Skip to content

7 September, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • climate risk

      Now is the time to take action on climate risk

      Whatever direction national policies take, nature and climate remain as drivers of value and risk...

      AI risk

      AI is about strategy, not technology

      Clients are judging how professional services firms are performing against their AI expectations, but most...

      organisational capability

      5 ways to assess organisational capability

      Strong strategy is not enough—boards also need to know whether the organisation has the people,...

  • Comment
      • View all
    • climate risk

      Now is the time to take action on climate risk

      Whatever direction national policies take, nature and climate remain as drivers of value and risk...

      ai skills gap

      Don’t forget to price up the AI skills gap 

      With AI set to be biggest force reshaping organisations, it is time to put workforce...

      qualities

      Audit quality: from progress to consistency

      Can the audit profession capitalise on its improvements to meet its next challenge—embedding quality across...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

      female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • Georgeson 2026 European AGM Season Review

      Georgeson’s deep dive into the evolving dynamics of investor voting across nine major European markets in...

      2026 MidYear Executive Benchmark Survey: The Verification Gap

      AI enthusiasm is running into reality: 1 in 4 executives in this Workiva survey say...

      Seven Steps for Futureproofing Business

      This guide from Business in the Community aims to help businesses build a practical strategy...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

Cyber resilience is a test of leadership

by Sarah Armstrong-Smith

Cyber threat is moving fast, and boards need to step up now in order to be prepared for a cyber-attack on the organisation.

disclosure

Image: astel design/Shutterstock.com

Favorite

Cybersecurity is still too often described as a technical issue to be solved, rather than a strategic enterprise risk. A cyber-attack can stop operations, expose sensitive data, disrupt customers, unsettle employees, attract regulatory scrutiny and put leaders under intense public pressure. This is a business crisis.

That is why cyber resilience belongs firmly on the board agenda. The threat is moving too fast: technologies are evolving, data is crossing borders, workforces are distributed, and attackers keep adapting. The methods will change; the mission will not: protect vulnerable people, sensitive data and the services that matter most.

Recent attacks brands show how quickly a cyber event can become an operational, reputational and leadership crisis.

Recent attacks on major UK brands should make every board uncomfortable because they show how quickly a cyber event can become an operational, reputational and leadership crisis. Stakeholders will judge your credibility, whether they can trust you, whether people and data are protected, and how you respond.

Resilience is not about preventing every attack. It is about absorbing shocks and uncertainty while maintaining the stability and confidence needed for long-term continuity.

It is about knowing what matters most, preparing for the worst case, and recovering with pace, clarity and empathy. Boards should stop asking, “Are we secure?” and start asking, “Are we prepared?” Have assumptions been replaced with facts? Do we know our critical dependencies? Are leaders empowered to make decisions under pressure?

Faster, more targeted, less visible threats

The threat landscape now includes geopolitical tensions, supply chain compromise and cyber influence operations designed to manipulate trust.

Attackers often look for the vulnerable point in the system, and that is not always technical. They have moved beyond breaking in to blending in, allowing them to watch and observe before considering their next move, which is often levied at the human layer.

AI gives attackers speed, scale and precision.

AI makes the problem more acute by giving attackers speed, scale and precision. Phishing is now highly targeted and written for its audience; poor grammar has been replaced by polished prose. Voice cloning can make requests feel personal, deepfakes can turn trust into a weapon, and synthetic identities can be created at scale.
For defenders, AI can improve detection, triage and response, but it is neither a silver bullet nor a side issue. It is a force multiplier that, without solid governance, can amplify existing weaknesses.

Boards need to understand how AI is being positioned and embedded across the organisation. What data is being shared or exposed? Who has access? What decisions rely on AI outputs? What happens when it gets things wrong? These are questions of accountability, ethics, trust and resilience, not technical detail. Innovation without governance is unmanaged risk with better branding.

People: the first line of resilience

One of the most damaging ideas in cybersecurity is that people are the weakest link. I have never agreed. Attackers know people are not only vulnerable but also among an organisation’s most valuable assets, which is why protecting them must be a priority.

