A recent Trend Micro report showed a significant number (79%) of cybersecurity leaders feel pressured by their boards to downplay the severity of cyberrisks, meanwhile, 80% of them believe that only a serious data breach would incentivize the board to act more firmly.

The report also found those security leaders were seen by their boards as “repetitive,” “nagging” and “overly negative.”

Trend Micro commissioned Sapio Research to survey 2,600 global IT leaders responsible for cybersecurity in their organization for the report. It found that among the cybersecurity leaders who have felt boardroom pressure, 43% of them said it is because they are seen as being “repetitive” or “nagging,” 42% that they are viewed as overly negative, and 33% have been dismissed out of hand.

“Over half of security leaders say cyber is their biggest business risk. But they're failing to communicate that risk in a language the board understands. As a result, they're ignored, belittled and accused of nagging,” said Trend Micro Technical Director Bharat Mistry in a statement.

“Unless they can engage better with senior leadership, corporate cyber-resilience will suffer. The first step is to attain a single source of truth across the attack surface,” Mistry added.

A persistent communication gap between business and security leaders The report showed only about half (54%) of the surveyed security leaders are confident their C-suite completely understands the cyber-risks facing the organization. 34% of respondents stated cybersecurity is still treated as part of IT rather than business risk.

Additionally, 80% of respondents believe only a serious breach would incentivize the board to act more decisively on cyberrisk.  “On average, a financial loss of £150,000 [about $191,000] would be enough, they claim. This points to a disinterested and unengaged board,” the report wrote.

“Unfortunately, C-suite action and investment that is driven by one-off events like this ends up being disjointed and lacking strategic cohesion. It can lead to the purchasing of point products which rarely fix the underlying cause of a breach/incident—and often cause additional cost and complexity headaches down the line,” Trend Micro noted.

What the C-suite and the board want to know about the cyberrisks This disconnect has serious implications for achieving security leaders’ long-term strategic goals and organizations' overall cyber-resilience, Trend Micro noted.

“The truth is that boards have little time for death-by-PowerPoint presentations from the CISO, crammed with industry jargon and irrelevant metrics,” the security firm wrote.

It added the C-suite wants insights into questions like, “How is cyber supporting our business objectives? What is the return on investment (ROI) of our investments in cyber? What are the cyber-risk implications of our latest digital transformation initiative?”

For the board members, they aren’t interested in the details of managing a cybersecurity program, but in big-picture strategic questions like “How secure are we? and how does our security program compare with our peers?”

According to the report, cybersecurity leaders who successfully measure and communicate the business value of their strategies find themselves viewed with more credibility (46%), given more responsibility (45%), seen as a more valued function (44%), given a larger budget (43%), and brought into senior decision making (41%).