top of page

Board Service From the Other Side of the Table

Updated: Jul 29

Over the years, I have served on nonprofit boards, built an organization alongside a board, worked directly with executives, and helped leaders think through cybersecurity and business risk.


6-months in, joining the ISC2 Board of Directors gave me a different view.


It moved me from working primarily inside organizations and programs to thinking more broadly about governance, oversight, long-term strategy, and the decisions that affect an international membership organization.


It has also been one of the most interesting learning experiences of my career.


There Is More Than One Kind of Board

When people say they want to join a board, one of my first questions is usually: What kind of board?

There are nonprofit and not-for-profit boards, public company boards, privately held company boards, private equity portfolio company boards, family business boards, and advisory boards.


The responsibilities, expectations, selection process, and compensation can be very different.


My earliest board experience came through nonprofit work. As CEO of the Women's Society of Cyberjutsu, I have spent years working alongside board members while building programs, managing growth, raising funds, serving members, and navigating organizational change. I understood what it meant to work with a board.


Serving on the ISC2 Board has allowed me to experience that relationship from the other side of the table. As an executive, I am responsible for helping move the organization forward. As a board member, my role is to provide oversight, ask questions, evaluate risk, and support the organization's long-term direction.


This has made me think more carefully about where governance ends and operations begin. The line can look clear on paper. It becomes more complicated when you are discussing real people, real money, real risks, and decisions that may affect the organization for years.

My Process for Joining the Board

My path to the ISC2 Board began with certification and membership in the organization.


That was an eligibility requirement for this particular board. Other organizations will have different requirements based on their bylaws, ownership structure, membership model, and governance process.


The process included submitting an application, being selected as a finalist, interviewing, participating in an election campaign for the membership vote, and completing the final eligibility and confirmation process.


The process required me to explain what I could contribute and why I was interested in serving.

It also required visibility. Members needed to know who I was, what experience I brought, and how I could support the organization. This is where you have to think beyond the résumé and speak clearly about the perspective you would bring to the boardroom.


That included my experience in cybersecurity, nonprofit leadership, workforce development, advocacy, business strategy, and organizational growth.


The Boardroom Expands the Conversation

One of the biggest shifts for me has been the way risk is discussed. In cybersecurity, we often talk about risk through vulnerabilities, threats, controls, incidents, and technical exposure.


At the board level, those issues connect to a much broader conversation.

  • How could this affect the organization's finances?

  • What does this mean for members or customers?

  • Could this create reputational damage?

  • Are we meeting our legal and fiduciary responsibilities?

  • Does the organization have the leadership, resources, and structure to respond?

  • How could this decision affect different countries, cultures, and communities?


Cybersecurity is part of the discussion, but it sits alongside finance, legal concerns, reputation, workforce, strategy, and the long-term health of the organization. Board service has made me more thoughtful about how security leaders communicate risk; identifying the problem is only part of the work. Leadership also needs to understand what the issue could mean for the business and what decisions may need to follow.


Learning From an International Board

One thing I will say: the amount of experience represented on the board is incredible. Each board member brings knowledge shaped by different industries, countries, cultures, professional disciplines, and leadership experiences.


The conversations include perspectives on business management, cybersecurity, workforce development, advocacy, finance, governance, risk, international operations, and member needs.


There are also differences in language, communication styles, cultural expectations, and how governance is understood across regions, challenging me to listen differently. Sometimes I enter a conversation believing an issue is fairly straightforward. Then someone raises a perspective based on their region, culture, or experience, and the conversation changes.


A policy or decision that seems clear in one country may land very differently somewhere else. It has made me more aware of context, and more thoughtful about how organizations communicate decisions and how those decisions may affect people across different regions.


Working With the CEO

The board is usually responsible for hiring the CEO — or the ED, or whoever leads the organization — and that person builds out their own team from there.

Working with ours has been one of the most valuable parts of this experience. Scott brings a wealth of knowledge and experience from his years in the Peace Corps that the board wouldn't otherwise have access to.


The board needs enough visibility to provide oversight and ask difficult questions. The CEO needs room to lead the organization and make operational decisions. That relationship depends heavily on communication and trust. The board needs honest information, especially when things are difficult. The CEO needs to know that the board can challenge a decision without stepping into day-to-day management.


Watching that relationship closely has helped me better understand how boards and executives work together around risk, strategy, performance, and the future of the organization.


What Committees Actually Do

Before joining a board, I had heard plenty of conversations about board committees.

