Effective Communication Strategies for Cybersecurity Leaders: Understanding the Preferences of Boards

Paul Connelly, former CISO turned board advisor, independent director and mentor, finds many CISOs focus too heavily on metrics while the board is looking for more strategic insights. The board doesn’t need to know the results of your phishing test, says Connelly. Boards are focused on risks the organization faces, strategies to address these risks, progress updates, obstacles to success, and whether they’re tackling the right things.

“I coach CISOs to study their board — read their bios, understand their background, and understand the fiduciary responsibility of a board,” he says. The goal is to understand the make-up of the board and their priorities and channel their metrics into risk and threat analysis for the business.

Using this information, CISOs can develop a story about their program aligned with the business. “That high-level story — supported by measurements — is what boards want to hear, not a bunch of metrics on malicious emails and critical patches or scary Chicken Little-type of threats,” Connelly tells CSO.

Paul Connelly, a former Chief Information Security Officer (CISO) who now serves as a board advisor, independent director, and mentor, believes that many CISOs place too much emphasis on metrics rather than providing strategic insights to the board. According to Connelly, the board is more interested in understanding the risks facing the organization, the strategies in place to address these risks, progress updates, obstacles to success, and whether the organization is focusing on the right priorities.

Connelly advises CISOs to familiarize themselves with the board members by reading their bios, understanding their backgrounds, and recognizing the fiduciary responsibilities of a board. By doing so, CISOs can tailor their metrics to provide valuable risk and threat analysis for the business.

Instead of bombarding the board with technical metrics such as phishing test results or patch updates, Connelly suggests that CISOs should focus on developing a high-level narrative about their security program that aligns with the overall business objectives. This narrative should be supported by relevant measurements that demonstrate the effectiveness of the security program.

In summary, CISOs should aim to communicate a compelling story about their security program to the board, emphasizing how it aligns with the organization's strategic goals and priorities. By providing strategic insights rather than just metrics, CISOs can better engage with the board and demonstrate the value of their security efforts.

Copyright © Flood IT Support 2026 | Designed and hosted by G-Host Web Services Ltd | Privacy Policy | Cookie Policy | Terms of Use