How Great CISOs Talk to the Board

Rick Orloff is a Fortune 1000 CISO and Strategic Advisor at A-LIGN, with over 20 years of experience at companies including Apple and eBay.

Many CISOs default to a polished board update, but that instinct to reassure and smooth over has ended more security careers than any actual breach.

The problem isn’t dishonesty. Boards are pattern-matchers, and the mismatch between “everything is fine” quarterly updates and the incident that eventually surfaces the truth is what causes their trust in a CISO to evaporate.

There’s a better approach, and it starts with letting go of the assumption that the board wants to hear how great things are.

Why the reassurance instinct is a career risk

The instinct to reassure is understandable. CISOs feel professional pressure to project competence, and boards expect polish. Nobody in the room wants to hear that things are difficult. If you’ve spent your career being the person who solves problems, the natural move is to present yourself as the person who has them solved.

That approach works as long as nothing surprises the board. The moment something does, the composure you carefully cultivated in every quarterly update becomes evidence that you didn’t know what was happening in your own program. It doesn’t matter that you actually were on top of things or the incident was outside your control. What matters is the gap between the reports the board consumed and the reality that eventually surfaced.

CISOs who consistently report an honest, sometimes uncomfortable posture build credibility that survives incidents. CISOs who report smooth, reassuring updates lose credibility the first time reality intrudes. The safer-looking option is actually the riskier one.

The problem with concealment

Here’s the rule I’d frame every board update against:

CISOs don’t get in trouble for communicating a bad situation. CISOs get in trouble when they know of a bad situation and they don’t communicate it.

This inverts what most CISOs assume about board risk. The career risk isn’t the report of a bad quarter, it’s the concealment of one.

Once you internalize that rule, the reassurance instinct looks different. Smoothing over an uncomfortable finding to keep the update clean doesn’t protect you. It accumulates exposure. Reporting what you know, what you don’t yet know, and what you’re going to do about it builds the credibility that survives when things get hard.

What “situational awareness” actually means

Situational awareness can be defined in many ways. In this context, it means you articulate exactly where your organization stands: what’s working and what isn’t, and you can walk into a room and describe that posture honestly, without hedging, deflecting, or reaching for jargon.

That’s often the opposite of the polished performance boards are used to seeing from other functions, and it’s the standard every board meeting should be approached with. “We have very good situational awareness” is the sentence I want to be able to say honestly. If the truth is that I don’t fully understand what’s happening in some part of my remit, then that’s what I say, and I explain what I’m doing to fix it.

If you can’t tell the board you have good situational awareness, and mean it, you’re failing at the job. Not because the posture is bad, but because you can’t see the posture clearly enough to describe it.

The three-part board update

Every board update boils down to three parts.

Part one: here’s the posture. The honest read of where the organization actually stands. Not a color-coded dashboard. A sentence or two that a director could repeat back to a peer without translation.

Part two: here’s what we know, and here’s what we don’t yet know. Boards are used to updates that pretend to know everything. The most credible thing you can do in the room is name the edges of your own visibility. It signals that you understand your program well enough to know where your gaps are.

Part three: here’s the plan, with dates and owners. Share a plan that is concrete enough that the board can hold you to it at the next meeting, but that doesn’t overcommit to work that hasn’t been scoped. This is the part where most CISOs either overpromise or say nothing. Both are traps.

If you can’t deliver all three parts, you’re not ready to be in the room. The frame works whether the posture is strong or weak. An honest and accurate update is the answer in a good quarter and in a bad one.

When the posture is bad

The harder case is when the posture actually is bad. Something went wrong, a finding is bigger than expected, a control isn’t performing the way you told the board it would.

The temptation in that moment is to soften the message. But if you do, the board will notice and they will start asking questions from a position of suspicion rather than partnership. The better move is to acknowledge the concern, don’t defend, arrive with a plan expressed in scope, schedule, and budget and accept accountability with clear checkpoints.

Boards don’t need false confidence in that moment. What they need to hear is that their CISO has line of sight into the problem and a credible path through it. Handled that way, a bad posture actually earns credibility rather than eroding it. You are not the person who was surprised by the problem. You are the person who saw it, named it, and is now going to fix it. That’s the CISO the board wants in the room.

Why this rule matters more now

Threat actors are using AI to chain high and medium vulnerabilities into effective critical-severity exploits. Programs that historically remediated only criticals are becoming inadequate. Highs and mediums that used to sit on the deferred list are now being combined into working attack paths, and any organization whose vulnerability management policy is built around “we only remediate criticals” is going to find itself exposed in ways it wasn’t planning for.

I believe the industry is entering a hockey-stick period of vulnerability management activity, followed by a burn-down and a plateau. In theory, the entire tech stack becomes more secure on the other side of that curve. But to get there, it will be less secure first. That’s the transition the industry is in.

This transition is exactly the kind of situation where the reassuring report stops working. Boards need to hear it clearly: here is what we’re doing, and here is what it will cost. CISOs who show up with situational awareness, even when what they see is uncomfortable, will be the ones the board still trusts on the other side.

The takeaway

Situational awareness is what earns board credibility. Silence and spin destroy it.

The CISOs who thrive over the next few years are going to be the ones who show up with the honest read, a candid statement of what’s known and unknown, and a plan the board can hold them to.

That’s the version of the job worth doing. It’s also the only version that lasts.