Cybersecurity has become a boardroom risk

Cybersecurity
Cybersecurity oversight now requires operational evidence with remote work, third-party software and AI tools widening corporate exposure.

Cybersecurity now belongs on the agenda of boards and chief executives because a successful attack can interrupt the business itself. Ransomware can stop production or prevent employees from reaching essential systems. Theft of customer information can bring regulators into the picture. A compromised employee laptop can give an attacker access to systems on which the company depends.

Directors do not need the technical knowledge of a security engineer. They do need to know which systems the business cannot operate without, who is responsible for protecting them and how long recovery would take after a serious breach.

READ | The digital fraud epidemic calls for stronger cybersecurity measures

Cybersecurity threats have moved beyond the corporate network

Ransomware-as-a-service has made attack tools available to criminals without the resources to build them. Companies also face weaknesses they do not directly control. An attacker may enter through a software supplier or another firm with legitimate access to corporate systems.

Work practices have widened the points at which an organisation can be attacked. Employees connect from home networks and public locations, sometimes through devices the company does not fully control. Files pass through cloud services and collaboration software. Employees may also enter company information into generative AI applications outside the employer’s systems.

A security model built mainly around the office network cannot deal with all these points of access. Management therefore needs information on how quickly suspicious activity is detected and how much of the business an attacker can reach after gaining entry.

Endpoint security reaches directly into business operations

Every employee device that connects to corporate systems creates a potential route into them. An unpatched laptop can expose systems protected by much larger investments elsewhere. A wrongly configured machine can create the same problem.

This is especially relevant where employees routinely handle client records or proprietary information. The controls around their devices determine whether those records remain within systems governed by company policy.

READ | Cybersecurity: US, India join forces for a safer digital world

Endpoint protection consequently extends well beyond antivirus software. Companies need an accurate record of the devices connecting to their systems and whether those machines meet their security requirements. They also need the ability to isolate a compromised device or remove company information from it.

Management can test the quality of these controls through operational data. It can ask how many devices are outside company policy and how long critical software patches take to reach the workforce. A large gap between policy and actual device status tells the board more than a general assurance that cybersecurity is being addressed.

AI is changing how attackers and security teams work

Generative AI allows attackers to produce credible phishing messages cheaply and at scale. Messages can be tailored to a recipient or organisation without the labour that personalised fraud once required.

That reduces the value of one familiar defence against phishing. Employees could once dismiss many fraudulent messages because the language was crude or the context implausible. Machine-generated messages can remove those obvious warnings.

Security teams are using machine-learning tools to identify unusual behaviour inside corporate systems. A user account accessing unfamiliar files or logging in from an implausible location can be flagged for investigation without waiting for a known malware signature.

The useful measure is whether such systems reduce the time required to detect and contain an intrusion. Purchasing an AI-labelled security product says little by itself about whether the company is harder to attack.

IT policy must reflect how employees actually work

Many corporate IT policies describe rules that are reviewed during an audit but receive much less attention during everyday work. The gap becomes serious when employees use applications or devices that the written policy barely addresses.

A workable policy should govern how devices enter and leave the organisation, which software employees may install and where company information may be stored. Employees also need clear instructions on what to do when they suspect that an account or device has been compromised.

Generative AI has created a specific policy problem. An employee can copy internal material into an external service within seconds. Companies need rules identifying information that cannot be entered into third-party AI systems and controls that make those rules enforceable where necessary.

Access rights also accumulate as people change jobs inside an organisation. An employee may retain permission to use files or systems required in an earlier role. Removing those permissions reduces the amount of information available to an attacker who compromises that account.

Incident-response plans require the same practical treatment. An organisation learns little from a plan that has never been exercised. Simulated breach exercises can show whether managers know who takes decisions, which systems receive priority and whether recovery procedures work as expected.

READ | Futureproofing businesses: A 5-point cybersecurity checklist for MSMEs

Cybersecurity regulation raises the financial cost of weak controls

A serious breach can expose weaknesses that extend beyond the affected computer systems. Data protection obligations and sector-specific cybersecurity rules can bring regulatory scrutiny after an incident. Customers may also ask whether the company took reasonable steps to protect information entrusted to it.

The ability to produce records then becomes important. Patch histories, access logs and evidence that incident procedures were tested can show whether stated controls were actually in force.

This gives boards a more useful basis for oversight than a general declaration of compliance. Directors can ask which controls have been tested, where failures were found and whether they were corrected.

Boards need evidence of cyber preparedness

Cybersecurity oversight becomes useful when directors can connect security controls to identifiable business risks. They should know which systems would stop the company from operating if they became unavailable and how long those systems could remain offline without serious loss.

They should also know how many devices have access to critical systems, whether overdue security patches remain on the network and when the incident-response process was last tested.

One question can concentrate the discussion. If an attacker disables a critical system tomorrow, how long will the affected part of the business remain unable to operate?

Jatin Sawhney is Director of Cyber Security at Team Computers.

READ | Telehealth services must strengthen privacy, cybersecurity practices