> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Does the CISO Need a Board Seat? That's Not the Real Question
- URL: https://www.cybrsecmedia.com/does-the-ciso-need-a-board-seat-thats-not-the-real-question/
- Published: 2026-09-16T16:22:14.000Z
- Updated: 2026-09-17T04:13:36.000Z
- Description: RegScale CISO Dale Hoak says the cybersecurity leadership debate should focus less on reporting lines and more on ensuring cyber risk reaches the board — while security, compliance and engineering stop fighting separate battles. (Sponsored by RegScale)
- Author: Bill Brenner
- Tags: CISO, Leadership, Article

Cybersecurity has spent years debating where the CISO belongs. Should the CISO report directly to the CEO? The CIO? The board? Should CISOs have their own seat in the boardroom?

Dale Hoak thinks there's a more important question. Is the board actually hearing — and understanding — the organization's cyber risk?

“Whether the CISO is in the boardroom or not in the boardroom, he has to be represented,” Hoak, CISO at RegScale, said during the latest episode of CYBR.SEC.CAST.

**Full episode and related article:**

[Compliance Whack-a-Mole with Dale HoakDale Hoak joins CYBR.SEC.CAST to discuss continuous cyber resilience, AI-driven risk, executive buy-in, and moving beyond checkbox compliance.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-b1e68373-8c37-4ba4-81c0-c1e19bbce73b.jpg)CYBR.SEC.Media, and CYBR.SEC.Media![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Dale-Hoak_Ghost-56914c7d-330e-436e-b37c-09546c0feb84.png)](https://www.cybrsecmedia.com/compliance-whack-a-mole-with-dale-hoak/)

[Cyber Compliance Is Not Cyber ResilienceRegScale CISO Dale Hoak explains why point-in-time cybersecurity compliance cannot keep pace with AI-driven threats — and why continuous controls, risk management and resilience must replace the checkbox mindset. (Sponsored by RegScale)![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-06ea8e62-6369-4ecf-b35e-cc1d8a181172.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/54c7f30a-c7fa-4983-91b4-046b1e8fb7d1-984931e6-afdd-4d53-b327-ce7c91a8e8cb.png)](https://www.cybrsecmedia.com/cyber-compliance-is-not-cyber-resilience-ai-is-widening-the-gap/)

Hoak personally believes the CISO should have direct access to the board. But he also argues that organizations can structure that communication differently. Maybe cyber counsel communicates the risk. Maybe a technically savvy CTO does it. Maybe the CISO presents it directly.

“The point is get the risk conversation in front of the board so that it's being had,” Hoak said.

That shifts the CISO board-seat debate away from status and reporting structures and toward something much more consequential: whether business leaders have the information they need to make informed decisions about cyber risk.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## Stop building cybersecurity kingdoms

Getting cyber risk into the boardroom is only part of the problem. Organizations also have to get security, compliance, risk, engineering and architecture talking to one another. That doesn't always happen.

Hoak described a familiar organizational structure in which different teams operate in their own bubbles, sometimes approaching the same problem from different directions and sometimes actively stepping on one another.

The result can be duplicated effort, conflicting priorities and security decisions that arrive too late.

The problem isn't necessarily disagreement. Different teams should challenge one another.

“Everybody wants the same outcomes whether you go about them differently from a different, from an opposite point of view,” Hoak said. “That may be a good thing.”

The trouble starts when those differences become turf wars. Instead of asking how security wants to solve a problem or how compliance wants to solve it, Hoak argues that organizations should ask what outcome the business needs.

“Identify the problem, address the problem, right, from a perspective of what is best for the business,” he said. “How do we handle it together to achieve the outcomes the business needs?”

## Get security, compliance and engineering in the same conversation

That collaboration needs to happen much earlier than it often does today. Hoak argues that compliance, security, engineering and architecture should be examining the same controls and asking their different questions at the same time.

“If you're all looking at the same control subset at the same time and asking these opposing questions to each other, you get a better answer earlier in the process,” he said.

That's a significant change from the traditional model in which developers build, security reviews, compliance checks requirements and somebody eventually discovers a problem that would have been much easier to address six months earlier.

But changing the organizational structure isn't enough. Organizations have to change how people think.

“You can adopt technologies and tools,” Hoak said. “If you don't change the way you think, you're not going to achieve the outcomes that you desire.”

That makes cybersecurity transformation as much a leadership and culture problem as a technology problem.

## Boards are getting smarter about cyber risk

The pressure on CISOs to make that transformation is increasing. Hoak sees boards becoming more technically savvy and developing a better understanding of risk. That creates a new expectation for security leaders.

CISOs have to be able to explain cybersecurity in terms the board can use to make decisions. That means moving beyond vulnerability counts, alerts and technical controls and framing the conversation around business risk.

Hoak said that effort needs support throughout the organization, including from the CTO, CEO and other members of the C-suite.

The objective is not to make everyone a security practitioner, but to get the organization working toward the same outcome.

Whether an organization is a large enterprise attempting to transform years of established processes or a startup building its security model from scratch, Hoak argues that the destination should look similar: assume compromise is possible, understand the risk and build the organization to withstand it.

## The CISO's seat matters less than the conversation

None of this means the CISO reporting structure is irrelevant. A security leader who lacks access to decision-makers can have difficulty getting risks understood, funded or addressed. Hoak himself favors direct CISO access to the board.

But a seat alone doesn't solve the problem.

Putting a CISO in the boardroom without giving the board a clear understanding of cyber risk accomplishes little. Likewise, an organization in which security, compliance, engineering and risk teams protect their own territory instead of working toward common business outcomes remains fragmented regardless of who reports to whom.

The real measure is whether cyber risk is reaching the people empowered to accept it, mitigate it or fund the response. And security leaders have a responsibility to make sure that happens.

Hoak's final advice to practitioners was broader than the boardroom discussion, but it captured the underlying theme of the conversation.

“Don't be afraid of change,” he said. “Be a change agent.”

Then came the line that perhaps best summarized the challenge:

“Be an agent of change or you're going to end up being an agent of chaos.”

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)