AIS Logo
← Back to Library
New Framing Dialogues on Cyber-Resilience on Boards
International Conference on Information Systems (ICIS) (2021) AI Processed Human Approved

Framing Dialogues on Cyber-Resilience on Boards

Sven-Volker Rehm, Laura Georg Schaffner, Lakshmi Goel
This study examines cybersecurity as a complex socially enacted context within organizational boards rather than a simple matter of technical infrastructure. Using the concept of technological frames, it investigates how individual, collective board, and regulatory cognitive models influence board dialogues and shape organizational cyber-resilience. Problem Non-executive board members often lack direct experience with cybersecurity technology, forcing them to rely on indirect proxies and cognitive interpretations. Consequently, cybersecurity dialogues at board levels frequently suffer from incongruent perspectives, resulting in superficial compliance checking, topic avoidance, or political maneuvering. Outcome - Identified three distinct technological frames operating in board discussions: Individual (I-Frame), Board (B-Frame), and Regulatory (R-Frame).
- Revealed dysfunctional dialogue patterns such as topic avoidance and political exploitation that hinder proactive cybersecurity governance.
- Emphasized the necessity of developing conversational guardrails to help boards re-frame discussions toward building true organizational resilience.
What it means for you
  • CIO / IT Executive: On Monday morning, prepare a concise, one-page executive summary for the board that translates the organization's current top 3 cyber threats into quantifiable business risks (e.g., potential revenue loss, reputational damage) and proposes specific, non-technical mitigation strategies with clear business outcomes. Avoid technical jargon; use analogies if necessary.
  • IT Manager: On Monday morning, gather a brief (5-minute) overview of the most recent significant cybersecurity incident (internal or external to the company) and identify one specific, tangible lesson learned that can be communicated to non-technical stakeholders without overwhelming them with technical details.
  • Business Strategist: On Monday morning, identify one strategic business objective for the upcoming quarter that is indirectly impacted by cybersecurity and brainstorm how a proactive cyber-resilience approach could enable or protect that objective. Frame this in terms of competitive advantage or market opportunity.
  • Researcher: On Monday morning, review the 'Key Findings' section of your research and identify one specific, actionable question from each identified dysfunctional dialogue pattern (topic avoidance, political exploitation) that you can pose to a board member to gently guide them towards a more resilient discussion.
  • Policymaker: On Monday morning, draft a short, one-paragraph statement for your next regulatory update that suggests a reporting framework for board-level cybersecurity oversight, focusing on the *outcomes* of cyber-resilience rather than prescriptive technical requirements.
Transcript
Host: Welcome to A.I.S. Insights — powered by Living Knowledge. I'm Anna Ivy Summers. Today, we're diving into an eye-opening study titled "Framing Dialogues on Cyber-Resilience on Boards." Joining me to break it down is our analyst, Alex Ian Sutherland. Welcome, Alex!

Expert: Thanks, Anna! It's great to be here.

Host: Alex, when most people think about cybersecurity, they imagine firewalls, software updates, and IT departments. But this study looks at it through a completely different lens—as a social process taking place at the highest levels of company leadership. What is this study really about?

Expert: You nailed it, Anna. Instead of treating cybersecurity as just a technical infrastructure problem, this study examines how organizational boards talk about it. It uses the concept of "technological frames"—which are basically the mental models or cognitive lenses people use to interpret technology—to see how board dialogues actually shape a company's cyber-resilience.

Host: That’s fascinating. But why is board dialogue such a problem when it comes to cybersecurity?

Expert: Well, according to the research cited in the study, even though cyber threats are soaring, many board members feel unprepared. In fact, in a survey of over 5,000 directors across 60 countries, cybersecurity preparedness ranked dead last among 23 board responsibilities.

Host: Dead last? Why is there such a massive disconnect?

Expert: Because non-executive board members rarely have direct, hands-on experience with the underlying technologies. They rely on indirect proxies, like high-level frameworks or security reports. So when cybersecurity comes up, board members are forced to make subjective, interpretive judgments. That leads to misalignments and what the study calls "equivoque" sensemaking—where everyone in the room is interpreting the issue through completely different lenses.

Host: So how did the researchers investigate what's actually happening in these boardrooms?

Expert: The researchers surveyed board members and conducted in-depth interviews with directors, security product CEOs, and incident management experts who serve on multiple boards. They analyzed these accounts to identify three key types of technological frames operating during board discussions.

Host: What are those three frames?

Expert: First, there's the Individual Frame, or I-Frame, which represents a board member’s personal background, assumptions, and awareness. Second, the Board Frame, or B-Frame, which relates to the board’s collective governance functions like oversight and strategy. And third, the Regulatory Frame, or R-Frame, which stems from formal compliance frameworks and reporting rules.

Host: And what happens when these three frames interact during a board meeting?

Expert: That's where things get tricky. The study revealed several dysfunctional dialogue patterns. For instance, an "avoidance pattern" often happens when individual board members lack technical depth. They get bogged down in granular, low-level questions—like asking about password policies—or they ask questions like, "Do we really have to document that we know this?" just to avoid liability.

Host: So instead of addressing real risk, they try to limit what's officially recorded?

Expert: Exactly. Another pattern identified in the study is "exploitation," where board members hijack cybersecurity discussions as a political lever to gain power or undermine colleagues, rather than focusing on protecting the firm.

Host: That sounds like a huge risk for organizations. What can business leaders and boards take away from this study to fix these dialogues?

Expert: The key takeaway is that simply bringing in outside experts or adding cybersecurity to the meeting agenda isn't enough to change mindsets. Boards need "conversational guardrails"—structured sets of questions and principles that help them re-frame discussions away from superficial compliance or political maneuvering, and toward building actual resilience.

Host: So it's about shifting the conversation from "Are we compliant?" to "How do we adapt and bounce back when an incident occurs?"

Expert: Precisely. Cyber-resilience isn't just a semantic issue that a meeting moderator can solve; it requires deeply re-framing how board members understand their role in managing indirect, complex technological threats.

Host: That is such an important perspective for modern corporate governance. Understanding how our mental frames shape our decisions is crucial, especially when technology moves faster than our direct experience with it. Alex, thank you so much for breaking down this study for us today.

Expert: My pleasure, Anna.

Host: And thank you to all our listeners for tuning into A.I.S. Insights — powered by Living Knowledge. Be sure to subscribe for more deep dives into business and technology research. Until next time, stay informed and stay resilient!
Cybersecurity, cyber resilience, boards of directors, technological frames, board dialogue