A threat report hands the risk back to the board. It lays out what is out there and leaves the decision to someone else. Security leader Kris Boike says this is why so many technologists never move from reporting to the board to deciding with it. “Boards don’t want a threat report,” Boike says. In her view, they want someone who will absorb the ambiguity and return a recommendation worth acting on.
Boike, Head of Information Security at Dorsey & Whitney and a former chief information officer, has spent more than 25 years leading cybersecurity, infrastructure, and risk programs for Fortune 10 and Fortune 50 organizations, including the Federal Reserve System. The seat at the strategic table goes to whoever will own a decision, as she explains here.
Speak the Language of Board Risk
Framing security in business terms is usually taught as translation, the same facts rendered in a vocabulary the board understands. Boike is after something harder than vocabulary. A leader who frames a risk around revenue, reputation, and growth, and against the organization’s stated appetite for it, has done more than change words. They have taken a position.
“You stop sounding like a technician,” she says, “and you start sounding like a strategist.” A technician presents the full picture and lets others choose, which keeps the technician safe when the choice goes poorly. A strategist commits to a direction before the outcome is known and accepts the exposure that comes with it. That exposure is the price of the seat.
Lead Transformation That Serves the Business
The strongest security leaders tie every initiative to where the company is going, not to the internal priorities of their own function, and Boike reads that alignment as proof of range. Building a scalable, defensible strategy inside a heavily regulated environment shows a board what it is actually assessing: whether a leader can be trusted with decisions that reach past their domain. A program run as a self-contained technical operation shows a board only that its leader is competent within a boundary. What the board is actually weighing is whether that leader will carry a consequential decision past the boundary and stand behind it.
Bring a Governance Perspective Boards Can Trust
Directors value fresh judgment on how an organization governs its security and infrastructure. What earns their trust is not a flawless technical assessment, but clear judgment paired with an achievable vision. A board can find technical assessments anywhere. What it cannot easily find is someone who will tell it plainly what to do and what is realistically within reach, and then be accountable for both.
That willingness to commit to an achievable direction turns a security leader into the person leadership calls when the stakes are highest. Earning the seat comes down to a single move. “Move from managing technical risk to shaping business direction,” Boike says, “and the boards will see you as one of their own.”
The expertise was never in doubt. What a board is waiting to see is whether a leader will step out from behind the report and own the decision it was describing. To learn more, connect with Kris Boike on LinkedIn or visit Dorsey & Whitney LLP.









