Why cyber risk now belongs in the boardroom
Why cyber risk now belongs in the boardroom
Cybersecurity is often discussed through the language of tools, controls and technical threats. But for boards and executive leaders, the more important questions are about operational resilience, business continuity and how much risk is accumulating beneath the surface.
We recently welcomed executive leaders from across our network to the Talent Sydney office for a session with cyber security expert Dr Vladas Leonas, a career technology leader who has served as CIO eight times and is the author of Cumulative Effect: Cyber Security Guide for Directors and CEOs.
Drawing on decades of technology leadership, Dr Leonas explored why modern organisations are becoming more exposed as their reliance on technology grows, and why cyber security needs to be understood and governed as a business risk.
As he made clear at the outset:
“It’s not about the tools. It’s not about shiny dashboards.”
Here are five key takeaways from the session.
Cyber risk is cumulative
Major incidents can look sudden, but the conditions that make them possible often develop over years.
Technology estates expand, new vendors and applications are introduced, integrations multiply, exceptions become permanent, and legacy systems remain because replacing them feels too difficult or expensive.
Each decision may appear reasonable in isolation, but together they create what Dr Leonas described as a cumulative effect: a sequence of changes over time that eventually produces an outcome nobody expected.
He emphasises the need to reframe the role of executive leadership. Cyber risk can’t be managed only at the point of attack or audit. Leaders need visibility into how strategic, procurement and delivery decisions are changing the organisation’s exposure over time.
Digital dependency is operational risk
Few organisations can operate for long without their core technology. That means even a non-malicious technology failure can create consequences that resemble a cyber incident.
The session used the July 2024 CrowdStrike outage as a stark example. A faulty software update affected approximately 8.5 million Windows devices and disrupted airlines, banks, healthcare providers, retailers, media companies and payment systems around the world.
“It wasn’t a cybersecurity incident, but just a bad update,” Dr Leonas said. Yet the economic and operational impact ran into billions of dollars.
The leadership lesson is that resilience planning cannot focus only on cyberattacks. Boards should also understand where the business is highly dependent on particular systems, platforms, vendors and integrations, and what happens when one of them fails.
As Dr Leonas posed the question:
“Can you name a business that is not dependent on technology today? Probably not.”
Complexity creates its own risk
One of the strongest messages from the session was that complexity is not simply an IT management challenge. It’s a material source of cyber risk.
In many organisations, knowledge of the technology environment is fragmented. Different teams understand different systems, but nobody has a complete end-to-end view. That makes it harder to predict the consequences of change, patch vulnerabilities safely, recover from disruption and identify where exposure is building.
The shift from large monolithic systems to microservices has enabled faster and more flexible delivery, but it’s also driven rapid growth in application programming interfaces, or APIs. Every API adds another connection that must be secured, monitored and governed.
As Dr Leonas put it:
“Complexity is your enemy. Whatever you can do to simplify the IT ecosystem is very, very important.”
For boards, simplification should be treated as a strategic objective rather than a technical clean-up exercise. Dr Leonas suggested that year-on-year reduction in unnecessary complexity could become a meaningful measure of progress.
Speed without assurance creates hidden exposure
Speed creates commercial value, but delivery pressure can also compress the time available for security design, threat modelling, independent review, testing and remediation.
Dr Leonas challenged leaders to reconsider the familiar delivery constraint of fast, cheap and good. In cyber security, prioritising speed and cost without equivalent attention to assurance can result in vulnerabilities being shipped incrementally, release after release.
The issue is not that organisations should stop using agile delivery but that governance and incentives must ensure security isn’t repeatedly deferred to a later sprint, a penetration test or a future remediation program.
This requires leadership discipline. Teams need the mandate, capability and time to build security into delivery, and not simply assess it after the fact.
Compliance is a baseline, not proof of resilience
Certifications, frameworks and regulatory obligations all play an important role. But the session repeatedly returned to one warning: compliance should not be mistaken for security.
Dr Leonas shared:
“Compliance is a very good step—a foundational step—but a lot of people feel that compliance is equal to security. It is not.”
A certification only provides assurance within its defined scope and at a particular point in time. It may not cover the systems, entry points or dependencies presenting the organisation’s greatest exposure. History also provides numerous examples of compliant and certified organisations suffering major breaches.
Dr Leonas argued that organisations need to move from periodic, point-in-time assurance towards continuous assurance. Technology environments change too quickly for a six-monthly audit to provide a complete view of current risk.
Boards need to govern the trade-offs
Cyber security ultimately comes down to decisions that are often made under pressure, with incomplete information and competing priorities.
Leaders are constantly balancing operational continuity, customer trust, regulatory expectations and commercial outcomes, and there’s rarely a perfect or risk-free option. Instead, the goal is to make deliberate choices that align with the organisation’s risk appetite and long-term strategy.
This requires a shift in mindset where cyber risk is treated in the same way as financial or investment risk: something to be weighed, prioritised and governed, not simply delegated or deferred.
Without clear guardrails, technology environments will continue to expand, and with them, the organisation’s exposure. Boards play a critical role in setting those boundaries to ensure that growth, speed and innovation are matched with appropriate levels of control and assurance.
For boards and executive teams, the key questions are:
- Where are our most critical technology dependencies?
- Is our environment becoming simpler or more complex?
- Is assurance keeping pace with the speed of delivery?
- Does our compliance status reflect genuine resilience?
Cyber security has entered the boardroom because it now affects whether organisations can continue operating, protect trust and recover when something goes wrong. The organisations best positioned to respond will be those that treat it not as a technical problem to delegate, but as a business risk to understand, challenge and govern.