Two MIT and Bentley University researchers, drawing on interviews with more than 75 directors and board-facing executives, argue that corporate boards are not keeping pace with the cyber risk they claim to prioritize. Most boards now accept that a serious cyber incident can be financially devastating and reputationally damaging, and cybersecurity spending has risen accordingly. Yet the authors find that boards' actual ability to reduce cyber risk has improved only marginally, even as reported cybercrime losses keep climbing year over year, including a 33% jump cited from the FBI's most recent annual crime report at the time.

The piece identifies three specific reasons this gap persists. First, most boards simply lack cybersecurity expertise among their own directors, and the researchers argue the fix isn't necessarily to add more technically qualified board members but to get better at selecting, evaluating, and holding accountable the security executives who report to them. Second, when boards do discuss artificial intelligence, security is frequently left out of the conversation entirely, even though AI adoption is simultaneously a strategic opportunity and a fresh governance and security risk that boards are not yet used to evaluating together. Third, many boards conflate passing a compliance audit with actually being secure, treating regulatory checklists as a proxy for resilience rather than recognizing them as a floor, not a ceiling.

The authors' recommended fixes map directly onto these three failures. Rather than chasing scarce, expensive board candidates with deep technical security backgrounds, they suggest boards focus their energy on rigorously vetting and overseeing the CISO or equivalent executive, since that person's judgment will matter more day-to-day than a director's personal expertise. On AI, they argue boards need a standing practice of evaluating security implications alongside every AI-related strategic decision, not as an afterthought once a tool is already in production. And on compliance, the recommendation is to reframe cybersecurity internally as a competitive and operational resilience issue rather than a regulatory box-ticking exercise, on the theory that market and reputational incentives push toward stronger outcomes than minimum legal requirements do.