When cybersecurity comes up at a board meeting, it's often treated as an operational item: a status update from the CISO, an overview of patches and incidents, confirmation that compliance requirements have been met. That's not wrong in itself, but it's insufficient. Cyber is not an IT risk. It's a business, operational and trust risk — and ultimately a capital risk. And it isn't just about complying with NIS2 — it's about mitigating real business risk, where from time to time it's the company's survival that's at stake.
The distinction matters. An IT risk gets handled by the IT department and reported upward. A business risk requires the board to understand the consequences well enough to ask the right questions itself — not just receive answers.
What's actually at stake
A serious cyberattack is rarely just a technical problem for a few hours or days. It's operational downtime that affects customers and suppliers. It's trust that has to be rebuilt — with customers, partners and employees. It's potential legal and regulatory consequences, particularly as frameworks like NIS2, DORA and GDPR place increasingly clear demands on leadership accountability. And it's a capital cost: insurance, recovery, lost revenue, and in some cases lasting damage to the company's value.
None of those consequences are solved by a technical incident response plan alone. They require the board to have taken a position on them before they become real.
What I bring from both sides of the table
I've spent a large part of my career in the security industry — as co-founder and CEO of an international security company that competed with global players to solve exactly this type of problem. That experience means I can go technical with a CISO without needing everything translated first. But the more important experience is the reverse: being able to translate the technical reality into something the rest of the board can make decisions from.
Four questions a board should be able to answer
- Do we know which data and systems are actually critical to our operations — and how long we could tolerate losing access to them?
- Do we have a response plan that's been tested — not just written — and that the board has itself seen exercised?
- Do we understand who has access to what across the organisation, and why?
- Is cybersecurity part of how we evaluate new investments, acquisitions and partnerships — or does it only enter the picture afterwards?
A board that can answer those questions with confidence has moved cyber from an IT item to an integrated part of the company's risk management. It isn't about becoming a technical expert. It's about taking the risk as seriously as any other risk that could threaten the business.
— David Hald