Skip to content

10 September, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • shareholder primacy

      What is a company for?

      We all have an ethical imperative to question whether shareholder primacy should still be dominating...

      data

      Every board needs a scientist or engineer

      STEM professionals are trained to work with incomplete data, and in business you rarely have...

      climate risk

      Now is the time to take action on climate risk

      Whatever direction national policies take, nature and climate remain as drivers of value and risk...

  • Comment
      • View all
    • shareholder primacy

      What is a company for?

      We all have an ethical imperative to question whether shareholder primacy should still be dominating...

      data

      Every board needs a scientist or engineer

      STEM professionals are trained to work with incomplete data, and in business you rarely have...

      climate risk

      Now is the time to take action on climate risk

      Whatever direction national policies take, nature and climate remain as drivers of value and risk...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

      female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • Georgeson 2026 European AGM Season Review

      Georgeson’s deep dive into the evolving dynamics of investor voting across nine major European markets in...

      2026 MidYear Executive Benchmark Survey: The Verification Gap

      AI enthusiasm is running into reality: 1 in 4 executives in this Workiva survey say...

      Seven Steps for Futureproofing Business

      This guide from Business in the Community aims to help businesses build a practical strategy...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

The cybersecurity gap that boards are missing

by Ghonche Alavi

Are you prepared for an attack on the organisation coming through a breach in a director’s personal network?

executive cybersecurity

Image: OPOLJA/Shutterstock.com

Favorite

When the US Securities and Exchange Commission (SEC) finalised its cybersecurity disclosure rules in 2023, it required public companies to describe how the board oversees cybersecurity risk and how management addresses it. It was a significant step, allowing investors to evaluate whether a company had been breached and if its leadership had a credible governance framework for the risk.

What those disclosures have not yet been asked to address—but what boards should be considering regardless—is whether the cybersecurity of individual leaders at the top of organisations receives the same rigour as the protection of networks and data. For most organisations, the honest answer is no.

Enterprise vs executive cybersecurity

The distinction between enterprise and executive cybersecurity is not widely understood. Enterprise programmes protect networks, endpoints and corporate data. They are well resourced, continuously audited and typically subject to board-level reporting.

Personal email accounts and home networks have become the leading attack vector against senior leaders.

Executive cybersecurity concerns the individual leader as a target rather than the corporate network. A CEO or CFO’s vulnerability extends across personal accounts, home networks that often lack enterprise-grade security, family members’ devices, household staff and an array of advisers and service providers who collectively hold enough data to reconstruct a leader’s movements, relationships and vulnerabilities.

This personal ecosystem sits almost entirely outside the corporate security perimeter, and enterprise IT teams typically have neither the mandate nor the visibility to protect it. However, it is precisely this ecosystem that threat actors are now targeting. In my experience advising clients, personal email accounts and home networks have become the leading attack vector against senior leaders, and compromising an executive personally is often the most efficient path to the enterprise.

Why this has become a governance concern

Three developments have elevated this from an operational concern to one of governance:

1  The changing nature of the threat. AI has made social engineering against senior executives markedly more sophisticated. Convincing impersonation of trusted contacts is now a routine fraud vector, with voices cloned or video generated using commercially available AI tools, based on public source material such as earnings calls, promotional videos or interviews. These attacks bypass enterprise controls by exploiting trust in individuals rather than network vulnerabilities, and most security training has yet to catch up. When the authenticity of a voice at the end of the phone or appearance on video call can no longer be taken for granted, the architecture of organisational trust must be revisited.

A successful attack on a CEO can expose board materials, client data, deal intelligence and strategic plans.

2  The expanding regulatory landscape. The SEC’s 2023 rules require boards to demonstrate credible oversight of cybersecurity risks material to the enterprise. But the relationship between executive compromise and enterprise harm is becoming more apparent. A successful attack on a CEO can expose board materials, client data, deal intelligence and strategic plans. Whether personal cybersecurity for key leaders overlaps with material risk is an increasingly pertinent question.

