eCommerceNews Australia - Technology news for digital commerce decision-makers
Australia
Boards, not just IT teams, are accountable for cyber risk

Boards, not just IT teams, are accountable for cyber risk

Tue, 25th Aug 2026 (Today)
Ben Mudie
BEN MUDIE Field CTO Asia Pacific and Japan Tenable

Boards are accountable for cyber risk, yet most treat it as the CISO's problem. As AI accelerates, exposure management can address serious AI governance issues

Under the rules of the Security of Critical Infrastructure (SOCI) Act, a responsible entity's board or governing body must approve the annual report on its own risk management program directly; not delegate the sign-off to management.  The same reforms set incident reporting windows of 12 hours for a significant impact and 72 hours for a relevant one, measured from when the entity becomes aware, not from when someone gets around to briefing the board. 

Under the Privacy Act reform, individuals can make a claim directly against an organisation for a serious invasion of privacy, and the Office of the Australian Information Commissioner has named reasonable steps to protect personal information as one of its active 2025–26 enforcement priorities. That obligation sits at the board level, not in the IT security team.

Despite these government mandates, most boards haven't rebuilt their governance to comply. The CISO still turns up, presents incident metrics and control coverage, takes a handful of questions about the last audit finding, and leaves. What tends not to happen in that meeting is any real discussion of what the organisation actually owns, where it's exposed, and what the board is attesting to when it puts its name on the audit report. That's a technical briefing standing in for a governance decision, and boards that treat the two as the same thing are the ones signing off on risks they can't see.

Where the exposure actually sits

The practical impact of board approval on cyber risk matters without the underlying visibility is that the CISO ends up carrying a decision the board made without full understanding. Tenable's research into the responsibility gap in organisations found that roughly half of the companies that adopted AI in some material form in the past year had also experienced a related security incident, while the governance structures meant to oversee that adoption hadn't moved at the same pace. That's not a failure of the security team. It's an AI governance issue at the board level.

A CISO briefing a board on compliance status and a CISO helping a board to fully understand its exposure are two different conversations. The first is a checklist: controls in place, audits passed, incidents logged. The second requires the board to see, in terms of what  it can act on, what's connected to what, which systems carry which regulatory exposure, and what closing a given gap would cost measured against leaving it open. Energy, healthcare, telecommunications and financial services boards all sit inside SOCI's mandatory reporting regime, and have no excuse for not having that second conversation.

What "governance partner" actually means

Making that shift doesn't start with a new committee. It starts with the board asking a different question: not are we compliant, but what do we own, and where are the gaps we haven't closed.

Tenable's guide for security leaders on building an exposure management strategy sets out what answering that question in practice actually requires: continuous visibility across identities and cloud and on-premise systems, not a point-in-time audit.

Boards that keep treating the CISO as the person who presents the numbers, rather than the person who tells them what the organisation owns, will keep signing reports on exposure they can't actually see. Under SOCI and the Privacy Act, that's simply not acceptable.