Contents
Get a Personalized Demo
See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

John White is the Field CISO for EMEA at Torq. A respected security executive with more than 20 years of leadership experience, John previously served as CISO at Virgin Atlantic, where he led a multi-year transformation deploying the Torq AI SOC Platform to modernize cyber operations. Prior to that, he built and transformed security functions for global organizations, including ASOS, Liberty Global, AEG Europe, and KPMG.
I’ve briefed a lot of boards, and I’ve watched plenty of sharp security leaders lose one. The strategy was sound and the spend was justified, but the room still went quiet in the wrong way because the briefing was built for a SOC standup rather than a boardroom.
Every serious conversation about AI in the SOC eventually reaches the board. Whether it lands depends on two things: a platform that can back the claims, and the language you use to make them. After 20+ years on the practitioner side, here are the four frames I’ve watched directors actually respond to, and the words I’d leave outside the door.
If you’ve followed this series, you know the scenario: More than 100 vendors now claim the “AI SOC,” most stop at triage or bolt chatbots onto legacy systems, and the AI SOC Apocalypse Manifesto laid out how to tell the real platforms from the pretenders. The boardroom is where all of that noise turns into a budget decision. Brief it well, and the platform you chose becomes an obvious yes. Brief it badly, and you hand the room a reason to wait another year, while attackers keep moving at machine speed.
Frame 1: Value and ROI
Boards don’t fund security. They fund business outcomes, and your AI SOC story has to connect to value creation as tightly as it connects to risk. The question in the room is simple: what do we get, and what does it cost?
So give them the all-in numbers, framed as risk-adjusted ROI. In plain terms, that’s three things:
- What the AI SOC delivers (faster containment, more threats handled, capacity recovered without new hires)
- What a breach would cost the business if our controls fail
- What we spend to close that gap while keeping the business fast
Don’t frame it as money saved. Adding AI agents rarely means cutting analysts, so the honest story is one of incremental returns. For the extra you invest, how much more do you get back in threats handled, time to contain, and work closed within SLA? The capacity you free up gets redeployed into higher-value work, and that redeployment is its own line of value. Measured that way, security spend reads as protection for the bottom line, not a tax on innovation.
The line I’d use: “Here’s the value our AI SOC creates, here’s what a failure would cost us, and here’s what we spend to keep moving fast safely.”
Frame 2: Strategic Focus
Most boards have sat through a dozen AI demos and watched none of them reach production. They know pilot purgatory when they see it, and their patience is thin. Don’t walk in with a menu of experiments. Walk in with a short, ranked list of high-impact commitments tied to what the business already cares about.
In the SOC, that means being honest about where AI earns its keep — autonomous triage and response on the high-volume, time-sensitive work — and where it’s merely table stakes. Governance effort should scale with impact: an agent that can contain a host or disable an account deserves board-level attention; one that drafts a summary doesn’t. Showing the board you’ve drawn that line demonstrates focus rather than FOMO.
The line I’d use: “We’ve pointed AI at the few SOC outcomes that move the needle, and we govern each one in proportion to what it can touch.”
Frame 3: Risk Appetite and Governance
This is the frame that may be the most consequential. AI has crossed a line our governance habits haven’t caught up to: it moved from suggesting to executing. It triggers live workflows, queries production systems, and takes actions that affect the business, sometimes before a human reviews the output. Once a system acts, governance has to graduate from a static PDF policy to active permissioning — who can touch what, under which approvals, with what rollback.
The framing that works in the room is autonomy as a dial, not a switch. You widen it as trust builds: start with low-risk, high-volume processes, verify the outcomes against what a good analyst would have done, and expand layer by layer. That measured, risk-based approach is exactly what boards and auditors want to see.
Give the board the risks in plain language: data leakage, model abuse, integrity failures, model supply-chain exposure, and compliance pressure as rules, such as the EU AI Act’s high-risk requirements, take effect in August 2026. Then show the guardrails are formal: documented as policy, operationalized in the platform so they’re enforced automatically, and reviewed on a set cadence — not a set of good intentions in a Slack channel.
Expect the board, and later the auditors, to get specific, so have the answers ready: What due diligence did we apply? Have we risk-assessed each process we’ve automated? Do we understand the data involved and the regulatory requirements around it? How do we evidence that what’s in place is working? The point that lands: as autonomy goes up, blast radius goes up, so governance has to scale with it instead of lagging behind.
The line I’d use: “As our AI started taking action, we tightened the guardrails to match: scoped permissions, human approval on high-impact moves, and a rollback for everything it does.”
Frame 4: Accountability and Ownership
The last question is the shortest: Who owns this? Boards want a single accountable owner and unmistakable role clarity across leadership. In nearly every AI incident I’ve tracked, the root cause wasn’t a purely technical failure. It was three executives in a room, each assuming the problem belonged to someone else. When it goes public, that confusion becomes the headline. The story isn’t “the model got it wrong.” It’s “no one was in charge.”
So bring a clean RACI. The business owns outcome and use-case risk acceptance; security owns the controls and monitoring; legal owns regulatory alignment; the AI solution owner sets standards and lifecycle governance; and the board owns oversight and risk appetite. For the SOC specifically, be explicit about who owns an autonomous agent’s actions, who reviews them, and how an escalation reaches this board.
The line I’d use: “Here’s exactly who owns the AI’s decisions, who reviews them, and how an escalation reaches this board.”
The Language to Leave Out
The fastest way to lose the room is to brief the board the way you’d brief your team.
Drop the jargon. “Agentic,” “LLM,” “SOAR,” product names, model names — none of it survives contact with a board, because directors don’t buy architecture; they buy outcomes. Drop the vanity metrics, too. Raw alert volume and integration counts measure how busy you are, not how protected the business is. And go easy on the superlatives. “Fully autonomous” and “revolutionary” invite skepticism faster than they build confidence.
Before any capability comes out of your mouth, translate it into risk, dollars, or defensibility. If it doesn’t map to one of these, it doesn’t belong in the room.
A Briefing That Lands in Three Slides
If you want a board briefing structure you can reuse, this is the one I keep coming back to:
- The risk. Machine-speed threats against human-speed response, in business terms.
- The move. An AI SOC that reduces exposure, expands capacity, and stays defensible.
- The proof. Your own before-and-after numbers — time-to-contain, capacity recovered — and the governance that backs them.
The AI SOC Decision Underneath the Briefing
The board conversation isn’t really about whether to adopt AI in the SOC. Machine-speed threats made that call for most of us already. It’s about which platform earns the risk, capacity, and defensibility story you’ll tell in that room.
This is where the AI SOC Apocalypse Manifesto‘s test follows you into the boardroom: If it can’t take action, it’s not an AI SOC. A triage-only tool can’t honestly promise a board faster containment, because it stops at the verdict and hands the real work back to your team. The same pretenders that look fine in a demo fall apart the moment a director asks, “So what happens after the alert fires?”
A true AI SOC gives you all of these frames at once. It reduces exposure by taking action across the full threat lifecycle. It expands capacity by handling the repetitive work, so your people can focus on judgment. And it stays defensible because every decision is grounded, logged, and reversible. That’s the platform that lets you walk into the boardroom with a story directors say yes to, and it’s the bar this series has held every “AI SOC” up against from the start.




