{"id":14262,"date":"2026-06-02T12:37:28","date_gmt":"2026-06-02T12:37:28","guid":{"rendered":"https:\/\/wildgreenquest.com\/?p=14262"},"modified":"2026-06-02T12:37:28","modified_gmt":"2026-06-02T12:37:28","slug":"why-your-board-is-still-not-ready-for-cyber-risk","status":"publish","type":"post","link":"https:\/\/wildgreenquest.com\/?p=14262","title":{"rendered":"Why Your Board Is Still Not Ready for Cyber Risk"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p><em>Insights from <\/em><a rel=\"nofollow\" href=\"https:\/\/www.linkedin.com\/in\/cdimitriadis\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.linkedin.com\/in\/cdimitriadis\/\" aria-label=\"Chris Dimitriadis\"><em data-ga-track=\"ExternalLink:https:\/\/www.linkedin.com\/in\/cdimitriadis\/\">Chris Dimitriadis<\/em><\/a><em>, Chief Global Strategy Officer, ISACA.<\/em><\/p>\n<figure class=\"embed-base image-embed embed-2\" role=\"presentation\">\n<div style=\"padding-top:66.53%;position:relative\" class=\"image-embed__placeholder\"><picture><source media=\"(min-width: 960px)\" sizes=\"50vw\" srcset=\"https:\/\/imageio.forbes.com\/specials-images\/imageserve\/695d8c866ec1052546d9098b\/\/0x0.jpg?width=960&amp;dpr=1 1x, https:\/\/imageio.forbes.com\/specials-images\/imageserve\/695d8c866ec1052546d9098b\/\/0x0.jpg?width=960&amp;dpr=1.5 1.5x, https:\/\/imageio.forbes.com\/specials-images\/imageserve\/695d8c866ec1052546d9098b\/\/0x0.jpg?width=960&amp;dpr=2 2x\"\/><\/picture><\/div>\n<\/figure>\n<p class=\"lexkit-paragraph\">\u200bCybersecurity is no longer a novel concept in the boardroom. There have been enough years\u2019 worth of headlines detailing cybersecurity breaches\u2014and the resulting financial and reputational damage\u2014to elevate cyber risk as a board-level issue. However, significant gaps remain in enterprises\u2019 preparedness. <\/p>\n<p class=\"lexkit-paragraph\">For the fifth year in a row, cyber incidents ranked as the top global risk, according to the <a rel=\"nofollow\" class=\"lexkit-link\" href=\"https:\/\/cybersecurity-magazine.com\/cyber-ranks-as-top-business-threat-according-to-2026-allianz-risk-barometer\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/cybersecurity-magazine.com\/cyber-ranks-as-top-business-threat-according-to-2026-allianz-risk-barometer\/\" aria-label=\"Allianz Commercial Risk Barometer\">Allianz Commercial Risk Barometer<\/a>. A disconnect exists between how prepared boards think their organizations are when it comes to cyber risk and the reality.<\/p>\n<section id=\"why-boards-struggle-prioritize-cybersecurity\">\n<h2 class=\"subhead-embed\">Why Boards Struggle To Prioritize Cybersecurity Investment\u200b<\/h2>\n<p class=\"lexkit-paragraph\">Much of this can be attributed to organizations struggling to clearly establish their return on investment from cybersecurity. Board directors are unlikely to push their leadership to make substantial investments in mitigating cyber risk without understanding how those investments materially influence the organization\u2019s financial health. <\/p>\n<p class=\"lexkit-paragraph\">For many organizations, this is tricky because of the variable nature of cyber risks and the hard-to-quantify aspect of factors such as reputational damage and loss of customer trust. Further complicating matters, many organizations lack sufficient internal expertise to authoritatively understand their cyber risk preparedness and existing gaps. Security and risk leadership need to be mindful of these potential hurdles and proactively educate board directors about the multifaceted benefits of cyber risk. <\/p>\n<\/section>\n<section id=\"measuring-cybersecurity-roi-more-effectively\">\n<h2 class=\"subhead-embed\">Measuring Cybersecurity ROI More Effectively\u200b<\/h2>\n<p class=\"lexkit-paragraph\">To support these efforts, organizations should explore methodologies that provide tangible metrics and frameworks for evaluating cybersecurity investments with a direct correlation to both potential financial impacts and gains\u2014impacts in terms of calculating contractual breaches, legal breaches, business disruption cost and customer loss, and gains in terms of being able to retain and acquire more customers, be more successful in bidding processes and overall by differentiating from competition.