Cybersecurity Begins in the Boardroom

Microsoft 365
Jackie Bilodeau

Written by Jackie Bilodeau

I am the Communications Director for CGNET, having returned to CGNET in 2018 after a 10-year stint in the 1990's. I enjoy hiking, music, dance, writing, cheering on Bay Area sports teams, and traveling near and far as much as I can. Read more about my work at CGNET here.

August 4, 2026

Most nonprofit boards spend their meetings talking about budgets, fundraising, programs, staffing, and long-term strategy. All of those deserve attention. But there’s one topic that still gets pushed aside far too often: cybersecurity.

The irony is that a cyberattack can disrupt every one of those priorities. A ransomware attack can halt operations for days. A compromised email account can expose donor information. A successful phishing scam can lead to financial losses, damaged reputation, and countless hours of recovery. Yet many organizations only discuss cybersecurity after something has already gone wrong.

The good news? Boards don’t need to become technology experts. They just need to make cybersecurity a regular part of the conversation.

Five Minutes Is Enough to Make a Difference

Adding a five-minute cybersecurity update to every board meeting creates something incredibly valuable: consistency.

Instead of treating cybersecurity as a once-a-year presentation filled with technical jargon, it becomes an ongoing governance issue—just like finances or compliance. Small, regular conversations keep risks visible and help board members ask better questions over time.

Those five minutes don’t have to be complicated. In fact, they shouldn’t be.

What Should Be Covered?

A brief cybersecurity update might include topics such as:

  • Have we experienced any security incidents or attempted attacks since the last meeting?
  • Are there any new threats that could affect organizations like ours?
  • How are employee cybersecurity training and phishing test results looking?
  • Are all critical systems fully patched and protected?
  • Have we completed or scheduled any important security improvements?
  • Is there anything the board should approve or be aware of?

That’s it. Five minutes. A handful of straightforward questions. But over the course of a year, those conversations build awareness and reinforce accountability.

Cybersecurity Is a Governance Issue

One of the biggest misconceptions about cybersecurity is that it’s solely the responsibility of the IT department. It isn’t. Technology teams manage security, but boards govern organizational risk. Cybersecurity now sits alongside financial oversight, legal compliance, insurance, and business continuity as one of the organization’s core governance responsibilities.

Board members don’t need to understand firewalls, encryption, or zero-trust architecture. They do need confidence that appropriate safeguards exist, that risks are being managed responsibly, and that leadership has a plan if something goes wrong. Those are governance questions—not technical ones.

Small Conversations Prevent Big Surprises

Many organizations discover cybersecurity weaknesses only after a crisis. The board learns about outdated systems, missing backups, or inadequate training during the worst possible moment—when attackers have already taken advantage of them.

Regular discussion helps prevent those surprises. When cybersecurity is reviewed every meeting, issues tend to be identified earlier, budgets become easier to justify, and security improvements happen incrementally instead of during an emergency.

It’s much easier to approve multifactor authentication, better backups, or security awareness training before they’re urgently needed than after a ransomware attack.

A Culture of Security Starts at the Top

Employees notice what leadership pays attention to. When cybersecurity appears on every board agenda, it sends a clear message throughout the organization: protecting data, donors, clients, and operations is everyone’s responsibility. That simple shift helps create a stronger security culture than any annual training session ever could.

The Bottom Line

Cybersecurity doesn’t need to dominate every board meeting. It just needs a permanent seat at the table.

Five minutes is enough to review current risks, ask a few important questions, and ensure the organization continues moving in the right direction. Those brief conversations can dramatically improve preparedness while helping the board fulfill one of its most important responsibilities: protecting the organization’s mission.

Because in today’s world, cybersecurity isn’t just an IT issue—it’s a board issue.

 

 

For forty-three years, CGNET has provided state-of-the-art IT services to organizations of all sizes, across the globe. We’ve done it all, from IT and cybersecurity assessments to cloud services management to generative AI user training. Want to learn more about who we are and how we might be able to help you? If so, check out our website or send us a message!

 

You May Also Like…

You May Also Like…

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Translate »
Share This
Subscribe
CGNET
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.