惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Cybersecurity and Infrastructure Security Agency CISA
月光博客
月光博客
Apple Machine Learning Research
Apple Machine Learning Research
量子位
Hugging Face - Blog
Hugging Face - Blog
罗磊的独立博客
小众软件
小众软件
T
Tailwind CSS Blog
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
The Exploit Database - CXSecurity.com
T
Tenable Blog
博客园 - 叶小钗
宝玉的分享
宝玉的分享
P
Privacy International News Feed
T
Tor Project blog
博客园_首页
AWS News Blog
AWS News Blog
雷峰网
雷峰网
C
Cisco Blogs
Help Net Security
Help Net Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 【当耐特】
T
Threat Research - Cisco Blogs
Last Week in AI
Last Week in AI
K
Kaspersky official blog
人人都是产品经理
人人都是产品经理
Recent Commits to openclaw:main
Recent Commits to openclaw:main
S
Schneier on Security
博客园 - Franky
W
WeLiveSecurity
L
LINUX DO - 热门话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Proofpoint News Feed
大猫的无限游戏
大猫的无限游戏
腾讯CDC
L
Lohrmann on Cybersecurity
J
Java Code Geeks
美团技术团队
博客园 - 司徒正美
The Cloudflare Blog
V
V2EX

informationweek

2026 tech company layoffs InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO's bullish AI take: 'Do not use LLMs; use agentic systems' AI on trial: The Workday case that CIOs can't ignore The AI infrastructure boom is coming for enterprise budgets How enterprises can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy and Cleveland Clinic CIOs slow down to scale AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce The AI contract gaps the Google-Pentagon deal just made visible Non-human identity sprawl is agentic AI's real risk Anthropic's Mythos forces a rethink of vulnerability management Outsourcing contracts weren't built for AI. CIOs are renegotiating now The AI spend hangover companies didn't plan for The power of CIO networking in the competitive AI world Why CIOs see AI projects stall: Speed without structure kills scale IT leaders should never let a good crisis go to waste SFO's digital twin maps airport operations from the curb to takeoff CIOs caught in the middle as AI startups disrupt vertical Saas How to submit an IT leadership column to InformationWeek Podcast: Rightsizing AI frameworks to avoid failure modes The invisible labor crisis inside IT: AI work the org chart can't see Why AI teams treat training data like capital Ask the Experts: How CIOs can identify and overcome cultural barriers to innovation Nobody told legal about your RAG pipeline -- why that's a problem Meta's new 'AI Zuckerberg' is a mirror for every C-suite Will the music stop for AI's funding dance? Rethink tech talent: Local is the smartest play for IT InformationWeek Podcast: Catching errors in AI-powered code CIOs can combat talent scarcity with AI-augmented leadership -- Gartner How Bellevue, Wash., is applying AI to streamline a broken permitting process Ignore the hype: Smarter tech bets at speed of change Who controls the fix? Colorado's repair fight tests CIO power Ask the Experts: The red flags that signal an AI project isn't worth pursuing The hidden high cost of training AI on AI Red Hat's Marco Bill: Resource control is key for AI sovereignty InformationWeek Podcast: New IT architecture, cloud, edge and AI Enterprises need Tier 1 provider relationships to deliver on AI How CIOs run and rebuild the business at the same time in the AI era It's not your tech stack, it's your structure -- fix it Confidential computing resurfaces as security priority for CIOs FinOps: Helpful tool, or a cloud control placebo for CIOs? Cleveland's open data overhaul: From sticky notes to public dashboards As Microsoft expands Copilot, CIOs face a new AI security gap Why build vs. buy doesn't fit modern IT systems InformationWeek Podcast: Is quantum computing slumbering? Your AI vendor is now a single point of failure Vibe coding: Speed without security is a liability A practical guide to controlling AI agent costs before they spiral AI fuels a new wave of technical debt The sunsetting of Sora: A hard lesson in AI portfolio resilience HP pushes broad internal AI use after early productivity gains Why value-based pricing is inevitable InformationWeek Podcast: Safeguarding ecosystems from outsiders Why AI scaling is so hard -- and what CIOs say works Humans are the North Star for AI-native workplaces -- Gartner How IT leaders build a culture for what comes next Compliance costs risk widening the AI gap AI-driven layoffs add new demands on CIOs to prove value AI transformation: Early wins are not enough for CIOs Why CIOs can't let users wait on IT Memory shortage doesn't have to spell disaster for IT budgets Accelerate AI adoption: 3 reasons for adopting MCP How techno-nationalism is complicating IT resilience and supply chains for CIOs InformationWeek Podcast: Compliance crackdown on AI and BYOD Workday’s AI reset: Agents and the race to remake SaaS Why enterprise AI initiatives keep dying before production Metrics of meaning: What do we really measure in AI? Techno-nationalism is reshaping CIO infrastructure strategy Using AI to pick team leaders -- without crossing legal or ethical lines What Oracle's layoffs reveal about running IT with fewer people Chief AI Officer on course-correcting when AI moves too fast Large enterprises need high-performing networks to scale AI InformationWeek Podcast: When do smaller AI models make sense? The future belongs to AI-driven IT Ways AI supercharges risk awareness and data insights for CIOs How automation prepares you for agentic NetOps Should the CIO, CFO or CEO hold the kill switch on AI? The CIO's new mandate: Redesign work itself Ask the Experts: CIOs say they wouldn’t pull workloads back from the cloud How AI is Reshaping the Enterprise
How cyber-risk can fall flat in the boardroom
Nichole Windholz · 2026-06-09 · via informationweek

Executive board members understand that cyber-risk can be expensive and disruptive, but they often lack a clear explanation of which exposures deserve immediate attention, how those risks compare with other enterprise priorities and what action leadership wants them to support. 

