The Danger of Information Filtering in the Boardroom: Are You in a Filter Bubble?

Kevin Richards’ article highlights a boardroom disconnect: boards ask the right cybersecurity questions but accept the wrong answers. The deeper problem is information filtering—boards receive curated reports that downplay risks. CISOs, under pressure to show progress, may present positive outcomes, masking the true threat landscape. Boards must break this cycle by embracing transparency, establishing cybersecurity committees, and demanding unfiltered insights.

Kevin Richards‘ article Boards Ask the Right Cybersecurity Questions, But Accept the Wrong Answers raises valid concerns about the disconnect between the questions boards ask about cybersecurity and the answers they receive. However, I believe the root cause of this issue lies in information filtering.

In today’s boardrooms, executives, advisors, and vendors often present curated information to the board, aiming to highlight key aspects of the company’s cybersecurity posture. While these reports may seem comprehensive, they can miss or downplay critical risks, often due to time constraints, industry trends, or external factors like geopolitical developments. These constraints can inadvertently lead to an incomplete understanding of the organization’s cybersecurity landscape.

While Richards points out that boards receive overly positive or technical answers, I argue that information filtering is the deeper issue. When boards are only exposed to selective, curated reports, they may be isolated from the broader picture—much like how selective information during an election can shape public perception. As a result, boards may accept answers that sound reassuring but fail to capture the true complexity and emerging risks they need to address.

Why Information Filtering Exists at the Cyber Level

Information filtering in the cybersecurity realm is not only a result of bias or corporate culture but also due to the pressure on cybersecurity professionals to demonstrate progress. Many CISOs are under immense pressure to show that the money spent on cybersecurity is reducing risk. The role of the CISO has become increasingly difficult, with turnover rates rising and job security being a growing concern. According to the 2023 CISO Report, CISOs are increasingly seeing shorter tenures, with many leaving after less than two years due to the constant pressure of the role. This creates an environment where CISOs may feel compelled to present positive outcomes, even if the actual risk landscape is more complex than what’s being reported.

The same report also shows that CISOs now report to the C-suite, highlighting the increasing recognition of cybersecurity’s strategic importance. However, as more executives begin to prioritize security, they might inadvertently demand simplified, less alarming reports to avoid the burden of addressing deeper, unresolved issues. This dynamic fuels information filtering, as organizations may prefer to believe in the effectiveness of their cybersecurity measures rather than face uncomfortable truths about vulnerabilities or the ongoing nature of the threat landscape.

Points for Boards to Consider

To help boards break out of the cycle of filtered, incomplete information, here are some practical points to consider:

  1. It’s Okay to Be Not Okay Cybersecurity is complex, and organizations will inevitably face issues—whether they’re new vulnerabilities, evolving threats, or challenges in maintaining an adequate security posture. It’s essential for the board to understand that it’s okay not to be perfect. Embracing the reality that problems will arise and being open to acknowledging them will allow the board to take a more proactive and informed approach to cybersecurity. Avoiding difficult conversations or downplaying risks only leads to bigger problems down the line.
  2. Set Up Long-Term Contracts with Clear Performance Measures One way to reduce the pressure on CISOs and cybersecurity teams is to establish long-term, performance-based contracts (e.g., five-year contracts) with clearly defined performance measures. This structure allows cybersecurity leaders to focus on securing the company without the constant fear of job insecurity or the pressure to deliver short-term results. It gives them the freedom to implement long-term strategies that reduce risk and strengthen security over time, knowing that their performance will be judged on real progress, not just short-term success.
  3. Establish a Cybersecurity Committee within the Boardroom As I discussed in my previous article on the importance of a cybersecurity subcommittee within the boardroom, it’s crucial to have a dedicated group of board members overseeing cybersecurity strategy. This group should include board members with the knowledge and expertise to ask the right questions, ensure transparency, and hold the organization accountable. By focusing on cybersecurity specifically, the board can ensure that the organization is not only aware of risks but is also actively engaged in mitigating them.

Breaking Free from the Filter Bubble

The challenge, as Richards points out, is not simply that boards ask the right questions—it’s that they are often presented with answers that don’t reflect the full truth. The key to breaking free from this cycle is transparency. By demanding direct, unfiltered communication from cybersecurity teams, boards can gain a clearer understanding of the risks at hand. This means moving beyond reports that simply reinforce a specific narrative and insisting on detailed, actionable insights that lay bare the organization’s true cybersecurity posture.

RELATED POSTS

Discover more from Stasiak

Subscribe now to keep reading and get access to the full archive.

Continue reading

[mailpoet_form id="5"]
[mailpoet_form id="1"]