"Where Are We On Cyber?" - A Qualitative Study On Boards' Cybersecurity Risk Decision Making
Jens Opdenbusch, Jonas Hielscher, M. Angela Sasse
Abstract
—Boards are increasingly required to oversee the cybersecurity risks of their organizations. To make informed decisions, board members have to rely on the information given to them, which could come from their Chief Information Security Officers (CISOs), the reports of executives, audits, and regulations. However, little is known about how boards decide after receiving such information and how their relationship with other stakeholders shapes those decisions. Here, we present the results of an in-depth interview study with n = 18 C-level managers, board members, CISOs, and C-level consultants of some of the largest UK-based companies. Our findings suggest that a power imbalance exists: board members will often not ask the right questions to executives and CISOs since they fear being exposed as IT novices. This ultimately makes boards highly dependent on those providing them with cybersecurity information, leading to losing their oversight function. Furthermore, cybersecurity risk is abstracted to budget decisions with no further involvement in cybersecurity strategies through boards. We discuss possible ways to strengthen boards’ oversight functions, such as releasing industry benchmarks through public cyber agencies or implementing support structures within the company - such as standing (cybersecurity) risk and audit committees.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e812d299-afa9-402f-9df8-dedfe47856e5Cited by top-tier papers1
Ask how each one uses itBuilds on4
- A Large-Scale Interview Study on Information Security in and Attacks against Small and Medium-sized EnterprisesNicolas Huaman, Bennet von Skarczinski, Christian Stransky, Dominik Wermke et al.USENIX Security 2021 · 30 citations
- "Cyber security is a dark art": The CISO as SoothsayerJoseph Da Silva, Rikke Bjerg JensenCSCW 2022 · 25 citations
- Security Obstacles and Motivations for Small Businesses from a CISO's PerspectiveFlynn Wolf, Adam J. Aviv, Ravi KuberUSENIX Security 2021 · 18 citations
- "Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred SecurityJonas Hielscher, Uta Menges, Simon Parkin, Annette Kluge et al.USENIX Security 2023
Related papers
- From Oversight to Insight: Transforming Cybersecurity Governance in BoardroomsTooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge JanickeCHI 2026
- "Perfect is the Enemy of Good": The CISO's Role in Enterprise Security as a Business EnablerKimberly Ruth, Veronica A. Rivera, Gautam Akiwate, Aurore Fass et al.CHI 2025 · 1 citation
- 'It's Confusing, Insecure, and Messy' - Mapping the Gaps Between Stakeholders' Cybersecurity Mental Models in the Danish Defence SectorJudith Kankam-Boateng, Marco Peressotti, Jan Stentoft, Kent Adsbøll Wickstrøm et al.CHI 2026 · 2 citations
- "A five-year-old could understand it" versus "This is way too confusing": Exploring Non-expert Understandings and Perceptions of Cybersecurity DefinitionsLorenzo C. Neil, Charlotte Healy, Julie M. HaneyCHI 2025 · 1 citation
- "You Just Assume It Is In There, I Guess": Understanding UK Families' Application and Knowledge of Smart Home Cyber SecuritySarah Turner, Nandita Pattnaik, Jason R. C. Nurse, Shujun LiCSCW 2022 · 16 citations