They also need to understand which risks matter most now, what tradeoffs come with delays and where management believes action should come first.

Highly technical details about threat activity, vulnerabilities, audit findings and control maturity are useful to the security team, but they don't give directors what they need to do their job. The board is there to evaluate business exposure, weigh tradeoffs and hold leadership accountable for how risk is managed.

The stakes are rising, and the threat picture is getting more complicated. Verizon's 2025 Data Breach Investigations Report studied 22,000 security incidents and found that ransomware was present in 44% of breaches, third-party involvement appeared in 30% of breaches and vulnerability exploitation as an initial access method rose 34% year over year. The numbers help explain why cyber-risk must now be framed as a business issue rather than solely a security issue. 

Related:AI and connected systems are forcing CIOs and COOs to rethink OT security

Reporting is not the same as communicating

Many board updates fail because they deliver information without clarifying the decision behind it.

Directors may hear that a key control is weak or that remediation is behind schedule. However, those facts alone do not tell them whether the business is operating outside its tolerance for financial loss, disruption or regulatory exposure. They also do not help directors understand what management is asking them to support, what can wait and what cannot.

Even as board engagement improves, communication gaps remain. The National Association of Corporate Directors' 2025 Public Company Board Practices and Oversight Survey found that 77% of 201 directors surveyed now discuss the material and financial implications of cyber incidents. That's up 25 points from 2022, and 72% have participated in individual cyber-risk training. 

At the same time, notable gaps remain in reporting, metrics and access to expertise. Splunk's The CISO Report 2025, which surveyed 500 IT professionals and 100 board members, points to a similar tension: 83% of CISOs say they participate in board meetings somewhat often or most of the time, yet only 29% say their board includes at least one member with cybersecurity expertise. 

Access is improving, but fluency doesn't always keep pace.

Related:Non-human identity sprawl is agentic AI's real risk

Frame cyber-risk exposure in business terms

Cyber-risk becomes easier to evaluate when it's presented in the same way as other enterprise risks. That means tying an exposure to financial loss, operational downtime, legal exposure, customer impact, regulatory consequences or delay to a strategic initiative. Boards need a disciplined explanation of what the organization stands to lose.

A maturity score may be useful in a program review. It's less useful in a boardroom than a direct statement that a known gap could interrupt a revenue-generating process, expand disclosure obligations or leave a critical third-party failure without a workable contingency.

Not every cyber-risk can be reduced to a perfect dollar figure, and boards don't expect false precision. They do, however, expect management to show their work.

Useful quantification often starts with scenario analysis. What is the likely range of business interruption if an identity compromise affects a critical system? What is the cost of recovery if a major third-party dependency fails? That kind of framing moves the discussion away from generic concerns and toward measurable consequences. It makes it easier to explain why one investment should move ahead of another and where limited resources will yield the greatest meaningful exposure reduction.

That comparison matters because boards are being asked to oversee cyber-risk in an environment where resilience still lags. PwC's 2025 Global Digital Trust Insights found that 77% of 4,042 tech executives and business leaders surveyed expected their cyber budgets to increase over the coming year, but only 2% said they implemented cyber resilience across the business. Boards want to know which investments will reduce meaningful exposure, not just expand the security stack.

Better cyber discussions start with sharper points

The strongest cyber updates identify the risks that matter most, explain the consequences of delay and clarify what support or acknowledgment is needed. Technical details still have a place, but they should come after the business case, not in place of it. 

The goal is not to surface every issue; it's to show which exposures carry the greatest business impact and how management is prioritizing them.

Candor matters here. Boards are more likely to trust leaders who present exposure with discipline than leaders who frame every quarter as a fresh emergency. If staffing limits are slowing remediation or visibility has improved, but response capacity hasn't, that should be explicit. Boards are more likely to trust leaders who present exposure with discipline. 

Over time, directors begin to see cyber updates as part of a broader governance process tied to accountability, tolerance and resource allocation.

Buy-in depends on clarity from the CISO

Cyber-risk becomes easier to govern when leadership explains it with the same discipline used for any other business issue. 

Directors need to see which exposures carry the greatest consequences, how those risks have been prioritized and where action will make the greatest difference. When that case is clear, board support becomes less about persuasion and more about sound governance. Cyber-risk can then be treated as part of business resilience and governance, not as a siloed technical concern.

About the Author

Nichole Windholz

Onspring

As CISO at Onspring, Nichole Windholz leads a team of professionals responsible for safeguarding Onspring's information assets from threats. Nichole works closely with cross-functional teams across the company to develop and maintain effective security controls, risk management strategies and incident response plans. She is also responsible for staying abreast of the latest security threats and industry trends, ensuring that Onspring remains at the forefront of information security best practices.