<\/p>\n<p class=\"lexkit-paragraph\">Calculating cybersecurity ROI also should factor in the value of business continuity, as disrupted operations caused by cybersecurity incidents can lead to major financial losses in the short-term and the even more concerning loss of customers over the longer term. There are few scenarios more chilling to boards of directors and enterprise leaders than their business being put out of commission for days due to a major cyber incident. <\/p>\n<p class=\"lexkit-paragraph\">Effective cyber risk management leads to improved business continuity by enhancing the organization\u2019s ability to respond to and recover from incidents swiftly, minimizing downtime and maintaining operational integrity. Integrating business continuity planning with cybersecurity risk planning helps organizations create a resilient infrastructure capable of withstanding and quickly recovering from attacks, safeguarding both short-term financial performance and long-term reputation with customers and key stakeholders.<\/p>\n<\/section>\n<section id=\"cybersecurity-as-competitive-advantage\">\n<h2 class=\"subhead-embed\">Cybersecurity As A Competitive Advantage\u200b<\/h2>\n<p class=\"lexkit-paragraph\">The potential to develop a significant competitive advantage is another element that should incentivize board directors. Sharpening cyber risk posture can lead to major competitive advantages for organizations, primarily as a key driver of customer trust and loyalty. By communicating to customers the steps that have been taken to protect their data, companies can turn their investments in mitigating cyber risk into a meaningful marketplace differentiator, particularly in sensitive industries like banking, healthcare and throughout the defense industrial base. <\/p>\n<p class=\"lexkit-paragraph\">As noted by Forbes author Jeffrey Bartel, \u201cOrganizations can use their cybersecurity position to gain market advantage through the inclusion of cybersecurity information in investor materials and ESG reports and competitive proposal submissions.\u201d<\/p>\n<\/section>\n<section id=\"what-boards-should-do-next\">\n<h2 class=\"subhead-embed\">What Boards Should Do Next\u200b<\/h2>\n<p class=\"lexkit-paragraph\">On top of calculating ROI so investments can be made in a more informed manner, boards should increase their readiness by:<\/p>\n<p class=\"lexkit-paragraph\">\u2022 Upgrading cyber risk to a board-level category rather than a technical issue, which may require training for improving the digital savviness of the board<\/p>\n<p class=\"lexkit-paragraph\">\u2022 Establishing clear governance and cyber risk ownership<\/p>\n<p class=\"lexkit-paragraph\">\u2022 Requesting metrics on top of the ROI that are quantified as part of the enterprise risk management program, delivered in board language rather than technical jargon<\/p>\n<p class=\"lexkit-paragraph\">\u2022 Requesting cybersecurity maturity and capability assessments that produce quantified results within the context of board-set priorities<\/p>\n<p class=\"lexkit-paragraph\">\u2022 Integrating cybersecurity in strategic and M&amp;A discussions<\/p>\n<p class=\"lexkit-paragraph\">\u2022 Achieving third-party assurance<\/p>\n<p class=\"lexkit-paragraph\">\u2022 Focusing on talent, ensuring that the organization is holistically trained, including in key emerging technologies and challenges, so decisions are made based on the realities of the present<\/p>\n<\/section>\n<section id=\"cyber-resilience-must-become-core\">\n<h2 class=\"subhead-embed\">Cyber Resilience Must Become A Core Enterprise Capability\u200b<\/h2>\n<p class=\"lexkit-paragraph\">A disciplined and proactive approach to