Study: 88% of S&P 500 company boards don't have a director with direct cybersecurity experience; only seven companies have a current or former CISO on the board
James Rundle / Wall Street Journal :
Context & Ripple Effects
The finding sharpens an existing governance gap: earlier research found cybersecurity experience accounted for just 14% of new Fortune 500 directors in 2022, down from the prior year. It also distinguishes direct practitioner experience from the broader expertise that 76% of directors said their boards possessed in a pre-regulation board survey.
That distinction matters because board-level cyber oversight is being assessed while reporting expectations are becoming more formalized. The limited presence of current or former CISOs suggests that operational security leadership has not yet translated into a common board credential.
First-order effects
- Most S&P 500 boards must oversee cyber risk without a director whose background is direct cybersecurity practice; only seven have a current or former CISO.
- The study makes the scarcity of CISO-to-board appointments visible, giving nominating committees and investors a clearer benchmark for evaluating cyber-governance depth.
Second-order effects
- Boards may rely more heavily on external advisers or broader risk and technology directors when testing cyber oversight, rather than adding a dedicated security practitioner immediately.
- The gap increases the strategic value of experienced CISOs as prospective directors and puts pressure on director-search pipelines to surface candidates with operational security backgrounds.
Third-order effects
- If disclosure and oversight expectations continue to rise, cybersecurity expertise could become a more distinct board-composition category rather than being folded into general technology or risk experience.
- The pattern points to cyber resilience becoming part of corporate competitive positioning: firms able to translate security operations into credible governance may differentiate their risk-management posture.
The trend: Cybersecurity is moving from a specialist operational function toward a board-level governance credential, though direct practitioner representation remains limited.