America’s corporations face a persistent and escalating cybersecurity crisis.
This issue has now escalated to a dire level, exemplified by the extensive systemic breach at CrowdStrike, which occurred despite not involving a direct cyber-attack.
As summer 2024 progresses, the severe consequences of incidents involving UnitedHealth Group and CrowdStrike have starkly highlighted the vulnerabilities embedded in America’s intricate digital infrastructures. The relative calm of the previous summer’s breaches at MGM and Caesars seems like a distant memory.
So, why does America’s cybersecurity dilemma continue to worsen?
It appears we’re treating symptoms rather than addressing the root cause—an egregious leadership failure within corporate boardrooms. Without tackling this fundamental issue, the symptoms will persist. Yet, some influential parties seem intent on maintaining the status quo of inadequate boardroom cybersecurity leadership.
Effective leadership in the boardroom is crucial for cybersecurity, and when done right, it enhances all other security measures. The presence of skilled cybersecurity leaders at the board level is essential for fostering cyber resilience. The rhetoric around cybersecurity culture and “tone at the top” means little without genuine expertise and leadership in the boardroom.
Currently, boards lack the cybersecurity proficiency required to be effective controls within the cybersecurity framework. This absence leaves CEOs to handle cybersecurity challenges largely on their own. Leadership is critical, or so we are often told, but it is frequently missing in boardroom discussions on cybersecurity.
The recent CrowdStrike incident should be shocking, but it is not surprising. Corporate directors with only a general understanding of risk fail to grasp the specific, complex risks associated with digital business systems. The systemic risk exploitation creating ongoing disruptions cannot be mitigated with outdated approaches that equate cybersecurity with other types of risk.
Part of the problem is the misleading guidance from regulators suggesting that broad risk management skills are sufficient for overseeing cybersecurity. For instance, the SEC’s 2023 cybersecurity disclosure rules implied that directors with general risk management experience could effectively supervise cybersecurity efforts without specific expertise.
However, this advice is misguided. There was considerable resistance to proposed rules requiring boards to disclose whether they had directors with cybersecurity expertise. Opponents included corporate governance groups, the American Bar Association, various law firms, and even a major IT and cybersecurity firm. Their arguments were largely unfounded but designed to create uncertainty.
In contrast, proponents of director cybersecurity expertise included prominent cybersecurity associations, institutional investors, some U.S. Senators, the AICPA, academic researchers, and industry leaders such as CrowdStrike. These groups provided substantial evidence showing that having cybersecurity experts on boards results in more robust oversight and proactive management of cyber risks.
The SEC’s decision to ignore this evidence was a missed opportunity. Historically, the SEC’s push for financial expertise in the boardroom through Sarbanes-Oxley reforms in 2002 proved effective in enhancing financial oversight.
Warren Buffet once said, “Risk comes from not knowing what you are doing.” Many boards lack the necessary cybersecurity knowledge. Incorporating cybersecurity experts into the boardroom transforms the oversight process and strengthens the overall cybersecurity posture.
Research from Virginia Tech confirms the benefits of having cybersecurity experts on boards, including more effective oversight and enhanced support for CISOs. Conversely, a lack of expertise can lead to inadequate oversight and reliance on CISOs without sufficient independence.
Addressing this issue is straightforward: boards should add cybersecurity experts. For an S&P 500 company, the cost is about $350,000 annually—essentially the cost of a director—and even less for smaller firms. This investment offers substantial returns in improving cybersecurity.
As RSAC’s Hugh Thompson noted, cybersecurity professionals bring valuable skills to the boardroom, enhancing its effectiveness. With numerous experts attending RSAC annually, their contributions to boardroom leadership are well-recognized.
The problem lies not with cybersecurity professionals but with the lack of cybersecurity leadership in boardrooms. To tackle America’s ongoing cybersecurity crisis, it is essential to embrace a boardroom leadership transformation.



