New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable
August 5, 2026, 3 min read
Las Vegas, United States, August 5, 2026, CyberNewswire
Pulse Security AI calls for boards and security leaders to define cyber risk appetite in its new report,
The CISO-Board Communication Gap.
Boards of directors believe they understand their company’s security posture and what it means for the business.
The security leaders presenting to them are far less sure. Only 12.5% of security leaders are very confident
their board walks away understanding the true state of the program, and 55% of boards have never formally
defined what cyber risk the company is willing to accept.
Pulse Security AI
unveiled these findings today in The CISO-Board Communication Gap, a research report drawing on
more than 80 senior practitioners and examining how security leaders report to their boards and what gets
lost between the two.
“For a decade, the industry has told security leaders to communicate better with the board,” said
Mike Armistead, CEO and co-founder of Pulse Security AI. “Our data says the problem is upstream of that.
You cannot report status against a baseline that was never set.”
Top Five Insights From the Research
- The Confidence Gap Is Measurable.
Just 12.5% of security leaders are very confident their board accurately understands the program after
a presentation. Forty-one percent are somewhat confident, while 38% are neutral or mixed. Both sides
leave the room, and the cycle continues largely unchanged.
- The Baseline Was Never Set.
Fifty-five percent of boards have never formally defined cyber risk appetite, and another 27% define it
only qualitatively. Without an agreed baseline, external noise fills the vacuum. Roughly 70% of security
leaders say board members bring third-party ratings and press coverage into the room, and 42% had to
defend a commercial security score in the past 12 months.
- Board Preparation Is an Operational Tax.
Seventy-one percent of security leaders spend 10 or more hours preparing for each board cycle, equivalent
to one or two full working days every quarter. Thirty-nine percent involve four or more contributors per
presentation. The top time sinks are building slides, gathering data across tools, and translating
findings into business language.
- Governance Runs on Instinct, Not Instrumentation.
Half of boards made no explicit decision to accept, mitigate, or transfer cyber risk in the past year.
Forty-eight percent of security leaders have no access to private executive sessions, 23% have no
predefined threshold for board-level escalation, and 33% say their own legal exposure shapes what they
tell the board.
- Trust Is Recoverable, and a Breach Should Not Be the Trigger.
Fifty-three percent of security leaders say board trust increased after a material security incident.
A real event forces a shared, concrete understanding of risk that quarterly updates rarely produce.
The report details five practices, drawn from leaders with the highest levels of board trust, for creating
that alignment.
“You cannot assemble a clear picture of the business when the underlying information lives in a dozen
disconnected places. Security leaders have earned the room. What they need now is the operating layer
underneath it,” Armistead continued.
Download the full report:
The CISO-Board Communication Gap
Methodology
The findings draw on a 42-respondent survey of security leaders and corporate directors, more than 20
in-depth interviews with sitting and former CISOs, and two moderated workshops involving approximately
22 CISOs.
Seventy percent of survey respondents are CISOs or heads of security. Industries represented include
technology and software at 34%, financial services at 25%, healthcare and life sciences at 9%, and
manufacturing at 9%.
These findings are not nationally representative statistics. Their value lies in the depth and seniority
of the participants, who regularly sit in audit committee meetings. Percentages are calculated based on
respondents who answered each question. A small corporate-director sub-sample is treated as directional
only. Quotes were anonymized at participants’ request.
About Pulse Security AI
Pulse Security AI is redefining how cybersecurity programs are run. Pulse is an operational management
platform for security leaders, where security professionals and AI agents work together to execute
procedures, capture decisions, and deliver real-time program visibility without manual overhead.
The result is a security organization that operates faster, costs less, and gives leaders clear confidence
in where their program stands.
Contact
Carmen Angela Harris
Pulse Security
carmen@pulsesecurity.ai