Dave DeWalt, founder and CEO of NightDragon, on how to get a board to buy in on cybersecurity

Dave DeWalt, founder and CEO of NightDragon, on how to get a board to buy in on cybersecurity

🎙 CyberScoop 👥 1K 📅 August 22, 2025 ⏱ 29 min 👁 120 📄 interview 🧭 2026-08-17
Available in: English (current) Français

Keywords

board of directorscyber riskgovernancemetricsresilience

Summary

In this episode of Safe Mode, host Greg Otto first discusses election security with reporter Derek Johnson, focusing on President Trump’s proposal to ban mail-in voting and electronic voting machines, which is constitutionally unlikely to succeed. The main segment features an interview with Dave DeWalt, CEO of NightDragon, at Black Hat. DeWalt shares insights on how boards can better engage with cybersecurity, noting that the average Fortune 500 board spends less than one hour per year on cyber issues and that fewer than 5% have a cyber expert. He emphasizes the importance of governance, using ERM dashboards, and tracking KPIs for response and resilience. He advocates for board involvement in tabletop exercises and increased cyber education for directors. He also discusses his role on the Exelon board, highlighting the critical intersection of energy and cybersecurity, especially in light of threats like Volt Typhoon and the energy demands of AI data centers.

151 words

Critical Evaluation

Value of the Information & Strength of the Argument

The interview provides valuable, practical advice from a seasoned expert, offering concrete metrics (response time, recovery time) and governance structures (ERM dashboards, board committees) that boards can use. DeWalt’s argumentation is persuasive, drawing on his extensive experience and specific examples like the CrowdStrike outage and Volt Typhoon. He effectively makes the case that cybersecurity is a board-level risk that requires more attention and expertise. The discussion is well-structured, moving from the problem (lack of board focus) to solutions (metrics, education, exercises).

Scientific Rigor, Source Quality, Title Accuracy

The interview is based on DeWalt’s personal experience and observations, which lends credibility but lacks formal citations. He references specific threats (Volt Typhoon) and regulations (SEC, SOX) but does not provide detailed sources. The title accurately reflects the content. The election security segment is a news discussion with potential bias, but it is clearly separated from the interview. The overall rigor is moderate, with a reliance on anecdotal evidence rather than empirical data.

169 words

Title / Content Match

The title accurately reflects the main interview content, focusing on how to get board buy-in for cybersecurity.

Quality & Reliability

7/10

The interview features an experienced cybersecurity executive with 25 years in the field, providing practical insights on board-level cybersecurity governance. The discussion is grounded in real-world experience and references specific threats (Volt Typhoon) and regulations (SEC, SOX). However, the content is largely anecdotal and lacks rigorous data or citations, and the election security segment is a news discussion with potential bias.

Key Moments

Cited Sources

Concurring Sources

  • NIST Cybersecurity Framework — Supports the need for standardized cyber risk management.
  • SEC Cybersecurity Disclosure Rules — Aligns with the discussion on regulatory considerations.

Dissenting Sources

  • Election security claims — The election security segment discusses claims of voter fraud that have been widely debunked; the segment itself notes the lack of evidence.

Contribution & Novelties

The interview provides a unique perspective from a board member with deep cybersecurity expertise, offering actionable advice for boards and executives. It emphasizes the need for standardized cyber risk metrics similar to financial reporting and highlights the importance of board education and involvement in cyber exercises. The discussion on the energy sector’s cybersecurity challenges, particularly in light of AI data center energy demands, is timely and insightful.

Pour aller plus loin :

  • NIST Cybersecurity Framework — A widely used framework for improving cybersecurity posture.
  • SEC Cybersecurity Disclosure Rules — SEC rules requiring public companies to disclose material cybersecurity incidents.
  • Volt Typhoon — CISA advisory on Volt Typhoon, a Chinese state-sponsored threat actor targeting critical infrastructure.
  • CrowdStrike Outage — CrowdStrike’s statement on the July 2024 outage, illustrating vendor resilience challenges.

129 words

Radar Profile

The radar profile shows a balanced score across all dimensions, with slightly higher scores in quality and reliability, reflecting the expert's credibility. The lower score in technical level indicates that the content is accessible to a general audience, while still providing valuable insights for professionals.

Reliability 7/10

💬 No comments were provided for analysis.