Leadership1 distinct publisher3 min readPublished
The 2023 disclosure rules ask public companies to describe their cyber oversight without asking whether any director can judge it, and a 2025 field study finds that gap produces oversight that only looks like oversight.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
The mechanism the Virginia Tech researchers name deserves more attention than their headline finding. A board without its own expertise depends on the chief information security officer to explain the concepts, the risks, the program objectives and, eventually, the oversight process itself, so the supervised executive ends up setting the benchmarks and deciding which risks are in scope [7]. The result follows from the structure itself, not from any particular director's weakness or any executive's overreach. Convert the proxy percentage and the asymmetry gets concrete: 14.7% of 1,000 is 147, which leaves 853 companies that disclosed a financial expert and no director with cybersecurity skills [1]. The comparison is between a mandatory disclosure and a voluntary one [9], and the mandatory one carries teeth of a specific kind, since after Sarbanes-Oxley a company had to state whether its audit committee held a financial expert and explain itself if it did not [10]. Those proxies are from 2019, which predates the current rules, so the record supplied here does not tell us what the disclosure rate is now [9]. The Commission's own logic cuts against a single fix: boards oversee rather than operate, and a lone named specialist can become the director everyone else defers to, a new dependency rather than a cure. The comment file added a practical objection, that mandated disclosure would push companies to compete for a small pool of specialists [2], and the Commission's own reasoning was that directors with broad risk and strategy experience can often oversee sophisticated technical matters [3]. The study does not retire that view. Its authors interviewed 38 people in total, flag possible self-serving bias among participants, and decline to say what the right mix of expertise is [4][6]. What it does support is narrower and more usable: the deficiency sits in who supplies the frame, not in the titles on the roster. The board-deck answer is a technology or risk committee with a standing cyber item. It is incomplete for a specific reason. Ader, whose account of the agenda slot comes from presenting in it, describes cyber landing after the items that carry a vote, with nearly all the questions covering the last 90 days [16]. Ninety-day questions are the ones the reporting function has already prepared for. The remedies that need no rule change are structural: a committee that commissions its own assessment instead of receiving one, and a named director accountable for reading the technical material. Both cost something. A board seat spent on a specialist is a seat not spent on someone who knows the company's markets, and an independently procured review is a line item plus a strained relationship with an executive who did not choose it. One caveat on provenance. The argument as published is a contributed Forbes council column by J Nathaniel Ader, co-founder of a quantum computing firm and author of a quantum almanac [15], so the post-quantum framing arrives with an interest attached; the Commission's stated reasoning and the study he cites stand on their own. The calendar is where this quarter's structure meets next decade's bill. Executive Order 14412, signed in June 2026, sets end-2030 for post-quantum key establishment and end-2031 for digital signatures on federal high-value and high-impact systems [11], directs the Federal Acquisition Regulatory Council to propose a contractor compliance rule by the end of 2030 [12], and the Department of War strategy runs to the same pair of years [13]. Ahead of all of that, CISA and NIST owe guidance on the minimum elements of a cryptographic bill of materials, due March 19, 2027, specified to support automated assessment of the cryptographic assets inside a product [14].
Ranked by verification strength, evidence, and original report placement.
In July 2023 the SEC finalized its cybersecurity disclosure rules and dropped proposed Item 407(j), which would have required public companies to disclose whether any director had cybersecurity expertise.
Commenters warned that the proposed director-expertise disclosure could pressure companies to recruit from a limited pool of cybersecurity specialists.
The Commission concluded that cybersecurity processes are largely administered by management and that directors with broad experience in risk management and strategy can often oversee sophisticated technical matters without specific domain expertise.
A 2025 field study in Management Science by researchers at Virginia Tech interviewed 20 directors and 18 cybersecurity executives and senior consultants.
The study found that directors without cybersecurity expertise produce oversight that remains largely symbolic even when they undertake similar oversight activities to expert directors; the non-experts did not perceive the deficiency, while the experts perceived it clearly.
The study is qualitative work with a small sample, and its authors caution that participants may carry self-serving biases and that the work does not establish the right mix of board expertise.
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Agents Took 150GB From Nine Mexican Agencies. The EU Deadline Just Slipped to 20271 distinct publisher
leadership
The SEC stopped grading proxy exclusions. Now the board's lawyers do.1 distinct publisher
build
NIST answers an NVD audit with an AI tool nobody outside NIST has seen1 distinct publisher
leadership
Harvest now, decrypt soon: post-quantum migration is a funded program, not a research topic1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Documentary spine, single narrator
The bones of this story are checkable documents — the July 2023 adopting release, Executive Order 14412, a peer-reviewed Management Science paper — and that is why it holds up as well as it does. But every one of them reaches the reader through one contributor's paraphrase, and the two most quotable elements are weaker than they look: 14.7% comes from background research inside the study, not a fresh count, and March 19, 2027 is the author's own arithmetic off a 270-day clock.
14.7% in 2019, uncounted since
The only measurement of boards actually seating cyber expertise is seven years old and drawn from a voluntary disclosure regime, which almost certainly undercounts. Nothing in this reporting tells us what happened after the 2023 rules took effect. On the cryptographic side there is no adoption at all yet — the 2030 and 2031 dates and the March 2027 guidance deadline are obligations on a calendar, not systems in production.
Caveated, then generalized anyway
Give the column its due: it flags the study as small and qualitative, calls the proxy figure historical, and insists the federal dates are printed rather than forecast. The stretch happens above that fine print. Thirty-eight interviews and a 2019 sample become a claim about how public-company boards oversee cyber risk generally, and the leap from a CISA guidance document to a contract clause in procurement is an analogy to SBOM doing the work of evidence.
The byline sells the remedy
The prescription — boards need cryptographic and technology-transformation expertise, and post-quantum migration is the test case — happens to be the market of the man writing. He co-founded a quantum company and wrote a quantum almanac, and Forbes' council format puts that byline in front of exactly the readers who buy such advice. Credit where it is due: the affiliation appears in the first line, and the argument leans on someone else's peer-reviewed study rather than his own product. But no editor or second source is visible standing between the thesis and the business case.
Facts checkable, thesis untested
We can be fairly sure of what the SEC dropped, what the executive order orders, and what the Virginia Tech researchers concluded. We cannot yet be confident that dropping Item 407(j) is why oversight goes symbolic — that causal step joins one small qualitative study to one practitioner's account of board agendas, published by a single outlet with a commercial interest in the answer.