Board directors should consider the risk of being targeted as part of hybrid warfare, either through a cyber-attack or an attack on national critical infrastructure, according to Derek Leatherdale, senior geopolitical risk adviser at consultancy Sibylline.
Speaking on geopolitics this week at the Chartered Governance Institute UK and Ireland (CGI)’s annual conference on governance, Leatherdale added that boards should also be aware of the medium-term risk of repeat air strikes in Iran if its adversaries think its nuclear programme has become too advanced.
In his presentation at the conference in London, Leatherdale said governance professionals can help boards to focus on geopolitical risk by carrying out impact assessments that show the tangible effect of geopolitics on the business. Doing so will change the tone of board conversations from abstract observations to practical discussions about a proportionate and material response.
His comments come in a week in which hostilities reignited between the US and Iran and NATO leaders gathered in Ankara to discuss the future of the alliance.
According to Leatherdale, organisations can adapt to the changing political climate by using existing strategies—for example, their policy or government affairs departments—to engage with newer political parties.
Larger organisations can also mitigate geopolitical risk by seeking early insight from the Foreign Office or the Cabinet Office. Often, by the time major events hit the news headlines, it’s too late for organisations to respond, he said.
The US and China
One risk Leatherdale highlighted for boards is Taiwan and the relationship between China and the US.
According to Leatherdale, China’s president Xi Jinping may use future meetings with Donald Trump to persuade him to dilute the US policy position on Taiwan in a way that future US administrations would struggle to change.
Elsewhere, the conference heard of the increasing concerns about cyber risk. The UK government has “lost faith in [organisations’] ability to manage cyber risk,” said George Quigley, head of ICA at IASME Cyber Assurance, speaking on ethics in cybersecurity. Quigley said it’s likely companies will have to comply or explain with the new Cyber Governance Code of Practice as the government pressures businesses to take cyber risk seriously.
Quigley added that organisations need to cover the basics of cybersecurity before even considering AI, which has “changed the velocity” of cyber-attacks.
Cybersecurity is a governance issue as well as a technical issue: most cyber breaches are caused by inadequate processes, Quigley said. Governance professionals should ask probing questions, he added, to get to the root cause of an attack and prevent it happening again.
Cyber risk should be a standing agenda item for the board and for the management team, according to Quigley.
Developing a fit-for-purpose cyber risk assessment should be management’s top priority. Worryingly, there are still organisations that don’t have a cybersecurity strategy and, if they do, many don’t review it often enough, he said.
Quigley advised caution on cyber risk suppliers or experts, saying the National Cyber Security Centre is worried about some of them and has a database of assured services that governance professionals can refer to.
“Governance today is about holding complexity together,” said Linda Ford, CEO of CGIUKI, opening the conference. She added that governance is “needed now more than ever” because it provides stability in volatile times, allowing companies to make good decisions in difficult conditions.


