Cybersecurity
Experts who help organisations understand digital threats, protect critical systems, and build genuine resilience
Most boards have signed off on AI strategies they cannot fully explain to their own people. The gap is not technical, it is translational: senior teams need a clear read on what the technology can already do, what is still hype, and which decisions cannot wait. Without that clarity, AI investment becomes a portfolio of pilots rather than a source of advantage.
Most security failures do not start with a system. They start with a person being persuaded, distracted or trusted into letting an attacker through the door. Boards keep funding controls that assume the workforce is the strongest defence, when attackers treat it as the easiest route in.
Senior leaders are being asked to commit capital and strategy to technologies whose second-order effects are still being written. The gap is not a shortage of information about AI, cybersecurity or platform shifts. It is the absence of a sober, editorially disciplined read on which signals matter, which are noise, and what the next eighteen months look like for the companies making the bets.
Boards are being asked to take real positions on geopolitics, sanctions exposure, hostile-state cyber risk and supply-chain dependencies that used to be someone else’s problem. Most do not have an intelligence-grade read on what is actually changing, or how fast. The gap between corporate risk registers and the picture inside national security briefings is widening, and the cost of getting it wrong is no longer theoretical.
Most breaches do not start with a flaw in the firewall. They start with a person who answered the wrong email, trusted the wrong voice, or approved the wrong wire. Security spend keeps rising while the attacker keeps targeting the human layer, and most organisations still treat that layer as a training problem rather than a behavioural one.
Every senior leader has been told that technology ethics matters. Very few have been given a way to make ethics decisions that also survive a board review or a regulator’s letter. In AI, surveillance, biometrics and the platforms now embedded in every function of the business, the question is no longer whether to worry about ethics, it is how to make defensible choices at the speed the technology is moving, with the operating, legal and reputational consequences those choices carry.
Cybersecurity and digital identity decisions are being made at the architecture layer faster than most boards can scrutinise them. The standards that will govern extended reality, distributed ledger systems and biometric identity are being drafted right now in working groups most senior leaders cannot name. Once those standards harden, the choices embedded in them shape regulatory exposure and competitive position for the decade that follows.
Most cyber breaches do not begin with a clever exploit. They begin with a person clicking, sharing, or trusting the wrong thing. Boards keep pouring budget into tooling while the human layer, where the real exposure lives, goes underdeveloped and largely unmeasured.
Boards are being asked to commit capital and credibility to AI before anyone has a settled view of what the technology will and will not do. The reflex is either to over-promise or to wait. Both positions are expensive, and neither produces the judgment a senior team needs to set policy on adoption, risk, and public trust.
Most breaches do not come through the firewall. They come through a tired employee, a shared password, a click on a convincing email, a process that nobody reviewed. Boards have spent a decade buying technology, and the human layer is still where attackers walk in.
Most boards now run two parallel conversations: how fast to adopt AI, and how to defend against attacks AI is making cheaper and harder to detect. The two rarely meet in the same room. Adoption races ahead while governance and trust catch up only after a breach forces the question.
Most boards still treat cybersecurity as a compliance line item managed by the CISO. The attackers do not. They move faster than procurement cycles, exploit the gap between IT controls and human behaviour, and turn ransomware into an operating crisis within hours. Leadership teams need a sharper feel for how attackers actually work, not another framework.