From Security Leader to Risk Translator: The Strategic Shift CISOs Must Make

gem3 cisoMost boards do not want to understand cyber security. What they want to understand is what cyber risk means for the business – and those are very different conversations. The CISO who has not yet made that distinction tends to present technically accurate briefings that generate polite attention and little else. The one who has made it tends to shape how the board thinks about risk.

That shift – from security leader to risk translator – is where the real strategic work of a CISO lives. It can also be, in most large organisations, the least well-executed part of the role.

 

What boards actually need

A board’s legitimate concern is not whether the organisation has patched 94% of critical vulnerabilities or whether mean time to detect has improved. Those are operational metrics. They matter to the people running the programme. They do not, on their own, help a non-executive director form a view about whether the organisation is exposed in ways that warrant governance attention.

What a board genuinely needs is a clear-eyed answer to a small number of consequential questions. Where are we most exposed, and why? What would a serious incident cost us – operationally, financially, reputationally? What decisions are being made that will increase or decrease that exposure? And is the level of residual risk one the organisation has consciously chosen to carry, or one that has accumulated by default?

These are risk appetite questions, and they are fundamentally different from control effectiveness questions. A CISO who conflates the two – or who defaults to controls reporting because it is easier to quantify – is not giving the board what it needs to govern effectively.

The language shift: from controls to consequences

The practical challenge is translation. Cyber risk, in its native form, is technical and granular. The board’s frame of reference is strategic and consequential. Bridging that gap requires more than simplification – it requires a genuine reimagining of what you are trying to communicate.

In practice, this means organising cyber risk reporting around business outcomes rather than security domains. Not “we have identified gaps in our network segmentation” but “a compromise of our trading infrastructure would halt settlement for a period we estimate at X days, with regulatory and financial consequences in this range.” Not “third-party risk assessment completion is at 78%” but “three of our critical service providers have unresolved findings that, in a failure scenario, would affect these business lines.”

This kind of framing requires the CISO to have a genuinely deep understanding of the business – not just its technology architecture, but its revenue drivers, its regulatory dependencies, its operational fault lines. That understanding cannot be delegated to a risk team. It has to be built through the same stakeholder relationships and business exposure that any other senior risk leader would be expected to develop.

The audit committee blind spot

There is one governance channel that receives surprisingly little proactive attention from CISOs, despite having significant influence over how the board perceives cyber risk: the Group Audit Committee.
Risk committee reporting – the regular cadence of cyber risk updates, appetite statements, and control assessments – is reasonably well understood by most experienced CISOs. It is, in financial services, bread and butter. The partnership with the second line is established, the formats are familiar, and the CISO typically has enough visibility to manage the narrative. The audit committee dynamic is different, and considerably more treacherous.

Internal audit findings travel upward through a thematic aggregation process. Individual findings from across the business – identified in audits of HR, finance, operations, technology – get consolidated into themes that are presented to the audit committee. When those themes touch on access management, identity governance, or systems controls, they tend to get labelled as cyber risk. And at audit committee level, that label sticks.

The problem is that many of these findings are not cyber control failures at all. Identity and access management is the clearest example. Movers, leavers, and joiners issues – late deprovisioning, incomplete access reviews, stale entitlements – appear in almost every internal audit that touches technology, across every business unit. For an auditor, IAM findings are, frankly, like shooting fish in a barrel. They are easy to identify, consistently present, and highly reportable.

But the root cause is rarely a failure of cyber controls. It is a failure of management discipline – HR not offboarding leavers in a timely way, line managers not completing access reviews with appropriate diligence, business units treating identity governance as an administrative inconvenience rather than a control obligation. When these findings aggregate into a thematic “cyber risk” item at the audit committee, the board receives a picture that suggests the cyber function is not managing access risk effectively. In many cases, the cyber function has the controls in place – and is watching other parts of the organisation fail to use them.

The CISO who does not actively manage this dynamic will find it managed for them, usually not in their favour.

Proactive audit committee management means several things in practice. It means maintaining a close enough relationship with the Head of Internal Audit to understand what is in the pipeline and how findings are likely to be themed. It means ensuring that root cause is accurately represented in audit reporting – that an IAM finding attributed to HR process failure is not allowed to travel up the chain as a cyber governance concern. And it means being willing to apply genuine pressure on the stakeholders who create the underlying problem – working with HR leadership to enforce timely offboarding, and ensuring that line managers who consistently fail their access review obligations face real consequences rather than repeated findings.
That last point is often where the effort stalls. Embedding punitive measures for access review failures requires organisational will that the CISO alone cannot generate. It requires the CRO, the COO, and in some cases the CEO to treat identity governance as a management accountability issue rather than a technology problem. Building that coalition is unglamorous work. But it is precisely the kind of upstream stakeholder management that separates a CISO who controls their own narrative from one who is perpetually responding to someone else’s.

Risk appetite as a governance mechanism

The final dimension of the translation role is risk appetite – and it is where many CISOs underperform, not through lack of capability but through a misunderstanding of what appetite is for.
Risk appetite statements in most large organisations are compliance artefacts. They are drafted, approved, filed, and revisited perhaps annually with minimal change. They do not drive decisions. A cyber risk appetite that is genuinely embedded in governance looks different: it is specific enough to be actionable, connected to business scenarios the board recognises, and used as a reference point when consequential decisions are made – a major acquisition, a cloud migration, an outsourcing arrangement that introduces new dependencies.

Getting there requires the CISO to be present in those decisions, not as a technical reviewer but as a risk voice. It requires the board to have enough confidence in the CISO’s judgement to treat their assessment as decision-relevant rather than advisory. And it requires the CISO to be willing to frame disagreements clearly – to say, in terms the board understands, when a proposed course of action carries cyber risk that sits outside the organisation’s stated appetite.

None of that is possible if the relationship with the board has been built on controls reporting. It is only possible if the CISO has consistently shown up as someone who understands the business, speaks in consequential terms, and earns credibility not through technical authority but through sound judgement.

The translation role is not a softer version of the CISO’s job. It is the harder version – and, ultimately, the one that determines whether the board was actually governing cyber risk, or simply being informed of it.

About the Author

This is the final blog from a series of three by Jim Roberts. With decades of senior experience – including former Global Head of Technology & Cyber Risk at Prudential PLC and Managing Director at Standard Chartered Bank – Jim has seen first‑hand how well‑intentioned governance structures can mask deeper organisational weaknesses. Now, as Founder of Whitecliff Advisory, he works with boards and executive teams to uncover these hidden dynamics and strengthen real‑world cyber resilience.

Connect with Jim on LinkedIn > Jim Roberts | LinkedIn

Share this Article
Facebook
X
LinkedIn
WhatsApp
Telegram
Email

Other Relevant Articles

Will AWS’s outage become patient zero for AI coding vulnerabilities?
The annual Cyber Breaches Survey – different year, similar problems

Board of Directors

Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat m dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor inc. Lorem ipsum dolor sit amet, consectetur.

Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat m dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor inc. Lorem ipsum dolor sit amet, consectetur.Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat m dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor inc. Lorem ipsum dolor sit amet, consectetur.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.