Christopher Hetner has seen the board conversation from every seat: building New York City data centers in the nineties, running global information security at GE Capital, advising two chairs of the SEC as senior policy advisor, and three years inside the insurance industry learning how brokers and carriers actually price cyber exposure. Today he is Chief Cyber Advisor at World Wide Technology, Cyber Risk Advisor to the National Association of Corporate Directors and its roughly 25,000 members, and chair of the AI and Cyber Insights Council for the NASDAQ Center for Board Excellence. In this conversation, Chris and Taylor dig into the numbers behind the board disconnect: roughly 70 percent of directors are still not in tune with how cyber and AI materially impact the business, many CISOs get 20 minutes with the audit committee once a year, and AI has compressed attack reconnaissance from months to minutes. Chris lays out the fix layer by layer. Build an enterprise risk management structure even when no regulator requires it, with a charter, a risk register, and the heads of the business in the room. Quantify exposure with annual loss expectancy analysis benchmarked to your peer group, in the same categories the insurance markets use. Then go the step further that traditional models skip: tell the board where to deploy capital, and trend the exposure down quarter over quarter. Also in here: why the CISO should never report to the board alone, the professionalization problem behind slow risk quantification adoption, treating AI agents like employees who commit agent error, and why post-quantum readiness has to start now. If you present to a board, sit on one, or want to someday, this episode is a masterclass. Chris's path: NYC data centers, GE Capital global CISO, senior policy advisor at the SECWhy sophisticated boards still struggle: business lens, not bits and bytesThe 70 percent problem and governing on 20-year-old assumptionsReconnaissance compressed from three or four months to minutesThe isolated CISO: M&A blind spots, inflated budgets, reactive postureBuilding enterprise risk management without a regulatory mandateCharters, risk registers, and the COSO frameworkReporting in tandem with the CFO, chief risk officer, and heads of businessAnnual loss expectancy analysis and the insurance markets as the ultimate arbiterPeer group benchmarks: why pharma, hospitals, and trading platforms all look differentGoing beyond FAIR: substantiating loss and directing capital"A language that we understand": what changes for the boardWhy cyber risk quantification adoption is still low, and the tactical CISO problemCulture and tone from the topAI agents as employees, agent error, and agentic-to-agentic monitoringQ-day and starting post-quantum readiness now Christopher (Cristobal) Hetner is the Chief Cyber Advisor at World Wide Technology, Cyber Risk Advisor to the National Association of Corporate Directors, and chair of the AI and Cyber Insights Council for the NASDAQ Center for Board Excellence. His nearly 30 years in cyber and technology include building data centers in New York City, serving as global CISO at GE Capital, four years as senior policy advisor to two chairs of the SEC, and three years working with major insurance brokers and carriers on sizing cyber exposure. He also advises the Cyber Future Foundation and engages roughly a dozen boards a year as an independent expert. Chris on LinkedIn: Christopher Hetner