From Oversight to Insight: Transforming Cybersecurity Governance in Boardrooms

Privacy by Design & User ControlPrivacy Perception & Decision-MakingCybersecurity Training & AwarenessGovernment Officials & Civil ServantsPrivacy Policy Makers

Paper Title

From Oversight to Insight: Transforming Cybersecurity Governance in Boardrooms

Publication Info

  • Topic area: Cybersecurity governance at the board level in organizations.
  • Keywords: Cybersecurity governance, board directors, decision-making, regulatory compliance, incident readiness, resilience, board-CISO engagement, consequence-forward metrics, qualitative study, Australia.

Background and Problem

  • Problem / challenge: Board directors often lack the cybersecurity literacy and confidence required to effectively oversee enterprise-wide cyber risks. Governance practices are fragmented, with directors struggling to translate technical metrics into meaningful oversight and decision-making.
  • Significance: Effective cybersecurity governance is critical for organizational resilience, regulatory compliance, and stakeholder trust, especially as cyber risks increasingly impact business continuity and reputation.
  • Motivation and related work: Prior research has focused on prescriptive frameworks and survey-based insights but lacks empirical understanding of how directors translate obligations into practice. Gaps remain in decision-useful information flows, structured governance routines, and incident readiness, which this study aims to address.

Solution

  • Proposed approach: The study introduces a Board Cyber Governance Model that integrates literacy, oversight mechanisms, structured incident engagement, and continuous learning to improve board-level cybersecurity governance.
  • Novelty:
    1. Empirical characterization of board-level cybersecurity governance practices in Australian organizations.
    2. Identification of factors linked to higher-quality cyber decisions, including board composition, information flows, and assurance mechanisms.
    3. Analysis of board-level incident governance practices and their impact on resilience.
    4. Development of a descriptive governance model with actionable insights for boards to enhance decision-making and organizational resilience.
  • Procedure and key techniques:
    • Conducted qualitative interviews with 13 board directors and senior executives across diverse sectors in Australia.
    • Thematic analysis of interview data to identify patterns in governance practices, decision-making, and incident readiness.
    • Synthesized findings into a governance model and director’s checklist, emphasizing consequence-forward metrics and structured routines.

Results

  • Concrete findings:
    • Boards typically review posture snapshots, incident trends, third-party risks, and compliance logs, but these artefacts often lack decision-useful framing.
    • Higher-quality decisions are linked to consequence-forward KPIs (e.g., mean-time-to-detect, mean-time-to-restore), in-camera CISO sessions, and independent assurance.
    • Incident readiness depends on clear escalation thresholds, disciplined communication, and post-incident learning loops.
  • Advantage over baselines: The proposed model shifts focus from compliance-heavy practices to consequence-aware governance, enabling boards to make timely, evidence-based, and auditable decisions.
  • Experiments / evaluation:
    • Interviews revealed gaps in cyber literacy, fragmented governance routines, and inconsistent incident preparedness.
    • Findings were aligned with global frameworks (e.g., ISO 27001, NIST CSF) to ensure broader applicability.
  • Limitations and future work:
    • Small, geographically concentrated sample; reliance on self-reported data.
    • Future work includes multi-country replication, longitudinal ethnography of board meetings, and field experiments on briefing redesign.

Summary

This study highlights the challenges board directors face in governing cybersecurity, including gaps in literacy, fragmented oversight practices, and inconsistent incident readiness. It proposes a Board Cyber Governance Model that integrates literacy, oversight mechanisms, structured incident engagement, and continuous learning to improve decision-making and resilience. Findings emphasize the importance of consequence-forward metrics, regular CISO engagement, and independent assurance in enabling higher-quality decisions. The model provides a practical framework for boards to enhance governance capabilities, with implications for global regulatory and organizational contexts.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/222404/2026

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3772318.3791142
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2026
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making, Cybersecurity Training & Awareness
work
Professions
Government Officials & Civil Servants, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers