Cyber security is due a paradigm shift away from “perimeter” security of systems to focusing on identifying the “external threat landscape”, according to a senior expert.
In the latest edition of Board Agenda’s Governance Watch podcast, Ruth Wandhöfer, non-executive director and head of European markets at cyber specialists Blackwired and visiting professor at Bayes Business School, says that boards should go through their own mind shift to become much more proactive in managing cyber risk.
Wandhöfer’s remarks come in a year in which cyber attacks on high-profile companies such as Marks & Spencer and Jaguar Land Rover have seen hundreds of millions lost in production and sales.
Earlier this month, Richard Horne, chief executive of the National Cyber Security Centre (NCSC), warned that criminal activity to breach corporate systems should be the “domain” of the boardroom, not just IT chiefs.
Wandhöfer says the “perimeter”—protecting a network from penetration through firewalls and controlling access—remains essential but is no longer sufficient in an age when cyber criminals are using AI as a key tool.
Threat identification is the next level in dealing with network incursions.
Cyber artifacts, machine learning and large language models can now be used to scan the threat landscape, seeking out bad actors.
Once the data is processed, companies can predict where an attack may come from.
“This is technologically possible now,” says Wandhöfer. “This is really the way you can defend forward by moving from detect and response to a proactive predict, prevent and defeat strategy.”
On boards, she says, “In some incidents we have seen, the board only usually gets involved when something bad has happened.
“This has to be another complete mind shift from a board level, because you need to be proactive now to understand what is my current cyber posture, what are my tools and protections…?”
In the NCSC’s annual report, CEO Richard Horne wrote that all organisations should be aspiring to respond well to cyber attacks.
“For too long, cyber security has been regarded as an issue predominantly for technical staff.
“This must change. All business leaders need to take responsibility for their organisation’s cyber resilience.”
He adds, “The recent cyber attacks must act as a wake-up call. The new normal is that cyber criminals will target organisations of all sizes, operating in any sector.”
This podcast was produced in association with NASDAQ Governance Solutions.
You can listen to the full episode on Spotify, Apple and all major podcast platforms.
You can also access the full podcast here.



