Boards Talk Cybersecurity — but NIS2 Directive Says They Must Own It

Note: This article was originally published on the Ivanti Blog.

Summary

Cybersecurity has finally secured a permanent seat in the boardroom, but a dangerous communication and governance gap remains between technical security teams and executive leadership. According to Ivanti’s research, while 89% of organizations now discuss cybersecurity at the board level and 88% include the CISO in strategic meetings, only 40% of security teams feel that risk exposure is communicated to executives “very effectively”. When technical teams translate risk into overwhelming dashboards filled with raw Common Vulnerabilities and Exposures (CVE) counts, patch rates, and tool inventories rather than clear business impact, boards miss the core message. This disconnect leads to misguided prioritization, diffuse budgets, and unaddressed vulnerabilities.

The implementation of the European Union’s updated Network and Information Security (NIS2) Directive completely changes the stakes. NIS2 expands the regulatory scope across multiple sectors, tightens supervision, and most consequentially, assigns direct legal and personal accountability to the management body. Under NIS2, ignorance is no longer a defense. Boards and senior leaders are legally required to approve, oversee, and ensure that operational risk-management measures are effective in practice. The directive expects organizations to actively manage risk across its entire lifecycle—spanning vulnerability management, incident handling, supply chain assurance, and employee training—rather than treating compliance as a one-size-fits-all checklist.

To bridge this governance gap and meet strict regulatory expectations, organizations must overhaul how they present and manage risk. Every board-level security update should be able to answer three foundational questions: What could go wrong that truly matters? What are we doing about it? And how will we know it worked? Furthermore, leadership must treat threats like AI-driven ransomware as recurring business risks rather than rare IT events, rehearsing the critical first 24 to 72 hours with top leadership, legal, and communications teams. By shifting visibility into a governance priority—integrating IT and security data, eliminating shadow IT, and using automation to map real-world exposures—boards can transition from passive participants to true owners of their cyber resilience.

Scroll to Top