3  Evidence of a preparedness gap. Our 2026 survey of more than 300 senior US business leaders at organisations worth more than $1 billion found cybersecurity to be the area where executives felt most underprepared. Further, 93% admitted their organisation had missed warning signs of crises, and more than a quarter said a single disruptive event had cost their company $25 million or more. The gap between awareness and action is substantial.

What most organisations get wrong

In working with organisations on executive cybersecurity, some common themes emerge. The first is treating executive cybersecurity as a subset of the enterprise IT function. In reality, enterprise security teams are rarely equipped with a mandate or cultural authority to conduct a personal risk assessment of the CEO, audit a board member’s home network or vet executive’s personal advisers. These are specialist requirements that demand a different capability and a different governance structure.

Enterprise security teams are rarely equipped with a mandate or cultural authority to conduct a personal risk assessment.

Next is the assumption that physical security and cybersecurity are separate domains. Just a few examples of how they can overlap include: a compromised email account revealing travel itineraries; a breached calendar exposing where an executive is physically vulnerable; or a social engineering attack on a personal assistant, yielding the home addresses and family routines that enable physical surveillance or coercion.

Finally, there can be a culture of accommodation around the most senior executives with cybersecurity policies such as password rotation or restrictions on using personal devices being waived for them. It’s also not uncommon for board members to receive confidential papers to personal email accounts without encryption or other enterprise-grade protections in place. IT teams comply or turn a blind eye because of the seniority of the requester.

What board-level oversight should look like

Effective governance of executive cybersecurity does not require boards to become technical experts. An initial step to take is ensuring the organisation has independently assessed the personal digital exposure of its most senior leaders and their immediate ecosystems. This should be done as a dedicated workstream with specialist capability that may be separate from the enterprise security programme. The assessment should cover home networks, personal devices, family members’ digital footprints and key third-party providers—and it needs to be refreshed regularly.

Fragmented oversight creates gaps that sophisticated threat actors exploit.

Within the organisations, there should be a single point of accountability for executive protection, ideally integrating cybersecurity with physical security and, where relevant, health and medical preparedness. Fragmented oversight creates gaps that sophisticated threat actors exploit.

Another important piece of the picture is building executive impersonation or personal compromise into incident response plans and tabletop exercises. One practical example is having pre-agreed verification protocols through a separate communications channel for sensitive actions, such as decision making during a crisis, financial authorisations and IT system credential resets. Too many organisations discover that their verification procedures do not work when they need them most.

There’s no doubt that executive cybersecurity belongs on the board agenda. However, boards cannot credibly claim to govern enterprise cybersecurity risk while leaving their most senior leaders’ personal exposure unexamined and unmanaged. There are also duty of care and fiduciary angles, as cybersecurity for senior executives touches the safety of individuals, the resilience of leadership and the protection of information whose loss would damage the enterprise.

While AI is accelerating this threat at unprecedented speed, the encouraging reality is that the governance response is well within reach. The frameworks and specialist capabilities to close this gap already exist, and the boards that move now will be the ones best placed for whatever comes next.

Ghonche Alavi is director, Cyber, at security consultancy Crisis24

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • UK cybersecurity chief warns of ‘perfect storm’
    April 22, 2026
    cybersecurity

    AI and global disruption have brought ‘tumultuous uncertainty’ to organisations, says the CEO of the National Cyber Security Centre.

  • The paradox of cyber risk and business growth
    August 1, 2024
    cyber risk and business growth

    Risk consensus and confidence in cybersecurity allow boards and organisations to innovate and drive the business forward.

  • Are you serious about cybersecurity?
    October 3, 2023
    cybersecurity chatbot

    Artificial intelligence chatbot hackers are just the latest in a long list of cyber threats, which are not going away any time soon.

  • Boards must change to survive cybercrime
    February 9, 2026
    cybersecurity

    Governance ‘needs to be completely rewritten’ because time is of the essence during a cyber-attack, according to an expert.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy