Blog de Zscaler Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler An Analysis of Board-Level Cybersecurity Risk Oversight Key Points: - Audit First Approach: The majority—almost four in five—of S&P 500 companies oversee cybersecurity risk from the Audit committee. - Picture Still Fragmented Outside Audit: Fewer than one in ten companies oversee cyber risk from the Risk committee, though among financial services companies this rises to 39%. Fewer than one in 20 oversee cyber risk from the full board level. - Converging on Audit Committee Oversight: Since 2024, the number of companies overseeing cyber risk from the Audit committee has increased. Fewer companies now formally assign oversight to the full board or a technology/cybersecurity committee. - Potential Oversight Gap: When cyber oversight sits within the Audit committee, boards may be viewing a fast-moving, highly technical risk through a narrow lens as part of an already-crowded agenda. Research Findings: Zscaler analyzed Securities and Exchange Commission disclosures (primarily 10-K and proxy statement filings) from S&P 500 companies to understand cyber risk oversight at the board level. The research highlights how leading public companies on the S&P 500 index are increasingly converging their cyber risk governance around the Audit committee. As of March 1, 2026, 79% oversee cybersecurity risk via the Audit committee. Of the remainder, 8% perform oversight of cyber risk from the Risk committee, 6.2% from a technology/cybersecurity committee, and 3.8% from the full board level. A small number of other companies oversee the risk from Safety/Operations, Governance/Nominating or Compliance/Regulatory committees. Oversight Option | 2026 Result (%) | 2024 Result (%) | |---|---|---| Audit | 79% | 71.2% | Risk | 8% | 8% | Technology/Cyber | 6.2% | 7.2% | Full Board | 3.8% | 8.2% | Safety/Operations | 1.6% | 2% | Governance/Nominating |