Opinion
Jul 24, 20267 mins
Cybersecurity isn’t an IT problem anymore — it’s a leadership issue that fails when CEOs rely on flashy dashboards instead of fixing outdated operating models.
For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.
Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organizations continue to suffer major cyber incidents with alarming regularity. Every week seems to bring news of another ransomware attack, supply chain compromise or data breach affecting organizations that many would have assumed were well protected.
The obvious conclusion is that we are asking the wrong questions.
Too many executive teams remain preoccupied with the latest threat actor, the newest security product the CISO wants to buy or the latest vulnerability making headlines. Those issues matter, but they are not what should be keeping CEOs awake at night.
In my view, there are three far more fundamental issues that deserve the attention of every chief executive.
1. Corporate complexity, and the widening gap between business leadership and cybersecurity reality
Perhaps the biggest cybersecurity risk facing large organizations today is not technical at all.
It is the growing disconnect between executive perception and operational reality.
Many boards genuinely believe their organizations are reasonably well protected. They receive regular dashboards showing improving maturity scores, increasing compliance levels, falling vulnerability counts and reassuring traffic-light reports.
Unfortunately, cyber attackers do not read dashboards.
Behind those executive reports often lies an increasingly complex technology landscape, thousands of unmanaged digital assets, ageing infrastructure, rampant shadow IT, fragmented ownership, inconsistent governance and security teams struggling to keep pace with relentless business change.
The problem is rarely a lack of effort.
It is that corporate complexity has reached a level where traditional governance mechanisms are no longer capable of providing an accurate picture of organizational resilience.
Executives believe they understand the level of cyber risk they face because they receive regular reports. Those reports often measure activity rather than resilience.
Governance committees end up debating around another percentage point of phishing awareness or vulnerability remediation, while fundamental issues remain unaddressed in the background.
2. Organizational inertia, and the need for executive structure to evolve faster
Cyber criminals continue to evolve rapidly. Large organizations generally do not.
This is the second issue that should concern every CEO.
Throughout my career, I have observed organizations repeatedly responding to new cyber threats by adding another technology platform, another monitoring capability, another compliance framework or another governance committee.
Very rarely do they stop to redesign how cybersecurity operates.
The result is what I described several years ago as the “Cybersecurity Spiral of Failure”.
- As complexity and regulation increase, organizations invest in more security products.
- More products create more complexity.
- More products and greater complexity generate more alerts.
- More alerts require more analysts.
- More analysts produce more reports.
- More reports continue to build up executive confidence.
- Meanwhile, the underlying structural weaknesses remain largely unchanged, technical debt piles up and costs escalate.
And when the inevitable breach eventually happens, reality reveals itself, but distrust also sets in between senior executives and security teams.
This is not a funding problem. Nor is it a skills problem. It is fundamentally an operating model problem.
Many organizations continue trying to solve twenty-first century challenges using governance, accountability, organizational and reporting structures designed twenty-five years ago.
The cybersecurity function itself has evolved dramatically. Many executive structures have not.
This organizational inertia extends beyond technology: It affects budgeting cycles, investment priorities, procurement processes, accountability models and decision-making speed.
Cyber attackers innovate every day. Organizational change often takes years.
That imbalance should worry every CEO.
3. Accelerating technological disruption, and how it challenges organizations in areas where they are intrinsically weak
The third issue is potentially the most significant over the coming decade.
- Artificial intelligence, autonomous agents and machine identities
- Software supply chain complexity.
- Quantum computing, and post-quantum cryptography
Each of these developments represents far more than another technical trend.
Together, they fundamentally change the dynamics of cybersecurity.
Artificial intelligence is transforming countless business processes. At the same time, it is also increasing both the speed and sophistication of cyber-attacks while simultaneously transforming defensive capabilities.
Organizations have become increasingly dependent on software ecosystems that extend far beyond their own direct control. Engaging with the supply chain in ways that lead to a genuine appreciation of the risks involved has become a key challenge for most cybersecurity practices.
Quantum computing may eventually invalidate much of today’s cryptographic algorithms, forcing organizations into one of the largest technology efforts since Y2K — but without the benefit of a fixed deadline and faced by a problem that is considerably more complex and hyperconnected IT estates that have little to do with those of the late 90s.
None of these challenges can be solved overnight: They require clear governance, sustained investment over a few years and cross-functional organizational coordination.
Most large organizations are weak on those three fronts: This is precisely why CEOs should be focusing on them now.
Waiting until some of those risks become obvious will almost certainly be too late.
Businesses naturally prioritise immediate commercial pressures. Cybersecurity often involves preparing for risks whose timing remains uncertain.
But one of the greatest leadership failures I keep seeing remains the inability of organizations to act decisively on known unknowns.
That tension explains why many organizations delay action until external events force them to respond. Unfortunately, cybersecurity rarely rewards late action.
Leadership will determine who succeeds
Cybersecurity discussions still frequently focus on technology. I believe they should focus far more on leadership.
Technology will continue evolving. Threat actors will continue adapting. Regulations will continue expanding. Those developments are inevitable.
What remains within the control of every CEO is how their organization responds.
Does cybersecurity remain an IT issue? Or is it recognised as an integral part of business resilience?
How is cybersecurity accountability assigned at executive level? Or does it still rest largely with a CISO hidden in the organization?
Does the board spend sufficient time discussing resilience? Or does cybersecurity appear only when approving budgets or reviewing incidents?
These questions will increasingly determine organizational success.
The companies that navigate the next decade successfully will not necessarily be those spending the most on cybersecurity. Nor will they be those deploying the latest security technologies first.
They will be the organizations whose leadership recognises that cybersecurity has become a permanent business capability — embedded into governance, strategy, operational decision-making and organizational culture.
That transformation cannot be delegated. It begins with the CEO.
And perhaps that is the single biggest issue that should keep every chief executive awake at night: Not when the next cyber-attack will happen, but whether their organization is evolving quickly enough on those matters to meet a threat landscape that is changing much faster than the business itself.
This article is published as part of the Foundry Expert Contributor Network.
Want to join?
JC Gaillard is the founder and CEO of Corix Partners, a UK-based boutique management consultancy firm, focused on assisting CIOs and other C-level executives in resolving cybersecurity strategy, organization and governance challenges. JC is a leading strategic advisor and a globally recognized cybersecurity thought-leader with more than 25 years of experience developed in several financial institutions in the UK and continental Europe. He has a track record of driving fundamental change in the security field across global organizations, looking beyond the technical horizon into strategy, governance, culture and the real dynamics of business transformation.
JC is the author of “The CyberSecurity Leadership Handbook for the CISO and the CEO“ and “The Cybersecurity Spiral of Failure.”
Show me more