People sense when something feels wrong, can stop an attack from escalating, and it is they who carry the consequences when organisations fail to prepare. Attackers target them because people are where trust, pressure and judgement meet.

Education and awareness cannot be an annual compliance tick-box exercise. Rather, it must be relevant, practical and human, tailored to the real risk that people are exposed to across their work and personal lives. This means moving beyond discussing methods, to truly understand motivations.

People need to understand why attackers use urgency, fear, curiosity and authority.

People need to understand why attackers use urgency, fear, curiosity and authority. They need permission to pause, challenge and verify, even when the request appears to come from someone senior. And they need to know that reporting a mistake quickly is an act of responsibility, not a career-limiting move.

Culture is where cyber resilience becomes real or falls apart. Bad cultures create silence and apathy: people hide mistakes, avoid challenge and assume someone else is managing the risk. Good cultures create psychological safety and accountability, making it normal to speak up, ask questions and surface risks before they become failures.

Protecting business priorities

Effective cyber defences start with a simple question: what are we here to protect? Strategic resilience must connect to the organisation’s purpose, whether it delivers products, services, infrastructure, care, advice or support. What critical services must continue? What data would cause the greatest harm if exposed or manipulated? Which people are most vulnerable to manipulation? Which processes would fail if technology was compromised?

Boards should demand evidence, not reassurance. It is easy to be told there is an incident response plan, or a cyber strategy. The harder question is whether anyone has verified them under acute pressure. Has the executive team understood the toughest decisions they will need to make? Do they have the confidence and the facts to make them? This requires diligence and honesty, where the truth is not sheltered from the top, but welcomed.

What can boards do now?

For boards and executive teams, the cyber resilience conversation needs to move beyond controls and into consequence. What is our risk appetite? What is our worst-case scenario? Where are we most exposed? What would cause the greatest harm to our customers, employees and stakeholders? What investment needs to be made to reduce risk, and increase resilience?

The real test is not whether an incident will happen, but whether the organisation can respond with clarity.

It also requires leaders to embrace the red. Too often organisations want assurance that everything is green because it feels neutral and safe. But green can also mask complacency. Red is not failure. Red is true insight. It shows where action is needed, where investment should be focused and where assumptions need to be challenged.

The organisations that recover stronger are the ones willing to face reality before reality becomes a crisis.

Cybersecurity is a business issue, not an IT one. It is about protecting what matters most, building trust and keeping the organisation operating through disruption. Boards do not need to become cyber specialists, but they do need to ask the right questions, demand evidence and lead from the front. The real test is not whether an incident will happen, but whether the organisation can respond with clarity, accountability and empathy when it does.

The organisations best placed for the next wave of threats will not be those that rely on technology alone. They will be those with the courage to confront reality, the discipline to prepare before crisis hits, and the leadership to build a culture where people act quickly, speak up early and learn without fear. Cyber resilience ultimately measures how well an organisation understands itself. If the board cannot answer what matters most, what could cause most harm and how to act when things go wrong, attackers may find those answers first.

Sarah Armstrong-Smith is chief strategy officer at Performanta and a former chief security advisor for Microsoft EMEA.

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Cybersecurity ‘is a boardroom issue’
    October 15, 2025
    cyber attack

    Leaders need to take responsibility for their organisation’s cyber resilience, warns the National Cyber Security Centre.

  • UK cybersecurity chief warns of ‘perfect storm’
    April 22, 2026
    cybersecurity

    AI and global disruption have brought ‘tumultuous uncertainty’ to organisations, says the CEO of the National Cyber Security Centre.

  • The paradox of cyber risk and business growth
    August 1, 2024
    cyber risk and business growth

    Risk consensus and confidence in cybersecurity allow boards and organisations to innovate and drive the business forward.

  • Call for boards to sign government Cyber Resilience Pledge
    April 22, 2026
    cyber resilience pledge

    The initiative, launched by cybersecurity minister Baroness Lloyd of Effra CBE, prompts ‘practical, achievable’ and ‘proven’ action.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy