boards to connect them to the outcomes they care about: disruption to services, financial impact, regulatory consequences and customer trust. Likewise, if boards don’t understand the intricacies of IT, they might make the wrong calls.

The answer isn't to make boards more technical. It's to help them understand cyber security in business terms through education, training and accessible conversations about business impact. The organisations making the most progress are those with people who can translate between these worlds, turning technical risk into business context and helping leadership teams make informed decisions.

It’s no surprise that companies with highly digital and AI-savvy boards recorded a

109

percentage point jump in return on equity compared to the industry average.

Boards lack expertise

Organisations have countless departments, systems, tools and processes, but not everything can be protected equally. Many struggle when trying to understand what’s truly critical to the business, focusing security efforts where they will have the greatest impact. Corporate Governance Institute statistics show a third of board members don’t think they could accurately describe their organisation's top digital assets.

The organisations that build resilience understand what keeps the business operating. Rather than attempting to defend everything, they identify their minimum viable business – the systems, services and information that are essential to survival – and focus their investment there first. Strong governance, visibility of the environment and disciplined planning create the foundations needed to respond to whatever threat comes next.

Boards face proactive regulatory scrutiny

This is perhaps the greatest catalyst for change. After several high-profile cyber incidents, regulators are demanding much more evidence, and will almost certainly require more when the Cyber Security and Resilience Bill becomes law. It's no longer enough to have policies on paper – you need to be able to demonstrate that security controls are working in practice.

In many respects, regulation is forcing conversations organisations should already have been having. Holding boards accountable encourages cyber security to become a strategic business priority rather than simply an operational cost.

Resilience isn't achieved through governance alone, though. It’s built through preparation: exercising incident response plans, testing security controls, scrutinising suppliers, educating stakeholders and continually improving based on what organisations learn. Accountability creates the mandate. Operational discipline creates resilience.

Holding boards accountable encourages cyber security to become a strategic business priority rather than simply an operational cost.

The organisations that will succeed won't necessarily be those that avoid cyber incidents altogether. They will be the ones that successfully bridge the translation gap between board-level accountability and operational execution, embedding resilience into every level of the organisation rather than treating cyber security as a technical function alone.

Keep reading