You’re in a board meeting when the question comes up:
“How secure are we?”
It sounds straightforward. But anyone responsible for IT or cyber security knows the answer rarely is.
You’re not simply reporting on the current state of your technology. You’re translating a mix of risks, controls, assumptions and trade-offs into something the board can understand, evaluate and act on.
And that’s where the challenge begins.
Most boards aren’t looking for a breakdown of security tools, configurations or technical controls.
They’re trying to understand the bigger picture:
These are reasonable questions. But cyber risk doesn’t always translate neatly into simple answers.
Threats continue to evolve. Controls reduce risk rather than eliminate it. And even organisations with strong security measures can still experience an incident.
So, when someone asks, “Are we secure?”, a simple yes or no rarely tells the full story.
There’s a balance to strike when discussing cyber security at board level.
Go too deep into the technical detail and you risk losing the room. Stay too high-level and your answer can sound vague or leave the board without enough information to make a decision.
A more effective approach is to frame cyber risk around business impact rather than technical mechanisms.
Instead of explaining exactly how a security control works, explain the risk it helps reduce.
Instead of listing the tools you have in place, explain what those tools mean for the organisation if an account is compromised, a system becomes unavailable or sensitive information is exposed.
That changes the conversation.
Cyber security stops being purely an IT issue and becomes a discussion about business continuity, financial exposure, reputation and operational resilience.
These are areas the board already understands and makes decisions about.
One of the most useful shifts is moving away from reporting what IT has done and towards explaining what it means for the organisation.
For example, reporting that multi-factor authentication has been deployed is useful.
But explaining that it significantly reduces the likelihood of stolen credentials being enough to access critical systems gives the board more context.
The same applies to backups, security awareness training, endpoint protection, incident response planning and other controls.
The question isn’t simply:
“Do we have this?”
It’s:
“What risk does this reduce, and what exposure remains?”
That second question creates a much more productive board-level conversation.
Cyber security is rarely about certainty.
You’re working with changing threats, probabilities and controls designed to reduce exposure. Trying to provide absolute reassurance can create unrealistic expectations.
Clear communication means being able to explain what is working, where the gaps are and what is being done about them.
That doesn’t mean presenting every vulnerability or technical issue to the board. It means giving enough context for decision-makers to understand the organisation’s overall position.
A strong cyber update should help the board understand where the biggest risks sit, how those risks are being managed and where further decisions or investment may be required.
This kind of communication can look simple once it reaches the boardroom.
Getting it there is another matter.
It takes time to step away from technical detail, analyse what matters, structure the message and anticipate the questions that are likely to follow.
For internal IT leaders, that preparation often sits alongside everything else: operational responsibilities, projects, user support, vendor management and security oversight.
That can make it difficult to give board reporting the attention it deserves.
This is where co-managed IT support can play a valuable role.
It doesn’t replace the internal IT team or take ownership of the board conversation. Instead, it strengthens the work happening behind it.
At Perigon One, that can mean supporting the analysis behind your reporting, helping identify and prioritise areas of risk, providing additional technical expertise, or simply creating more capacity within your team to prepare properly.
You’re still the one leading the conversation and providing the organisational context.
The difference is that you’re not carrying all the work behind it alone.
Cyber risk isn’t going to become simpler, and board-level expectations around security, resilience and accountability aren’t going away.
For IT leaders, the ability to explain cyber risk clearly is becoming just as important as managing it technically.
The goal isn’t to turn board members into cyber security experts.
It’s to give them enough clarity to understand the organisation’s exposure, ask the right questions and make informed decisions.
And when that happens, cyber security becomes less about explaining technology and more about protecting the business.
Strong cyber security isn’t just about having the right controls in place. It’s about understanding your exposure, knowing where the gaps are, and giving decision-makers the clarity they need to act with confidence.
Perigon One can help strengthen the work behind those conversations, from cyber risk analysis and reporting to additional expertise and co-managed IT support.
Ready to make your next board-level cyber conversation clearer and more actionable? Get in touch with Perigon One today.