skip to content

Article

How boards can enhance their cybersecurity knowledge

Six strategies to protect your organization from cyber threats.

Updated: October 01, 2026

At a glance

  • AI-driven attack vectors are raising breach costs, while AI expertise remains limited on boards. 
  • Cyber governance requires boards to align cybersecurity, AI adoption, business strategy, and risk tolerance. 
  • Board oversight should focus on areas including strategic alignment, regulatory compliance, and monitoring and reporting. 
  • Boards can strengthen cyber governance through cyber simulations, regular education sessions, and other practical strategies. 

Navigating today’s cybersecurity landscape: Areas of focus for the board

Technology capabilities have grown significantly over the years, empowering organizations to operate more efficiently and drive expedited outcomes. As technology becomes increasingly intertwined with business objectives, board members need to evaluate technology decisions in the same way they evaluate strategic business decisions. 

Just as the board guides an organization’s business direction, it is also now responsible for ensuring that the correct technology elements are enabled to support the business strategy and the right level of cyber risk tolerance is achieved and managed.

To ensure responsible oversight, the board should focus on the following areas:

Strategic alignment
Ensure that cybersecurity initiatives are aligned with the business and technological goals of the organization, including the responsible adoption and use of AI. To be proactive, boards should also ensure future risks and trends are considered, including how advances in AI may impact the organization's cyber risk profile.
Regulatory compliance
Provide oversight of the organization's compliance with relevant regulations and laws. This includes ensuring that the required audits and assessments are performed and that the board has insight and a clear understanding of the results.
Governance and oversight
Oversee the organization’s cybersecurity-related policies, strategies, and alignment with the overall risk management framework. Boards should also understand how relevant frameworks and standards, such as ISO 27001 and ISO 42001, support the organization’s approach to cybersecurity and AI-related risks.
Monitoring and reporting
As a board member, it’s important to make sure you receive regular updates regarding the cyber health of the organization, including progress on key cybersecurity initiatives, key metrics, and key performance indicators. Boards should also seek visibility into emerging threat trends, including how AI is changing attacker capabilities and influencing the organization's risk landscape.
Expert engagement
Engage with the right experts, either through the appointment of a director with AI and cybersecurity expertise, leveraging a Chief Information Security Officer (CISO) on the management team, or consulting an external Virtual CISO (vCISO). This will ensure the board is well informed on emerging cyber threats, evolving AI risks, overall technology trends, and changing regulatory expectations, while also understanding how AI and automation can be used to strengthen cyber detection, response, and resilience.
Cyber incident response
Ensure the organization has a defined incident response program and regularly reviews the results of incident response testing. In the event of a cyber incident, the board should play a role in overseeing how the organization communicates with the public and stakeholders.

Six strategies to increase your cybersecurity knowledge

For boards to successfully oversee their organization’s cybersecurity program, bridging the current knowledge gap is essential. This will help ensure cybersecurity is adequately addressed in regular board meetings and allow boards to confidently carry out their duties where cybersecurity is concerned.

Here are six strategies you can use to build your knowledge and become more prepared to integrate technology risk into decision-making processes:

Ensure you are getting regular updates about cybersecurity and AI-related risks. During these sessions, carve out time to discuss the top risks in your industry and relevant experiences of similar organizations, and ask questions around what your business is doing to mitigate, prevent, or respond to the risk of those types of incidents. The answers you receive may be key in strengthening your organization's defence framework. 

It's important to shift the focus from technical metrics to common sense metrics that highlight risk and value. For example, identifying the number of end-of-life systems with vulnerabilities and the controls in place to mitigate their risks, or discussing the complete costs of cyber breaches, which includes the actual response team, legal support, as well as the impacts to insurance premiums and the organization's revenue. Use industry benchmarks to compare your organization with others in your vertical, helping you understand where the organization stands and what improvements are required. 

By bringing in external cybersecurity experts, especially those with extensive technology or AI experience, board members can not only enhance their cybersecurity knowledge, but also get support “translating” technology-focused information into risk-focused insights and strategies. Ultimately, adding a cyber seat to the board will offer regular access to the expertise you need that complements your organization's risk management, security, and technology teams. 

To get a deeper understanding of actual cyber threats and how to respond to them, consider hosting facilitated incident simulations. These exercises should reflect modern threat scenarios, including AI-enabled attacks, compromised AI tools, or vulnerabilities stemming from the organization's broader technology ecosystem. They will help you understand your role as a board member during a cyber event, potential impacts, areas for continuous improvement in process flows, and build muscle memory. 

In the event of a cyber attack, board members should actively engage with and receive updates from the security experts and incident response teams. By staying updated on the incident progress and outcomes, they can offer independent oversight and ask questions to uncover any lingering risks. It's also important for boards to understand how the organization plans to respond to future cyber attacks. 

What you can learn from close calls or even a previous cyber incident may be what stops it from happening again. Cyber incidents are rarely isolated events, and recurring weaknesses often create opportunities for future attacks. Ask how many times these close calls or actual incidents have happened and what the organization has learned to identify gaps and develop appropriate measures. 

The board’s critical role in managing cyber risk 

What has changed in recent years is the level of scrutiny around the board of directors. After all, boards are there to help the organization manage risk—and that includes risks from cybersecurity incidents. 

In a recent Gartner study, 88% of boards of directors said they view cybersecurity as a business risk, which highlights the move to prioritize cybersecurity as a focus of the board. It is your fiduciary duty to not only provide independent oversight to manage the company’s cybersecurity posture, but also to challenge your organization in different ways to raise the bar for your defense framework.

Two employees one woman and one man working around a computer in a dark office.
A young businesswoman working on a computer in an office at night.

How BDO can help

At BDO, our approach to cybersecurity includes a business focused approach for managing cyber risk. We offer board education sessions to help bridge the knowledge gap and enable board members to stay ahead of the rapidly evolving technology landscape. In these sessions, we show board members how to refocus a technology-centered conversation into one about business risk, so that boards can effectively offer a responsible level of oversight and ask the right questions of their teams. Our board education sessions also cover the latest cyber risks organizations are facing today and what organizations are doing to mitigate those threats.

In addition, our Perpetual Defence framework can help organizations elevate their cybersecurity posture, and get pre-emptive threat management that adapts to evolving cybersecurity risks. The framework includes comprehensive preparation; 24x7x365 monitoring, detection, and response; and operational and offensive security testing.

Explore our cybersecurity services