When the US Securities and Exchange Commission (SEC) finalised its cybersecurity disclosure rules in 2023, it required public companies to describe how the board oversees cybersecurity risk and how management addresses it. It was a significant step, allowing investors to evaluate whether a company had been breached and if its leadership had a credible governance framework for the risk.
What those disclosures have not yet been asked to address—but what boards should be considering regardless—is whether the cybersecurity of individual leaders at the top of organisations receives the same rigour as the protection of networks and data. For most organisations, the honest answer is no.
Enterprise vs executive cybersecurity
The distinction between enterprise and executive cybersecurity is not widely understood. Enterprise programmes protect networks, endpoints and corporate data. They are well resourced, continuously audited and typically subject to board-level reporting.
Executive cybersecurity concerns the individual leader as a target rather than the corporate network. A CEO or CFO’s vulnerability extends across personal accounts, home networks that often lack enterprise-grade security, family members’ devices, household staff and an array of advisers and service providers who collectively hold enough data to reconstruct a leader’s movements, relationships and vulnerabilities.
This personal ecosystem sits almost entirely outside the corporate security perimeter, and enterprise IT teams typically have neither the mandate nor the visibility to protect it. However, it is precisely this ecosystem that threat actors are now targeting. In my experience advising clients, personal email accounts and home networks have become the leading attack vector against senior leaders, and compromising an executive personally is often the most efficient path to the enterprise.
Why this has become a governance concern
Three developments have elevated this from an operational concern to one of governance:
1 The changing nature of the threat. AI has made social engineering against senior executives markedly more sophisticated. Convincing impersonation of trusted contacts is now a routine fraud vector, with voices cloned or video generated using commercially available AI tools, based on public source material such as earnings calls, promotional videos or interviews. These attacks bypass enterprise controls by exploiting trust in individuals rather than network vulnerabilities, and most security training has yet to catch up. When the authenticity of a voice at the end of the phone or appearance on video call can no longer be taken for granted, the architecture of organisational trust must be revisited.
2 The expanding regulatory landscape. The SEC’s 2023 rules require boards to demonstrate credible oversight of cybersecurity risks material to the enterprise. But the relationship between executive compromise and enterprise harm is becoming more apparent. A successful attack on a CEO can expose board materials, client data, deal intelligence and strategic plans. Whether personal cybersecurity for key leaders overlaps with material risk is an increasingly pertinent question.
3 Evidence of a preparedness gap. Our 2026 survey of more than 300 senior US business leaders at organisations worth more than $1 billion found cybersecurity to be the area where executives felt most underprepared. Further, 93% admitted their organisation had missed warning signs of crises, and more than a quarter said a single disruptive event had cost their company $25 million or more. The gap between awareness and action is substantial.
What most organisations get wrong
In working with organisations on executive cybersecurity, some common themes emerge. The first is treating executive cybersecurity as a subset of the enterprise IT function. In reality, enterprise security teams are rarely equipped with a mandate or cultural authority to conduct a personal risk assessment of the CEO, audit a board member’s home network or vet executive’s personal advisers. These are specialist requirements that demand a different capability and a different governance structure.
Next is the assumption that physical security and cybersecurity are separate domains. Just a few examples of how they can overlap include: a compromised email account revealing travel itineraries; a breached calendar exposing where an executive is physically vulnerable; or a social engineering attack on a personal assistant, yielding the home addresses and family routines that enable physical surveillance or coercion.
Finally, there can be a culture of accommodation around the most senior executives with cybersecurity policies such as password rotation or restrictions on using personal devices being waived for them. It’s also not uncommon for board members to receive confidential papers to personal email accounts without encryption or other enterprise-grade protections in place. IT teams comply or turn a blind eye because of the seniority of the requester.
What board-level oversight should look like
Effective governance of executive cybersecurity does not require boards to become technical experts. An initial step to take is ensuring the organisation has independently assessed the personal digital exposure of its most senior leaders and their immediate ecosystems. This should be done as a dedicated workstream with specialist capability that may be separate from the enterprise security programme. The assessment should cover home networks, personal devices, family members’ digital footprints and key third-party providers—and it needs to be refreshed regularly.
Within the organisations, there should be a single point of accountability for executive protection, ideally integrating cybersecurity with physical security and, where relevant, health and medical preparedness. Fragmented oversight creates gaps that sophisticated threat actors exploit.
Another important piece of the picture is building executive impersonation or personal compromise into incident response plans and tabletop exercises. One practical example is having pre-agreed verification protocols through a separate communications channel for sensitive actions, such as decision making during a crisis, financial authorisations and IT system credential resets. Too many organisations discover that their verification procedures do not work when they need them most.
There’s no doubt that executive cybersecurity belongs on the board agenda. However, boards cannot credibly claim to govern enterprise cybersecurity risk while leaving their most senior leaders’ personal exposure unexamined and unmanaged. There are also duty of care and fiduciary angles, as cybersecurity for senior executives touches the safety of individuals, the resilience of leadership and the protection of information whose loss would damage the enterprise.
While AI is accelerating this threat at unprecedented speed, the encouraging reality is that the governance response is well within reach. The frameworks and specialist capabilities to close this gap already exist, and the boards that move now will be the ones best placed for whatever comes next.
Ghonche Alavi is director, Cyber, at security consultancy Crisis24


