Cybersecurity Awareness Month is becoming the corporate version of Valentine’s Day; a yearly ritual of attention, speeches, and social media posts… followed by silence. We light the candles in October, and by November, we are back to business as usual, unsecured, untested, and unprepared.
The problem is not awareness. You already know cyber risk is real; the problem is habit. Awareness is what you remember. Lifestyle is what you do; every single day, without being reminded.
- Awareness is a poster. Lifestyle is a protocol.
Most organizations stop at awareness, banners, training slides, and inspirational quotes about phishing. But culture changes when cybersecurity becomes a reflex, not a reminder
Ask yourself: Does your team stop to question every data request, every USB stick, and every “urgent” email? If not, you have awareness, not culture.
Real cybersecurity lives in the bloodstream of the organization; in how systems are configured, how passwords are managed, how access is reviewed, and how leaders respond to breaches.
- The weakest link is not the intern; it’s the board
Boards love dashboards showing red, amber, and green. But cybersecurity is not a colour; it’s a consequence.
When a breach occurs, it’s not the IT department that loses reputation; it’s the brand you sit on.
Boards must treat cybersecurity the way they treat liquidity or audit reports: as a standing agenda item, with quantified appetite, response plans, and accountability. And make managers face consequences when they fail to implement the directives that lead to breaches.
Until the Board asks, “What’s our tested recovery time objective?” with the same intensity as “What’s our cash position?” nothing changes.
- Fire drills for buildings exist. Where are your cyber drills?
Every quarter, employees know how to evacuate in case of fire. But when the servers burn, metaphorically, who moves first? Who calls the regulator? Who isolates the network? Who authorizes the ransom response?
Cyber drills are not optional extras; they are the only rehearsal you’ll get before the real attack.
Summit Consulting’s investigations show a consistent pattern: the companies that suffer the most are not the least aware; they are the least prepared. They knew the risks. They just never practiced the response.
- Cybersecurity must migrate from IT to governance.
Treating cybersecurity as a technical issue is the modern board’s blind spot.
It’s not about firewalls; it’s about fiduciary duty. It’s not about antivirus updates; it’s about accountability structures. The question is not “Do we have tools?” It’s “Do we have resilience?”
That means budgeting for it, measuring it, and embedding it into strategic planning. Cybersecurity is now part of ESG; your G (Governance) is incomplete without it.
- The future belongs to paranoid leaders.
Today, optimism is a vulnerability. The most secure organizations are not the ones with the best software, but with the most constructively paranoid leadership; leaders who constantly ask, what could go wrong?
They invest not because they were breached, but because they assume they already have been. As Mr Strategy, when I engage boards on cybersecurity, I advise them:
- Make cybersecurity permanent. Every board pack must include a cyber risk section, not once a year, but at every sitting.
- Define your cyber risk appetite. Quantify what level of disruption, data loss, or downtime your organization can survive.
- Demand simulations. Insist on at least two board-level cyber incident drills annually.
- Fund the lifestyle. Cyber resilience isn’t an IT line item. It’s a business continuity investment.
- Lead by example. If the board doesn’t use 2FA, secure passwords, and encrypted devices, no one else will.
This is not about October. It’s about October through September next year. Cybersecurity is not a campaign. It’s character.
And in the digital age, your organization’s integrity will be judged not by how fast it grows, but by how well it defends what it values.
I remain, Mr Strategy
