We Ran the Same Board Presentation Twice
Same company. Same vulnerabilities. Same presenter. The only thing that changed was the framing — and the room’s reaction flipped completely.
At our Spring Summit, we put a group of senior security leaders inside a scenario most of them have already lived: two months into a new CISO role at a publicly traded logistics company, 1,500 people, operations in three countries, and twenty minutes on the board agenda for a cybersecurity State of the Union.
Then we ran it twice.
Take 1 was deliberately bad — not cartoonishly bad, just the ordinary kind of bad that happens when a competent security leader walks into a room they haven’t read. Take 2 used the same presenter, the same company, and the same underlying vulnerabilities. Everything that changed was framing.
The debrief afterward was the most useful hour of the summit, mostly because of how many people in the room recognized themselves in Take 1.
What went wrong the first time
The presenter opened with the problem list. One analyst covering the SOC. Thousands of unpatched vulnerabilities. Antivirus well past its useful life. A team stretched thin and undertrained. And then, inside the first few minutes, a request for $15–25 million.
Every item on that list was true. That was the point. The board still walked away alarmed rather than informed, because a problem inventory delivered without a roadmap doesn’t read as candor — it reads as panic.
It got worse from there:
-
The jargon. EDR, SOAR, SIEM, endpoint — all deployed without definition. One participant recalled presenting endpoint protection results to a board years ago and being stopped mid-slide: what is an endpoint? Assume nothing about vocabulary. You will never lose points for defining a term. You will absolutely lose the room by not defining one.
-
The blame. The presenter suggested the prior CISO had left a mess and the auditors had missed things. The room flagged this instantly. Undercutting your predecessor and your external partners burns the exact political capital you’re going to need in about six months when you ask for something hard.
-
No introduction. First board appearance, and the presenter never said who they were, where they’d come from, or why the board should trust the assessment they were about to hear. Credibility isn’t automatic. It’s granted, usually by people who’ve decided they like you.
-
The budget ask. Directed at the board — which, as one board member pointed out, doesn’t approve operating budgets. That conversation belongs to the CFO and CEO, and it belongs there before the meeting.
-
And then the B-word. Asked point-blank whether the company was currently breached, the presenter hedged: I believe so. The room went cold. If you’re going to say that sentence, you’d better be able to back it up — and if you genuinely suspect a breach, that conversation happens proactively with the CEO and board chair, never for the first time in an open session.
What the second take did differently
Same posture. Same gaps. Completely different room.
The presenter opened by mapping security milestones to the board’s own stated objectives: growth into Fortune 500 and government accounts, European expansion, AI governance, and operational efficiency. Not a control list. A set of things the company was already trying to do, and what security was doing to make each one possible.
Then this, up front:
I know you have a busy day. I’ll be brief, be heard, and be gone.
That line landed. The most experienced voices in the room went further — plan for half the time you were given. Build seven slides and be ready to deliver the top three in five minutes. Your twenty-minute slot will become five, and it will happen on the day, without warning, because the audit committee ran long.
The rest of Take 2 followed the same logic. Security framed as a competitive advantage rather than an absence of incidents: faster deal conversion, less compliance drag entering new markets, the ability to move at the speed the business wants to move. When a director asked about nation-state threat activity, the answer was calm, contextual, and in plain language. When asked about competitor benchmarks, the answer was direct.
And when asked about board-level KPIs — which weren’t ready — the presenter said so, and committed to a date at the next session. Nobody expects a perfect program from a two-month CISO. They expect a plan and the discipline not to oversell.
On metrics: less is more
This came up in both preparatory sessions and again in the debrief. Boards receive a lot of data and absorb very little of it. The glazed-over look is a familiar one.
Consensus in the room was three to six KPIs, chosen because they connect security performance to a business outcome. The ones that tested well included: security review time in the deal cycle, strategic deals with security support attached, privileged users under MFA, critical vulnerabilities remediated to SLA, AI use cases under formal governance, and operational savings from automation. Each of those is a business metric that happens to be measured by the security team.
Tell the story first. Then bring one or two numbers that make the story tangible. Present risk as a range rather than a point estimate, be ready to defend it, and don’t lead with it.
Our earlier session on risk quantification fed directly into this. Financial framing — annualized loss exposure, loss exceedance, ROI — resonates with financially-minded directors. But the deeper insight was this: boards don’t actually want a number. They want to understand their own risk appetite. Your job is to surface it, help them define what exposure is acceptable, and then run the program to that standard. It changes the conversation from give me money to reduce risk to here is the risk you’ve accepted, and here’s how I’m managing it.
Before you walk in
The pre-work matters more than the deck:
- Find your board advocate. Someone who can brief you on the politics, the preferences, and the topics to leave alone. Meet at least once a quarter.
- Align with the CEO and CIO first. No surprises in the room — not in your messaging, not in your numbers, not in your tone.
- If there’s bad news, socialize it beforehand. With the CEO, the CIO, and the board chair.
- Read the previous board minutes. Learn what your predecessor presented and what cadence the board expects.
-
Find out whether this board wants slides, a narrative, or a clean packet read in advance. They are not all the same.
That last point deserves emphasis, because the simulation was an idealized boardroom and real ones vary enormously. Some directors want no slides at all. Some CISOs present directly; others have every message filtered through a CIO. One participant shared a story about talking to a reporter at a security conference a week into a new job, describing vulnerabilities only in general terms, and nearly being fired for it. Communication discipline doesn’t stop at the boardroom door.
The actual measure of success
A board member in the simulation summed up the difference between the two takes better than any of our frameworks did:
The first presentation left me scared and frustrated. This one made me feel good.
Not the data. Not the maturity model. The emotional response in the room.
CISOs who prepare properly, align to the business, project confidence, and earn one genuine advocate around that table find the boardroom becomes a place where they do their best work — instead of a quarterly performance review with higher stakes.
This piece draws on two Inner Circle roundtables and the live boardroom simulation at our Spring Summit. Sessions run under Chatham House Rules; all examples are anonymized and the company scenario is fictitious.
The Inner Circle meets monthly for sessions like this one — closed room, working problems, no vendors. Learn more about membership