Site icon bbrief

Why every board agenda needs a cyber conversation


Jason Oehley | Director | Regional Sales | Arctic Wolf | mail me |


Boards spend a great deal of time asking questions. They challenge strategy, review financial performance, interrogate financial statements and revisit decisions that made sense six months ago but may no longer make sense today.

That is why one question stands out: “Why are executives and boards not doing the same when it comes to their cybersecurity?” My view is simple. As organisations become more digital, it becomes increasingly difficult to justify treating cyber resilience as something that sits outside regular business discussions. In fact, every board agenda needs a cyber conversation.

Cyber resilience belongs in every board discussion

According to IBM’s Cost of a Data Breach Report, the average data breach in South Africa costs organisations more than R44 million. Yet cyber incidents continue to affect organisations of every size, despite growing investment and greater awareness.

I do not believe businesses are failing to take cybersecurity seriously. Most organisations understand its importance and have invested accordingly. Instead, I question whether organisations have enough visibility to understand their actual level of risk.

You can’t protect what you can’t see. At first glance, that statement sounds obvious. However, in practice, it highlights a challenge that many organisations underestimate.

Visibility is the foundation of security

Most companies struggle with understanding what they actually have in their environment. For many businesses, this challenge goes far beyond maintaining an inventory.

Understanding exposure begins with understanding exactly what the organisation owns. It also requires knowing where assets are located, whether teams manage them correctly, and whether security controls are applied consistently. Today, those responsibilities are just as important as detecting threats. That is another reason every board agenda needs a cyber conversation.

Businesses have become significantly more digital during the past few years. At the same time, the way people work has changed. Many organisations now support environments that extend well beyond the traditional office. Consequently, maintaining a complete picture of everything that requires protection has become much more difficult. Over time, assumptions that once seemed reasonable quietly become outdated.

For example, a temporary change may remain in place because nobody revisits a configuration. Eventually, different teams can develop very different views of the same environment.

One consequence is that organisations have become highly effective at responding to problems. However, they often spend far less time reducing the likelihood of those problems occurring in the first place. Everybody thinks that because I’ve got a SOC and I’m monitoring this, I’m protected.

Monitoring is not the same as reducing risk

Monitoring remains essential. However, recognising that something has happened is not the same as reducing the likelihood that it will happen.

Another challenge is complexity itself. The amount of noise becomes overwhelming. Most organisations do not suffer from a shortage of information. Instead, they are overwhelmed by it. New technologies promise greater visibility. However, they also introduce additional complexity. As a result, teams must interpret enormous amounts of information while balancing countless competing priorities.

Artificial intelligence (AI) has introduced another layer of complexity. Much of the discussion around AI focuses on productivity and efficiency. However, organisations should pay equal attention to their effect on the speed of cyber attacks.

The pace of cyber risk keeps accelerating

Current estimates suggest that between 80% and 90% of cyber attacks are now fully automated. Tasks that once required considerable time and effort can now happen at machine speed. As a result, threat actors can identify weaknesses and exploit them much faster than ever before.

It’s become a game of speed. Many of the processes organisations still rely on today were designed for a much slower world. Reviews occurred periodically because organisations could reasonably keep pace with change. However, those assumptions no longer hold true when cyber risk changes continuously.

Cybersecurity changes every minute, every second, never mind every day. In an environment where attacks become increasingly automated, the gap between the speed of risk and the speed of decision-making becomes critical. That does not mean boards must become cybersecurity experts. However, they can no longer assume the job is complete simply because the organisation has deployed the right security tools. Therefore, every board agenda needs a cyber conversation.

In conclusion

Perhaps the more important discussion is not whether cybersecurity belongs in the boardroom. Instead, organisations should ask why so many still behave as though it does not. Leaders are already used to challenging assumptions and asking difficult questions in every other area of the business.

There is no reason cyber resilience should be any different. It should sit at the top of the agenda, alongside profitability and revenue discussions.

It is no longer true that organisations with the biggest budgets or the longest list of security tools enjoy the strongest protection. Instead, the organisations that succeed may simply be those that develop the habit of asking better questions. Cybersecurity changes every minute, every second, never mind every day. Perhaps it is time we started treating it that way.


 

Exit mobile version