Cybersecurity
Experts who help organisations understand digital threats, protect critical systems, and build genuine resilience
Speakers Associates represents 64 speakers on Cybersecurity, including Limor Ziv, Harriet Farlow, Saakshar Duggal, Marc Saltzman, Theresa Payton, Jim Sciutto, Susi O’Neill, Georgia Harrison, Nina Schick and Sol Rashidi.
Most breaches do not come through the firewall. They come through a tired employee, a shared password, a click on a convincing email, a process that nobody reviewed. Boards have spent a decade buying technology, and the human layer is still where attackers walk in.
Boards are being asked to take real positions on China exposure, Russia, sanctions regimes, and the next conflict before the analyst notes catch up. Most leadership teams have no internal capacity to read state-level competition with confidence. The cost of getting it wrong now sits in revenue lines, not just risk registers.
Technology-first approaches to AI and digital transformation tend to produce systems that solve technical problems, not organisational or civic ones. When the people affected by those systems have no stake in how they are designed or governed, trust erodes and adoption fails. The gap between deployment speed and governance readiness is where most digital strategies break down.
Most leadership teams know they are behind on consumer technology, but cannot tell which trends will reshape their category and which will fade in eighteen months. The cost of guessing wrong is real: misjudged AI rollouts, security gaps, retail experiences that miss the customer, product roadmaps built on yesterday’s behaviour. Senior teams need a working filter, not another vendor pitch.
Most cyber breaches do not begin with a clever exploit. They begin with a person clicking, sharing, or trusting the wrong thing. Boards keep pouring budget into tooling while the human layer, where the real exposure lives, goes underdeveloped and largely unmeasured.
Boards are being asked to make defensible decisions about exposure they cannot fully see: criminal networks embedded in supply chains, cyber intrusion routed through state actors, sanctions risk that shifts faster than legal opinion. The old separation between security, geopolitics and commercial strategy no longer holds. Leaders need a coherent picture of how these systems actually interact, written by someone who has spent decades inside them.
Most boards now run two parallel conversations: how fast to adopt AI, and how to defend against attacks AI is making cheaper and harder to detect. The two rarely meet in the same room. Adoption races ahead while governance and trust catch up only after a breach forces the question.
Cybersecurity and digital identity decisions are being made at the architecture layer faster than most boards can scrutinise them. The standards that will govern extended reality, distributed ledger systems and biometric identity are being drafted right now in working groups most senior leaders cannot name. Once those standards harden, the choices embedded in them shape regulatory exposure and competitive position for the decade that follows.
Most organisations build payment systems faster than they understand the security and compliance risks embedded in them. Fraud prevention and cybersecurity are treated as separate disciplines – and the gap between those two teams is where exposure accumulates. Senior leaders approving payments infrastructure and fintech partnerships rarely have the regulatory and technical literacy to evaluate what they are committing to.
Most boards still treat AI as a software question their CIO will solve. The story is bigger than that. The contest is over compute, fabs, energy supply, and the sovereign infrastructure that will decide which companies and which countries hold the next decade of pricing power. Leaders who frame AI as a productivity tool are already a strategy cycle behind.
Boards are being asked to take real positions on geopolitics, sanctions exposure, hostile-state cyber risk and supply-chain dependencies that used to be someone else’s problem. Most do not have an intelligence-grade read on what is actually changing, or how fast. The gap between corporate risk registers and the picture inside national security briefings is widening, and the cost of getting it wrong is no longer theoretical.
Most digital transformation programmes stall in the gap between strategy decks and operating reality. The harder question is sovereignty: who controls the code, the infrastructure, the talent pipeline, and the standards your business now depends on. Boards rarely have a credible internal voice that can speak to both the technology stack and the policy machinery around it.