It’s 11:45 AM on an ordinary Tuesday. The risk committee meets to approve the corporate risk map. Everyone nods with satisfaction: the 5×5 matrix is perfectly color-coded, the risks ranked by probability and impact, the mitigating actions assigned. The committee chair signs the document. Meanwhile, 8,000 kilometers away, an attacker has already been inside the company’s systems for three days.

How is it possible that, with so much sophistication in risk management, boards are still caught off guard by cyber crises?

The paradox of control

The uncomfortable answer is that our traditional corporate-governance tools were designed for a world that no longer exists. Risk maps, probability-impact matrices, and quarterly committees were born in an era when risks were static, reasonably predictable, and localizable. Cyber risk respects none of these premises.

Consider what we assume when we build a traditional risk map: that we can identify threats in advance, that the probability of occurrence is relatively stable, that impact can be estimated within reasonable ranges, and that we have time to implement controls before the risk materializes. In cybersecurity, every one of these assumptions is, at best, naive.

Traditional risk management is in an intrinsic crisis in the face of the dynamism, uncertainty, and ambiguity of the digital environment. What was once moderately feasible to anticipate is now practically impossible.

The committee that approves while the attacker operates

According to Mandiant’s M-Trends 2025 report, based on more than 450,000 hours of incident investigations, the median time an attacker remains in systems before being detected is 11 days. It may seem short, but here comes the figure that should make any board uncomfortable: 57% of organizations learn of the attack from external sources, not from their own detection systems. And of those external notifications, 14% come from the attacker itself, through a ransom note.

Put another way: more than half of companies need someone from the outside to tell them they have been compromised. In many cases, that “someone” is the very criminal who has already extracted the information.

The U.S. SEC now requires disclosure of material incidents within four business days. But if your organization belongs to that 57% that does not detect internally, the compliance clock only starts ticking once you have already lost control of the narrative.

Where cybersecurity regulatory frameworks are still maturing and many boards are only beginning to put the topic on their agenda, this gap between the speed of the risk and the pace of governance is particularly pronounced. A high concentration of family ownership adds another complication: when the owner also chairs the board, the temptation to treat cybersecurity as an “IT matter” that does not deserve strategic discussion is hard to resist.

The illusion of the checklist

There is a growing tendency to turn cyber-risk oversight into a compliance exercise. Committees meticulously review checklists, complete control matrices, and follow detailed procedures. But in this mechanical process something fundamental is lost: critical judgment, seasoned intuition, the ability to detect weak signals.

The best problem detectors are not necessarily those who master the technical jargon, but those who deeply understand the business and can tell when something simply does not smell right, even when the formal indicators are all green. A director who asks why certain systems never report incidents may be closer to the truth than one who celebrates the flawless dashboard.

Toward a new model of oversight

The answer is not to abandon risk management, but to transform it radically for the digital context.

The first necessary transformation is to move from periodic assessment to continuous monitoring. The board cannot rely on quarterly reports for a risk that evolves in hours. This does not mean directors must become technicians, but it does mean they need access to up-to-date information and escalation channels that do not wait for the next scheduled meeting.

The second transformation involves abandoning the illusion of perfect prediction and adopting a resilience mindset. Instead of asking only how likely an attack is, the board should ask how quickly we can detect it internally (rather than waiting to be told from outside), how prepared we are to respond, and how long it would take to recover critical operations.

The third transformation, perhaps the most difficult culturally, requires creating spaces where bad news can emerge early. Where the culture values harmony and questioning the boss is frowned upon, cybersecurity problems stay hidden until they explode. The board that genuinely wants to oversee this risk must actively cultivate dissenting voices and protect those who raise uncomfortable alarms.

For reflection in your boardroom

It is worth asking whether your organization is part of the 43% that detects internally or the 57% that needs to be told from outside. When was the last time your risk committee seriously questioned something that looked perfect on the cybersecurity dashboard? And the most uncomfortable question: if a systems manager detected a critical vulnerability the night before a board meeting where the company’s digital transformation was to be celebrated, would they feel safe reporting it?

A board’s true strength against cyber risk lies neither in the sophistication of its matrices nor in the frequency of its committees. It lies in its capacity to see what the dashboards do not show and to create a culture where reality, however uncomfortable, always finds its way into the boardroom.

P.S. The risk map the committee signed that Tuesday morning had 47 identified risks. The attack already underway matched none of them.

References

Leer en español →

This essay also appeared in