Why Boards Cannot Act on Technical Cyber Reports and What CISOs Must Do Instead

Boards across the GCC are asking CISOs how much a ransomware attack would cost. Most security teams cannot answer in financial terms. Here is why that gap exists and what needs to change.

Layla Haddad
Cyber Policy & Digital Risk Correspondent4 min read
Presenting cyber risk quantification dashboard to corporate board in a modern executive boardroom

Presenting cyber risk quantification dashboard to corporate board in a modern executive boardroom

There is a growing tension in boardrooms across the GCC and globally. Directors ask their security teams how much a ransomware attack would cost the organisation. What they receive in response is a red, amber, or green risk dashboard that tells them nothing useful about capital allocation.

The gap is structural. Most security risk reporting tools generate technical output. Converting that output into financial risk exposure requires a separate modelling exercise, typically done in spreadsheets using industry assumptions that bear little resemblance to the specific risk profile of the organisation in question.

The result is that cyber risk remains a technical conversation rather than a governance conversation, even as regulators and investors increasingly expect boards to be able to demonstrate that they understand and have provisioned for the financial exposure that cyber threats represent.

Why qualitative reporting is no longer sufficient

The distinction between qualitative and quantitative cyber risk reporting matters increasingly in 2026. Qualitative reporting, based on subjective severity ratings and red-amber-green frameworks, produces risk awareness. Quantitative reporting, grounded in actual loss data, threat probabilities, and asset values, produces the input boards need to make investment prioritisation decisions.

This matters practically. When M&S disclosed that a cyber incident had contributed £131.3 million in direct costs and a 23.8% fall in adjusted profit, that was the kind of financial evidence that moves boards to act. For any organisation that has not already experienced that level of disruption, the challenge is producing credible financial estimates before the event rather than after it.

The most defensible method for doing so is probabilistic financial modelling. Running thousands of randomised attack scenarios against an organisation's actual asset values, threat frequency data, and control effectiveness ratings produces a probability distribution of financial losses. A board told that there is a 30% probability of a £10 million loss from a specific ransomware scenario has something it can act on. A board told that ransomware is a "high" risk does not.

The data integration problem

Producing that kind of output requires merging technical security data with business context: asset criticality classifications, data sensitivity tiers, revenue dependency maps, and historical incident cost data. Most organisations do not have these data sources in the same environment, which is precisely why the spreadsheet workaround persists.

Emerging platforms are beginning to address this by placing security posture data, asset data, and business impact data in a single governed environment, allowing risk leaders to query across all three simultaneously. For CISOs in the GCC, where regulatory frameworks from the UAE Cyber Security Council and the Saudi NCA are increasingly moving toward quantified risk disclosure requirements, that capability is becoming a compliance necessity rather than a competitive advantage.

What good board reporting looks like

Effective cyber risk governance for boards depends on a tiered reporting cadence: a quarterly full briefing covering strategic risk posture, a monthly operational review tracking trend lines, and ad hoc reporting triggered by significant incidents or material shifts in the threat landscape.

Each of those briefings should anchor to financial terms. Time to detect, time to contain, and time to recover for critical services should be expressed alongside the revenue and cost exposure those timelines represent. Scenario-based communication, showing the expected financial impact of the top three or four threat scenarios relevant to the organisation's actual risk profile, allows directors to connect security posture to capital decisions in a way that abstract frameworks do not.

For enterprises operating across multiple GCC jurisdictions, including those with exposure in Dubai, Riyadh, and Abu Dhabi, the additional complexity of cross-border regulatory obligations and multi-jurisdiction incident notification requirements reinforces the case for standardised, data-grounded risk reporting rather than country-by-country technical summaries that boards cannot compare or consolidate.

The organisations that get this right are not necessarily the ones with the largest security budgets. They are the ones that have made the translation from technical security data to financial risk language a deliberate, systematic capability rather than an occasional exercise done in preparation for a board meeting.

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.

Intelligence Focus Areas

cyber risk quantificationBoard-Level CybersecurityCISO Intelligence MENAEnterprise Resilience 2026Security Leadership GCC