Cybersecurity That Boards Care About: Business-Relevant Metrics & Faster Response

Boards are asking more of their cybersecurity leaders than ever before. Altum Strategy Group’s 2026 Cybersecurity Survey found that 51% of boards are now requesting foundational security metrics and business resiliency risk reporting. The appetite for oversight is there. The challenge is that what security teams report and what boards can actually use to make decisions remain two different things.
The gap isn’t a failure of intent on either side. It’s structural. “Historically, CISOs did not have the authority or the reporting structure to drive fundamental changes across architecture,” says Matthew Gantner, Founder and CEO of Altum Strategy Group. “The role was positioned as a technical function, not a strategic one. That’s changing — but the reporting models haven’t caught up.”
Andy Pojuner, CISO, Managing Director of Intelligence, Data & Technology and CISO at Altum, adds that the cybersecurity function itself has an underappreciated communication challenge. “Cybersecurity teams need to build a marketing capability,” Pojuner says. “Not in the traditional sense, but in how they communicate their contributions and value to the rest of the organization. If the board can’t see how security connects to revenue, customer experience, and operational continuity, the investment will always feel like a cost rather than a strategic enabler.”
What boards actually engage with
When it comes to board-level reporting, the signal is clear: boards lean forward on metrics that connect to business outcomes. Both Gantner and Pojuner observe that the strongest engagement comes when cybersecurity is framed around three things — its impact on revenue protection, its role in safeguarding customer experience, and how it enables back-office operations to run without disruption.
Gantner notes that boards are also increasingly interested in security posture around non-human identities, particularly as AI and agentic workloads become more prevalent. “Boards are starting to ask about machine-to-machine interactions and automated decision-making,” he says. “That’s a new frontier for cybersecurity reporting, and most organizations aren’t yet equipped to answer those questions well.”
What makes boards disengage is equally instructive. Tool counts, scan volumes, and patch rates — the traditional currency of security reporting — don’t give a board what it needs to govern. They describe activity, not outcomes. The shift from activity-based to outcome-based reporting is where the real work lies.
Building the board-ready scorecard
Altum’s cybersecurity playbook recommends standing up a board-ready scorecard aligned to resiliency outcomes within the first 90 days. Pojuner explains that what goes on the scorecard depends on the organization’s specific risk profile — whether the primary exposure sits in software, business processes, or operations — and how those risks are being mitigated over time.
“The scorecard has to show trajectory, not just position,” Pojuner says. “A board doesn’t just want to know where you are. They want to know whether you’re getting better, how fast, and what’s still exposed.”
Gantner adds that pressure-testing the scorecard matters as much as building it. “Align the metrics with business fundamentals and make sure they match what the executive team actually needs to manage and monitor,” he says. “If the scorecard doesn’t connect to how the business runs, it becomes another report that gets reviewed and filed.”
Cybersecurity as a value driver
One of the most compelling examples from the interview illustrates a shift in how cybersecurity should be positioned within the enterprise. Pojuner describes a scenario where automated security testing and policy-as-code reduced software deployment timelines from weeks to a single day. The security function didn’t slow the business down — it accelerated it.
“That’s the story cybersecurity teams need to be telling,” Gantner says. “When security is embedded properly, it creates enterprise value. It’s not a compliance checkbox. It’s a capability that makes the business faster, more resilient, and more competitive. The board needs to see it that way.”
This framing connects to the argument Altum has made across its insight series: in the SOC 2 and PCI article, compliance became a revenue enabler. In the cloud transitions piece, security during migration was positioned as a governance design principle. The through-line is consistent — cybersecurity investment delivers business returns when it’s governed as an enterprise function rather than isolated as a technical one.
Time-to-detect and time-to-contain
These two metrics sit at the heart of any board-ready cybersecurity conversation. They measure how quickly an organization identifies a threat and how quickly it limits the damage — and they translate directly into business impact in a way that boards can understand.
Pojuner explains that AI is transforming both metrics by enabling faster data querying, enhanced visibility, and the ability to process indicators of compromise at scale. “Building data analytics muscle within the cybersecurity function is essential,” he says. “AI tools can accelerate detection by analyzing volumes of data that would take a human team significantly longer. The key is integrating indicators of compromise into the data analytics pipeline so that detection is continuous, not periodic.”
From the board’s perspective, Gantner emphasizes that these metrics only become meaningful when there’s a baseline to measure against. “The board needs to see where you started, where you are now, and where you’re heading,” he says. “That requires establishing baselines early and understanding the organization’s risk tolerance. Without that context, time-to-detect is just a number.”
MDR as the operating backbone
Altum’s survey shows MDR as the top function for both investment and automation at 64%. Pojuner describes a well-functioning MDR capability as one that monitors for malicious code and detects changes in user behavior patterns — the kind of anomalies that signal a potential compromise before it escalates.
The shift toward automation within MDR is significant, but Pojuner is careful to distinguish between automation that enhances human decision-making and automation that replaces it. The governance principles Altum applies through Poseidon — deterministic code, human oversight, auditable outputs — apply equally to MDR automation. Speed without reliability creates its own risk.
Closing the visibility gaps
The survey flagged mobile devices at 51%, cloud workloads at 40%, BYOD at 39%, and SaaS at 34% as the top visibility gaps in cybersecurity — and these are the environments where the majority of modern work actually happens.
Gantner’s approach to prioritization is practical: start with where employees actually spend their time. “If most of your workforce is on mobile devices and laptops, that’s where visibility has to come first,” he says. “Implement a unified mobile device management solution and get coverage in place within the first 90 days. You can’t protect what you can’t see.”
The broader message for boards is that cybersecurity investments need to adapt as quickly as the technology environment changes. Both Gantner and Pojuner emphasize the importance of maintaining a current investment thesis — one that’s reviewed and updated regularly rather than set once and assumed to hold.
“The threat landscape evolves continuously,” Pojuner says. “The companies that stay ahead are the ones that treat their cybersecurity posture as a living capability, not a fixed state.”
For more insights on cybersecurity strategy, responsible transformation, and AI governance, visit altumstrategy.com/insights
- Date August 3, 2026
- Tags Insights, Intelligence, Data & Technology Insights

