Start with diagnosis, not checklists
Once, I was asked to conduct a board strategy retreat for a financial institution that had just suffered a silent cyberattack. Silent because they didn’t even know it happened until an anonymous tipster sent proof of client data, board emails, and KYC files, leaked online. That’s when I realised something worrying. The board didn’t even know what “phishing” meant. But here they were, approving a multimillion-dollar digital transformation strategy, yet they didn’t know what zero trust architecture entailed. The blind approve the digital roadmap for the blind.
Boards do not need cybersecurity literacy, but they need cyber fluency.
Cyber is not an IT problem, it’s a survival issue.
If you’re still treating cyber risk as a “CIO update” buried in item 11 of your board agenda, good luck. You’re running a 21st-century enterprise with 19th-century governance. In the insurance industry, for instance, most boards are comfortable discussing actuarial assumptions but avoid cyber discussions like a disease.
Yet, the biggest risk to the business model today is not fraud, it’s ransomware halting operations for 10 days, destroying customer trust, and attracting regulatory fines.
Last year, in one East African insurer, a compromised third-party payroll vendor exposed personal data of 2,000+ employees. The board was clueless because their risk register hadn’t been updated in 3 years.
Cybersecurity must move from a passive oversight role to active stewardship. That means
a) including cyber risk explicitly in board risk appetite frameworks;
b) embedding cybersecurity KPIs in executive performance contracts; and
c) demanding third-party audits of critical systems.
Don’t wait for an internal breach to wake up. Do what top boards do: scenario-based tabletop exercises with real-world attack simulations. If your board can’t navigate a ransomware attack under pressure, you are unprepared.
Leadership challenge: Most board members are intimidated by tech talk and defer to the CIO. Big mistake. If you can understand financial derivatives, you can learn how lateral movement works in a network breach.
Leadership tool: Institute a quarterly “Digital Risk Deep Dive” as a standing board item. In this session, rotate focus will rotate on cloud security, third-party risk, social engineering, and incident response readiness. Make it board-owned, not IT-delivered.
Boards do not need to become cyber experts. But they must become cyber-responsible. Because digital trust is the new capital. Lose it, and even your best actuarial models won’t save you.
