Council Post: ​Your Board Has A Financial Expert—Why Doesn't It Have A Cyber One?

August 2026 · 5 minute read

J Nathaniel Ader is the chief innovation officer and co-founder of Qtonic Quantum Corp. and author of "The Quantum Almanac 2026-2027."

getty

​Cybersecurity tends to land near the end of a board agenda, after the items that carry a vote. I have presented in that slot. The directors are prepared, the questions are sharp, and nearly all of them are about the last 90 days. "How did the incident take place? Which vendors did it impact? Has it been resolved?"

Those are fair questions. They are also the only questions a board can ask about a subject it has been taught by the person it is supervising.

In July 2023, the Securities and Exchange Commission finalized its cybersecurity disclosure rules and dropped one thing from the proposal. Item 407(j) would have required public companies to disclose whether any director had cybersecurity expertise. Commenters warned the disclosure could pressure companies to recruit from a limited pool of specialists. The Commission concluded that cybersecurity processes are largely administered by management and that directors with broad experience in risk management and strategy can often oversee sophisticated technical matters without specific domain expertise.

The Commission left the empirical question unresolved. Subsequent field evidence challenges that assumption.

A 2025 field study in Management Science by researchers at Virginia Tech interviewed 20 directors and 18 cybersecurity executives and senior consultants. It found that directors without cybersecurity expertise produce oversight that remains largely symbolic even when they undertake similar oversight activities to expert directors. The non-experts did not perceive the deficiency. The experts perceived it clearly. It is qualitative work with a small sample, and the authors caution that participants may carry self-serving biases and that the study does not establish the right mix of expertise.

The paper names the mechanism: circular governance. A board without expertise relies on the chief information security officer to explain the concepts, the risks, the program objectives and eventually the oversight process itself. The person being supervised ends up shaping the benchmarks and defining which risks are in scope. The structure produces the outcome on its own.

Then the proxy number. As background research, the authors analyzed 1,000 randomly selected proxy statements from the 2019 Russell 3000. Only 14.7% disclosed at least one director with cybersecurity or related skills and experience. All 1,000 disclosed a financial expert. That analysis used 2019 proxies, so it is a historical baseline, not a current count. Financial-expert disclosure was mandatory. Cyber-skills disclosure was voluntary. That asymmetry is the point.

After Sarbanes-Oxley, public companies had to disclose whether their audit committee included an audit committee financial expert, and explain why if it did not. We have never imposed an equivalent transparency discipline for cybersecurity or cryptographic expertise.

Post-quantum migration is a test case because it combines technical complexity, fixed external deadlines, procurement consequences and decisions that must be made years before they produce a visible incident.

Executive Order 14412, signed in June 2026, directs federal high-value assets and high-impact systems to use post-quantum cryptography for key establishment by the end of 2030 and for digital signatures by the end of 2031. It also directs the Federal Acquisition Regulatory Council to propose a rule requiring covered contractors to comply with applicable post-quantum Federal Information Processing Standards by the end of 2030. Separately, the Department of War's strategy says all department systems must support post-quantum cryptography or be phased out by the end of 2030 and must use it by the end of 2031, unless otherwise noted. Those are printed dates, not forecasts.

There is a second clock most directors have not seen. The same order directs CISA, in coordination with NIST, to publish guidance within 270 days on the minimum elements of a cryptographic bill of materials, and requires those elements to support automated assessment of the cryptographic assets inside a product. That deadline falls on March 19, 2027. Anyone who watched the software bill of materials travel from technical curiosity to contract clause can see the likely direction. The question may begin inside the security function, but it will increasingly be answered in procurement.

The exposure is not deferred to 2030. Encrypted traffic captured today can be stored and decrypted later, which turns a future cryptanalytic capability into a present question about data retention and vendor contracts.

Many boards will not reach any of this under the current agenda structure. A board with 20 minutes on security spends all 20 on the quarter, because that is what management is measured on and management heavily influences the agenda. A risk with a five-year fuse and no news cycle does not survive that filter. More agenda time yields a longer conversation about the same quarter.

Composition is a durable lever because it changes the questions before the agenda changes, and the specification matters. This is not a call to seat any technical credential. A former CISO may be expert in incident response and have never run an algorithm transition or a cryptographic inventory. What a board needs is broad operating and governance judgment combined with enough cryptographic and technology-transformation experience to test management's assumptions independently.

Two objections matter. The pool of such people is thin, and it will be thinner the year every board decides it needs one. A single specialist can also create a new kind of delegation, where the rest of the board quietly assigns cyber to the cyber director. The goal is not to give one person ownership but to introduce enough independent expertise that management's assumptions get tested while the full board keeps the responsibility.

In my experience, prudent boards begin succession planning 12 to 18 months before a vacancy, and major cryptographic migrations take years. The seating that arrives in time to shape these decisions rather than review them is the one you plan for now.

If your board has a financial expert and nobody who can interrogate a cryptographic road map, that is not an oversight. It is a decision about which failures you have equipped yourselves to see coming.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?