Board oversight and management's role
The SEC requires public companies to disclose the processes by which their board of directors oversees cybersecurity risks and the specific role management plays in assessing and managing those risks. This means you must document and describe who is responsible for cyber risk, how information flows from technical teams to leadership, and how the board exercises its oversight.
What it means
In practice, this requirement moves cybersecurity from a purely technical "IT issue" to a corporate governance obligation. The SEC wants to see that there is a structured relationship between the people managing the day-to-day security operations (management) and those responsible for the company's overall risk appetite and strategic direction (the board).
The scope includes identifying which management positions or committees are tasked with cybersecurity duties and describing the board’s expertise in this area. If the board relies on a specific committee or external experts to provide oversight, that mechanism must be clearly defined and operationalized.
Crucially, this is about the *process* of oversight. It is not enough to have a CISO; the organization must demonstrate how that CISO informs the board and how the board uses that information to make risk-based decisions regarding materiality and resource allocation.
How to meet it
- Define and document specific roles and responsibilities for cybersecurity within management, explicitly naming titles or committees (e.g., Risk Committee, CISO) responsible for assessment and mitigation.
- Establish a formal reporting cadence where management provides regular cybersecurity updates to the board or a designated subcommittee.
- Create a written framework for "materiality" that guides management on when a cyber incident or risk must be escalated from the technical level up to senior leadership and the board.
- Integrate cybersecurity into the broader Enterprise Risk Management (ERM) process rather than treating it as a standalone technical report.
- Document the board's approach to oversight, including how they evaluate management’s performance in managing cyber risks and their method for filling expertise gaps through external advisors.
Evidence an auditor asks for
- Board and committee meeting minutes showing cybersecurity was discussed, questions were asked, and decisions were made.
- Updated Board Charters or Committee Charters that explicitly include oversight of cybersecurity risk as a core responsibility.
- Organizational charts and job descriptions detailing the reporting lines between the CISO/security team and executive leadership/the board.
- Copies of management reports or dashboards presented to the board that track key cyber risk indicators and mitigation progress.
- The written policy or procedure used to determine if a cybersecurity event is "material" and requires escalation to the board.
Common pitfalls
- Treating oversight as a "checkbox" exercise where the board receives a report but there is no evidence of active questioning or governance.
- Failing to document the *process* of communication, leaving it to informal conversations that cannot be evidenced during an audit.
- Over-reliance on technical jargon in reports to the board, which prevents directors from exercising meaningful oversight because they do not understand the business risk.
- Lack of alignment between the reported governance structure and the actual daily operational reality of how risks are escalated.