Cybersecurity Is No Longer an IT Issue. Today, the Entire Board Is Responsible
Just a few years ago, cybersecurity was viewed primarily as the responsibility of the IT department. Today, that approach is not only outdated but can also expose an organization to significant legal, financial, and reputational risks. As cybercriminals increasingly leverage artificial intelligence, deepfake technology, and sophisticated social engineering techniques, their primary targets are no longer IT systems but the people responsible for making critical business decisions.
A New Era of Cyberattacks: Decision-Making Is the Real Target
Modern cyberattacks are becoming less about breaching technical defenses and more about manipulating people. Cybercriminals understand that influencing human judgment is often easier than bypassing advanced security systems.
The most common attack methods include:
- Business Email Compromise (BEC)
- Spear phishing
- AI-generated deepfake audio and video
- Fake invoices
- Impersonation of business partners
- Manipulation of payment approval processes
One increasingly common scenario involves attackers compromising a supplier’s email account and sending highly convincing requests to change bank account details. Because the messages often include authentic conversation history and realistic documentation, organizations may unknowingly authorize payments to fraudulent accounts.
This shift illustrates a fundamental change in cybercrime: attackers are now targeting business decision-making rather than technology alone.
Artificial Intelligence Has Increased the Effectiveness of Cybercrime
Generative AI has dramatically improved the quality and credibility of social engineering attacks.
Modern AI tools can:
- Write flawless business emails.
- Replicate an executive’s communication style.
- Translate messages without obvious language mistakes.
- Generate realistic voice recordings.
- Produce convincing deepfake videos.
Only a few years ago, phishing emails could often be identified by poor grammar or awkward phrasing. Today, those warning signs have largely disappeared, making traditional awareness training less effective on its own.
Organizations must now prepare employees and executives for attacks that appear entirely legitimate.
Board Responsibility Extends Beyond Business Decisions
Corporate governance has always required board members to exercise due care when managing a company. Increasingly, this standard includes cybersecurity governance.
If an organization fails to:
- implement appropriate security policies,
- address known cyber risks,
- train executives,
- perform regular risk assessments,
- establish incident response procedures,
it may face allegations that management failed to fulfill its fiduciary duties following a serious cyber incident.
In many cases, legal scrutiny focuses not on the attack itself but on whether management took reasonable steps to prevent foreseeable risks.
NIS2 Raises the Standard for Cybersecurity Governance
The European Union’s NIS2 Directive significantly strengthens cybersecurity obligations for organizations operating in critical and important sectors.
Among other requirements, organizations must:
- conduct regular cybersecurity risk assessments,
- implement appropriate security policies,
- manage third-party cybersecurity risks,
- report significant incidents,
- provide cybersecurity training for management,
- ensure active involvement of governing bodies in cybersecurity oversight.
Importantly, members of management bodies are expected to acquire sufficient knowledge to understand cyber risks and make informed decisions regarding organizational resilience.
DORA Establishes New Requirements for the Financial Sector
For financial institutions, the Digital Operational Resilience Act (DORA) introduces even more comprehensive obligations.
The regulation requires organizations to:
- continuously monitor cyber threats,
- regularly test digital operational resilience,
- manage ICT third-party risks,
- report significant incidents,
- maintain business continuity capabilities.
Under DORA, cybersecurity is formally recognized as a core element of corporate governance rather than solely an IT responsibility.
The Business Judgment Rule Does Not Protect Negligence
The Business Judgment Rule recognizes that directors should not be held personally liable simply because a business decision results in an unfavorable outcome.
Instead, the focus is on whether the decision-making process was reasonable and informed.
Board members are generally better protected when they:
- assess relevant risks,
- consult qualified experts,
- evaluate alternative options,
- act in good faith,
- prioritize the company’s best interests.
However, failing to address well-known cybersecurity risks or neglecting fundamental governance responsibilities may expose directors to personal liability.
Compliance Has Become a Strategic Shield
Modern compliance programs serve purposes far beyond regulatory compliance.
They demonstrate that an organization has exercised appropriate care and established reasonable governance practices.
An effective compliance framework typically includes:
- payment authorization procedures,
- cybersecurity policies,
- conflict-of-interest management,
- whistleblower protection,
- internal audits,
- documentation of decision-making processes.
Well-maintained documentation often becomes crucial evidence that management fulfilled its governance responsibilities.
Deepfake Technology Represents One of the Fastest-Growing Threats
Advances in AI have made deepfake attacks increasingly realistic.
Organizations should expect more attempts involving:
- fake phone calls from CEOs,
- fabricated executive video conferences,
- AI-generated voice messages authorizing payments,
- manipulated crisis communications,
- impersonation of board members.
As AI-generated content becomes more convincing, verifying the authenticity of communications will become an essential part of corporate security.
Many organizations are therefore adopting Zero Trust principles not only for network security but also for executive communications.
Third-Party Risk Management Is More Important Than Ever
Many cyber incidents now originate through suppliers, service providers, or software vendors rather than the targeted organization itself.
An effective cybersecurity strategy should therefore include:
- supplier cybersecurity assessments,
- contractual security requirements,
- periodic vendor audits,
- continuous monitoring of third-party risks,
- incident response procedures covering the supply chain.
This is particularly important as organizations increasingly rely on cloud services and outsourced business operations.
Directors & Officers Insurance Is Not a Substitute for Good Governance
Directors & Officers (D&O) liability insurance has become increasingly popular as organizations seek to protect executives from claims arising from their management responsibilities.
However, insurance should never be viewed as a replacement for effective governance.
Coverage is subject to policy terms and exclusions, and it does not eliminate statutory duties or excuse negligent conduct. Strong governance and proactive cybersecurity management remain the most effective forms of protection.
How Boards Can Reduce Cyber Risk
Organizations with mature cybersecurity programs focus on resilience rather than technology alone.
Best practices include:
- requiring dual approval for high-value financial transactions,
- verifying banking information changes through independent communication channels,
- providing regular cybersecurity training for executives,
- conducting phishing simulations,
- maintaining documented incident response plans,
- organizing executive-level cyber crisis exercises,
- monitoring supplier cybersecurity risks,
- documenting governance decisions,
- performing regular cybersecurity audits,
- fostering collaboration between IT, legal, compliance, finance, and executive leadership.
Conclusion
Cybersecurity has evolved into a fundamental element of corporate governance, enterprise risk management, and board accountability. As artificial intelligence enables increasingly sophisticated cyberattacks, organizations can no longer rely solely on technical defenses.
Success depends on building cyber resilience through strong governance, effective compliance programs, executive education, robust internal controls, and a culture of security awareness.
For today’s boards of directors, cybersecurity is no longer a technical consideration—it is a strategic leadership responsibility that directly influences business continuity, regulatory compliance, stakeholder trust, and long-term organizational success.
0 Comments