In today’s hyperconnected (and hyper-exposed) world, the role of boards has evolved dramatically. Among the emerging risks they must confront, cybersecurity stands out not only for its technical complexity but for its capacity to inflict devastating impact on operations, shareholder value, and even entire industries.
According to a recent ISS study, the data is alarming: nearly 700 incidents reported among Russell 3000 companies in just two years, affecting more than 10% of the firms. More worrying still, a third of these breaches originated in the digital supply chain — a vulnerability that many companies still struggle to understand and manage effectively.
Digital interdependence: a double-edged sword
Reliance on external technologies and providers has created an ecosystem of interdependencies as intricate as it is fragile. More than 90% of Russell 3000 companies use certain technology platforms considered high-risk. When these platforms are compromised, the effects can be catastrophic. A single cloud-services provider, for instance, supports more than a third of these companies, creating a single point of failure that would make any risk manager turn pale.
Meanwhile, ransomware attacks continue to be the nightmare of chief financial officers, with costs that, in large companies, average US$43.4 million per incident. The impacts go far beyond the financial, eroding shareholder confidence and market value. The cases of MGM Resorts and UnitedHealth are sharp reminders of how data breaches can trigger a domino effect of operational disruptions and financial losses that no board can afford to ignore.
The leadership imperative: concrete actions for boards
Faced with this heightened risk landscape, boards must act immediately and decisively. Three crucial steps no board can afford to postpone:
- Elevate cybersecurity to the status of a strategic priority. Sporadic reports and superficial presentations are no longer enough. Directors must engage actively with cybersecurity risk officers, challenging assumptions and pressing for a deeper understanding of the organization’s vulnerabilities and response strategies.
- Master the art of third-party risk management. With a third of breaches originating in third-party relationships, boards must insist on robust risk-management frameworks that extend beyond direct suppliers to encompass the entire digital supply chain. A formal third-party risk-management program is non-negotiable; it is a strategic necessity.
- Adopt a data-driven approach to risk management. Objective risk scores should become required reading for boards. They offer an assessment of the company’s risk profile and a roadmap for continuous improvement. Boards should demand periodic updates and use them as a basis for decision-making.
Metrics boards should understand and monitor regularly include:
- Mean Time to Detect (MTTD): how long it takes to identify a security incident.
- Mean Time to Respond (MTTR): how long it takes to contain and mitigate a threat once detected.
- Security rating: an overall security score based on externally observable data.
- Vulnerability management: known vulnerabilities, average time to patch, percentage of systems updated.
- Incident rate: the number of security incidents over a given period.
- Data Loss Prevention (DLP) events: prevented attempts to exfiltrate sensitive data.
- Security awareness: training completion rates and performance on simulated phishing tests.
- Access management: failed login attempts, password resets, inactive accounts.
- Compliance score: how well the organization meets regulatory and industry standards (GDPR, HIPAA, PCI DSS).
Final reflections: the board as digital guardian
Ultimately, the true test for boards will not be whether they can prevent every attack, but how resilient they can make their organizations. This requires a shift in mindset: from seeing cybersecurity as a cost to understanding it as an investment in the continuity and credibility of the business.
Boards that fail to adapt will find themselves navigating increasingly turbulent waters. Those that embrace their role as digital guardians will not only protect their organizations but also unlock new sources of value in a world where digital trust is the new currency.
The question is no longer whether your company will be the target of a cyberattack, but when. And when that day comes, will your board be prepared to lead, or condemned to react?
For reflection
- Are we asking the right questions about our company’s cybersecurity preparedness? How often do we engage with management on cyber risk, and do we understand our most critical vulnerabilities?
- What is our board’s plan for third-party risks, particularly those posed by technology providers and platforms? Have we assessed the potential impact of a major incident involving a key supplier?
- How are we using external cyber-risk metrics to guide our oversight? Do we know how our posture compares with peers and industry benchmarks?
Cybersecurity risk is no longer a technical problem confined to IT; it is a strategic concern that demands the attention of every director. By adopting a proactive approach, boards can protect their organizations and safeguard shareholder value in an era of increasingly sophisticated threats.