Cybersecurity is still too often described as a technical issue to be solved, rather than a strategic enterprise risk. A cyber-attack can stop operations, expose sensitive data, disrupt customers, unsettle employees, attract regulatory scrutiny and put leaders under intense public pressure. This is a business crisis.
That is why cyber resilience belongs firmly on the board agenda. The threat is moving too fast: technologies are evolving, data is crossing borders, workforces are distributed, and attackers keep adapting. The methods will change; the mission will not: protect vulnerable people, sensitive data and the services that matter most.
Recent attacks on major UK brands should make every board uncomfortable because they show how quickly a cyber event can become an operational, reputational and leadership crisis. Stakeholders will judge your credibility, whether they can trust you, whether people and data are protected, and how you respond.
Resilience is not about preventing every attack. It is about absorbing shocks and uncertainty while maintaining the stability and confidence needed for long-term continuity.
It is about knowing what matters most, preparing for the worst case, and recovering with pace, clarity and empathy. Boards should stop asking, “Are we secure?” and start asking, “Are we prepared?” Have assumptions been replaced with facts? Do we know our critical dependencies? Are leaders empowered to make decisions under pressure?
Faster, more targeted, less visible threats
The threat landscape now includes geopolitical tensions, supply chain compromise and cyber influence operations designed to manipulate trust.
Attackers often look for the vulnerable point in the system, and that is not always technical. They have moved beyond breaking in to blending in, allowing them to watch and observe before considering their next move, which is often levied at the human layer.
AI makes the problem more acute by giving attackers speed, scale and precision. Phishing is now highly targeted and written for its audience; poor grammar has been replaced by polished prose. Voice cloning can make requests feel personal, deepfakes can turn trust into a weapon, and synthetic identities can be created at scale.
For defenders, AI can improve detection, triage and response, but it is neither a silver bullet nor a side issue. It is a force multiplier that, without solid governance, can amplify existing weaknesses.
Boards need to understand how AI is being positioned and embedded across the organisation. What data is being shared or exposed? Who has access? What decisions rely on AI outputs? What happens when it gets things wrong? These are questions of accountability, ethics, trust and resilience, not technical detail. Innovation without governance is unmanaged risk with better branding.
People: the first line of resilience
One of the most damaging ideas in cybersecurity is that people are the weakest link. I have never agreed. Attackers know people are not only vulnerable but also among an organisation’s most valuable assets, which is why protecting them must be a priority.
People sense when something feels wrong, can stop an attack from escalating, and it is they who carry the consequences when organisations fail to prepare. Attackers target them because people are where trust, pressure and judgement meet.
Education and awareness cannot be an annual compliance tick-box exercise. Rather, it must be relevant, practical and human, tailored to the real risk that people are exposed to across their work and personal lives. This means moving beyond discussing methods, to truly understand motivations.
People need to understand why attackers use urgency, fear, curiosity and authority. They need permission to pause, challenge and verify, even when the request appears to come from someone senior. And they need to know that reporting a mistake quickly is an act of responsibility, not a career-limiting move.
Culture is where cyber resilience becomes real or falls apart. Bad cultures create silence and apathy: people hide mistakes, avoid challenge and assume someone else is managing the risk. Good cultures create psychological safety and accountability, making it normal to speak up, ask questions and surface risks before they become failures.
Protecting business priorities
Effective cyber defences start with a simple question: what are we here to protect? Strategic resilience must connect to the organisation’s purpose, whether it delivers products, services, infrastructure, care, advice or support. What critical services must continue? What data would cause the greatest harm if exposed or manipulated? Which people are most vulnerable to manipulation? Which processes would fail if technology was compromised?
Boards should demand evidence, not reassurance. It is easy to be told there is an incident response plan, or a cyber strategy. The harder question is whether anyone has verified them under acute pressure. Has the executive team understood the toughest decisions they will need to make? Do they have the confidence and the facts to make them? This requires diligence and honesty, where the truth is not sheltered from the top, but welcomed.
What can boards do now?
For boards and executive teams, the cyber resilience conversation needs to move beyond controls and into consequence. What is our risk appetite? What is our worst-case scenario? Where are we most exposed? What would cause the greatest harm to our customers, employees and stakeholders? What investment needs to be made to reduce risk, and increase resilience?
It also requires leaders to embrace the red. Too often organisations want assurance that everything is green because it feels neutral and safe. But green can also mask complacency. Red is not failure. Red is true insight. It shows where action is needed, where investment should be focused and where assumptions need to be challenged.
The organisations that recover stronger are the ones willing to face reality before reality becomes a crisis.
Cybersecurity is a business issue, not an IT one. It is about protecting what matters most, building trust and keeping the organisation operating through disruption. Boards do not need to become cyber specialists, but they do need to ask the right questions, demand evidence and lead from the front. The real test is not whether an incident will happen, but whether the organisation can respond with clarity, accountability and empathy when it does.
The organisations best placed for the next wave of threats will not be those that rely on technology alone. They will be those with the courage to confront reality, the discipline to prepare before crisis hits, and the leadership to build a culture where people act quickly, speak up early and learn without fear. Cyber resilience ultimately measures how well an organisation understands itself. If the board cannot answer what matters most, what could cause most harm and how to act when things go wrong, attackers may find those answers first.
Sarah Armstrong-Smith is chief strategy officer at Performanta and a former chief security advisor for Microsoft EMEA.


