Cybersecurity has become a standing agenda item for most public company boards, but many CEOs still struggle to communicate risk in terms that resonate with directors.