# The Board Room Isn't Ignoring Your CISO — It's Gagging Them


Ninety-five percent. That's the share of CISOs who told Checkmarx researchers they've felt pressured by leadership to suppress security vulnerabilities found inside their own organizations. Not to downplay them. Not to contextualize them. To bury them.


That number has been floating around security conferences this month, usually attached to a reassuring caveat: boards don't actually hate security, they just don't speak the language. The real problem, goes the conventional wisdom, is a communication gap — a translation failure between CISOs talking about attack surfaces and board members focused on quarterly numbers.


That framing is too generous. And it lets the wrong people off the hook.


## The Language Barrier Defense


There's genuine truth in the communication gap thesis. Edna Conway, who has served on company boards and spent years as chief security and risk officer at Microsoft, pushes back on the narrative that boards are indifferent. "Strong directors care deeply," she told Dark Reading — about cyber risk, about people, about what's happening outside the organization.


She's not wrong, and it would be unfair to paint every board member as a spreadsheet-obsessed suit who checks out when the CISO starts talking about zero-day exploits. Boards have gotten materially better at this over the past three years. The UnitedHealth Group disaster — which took down Change Healthcare and disrupted prescription payments for millions of patients — landed in congressional hearings and wiped billions off the company's market cap. That kind of visibility changes board behavior fast.


But here's the thing about a language barrier: it's fixable. You hire translators. You change how you present risk. You use dollar figures instead of CVE scores. Security teams have been doing exactly this for a decade — building business-case frameworks, risk quantification models, board dashboards written in financial language rather than technical jargon.


If the only problem were linguistic, that 95% suppression stat wouldn't exist.


## What the Pressure to Suppress Actually Tells You


Transparency is where the CISO-board dynamic gets genuinely adversarial, and it doesn't come down to miscommunication.


When a CISO discovers a vulnerability — or worse, detects an active intrusion — their instinct is to get ahead of it. Notify stakeholders. Document the response timeline. In a post-SEC-disclosure-rules world, they're also thinking about whether they're looking at a material incident that requires public reporting within four business days.


A board's instinct is frequently the opposite. A disclosed vulnerability signals weakness to competitors. A public breach announcement invites class-action litigation, regulatory scrutiny, and journalist interest. Suppressing the security finding isn't a communication failure — it's a calculated business decision that happens to put the CISO in legal and ethical jeopardy.


The SEC's 2023 cybersecurity disclosure rules changed the calculus somewhat. Material incidents must now be disclosed, and boards can no longer easily claim ignorance. But "material" is a judgment call, and there's enormous pressure on security teams to make that call in the direction that protects the stock price.


CISOs who push back on that pressure get managed out. The ones who stay learn to calibrate their definitions of what counts as worth escalating. This isn't a language problem. It's a structural one, and rebranding it as a communication gap papers over the accountability question entirely.


## Where Alignment Actually Happens — And Where It Doesn't


To be fair to the "it's improving" crowd: board engagement with cybersecurity has changed substantially since the Biden administration's national cybersecurity strategy and the wave of ransomware attacks on critical infrastructure. Many boards now have dedicated cyber risk committees. Some have brought on directors with actual security backgrounds rather than just asking the general counsel to handle it.


Alignment tends to be strongest in the sectors that have been punished publicly — financial services, healthcare, energy. When your peer company makes front-page news for a ransomware attack that shuts down hospital operations, it focuses the mind.


The gaps persist in a few predictable places:


  • Speed versus security tradeoffs: Every product launch, merger, and cloud migration creates pressure to skip security reviews. The business side sees security as friction. The CISO sees it as the thing preventing the next incident.
  • Budget fights: Security teams consistently report difficulty getting investment ahead of incidents, then watch emergency funds materialize after breaches. Boards understand reactive spending better than preventative spending — the former has a visible cause, the latter requires trusting threat models that haven't materialized yet.
  • The suppression problem: Already covered, but worth restating: when 95% of CISOs say they've felt pressure to hide findings, the organization does not actually have a mature security culture, regardless of what the board's official posture says.

  • ## What Would Actually Help


    Conway and others in the "let's bridge the gap" camp suggest CISOs need to get better at framing security in business risk terms — and they're right that this is a necessary skill. But the structural fixes are harder than communication training.


    Boards need independent cybersecurity expertise, not just a CISO who reports through the CTO. Audit committees need the ability to receive confidential security reporting without it being filtered through executive leadership. And CISOs need clearer legal protection when they push back on suppression pressure — right now, many operate in a gray zone where following their professional ethics could cost them their job.


    The good news is that the threat environment itself is doing some of this work. Attacks that used to stay contained now cascade across supply chains and hit operations hard enough to show up in earnings calls. That visibility is forcing boards to treat cybersecurity less like an IT problem and more like the enterprise risk it actually is.


    The bad news is that forced board engagement driven by catastrophic incidents is a terrible way to build security culture. You want the alignment before the breach, not during the congressional testimony.


    ---


    ## HackWire Analysis


    The "CISOs vs. Boards" framing has always had a convenient villain — the out-of-touch executive who doesn't understand technical risk. This year's version of the conversation tries to rehabilitate boards by blaming the gap on communication rather than priorities. It's a more flattering story for everyone involved, and it's probably wrong in the ways that matter.


    The Checkmarx 95% stat is the thing that should be getting more attention. Pressure to suppress security findings isn't a miscommunication — it's active interference with the security function. And in an environment where SEC disclosure rules create legal exposure for material incidents, that pressure puts individual CISOs in an impossible position: comply with leadership and risk personal liability, or escalate and risk your career.


    This pattern has a precedent worth naming. The cover-up of Uber's 2016 breach — which the company paid $100,000 in bug bounty money to conceal, rather than disclose — resulted in criminal charges for the CISO. Joe Sullivan's prosecution was controversial, but it established that the "I was following orders" defense has limits. More CISOs should cite that case in board meetings when suppression pressure comes up.


    The deeper issue is that security governance hasn't caught up with security risk. Boards have cyber committees now, but most of those committees still rely on information that flows through the same chain of command that generated the suppression pressure in the first place. Independent board-level access to security reporting — without executive filtering — is the reform that would actually change the dynamic. It's also the reform least likely to be adopted voluntarily.


    The communication gap is real. But treating it as the primary problem lets boards avoid the harder question: what happens when the business case for suppressing a finding is stronger than the ethical case for disclosing one?


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)