Is cyber risk data reliable enough for executive committee decisions?

Cyber risk now sits on nearly every board agenda. But does the data behind those conversations actually reflect what’s happening inside the information system? That’s the question every CISO eventually has to answer in front of their ExCo or board.

Three figures from the latest OpinionWay barometer for CESIN caught our attention:

  • 92% of companies rank cyber risk among their top 5 business risks.
  • 29% review it only once a year, at ExCo or board level.
  • 61% review it several times a year, at the same level.

So cyber risk has clearly become a strategic business risk, not just a technical one. And that status comes with a consequence: CISOs are now expected to support real strategic decisions in the boardroom, not just report on past incidents.

Cyber risk earned its seat at the table — the data hasn’t caught up

Financial data reaching the board goes through audits, standardized formats, and controls built over decades. Cyber risk data, in most organizations, still doesn’t.

This gap isn’t just a reporting habit. It shows up in the decisions that follow, too. For the first time in three years, the share of French companies allocating 5% or more of their IT budget to security actually fell in 2025, down from 48% to 42% (CESIN, 2026). When the data behind that decision is a stale snapshot, the budget that follows gets calibrated on old information — not on the risk as it stands today.

A question that keeps coming up with CISOs

Here’s what we keep hearing in our conversations with CISOs: does data consolidated at a few key moments in the year actually reflect the operational reality of the information system? And is that data reliable enough to inform a CISO’s strategic decisions at ExCo or board level?

In many organizations, teams still pull that data together manually, from scattered tools, just before the meeting. By the time it reaches the board, it’s already a snapshot of where things stood weeks earlier — not where they stand today.

At SharpenCISO, we’re convinced the real issue isn’t measuring more often. It’s building on more reliable data in the first place. Reporting frequency without data quality just means reporting the wrong picture, more often.

What “reliable” actually means here

Reliable doesn’t just mean accurate at the moment of collection. It means current when it reaches the decision-maker.

Take third-party risk as an example. Only 23% of French companies monitor their attack surface continuously — most still rely on a contract clause, reviewed once and rarely revisited. That’s a governance choice as much as a technical one, and it’s exactly the kind of gap that a single point-in-time report can hide.

The same shift is already happening elsewhere in security. The share of organizations that assess their AI tools before deployment nearly doubled in a year, from 37% to 64% (WEF, 2026). Continuous verification is becoming the norm for AI risk. Cyber GRC reporting for the board needs to make the same move — from a periodic snapshot to a live picture.

So, what’s your confidence level?

We’re curious: how much confidence does your organization place in its cyber GRC data when it’s time to make a decision at ExCo or board level?

CISOs, does the data you present match what’s really happening on the ground? And board members, do you feel you’re deciding on today’s risk, or on last quarter’s? Tell us in the comments — we’d like to hear how this looks from where you sit.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA

Share this article