Cyber risk has moved well past the IT department. Regulators on both sides of the Atlantic now treat board oversight of cybersecurity as a legal obligation. Directors who cannot document active engagement face personal liability under the EU’s NIS2 Directive, and disclosure obligations under the SEC’s 2023 rules. The question is no longer whether boards should be involved. It is how.
This guide covers the regulatory framework in force today, the governance structures boards need to put in place, and what directors should be asking management at every stage.
Key takeaways
- Cybersecurity oversight is a fiduciary duty: under SEC rules (US), NIS2 (EU), and DORA (EU financial sector), boards must demonstrate active, documented engagement.
- EU directors can be held personally liable for cybersecurity compliance failures under NIS2.
- The global average cost of a data breach reached $4.44 million in 2025 (IBM).
- 86% of Fortune 100 companies now seek cybersecurity expertise on the board or in director biographies, up from 53% in 2019 (EY).
- AI-powered attacks and supply chain intrusions are the two fastest-growing threat categories.
- 72% of directors undertook cyber risk education or training in the past year, compared to less than half in 2022 (NACD).
What is board cybersecurity governance?
According to the National Institute of Standards and Technology, cybersecurity risk “relates to the loss of confidentiality, integrity, or availability of information, data, or information (or control) systems.” At the board level, governing that risk means setting the organization’s risk appetite, holding management accountable for executing the security program, and producing the governance records that regulators, auditors, and investors expect.
This is distinct from operational cybersecurity. The CISO and IT team manage technical defenses. The board’s role is oversight: approving strategy, challenging assumptions, and ensuring the organization has adequate resources.
| Dimension | Board responsibility | Management responsibility |
|---|---|---|
| Risk appetite | Set and approve | Operate within |
| Cybersecurity strategy | Oversee and challenge | Design and execute |
| Incident response | Confirm it exists and is tested | Activate and manage |
| Regulatory disclosure | Authorize and sign off | Prepare and file |
| Reporting cadence | Define expectations and review | Deliver |
Cybersecurity as a legal obligation for boards
SEC disclosure rules
Since 2023, US public companies must report material cyber incidents via Form 8-K within four business days of determining materiality. Annual Form 10-K reports must describe how the board oversees cybersecurity risk, which committee holds that responsibility, and how management reports to the board. Disclosures need to reflect active involvement. Generic oversight language has drawn regulatory scrutiny.
NIS2: personal liability for EU directors
The NIS2 Directive entered application across EU member states in October 2024. Boards must formally approve cybersecurity risk-management measures and oversee their implementation. Directors can be held personally liable for compliance failures, and regulators can suspend individual board members until deficiencies are resolved. The directive covers energy, transport, banking, health, digital infrastructure, and public administration.
DORA: financial sector accountability
The Digital Operational Resilience Act entered full enforcement in January 2025. It applies to financial entities operating in the EU. Boards of DORA-covered organizations must maintain direct accountability for ICT risk management: continuous risk programs with documented board-level approval, incident reporting within defined timelines, third-party oversight, and resilience testing. Fines for individuals can reach €1 million under DORA, and €10 million or 2% of global annual turnover under NIS2.
As CISA put it plainly: “security isn’t an IT function, but rather a culture and set of repeatable practices driven by the CEO and senior executives.” Cyber literacy is now expected of board members the way financial literacy has always been. Not every director needs to be a security expert, but every director should be able to engage with cyber risk reporting, understand the implications of a breach, and hold management accountable.
Produce audit-ready governance records that demonstrate board-level cybersecurity oversight to regulators. See how DiliTrust’s Board Portal supports compliance documentation
Who is responsible for managing cyber risk?
Boards and CISOs handle fundamentally different parts of the same problem. The CISO manages the technical program. The board sets the parameters within which that program operates and holds management accountable for staying within them.
The most effective oversight arrangements give boards direct, periodic access to the CISO, outside of the standard management reporting chain. This matters when the CISO needs to raise concerns that management may prefer to minimize. Best practices include:
- Scheduled CISO presentations to the board or a relevant committee at least twice a year.
- A defined escalation protocol so the board receives direct notification of significant incidents, without requiring management to initiate it.
- Reporting framed in business terms: exposure level, financial impact, and mitigation progress, not raw technical metrics.
