Skip to content
BIZENIUS

How a CIO briefs the board: altitude, honesty and never a demo

BIZENIUS Advisory Team · Last updated: 3 September 2026

Written and reviewed by the BIZENIUS advisory practice — senior practitioners from risk, treasury, finance and supervision.

What a CIO board presentation is for, why boards are shown demos instead of told the truth, how cyber accountability is divided between the CIO, the CISO and the board, and what a technology report to the board should volunteer before the question is asked.

In short

  • A CIO briefs the board so that the board can answer three questions it will be held to: whether the institution is investing in the right technology, whether it is safe, and what happens when it stops. Anything that does not serve one of those does not belong in the briefing.
  • The demo is the CIO’s characteristic failure: the board is shown something that works because telling it what does not is harder. A board that has seen a demo knows less than before it walked in.
  • Altitude means investment, risk and capability, never systems. The board cannot convert a platform name into a decision; it can convert a portfolio, an exposure or a foregone capability into one.
  • Cyber accountability is divided, and the division must be stated: the CISO answers for the defence, the CIO answers to the board for the exposure, and the board answers for what it has chosen to accept.
  • The briefing that earns trust volunteers: the question the board should have asked is raised by the CIO first, and bad news arrives from the seat before it arrives from anywhere else.
On this page
  1. What the briefing is for
  2. The demo
  3. Altitude
  4. Honesty, and who answers for cyber
  5. What to volunteer
  6. What to do next

What the briefing is for#

A CIO briefs the board so that the board can answer three questions it will be held to: whether the institution is investing in the right technology, whether it is safe, and what happens when it stops. That is the whole purpose. The briefing is not a progress report on the technology function, not an education in what the estate contains, and not a showcase. Anything in it that does not help the board answer one of the three questions is taking up time the board needed for the answer.

Boards know this. They rarely say it, because technology has historically arrived at the table in a language they do not speak, and a board that cannot follow a presentation tends to thank the presenter rather than interrupt. The silence is not approval. It is the sound of a board that has decided to ask its questions somewhere else.

The demo#

The demo is the CIO’s characteristic failure, and it is worth understanding why it happens rather than simply forbidding it. A demo is offered because it is the easiest true thing to show. Something works; here it is working. The alternative — telling the board what does not work, what it is exposed to and what it will cost — is harder to prepare and harder to say, and the demo fills the slot so that the harder thing never has to be said.

A board that has seen a demo knows less than before it walked in. It has been given an impression of competence in place of an answer, and it will carry that impression until the day the estate stops, when it will remember the demo and not the briefing that should have replaced it.

A board that has seen a demo knows less than before it walked in.

Altitude#

Altitude is the discipline of presenting the estate as investment, risk and capability, never as systems. The test is simple: could a director convert each statement into a decision? A platform name cannot be converted into anything. A portfolio — this much to run, this much to grow, this much to transform, and here is what the mix says about us — can be. So can an exposure stated as what the board is being asked to accept, and a foregone capability stated as what the institution cannot currently do and what it would cost to be able to.

Altitude also governs what is left out. The board does not need the architecture, the roadmap by quarter or the vendor comparison. It needs the three answers, the decisions it is being asked to take, and the things it would be embarrassed to learn later from someone else.

Honesty, and who answers for cyber#

Honesty in the briefing is most tested on cyber, because cyber is where the CIO is most tempted to step aside and let the chief information security officer speak. The division of accountability must be stated to the board in plain terms, and the CIO must state it.

  • The CISO answers for the defence: its design, its operation and its quality.
  • The CIO answers to the board for the exposure: what the institution could lose, where it is concentrated, and what has been rehearsed for the day it stops.
  • The board answers for what it has chosen to accept, which it can only do if the exposure has been stated to it in terms it could refuse.

An executive who hides behind the CISO has delegated the conversation and not the risk. The board will discover the difference on the day it matters, and it will hold the CIO to the accountability the CIO declined to state.

What to volunteer#

The briefing that earns trust volunteers. There is always a question the board should have asked and did not — about concentration in a provider, about a component nobody can patch, about an adoption that is theatre rather than capability, about what was learned the last time something stopped. The CIO who raises it first has told the board something it could have learned elsewhere, and a board that learns of risk from its CIO trusts the seat in a way that a board which learns of it from the press never will.

The same holds for bad news. Delivered early, from the seat, with the exposure stated and the options costed, it is the strongest evidence a board can receive that the seat is held. Delivered late, or discovered, it ends the trust the briefings were meant to build.

What to do next#

Take the last technology paper that went to the board and strike out every system name. What remains is the briefing the board actually received. If it does not answer the three questions, state the cyber division of accountability and volunteer at least one thing the board did not ask, the next paper is the place to start — and the directors’ side of the same conversation is set out in Board risk oversight: the questions directors should be able to answer. The CIO Mandate works the craft of briefing a board — altitude, honesty, never a demo — with technology leaders who answer for outcomes.

Frequently asked

What should a CIO include in a board presentation?

The answers to three questions — is the institution investing in the right technology, is it safe, and what happens when it stops — presented as investment, risk and capability rather than as systems; the decisions the board is being asked to take; the division of cyber accountability between the CIO, the CISO and the board; and at least one thing the board did not ask but should have. Not the architecture, the roadmap or a demo.

Why should a CIO never give the board a demo?

Because a demo replaces an answer with an impression. It shows something that works because telling the board what does not work, what it is exposed to and what it will cost is harder. A board that has seen a demo leaves with less than it needed, and will remember the demo on the day the estate stops.

Who is accountable for cyber risk at board level?

The accountability is divided and the division must be stated. The chief information security officer answers for the defence. The chief information officer answers to the board for the institution’s exposure — what it could lose, where it is concentrated, what has been rehearsed. The board answers for what it has chosen to accept, which requires the exposure to have been stated in terms it could have refused.

How should a CIO report technology risk to the board?

As what the board is being asked to accept: where the estate is concentrated, what cannot be patched or replaced, what would happen on the day it stops and what has been rehearsed for that day. Stated early, from the seat, with options costed. A board that learns of a risk from its CIO trusts the seat; a board that learns of it from elsewhere does not.

More where this came from

Browse the full resources hub, or subscribe in the footer for occasional substantial pieces.

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.