Serving on them helped me understand how much of the board's work happens there.

Committees allow members to spend more time on specific areas such as finance, audit, risk, compensation, governance, nominations, bylaws, and investments.


Some are standing committees listed in the organization's bylaws or governance documents. Others may be created for a specific issue or period of time.


A bylaws committee, for example, reviews the organization's governing documents and may recommend changes. Depending on the organization, those recommendations may require approval from the board, the membership, or another governing body.


This year I am serving on the Risk and Governance committees.


Risk discussions consider the internal and external factors that could affect the organization's finances, reputation, strategy, operations, technology, members, and long-term sustainability.


Governance focuses on how the board operates. That can include bylaws, committee structure, board responsibilities, evaluations, nominations, succession, policies, and whether the current model still supports the organization's needs.


Before serving, governance could sometimes feel like documents, policies, and procedures. Once I joined the board, I saw how those documents shape real decisions: who has authority, how issues are escalated, how changes are approved, and how the board holds itself accountable.


Preparing Before the Opportunity Appears

Preparation started long before the board seat did. Several years ago, the Black Corporate Board Readiness (BCBR) training laid the groundwork: board responsibilities, terminology, financial discussions, governance expectations, and the kinds of conversations that happen at the board level. Around the same time, the inaugural MiC Lead cohort through Minorities in Cybersecurity added another layer: developing as a leader while building relationships with others aiming for executive and board service.


That development is ongoing now through the National Association of Corporate Directors (NACD) and Institute of Corporate Directors (ICD) training, podcasts, reading, and conversations with directors already in the room. The formal training builds the structure and vocabulary. The work experience is what actually gets used once you're seated at the table.


Cybersecurity gives me the technical grounding to speak to risk. Nonprofit leadership taught me mission, members, funding, workforce development, and organizational growth from the inside. Consulting and business work connects those decisions to operations and long-term strategy.

Knowing where that experience adds value and where it still falls short has taken just as much honesty as the preparation itself.


Networking and Visibility

There is no single path into board service. Some opportunities come through formal applications. Others come through professional relationships, referrals, board development programs, or conversations that happen over time.


I have learned to be more open about my interest in board service. Some of the most useful conversations have been with people who are already serving. They have helped me understand how opportunities come together, what boards are looking for, and where my own experience may fit.


If this is something you are interested in, be specific about what you are looking for. Saying, "I want to serve on a board," leaves a lot open. Being able to explain the types of organizations you are interested in and the experience you bring makes it easier for people to think of you when an opportunity comes up.


For me, that includes cybersecurity risk, AI governance, organizational transformation, workforce development, nonprofit leadership, and business strategy. The more I talk about board service, the more I understand the importance of relationships, visibility, and being able to communicate my value clearly. I have a coach that I work with on this clarity, Dominque West.


Board Service as Part of My Preferment Plan

If you aren't familiar with preferment, it's doing what you prefer to do in retirement vs what you have to do. Board service is also part of my preferment plan. T-shirt linked.


Yes, paid board work is a real thing.


For-profit boards may compensate directors through cash retainers, equity, meeting fees, committee compensation, or a combination of these. The structure depends on the company, its size, its stage, its ownership model, and what it needs from its board.

Here is one resource that provides an overview of board compensation:

On the other hand, many nonprofit board positions are voluntary. Some organizations may also expect board members to make personal contributions, support fundraising, or help attract sponsors and partners.


Paid board work appeals to me because it creates another way to use the experience I have built throughout my career, and it fits the future I am creating — one that includes advisory work, consulting, speaking, teaching, investing, community leadership, and board service.


I am not planning to stop working or contributing. I am creating more choices around the work I take on, the organizations I support, and how I use my time and experience.


Disclaimer: The ISC2 board is not a paid board.


Start Before the Opportunity Appears

For anyone considering board service, start preparing before the opportunity appears.

Learn about the different types of boards. Understand what they expect. Build relationships with people who are already serving. Think carefully about the perspective and experience you can contribute. And let people know that board service is part of your plan.


My board journey is still being written. And yes, I am still working toward that paid board seat.


Connect with me if you are exploring board service or building it into your own preferment plan.

Links

Black Corporate Board Readiness (BCBR) - https://www.scu.edu/execed/bcbr/

Decoded with Dominque - https://dominiquewest.com/

Minorities in Cybersecurity (MiC Lead) - https://www.mincybsec.org/


Comments


  • LinkedIn

©2020 - 2026 by A&M Strategies. Shop

bottom of page