Beyond the CISO, cybersecurity involves the entire organization. Employees, contractors, clients, and service providers each represent potential entry points. A security model that stops at the IT department misses most of the attack surface.
Think of cyber risk the way you think about financial risk. Not every board member is an auditor, but every board member can read a balance sheet and ask probing questions. The same standard applies here.
The current challenges of cybersecurity
AI-powered attacks
Cybercriminals now use generative AI to produce targeted phishing messages, automate attack sequences, and impersonate executives convincingly. Attacks have moved from AI-assisted to fully AI-generated and managed, a shift the board must understand.
For boards, this raises two questions: how has the external threat changed, and are AI tools used inside the organization creating new exposure? In 2025, 48% of Fortune 100 companies named AI risk oversight as a board-level priority, up from 16% in 2024 (EY). Read more on AI governance as a board responsibility. Prompt injection attacks and data poisoning have moved from theoretical categories to active threats.
Supply chain vulnerabilities
Many breaches enter through a vendor or third-party provider rather than the target organization. One compromised supplier can affect hundreds of connected organizations. NIS2 converts third-party cyber risk oversight into a direct legal obligation for EU boards.
Boards should ask management how security requirements are built into supplier contracts, how new vendors are assessed before onboarding, and how vendor performance is monitored over time.
Human risk
Remote work and undertrained staff remain persistent entry points. Nearly 75% of CISOs identify human error as the most significant cybersecurity risk factor (Proofpoint, 2024). Technical controls alone do not close this gap. Boards should ask for training completion rates and coverage data, not just confirmation that a program exists.
Cybersecurity governance and committee structures
96% of Fortune 100 companies disclose at least one board-level committee with cybersecurity oversight responsibility (EY, 2025). Choosing the right structure matters.
| Committee model | Advantages | Limitations |
|---|---|---|
| Audit committee | Existing structure and scheduled meetings | Heavy workload; members may lack cyber background |
| Risk or technology committee | More focused mandate; relevant expertise more likely | May require composition changes |
| Dedicated cybersecurity committee | Strongest governance signal; best for high-risk organizations | Requires investment in composition and scope |
78% of Fortune 100 companies assign cybersecurity oversight to the audit committee (EY, 2025). A dedicated committee is increasingly common in organizations where digital risk is a primary business exposure. Whatever structure the board adopts, the committee needs a clear mandate, regular management reporting, and documented evidence of its oversight activity.
Questions every board should be asking
Effective governance requires ongoing dialogue with management, not one annual briefing. Boards build a defensible governance record through structured, recurring questions.
On risk exposure
- What are our three most significant cyber risks right now, measured in business terms?
- How has our risk profile changed over the past 12 months?
- How are third-party and supply chain risks being assessed and managed?
On policy and preparedness
- When did we last test the incident response plan, and what did the test reveal?
- Are employees at all levels receiving regular cybersecurity training?
- What is our exposure to shadow IT or unsanctioned digital tools?
On governance and reporting
- What metrics does management use to report cybersecurity performance to the board?
- Is our current committee structure suited to our level of cyber risk?
- How do we ensure that AI tools used in board preparation do not expose materials to external systems?
Boards that build these questions into a regular oversight cadence are better placed to satisfy regulatory expectations and to catch problems before they become crises.
The board’s role in incident response
Governance responsibilities do not stop at prevention. When a breach occurs, the board has a specific and defined role.
Before an incident
- Confirm a tested response plan exists, with documented escalation thresholds and communication protocols for regulators, customers, and the board itself.
- Establish clear criteria for what constitutes a “material” incident requiring disclosure under SEC or NIS2 timelines.
- Verify that board communication channels do not depend on potentially compromised infrastructure.
During an incident
- The board must be briefed promptly and consistently. Management cannot respond to a crisis effectively if the board is kept at arm’s length.
- Board communications sent over standard email during a crisis can compound the original breach.
- Direct access to legal counsel and crisis advisors should be pre-arranged, not improvised.
After an incident
- Commission a structured review of what failed. Document the findings for the governance record.
- Confirm regulatory disclosure obligations are met within required timeframes: four business days under SEC rules; defined windows under NIS2 and DORA.
- Ensure lessons learned feed back into the security strategy and governance processes.