addressing cyber risk must become a core enterprise capability, and that starts with enterprise boards making cyber risk a focal point. As artificial intelligence and the proliferation of data make the threat landscape increasingly difficult to combat, the ability to swiftly respond to incidents and maintain operational integrity will set successful organizations apart. <\/p>\n<p class=\"lexkit-paragraph\">By prioritizing the mitigation of cyber risk as a fundamental measure of their organization\u2019s long-term viability, boards can ensure that their companies are not only protected but are also positioned as leaders in their industries. Equipping board members with relevant data on the ROI of cyber risk investment and how mitigating risk can become a competitive advantage can turn the board into a powerful ally on the path to becoming a cyber-resilient organization.  <\/p>\n<hr class=\"embed-base rule-embed color-accent border-solid weight-light\"\/>\n<p><a rel=\"nofollow\" href=\"https:\/\/councils.forbes.com\/forbestechcouncil?utm_source=forbes.com&amp;utm_medium=referral&amp;utm_campaign=forbes-links&amp;utm_content=in-article-ad-links\" data-ga-track=\"InternalLink:https:\/\/councils.forbes.com\/forbestechcouncil?utm_source=forbes.com&amp;utm_medium=referral&amp;utm_campaign=forbes-links&amp;utm_content=in-article-ad-links\" target=\"_self\" aria-label=\"Forbes Technology Council\"><u data-ga-track=\"InternalLink:https:\/\/councils.forbes.com\/forbestechcouncil?utm_source=forbes.com&amp;utm_medium=referral&amp;utm_campaign=forbes-links&amp;utm_content=in-article-ad-links\">Forbes Technology Council<\/u><\/a> is an invitation-only community for world-class CIOs, CTOs and technology executives. <a rel=\"nofollow\" href=\"https:\/\/councils.forbes.com\/qualify?utm_source=forbes.com&amp;utm_medium=referral&amp;utm_campaign=forbes-links&amp;utm_term=ftc&amp;utm_content=in-article-ad-links\" data-ga-track=\"InternalLink:https:\/\/councils.forbes.com\/qualify?utm_source=forbes.com&amp;utm_medium=referral&amp;utm_campaign=forbes-links&amp;utm_term=ftc&amp;utm_content=in-article-ad-links\" target=\"_self\" aria-label=\"Do I qualify?\"><em data-ga-track=\"InternalLink:https:\/\/councils.forbes.com\/qualify?utm_source=forbes.com&amp;utm_medium=referral&amp;utm_campaign=forbes-links&amp;utm_term=ftc&amp;utm_content=in-article-ad-links\"><u data-ga-track=\"InternalLink:https:\/\/councils.forbes.com\/qualify?utm_source=forbes.com&amp;utm_medium=referral&amp;utm_campaign=forbes-links&amp;utm_term=ftc&amp;utm_content=in-article-ad-links\">Do I qualify?<\/u><\/em><\/a><\/p>\n<hr class=\"embed-base rule-embed color-accent border-solid weight-light\"\/><\/section>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.forbes.com\/councils\/forbestechcouncil\/2026\/06\/02\/why-your-board-is-still-not-ready-for-cyber-risk-and-what-actually-needs-to-change\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Insights from Chris Dimitriadis, Chief Global Strategy Officer, ISACA. \u200bCybersecurity is no longer a novel concept in the boardroom. There have been enough years\u2019 worth of headlines detailing cybersecurity breaches\u2014and the resulting financial and reputational damage\u2014to elevate cyber risk as a board-level issue. However, significant gaps remain in enterprises\u2019 preparedness. For the fifth year in<\/p>\n","protected":false},"author":1,"featured_media":14263,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[37],"tags":[],"class_list":["post-14262","post","type-post","status-publish","format-standard","has-post-thumbnail","category-brand-spotlights"],"_links":{"self":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts\/14262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14262"}],"version-history":[{"count":0,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts\/14262\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/media\/14263"}],"wp:attachment":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}