August 5, 2026
For many years, cyber security comfortably sat within the technology function – appearing as an IT update, surfacing during audit discussions and often viewed through the lens of systems, infrastructure and compliance.
Today, that distinction has disappeared.
A cyber incident has the potential to disrupt operations, damage reputation, erode customer trust and materially affect shareholder value.
The challenge facing boards today is no longer recognising cyber as an organisational priority, rather governing it accordingly.
That was the central theme explored in Board Matters, a new vodcast series hosting the most forward-thinking directors, chairs and executive leaders to unpack the strategies shaping today’s boardroom.
To watch the full episode of Cyber Risk Is Business Risk – click here.
Cyber may feature on almost every board agenda but meaningful engagement remains inconsistent.
According to Saleshni Sharma – CISO of Asia Pacific at Berkley Insurance – there is still a clear difference between organisations that acknowledge cyber risk and those that genuinely understand it.
“Some of the board members would say that, yes, we are interested in cyber, but when they really discuss cyber, it’s probably five minutes at the end of the meeting,” Sharma observed.
Building on this, Sharma also highlighted a disconnect that continues to limit effective governance.
“A CISO sometimes doesn’t even get a chair around that table,” Sharma added. “What boards should be concentrating on is resilience. In case something does happen, how quickly can we come back online and actually ensure that business continues?”
Building on this, David Allott – Field CISO across Asia Pacific and Japan (APJ) at Veeam – referenced a similar, and potentially severe, mindset still in operation throughout the region.
Rather than debating whether an attack will occur, is now the time for boards to rethink assumptions?
“I still see there are organisations that focus on cyber risk as an IT problem,” Allott acknowledged.
“They spend too much time debating on the probability of something happening instead of the certainty that something will. Resilience is where we’re starting to see a lot more investment.”
For Su-Yen Wong – Board Chair and Board Director of City Developments Limited, James Cook University, CSE, Kemin Industries and First Resources among others – the defining characteristic of high-performing boards in the context of cyber security must evolve.
“Boards that get it don’t look at it as an IT risk,” Su-Yen shared. “That exposure can be financial, can be technical, can be operational, can be reputational, can be organisational.”
In this framing, Su-Yen challenged boards to rethink how they build cyber capability around the table – “they don’t pretend to be lawyers. Equally, they shouldn’t pretend to be technical folks.”
Instead, organisations increasingly require directors with broader digital expertise.
“There is a need for digital acumen at the board level,” Su-Yen stated.
One word consistently surfaced throughout the discussion – resilience. Not because prevention is no longer important but because every organisation must now assume disruption is possible.
As outlined by Tara Dharnikota – CISO at Victoria University – that requires businesses to move thinking and decision making beyond technology.
“The temptation is to look for a tool that will solve the problem but it’s not a tooling question,” Dharnikota advised. “Instead, leaders should ask whether the organisation can: prevent, detect, respond, recover when something goes wrong, and whether people understand their roles when pressure is applied.”
Dharnikota also recommended that boards shift the conversation away from technical vulnerabilities towards organisational impact.
“The conversation becomes less about tools or vulnerabilities and focuses more about what could materially disrupt our university,” Dharnikota explained. “Resilience can often be proven through exercises, incidents, lessons learned, continuous improvement.”
In moving away from the assumption of resilience – instead focusing on measuring maturity at much more frequent intervals – Allott believes this broader view of resilience is also changing accountability itself.
“With AI, we’re now seeing multiple points of accountability,” Allott outlined. “You’ve got compliance sitting at the table, you’ve got legal sitting at the table, and so we’re looking at accountability very differently.”
In other words, this is no long a challenge exclusive to the CISO. Su-Yen reinforced that while boards do not need to become technical specialists, accountability ultimately remains unchanged.
“At the end of the day, the board is accountable for everything,” Su-Yen added.
The responsibility, Su-Yen explained, is establishing the right governance structures, understanding what is truly critical and creating the organisational guardrails that enable management to execute effectively.
The conversation concluded by examining what boards should actually measure – not activity, not dashboards and not thousands of technical alerts.
Instead, understanding what genuinely matters to the organisation.
Su-Yen Wong argued that effective governance begins with partnership between directors and security leaders, blending wider accountability with a bridge in communication between business and technology.
“The board needs to lean in and take an interest but CISOs must help translate this into value and the risk to the business,” Su-Yen advised.
For Allott, this disconnect remains one of the biggest blind spots facing organisations today.
“There’s still a lot of organisations that are trying to grapple with that question… what is my most critical data?” he challenged.
Before organisations can confidently embrace emerging technologies, they first need a much clearer understanding of where critical assets sit and who ultimately owns them.
Particularly within higher education, the answer is not restricting access, however.
“Accessibility is not necessarily a weakness,” Dharnikota clarified. “It is part of the operating model and security then becomes an enabler.”
Sharma agreed that communication plays a defining role in helping boards make better decisions. Rather than presenting thousands of vulnerabilities, CISOs should outline information in business terms.
“These are your critical assets, these are the vulnerabilities and I need support for this,” Sharma noted. “Cyber security risk is a business risk, so boards must let CISOs come to the party. Don’t talk to your CISOs only when an incident happens.”
While backgrounds span the boardroom, education, financial services and technology, all leaders arrived at a consistent conclusion: resilience – not prevention – has become the measure of organisational maturity.
This means deliberately avoiding presenting cyber security as a technology challenge. Instead, positioning cyber as one of the clearest indicators of whether governance itself is evolving quickly enough to keep pace with modern business.
As organisations continue navigating AI, digital transformation, regulatory change and increasingly complex risk environments, the questions facing directors become less about technology and more about leadership.
Su-Yen Wong perhaps captured the challenge best in two simple words – “level up.”
To watch the full episode of Cyber Risk Is Business Risk – click here.
Board Matters – in partnership with Moxie Insights and Veeam – hosts the most forward-thinking directors, chairs and executive leaders to unpack the strategies shaping today’s boardroom.
Inform your opinion with executive guidance, in-depth analysis and business commentary.