NACD’s 2025 survey found that 77% of boards now discuss the material and financial implications of cyber incidents, up from 52% in 2022. The governance record of those discussions is what regulators will ask to see.
One frequently overlooked detail: how board communications are handled during a crisis matters as much as the crisis itself. Sensitive deliberations sent over standard email can compound the original breach. A dedicated board portal ensures that directors can exchange documents, discuss strategy, and coordinate decisions on encrypted, access-controlled infrastructure, with a full audit trail that regulators may request. For a detailed framework covering all phases of crisis governance, see DiliTrust’s board crisis management guide.
See how boards maintain secure communications and audit-ready records during an active incident. Request a Board Portal demo
What’s changing in 2026 and beyond
Cyber and AI governance are converging
Boards that manage cyber risk and AI risk as separate agendas are likely to find gaps at exactly the intersection regulators are watching most closely. EY found that 40% of Fortune 100 companies now have a board-level committee dedicated to AI oversight, up from 11% in 2024. NACD’s 2026 Director’s Handbook on Cyber-Risk Oversight identifies six updated oversight principles, covering risk integration, legal and disclosure obligations, board expertise structures, and the intersection of cyber and AI governance.
Prompt injection attacks, data poisoning, and AI systems generating incorrect regulatory outputs are now active threat categories, not hypothetical ones.
Executive accountability is strengthening
In 2025, 10% of public companies tied cybersecurity performance directly to executive compensation, up from 1% in 2019 (EY). Director education requirements are increasing at the same pace. 72% of directors undertook cyber risk education or training in the past year (NACD, 2025), compared to less than half in 2022.
EU enforcement is accelerating
NIS2 and DORA are in active enforcement across EU member states. Boards of organizations with EU operations should have documented evidence of cybersecurity program approval at board level, evidence of director training on NIS2 obligations, and audit-ready records of incident reviews. For financial entities specifically, DORA compliance requires continuous ICT risk management with documented board accountability at every step.
How board governance tools support cybersecurity oversight
The tools a board uses to manage its work are part of its cybersecurity posture. Board materials distributed by email create an uncontrolled document trail. Generic file-sharing platforms lack the access controls and audit capabilities that regulated governance environments require.
Purpose-built governance platforms address specific risks:
- Encrypted document distribution: Board packs, resolutions, and committee materials stay inside an access-logged environment rather than email inboxes.
- Complete governance records: Every meeting, vote, and decision creates a timestamped, auditable record demonstrating active board oversight to regulators.
- Closed AI processing: Where boards use AI for minute generation or document summarization, closed-platform AI keeps board materials out of external systems.
The DiliTrust Board Portal holds ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II certifications. Data is hosted on sovereign servers in France, Canada (Quebec), and the Middle East, outside the scope of the US CLOUD Act for non-US clients. Lini, DiliTrust’s AI engine, processes all data within DiliTrust’s own infrastructure. No board data is shared with third-party AI models. Full technical detail is available on the DiliTrust security page.
For organizations subject to NIS2 or DORA, DiliTrust’s hosting model and certifications are directly relevant to evidencing the controls those frameworks require.
Practical resource: Download the Data Governance and Privacy: A Checklist for Boards to assess your board’s current data protection posture against regulatory expectations.
FAQ: board cybersecurity governance
Cybersecurity governance refers to the board’s role in overseeing how the organization identifies, manages, and responds to cyber risks. This includes reviewing the cybersecurity strategy, holding management accountable for execution, and ensuring the organization has the resources and structures in place to protect its most critical assets.
Under the NIS2 Directive, which applied across EU member states from October 2024, board members must approve cybersecurity risk management measures, oversee their implementation, and can be held personally liable for non-compliance. In the US, the SEC’s 2023 rules require public companies to disclose annually how the board oversees cybersecurity risk. Both frameworks treat cyber oversight as a fiduciary duty.
Boards should ask management about the organization’s critical digital assets and how they are protected, when the incident response plan was last tested, how third-party and supply chain risks are monitored, and what cyber risk metrics are being tracked. These questions should be raised on a regular, structured basis, not only after an incident occurs.
During an incident, board communications should run through channels that are independently secured and entirely separate from company systems. A dedicated board portal with end-to-end encryption, document-level access controls, and a full audit trail ensures that board deliberations remain protected even when the broader network is under threat.



