The SEC Won't Name Your Board's Cyber Expert. It Will Name Your CISO.
September 25, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Does the SEC require a certified cybersecurity expert on your board? No. The Commission scrapped that proposal in 2023. But it kept a different requirement that matters more: naming, in public filings, the specific executive responsible for cyber risk and describing that person's expertise. That executive is usually your CISO, and the SolarWinds case just showed what happens when the disclosure and the expertise don't match up.
Why did the SEC drop the board expertise rule in the first place?
The Commission worried the proposal would backfire. In a 2023 speech explaining the final rule, SEC official Erik Gerding noted that the Commission removed a proposed requirement that public companies disclose whether any board members have cybersecurity expertise, out of concern that it would pressure companies into hiring a token board expert while diverting spending from actual security investment.
That decision shifted the weight of disclosure downward, from the boardroom to the executive floor. Instead of naming a board-level expert, Item 106 of Regulation S-K requires companies to describe management's role and expertise in assessing and managing cybersecurity risk, including which positions or committees hold that responsibility. The rule text is specific about what counts as expertise: prior work experience, relevant degrees, and certifications.
What does Item 106 actually make a company put in writing?
It makes a company identify the people accountable for cyber risk and justify why they are qualified to hold that job. Annual filings must lay out the company's processes for assessing, identifying, and managing material cybersecurity risks, along with any material effects on the business, and must describe management's expertise in plain terms investors can evaluate.
PwC's guidance to public company clients puts the practical question directly to boards: how will directors individually and collectively confirm that they continue to learn, and will they attend classes or other kinds of training? That question does not go away just because the board itself is not required to disclose a named expert. It just moves to whoever is named as management's cybersecurity lead, and that person's credentials become part of the public record the moment the 10-K is filed.
The SolarWinds case changed what "named" means
Disclosure risk used to feel abstract. It stopped being abstract in October 2023, when the SEC filed a civil complaint that named SolarWinds and its Chief Information Security Officer, Timothy Brown, as defendants, alleging that public statements about the company's security practices were misleading. It was the first time the agency had brought securities fraud claims against an individual CISO over cybersecurity disclosures, according to an analysis from Perkins Coie.
A federal judge dismissed most of the claims in July 2024, and the SEC later agreed to end the remaining claims against the company and its CISO. That outcome has been read as a retreat from aggressive enforcement theories, not a retreat from the underlying exposure. The court still found that the SEC had adequately pled claims tied to the company's prior public representations about its cybersecurity practices and policies. The lesson for any executive whose name ends up in a filing is not that the risk disappeared. It is that the standard for what counts as a defensible public claim about your security program just got tested in court, and the person whose expertise backs that claim is exposed personally, not just professionally.
Why the named executive's credentials are now a governance decision
Nominating committees and general counsel now treat certification as more than a resume line. It is documentation that supports the expertise claim a company makes about itself in a public filing. Governance research backs this up: one analysis of board composition trends found that 86% of Fortune 100 companies now seek cybersecurity expertise on the board or in leadership biographies, and the same report puts the average cost of a data breach at $4.44 million globally, a figure that raises the stakes on getting the disclosure right the first time.
This is where the choice of certification stops being a personal career decision and becomes a company decision. A CISO named in a 10-K needs credentials that map to the disclosure language the SEC is looking for, meaning governance, risk management, and program oversight rather than pure technical depth. Programs built around that scope, such as ISACA's CISM or EC-Council's Certified Chief Information Security Officer track, exist specifically to validate the executive-level judgment the rule is asking companies to describe.
That is a different bar than the one most technical staff train for. A network engineer's certification proves they can configure a firewall correctly. A CISO's certification, when it shows up in a governance filing, is functioning as evidence that the company did its diligence before putting someone's name on a public disclosure. If your organization has not mapped which certifications your named executives actually hold against what your filings claim about their expertise, that gap is worth closing before an incident forces the comparison for you.
What this means for how you build the team around your CISO
The disclosure obligation does not stop at the top of the org chart. Item 106 also asks how cyber risk information moves between the people managing it day to day and the people signing off on it, which means the analysts, architects, and managers underneath your named executive need credentials that support the chain of accountability, not just the top line. A CISO with a strong governance certification backed by a team with no formal security credentials is a harder story to defend under scrutiny than one where the whole reporting structure can show relevant training.
Building that bench does not require guessing at what to prioritize first. A curriculum overview that maps entry-level, analyst, and management-track certifications against actual job responsibilities gives you a clearer starting point than treating certification spend as one undifferentiated line item. If you are the executive whose name might end up in a filing, or you are advising one, you can start training toward the credential that matches the scope of what you are actually being asked to attest to.
The practical takeaway for leadership
The SEC did not eliminate the pressure to have a documented cybersecurity expert, it just moved where that documentation has to live and who is personally on the hook for it. A board can decline to name an internal expert. A CISO named in a 10-K cannot decline to have their expertise described, and after SolarWinds, that description carries more legal weight than it used to. Treat certification decisions for named executives as a governance control, not a training budget line, and revisit them every time your disclosure language changes.