Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

Delivering an impactful 15-minute board briefing

The insights in this article were extracted from an interview with Caroline Tsay, board director at The Coca-Cola Company, Morningstar, Semrush, and NiCE.

Cyber risk oversight is increasingly becoming an audit committee conversation. In our recent review of S&P 500 proxy and governance disclosures, we found that 79% of companies assign primary board-level cybersecurity oversight to the audit committee, up from 71.2% two years earlier. 

The shift to audit often comes with a practical constraint. In audit committee meetings, cyber is added to a packed agenda alongside financial reporting, internal controls, external audit, compliance, and disclosure obligations. The cyber portion of the agenda is rarely a long strategic session, but rather 10 to 15 minutes, once a quarter.

That reality should change how CIOs and CISOs think about briefing the board: the goal is not to be comprehensive, but to give directors what they need to govern.

Why many cyber briefings do not land

A common failure mode is an update that is thorough but not actionable. CISOs too often bring dashboards, metrics, and project lists. Directors hear about activity, but they cannot tell what matters most, what is getting better or worse, and what management needs from them. In a short slot, that kind of reporting simply doesn’t work. If the committee cannot take an action, the discussion becomes a status report.

Context is usually the missing ingredient. Many audit committee members are strong in finance, risk, and controls, but they do not necessarily know how to interpret a wall of security signals. If you show a metric, you need to explain why it matters, what good looks like, and what decision it drives.

What audit committees expect to hear

In a typical quarterly briefing, directors expect three categories of information.

  • What is material to the business. That includes incidents and near misses, plus any event that meaningfully changed exposure. Directors want to know whether it mattered, what you learned, and what you changed.
  • What changed in the external environment. This should not be a threat briefing. It should be a short description of new vulnerabilities, attacker behavior, or regulatory developments that actually alter your risk profile or priorities.
  • Program health. Directors want to know whether the security program is executing across the enterprise. Are the right functions aligned? Are priorities landing with IT, product, and engineering? Is the culture capable of implementing what is required?

The board does not need to know everything you are doing, but when the conversation ends, it needs to be able to validate the top risks, align on priorities, and make decisions. If your update does not drive one or more of those outcomes, you are educating, not governing.

The cybersecurity leaders who consistently earn trust and attention show up as business executives, not technical experts. They speak the language of strategy, risk, and outcomes. They are concise. They connect cybersecurity issues to business impact in plain terms, such as implications for revenue, operations, regulatory exposure, and recovery. They are explicit about tradeoffs because tradeoffs are where directors can add value.

They also demonstrate cross-functional alignment on priorities, roles, and accountability, and are intellectually honest. They say what they do not know, what could go wrong, and how they are managing uncertainty. That honesty builds trust.

Effective oversight is not built in a single quarterly slot. Engagement between meetings with the audit chair, and sometimes other committee members, can be critical. That can include short education sessions, quick check-ins on emerging issues, and briefings on sensitive topics in advance of a meeting. The committee should never be surprised by what it hears in the formal meeting.

A structure that works in 10 to 15 minutes

When time is limited, format becomes strategy. The strongest briefings follow a simple narrative arc and end with an explicit ask.

Start with the top three enterprise risks. For each, state the trend and whether it is within tolerance, then cover what changed since last quarter. Focus on the few shifts that alter exposure, including incidents and near misses, major business changes, or regulatory developments.

Next, go deep on one realistic scenario that maps to how the business operates, and explain what containment and recovery look like under real constraints. Close with two or three proof points on program health. Evidence from exercises, recovery tests, or control effectiveness always beats a long roadmap.

Finally, make the ask. What decision do you need? Approve funding, endorse a timeline, accept a defined risk, support a policy change, or request an independent review. If there is no decision required, be explicit about what you want the committee to take away and what you will report back next time.

The fastest way to elevate cybersecurity at the board level is to respect the board’s time. Amplify the signal, cut the noise, anchor the discussion in business impact, and explicitly ask for what you need. When directors can act, they can move the conversation from awareness to governance: clear direction, clear ownership, and clear accountability.

Rob Sloan will be hosting a panel discussion related to how CIOs/CISOs must engage the board during a cyber crisis at Zenith Live 2026. To find out more, click here.


Read More from This Article: Delivering an impactful 15-minute board briefing
Source: News

Category: NewsApril 24, 2026
Tags: art

Post navigation

NextNext post:Germany’s sovereign AI hope changes hands

Related posts

Germany’s sovereign AI hope changes hands
April 24, 2026
What Google’s “unified stack” pitch at Cloud Next ‘26 really means for CIOs
April 24, 2026
CIO ForwardTech & ThreatScape Spain radiografía las tendencias tecnológicas y de ciberseguridad en 2026
April 24, 2026
The AI architecture decision CIOs delay too long — and pay for later
April 24, 2026
La relación entre el CIO y el CISO, a examen: ¿por fin se ha roto la frontera entre innovación y seguridad?
April 24, 2026
CIOs struggle to find clarity in their organizations’ AI strategies
April 24, 2026
Recent Posts
  • Delivering an impactful 15-minute board briefing
  • Germany’s sovereign AI hope changes hands
  • What Google’s “unified stack” pitch at Cloud Next ‘26 really means for CIOs
  • CIO ForwardTech & ThreatScape Spain radiografía las tendencias tecnológicas y de ciberseguridad en 2026
  • The AI architecture decision CIOs delay too long — and pay for later
Recent Comments
    Archives
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.