The Board's Role in Cyber Vigilance and AI Governance: Leading Organisational Resilience in a Digital Age Cybersecurity is no longer just an IT concern.
Nor is Artificial Intelligence (AI) simply an emerging technology trend. Both cybersecurity and AI have become strategic business issues that influence organisational resilience, reputation, operational effectiveness, regulatory compliance, and long-term sustainability. As organisations increasingly adopt AI-powered tools, automate business processes, and rely on digital ecosystems, Boards of Directors have a growing responsibility to oversee not only cyber risk but also the governance of AI. The organisations that will thrive in the coming decade will be those whose boards recognise that cyber resilience and AI governance are not technical issues alone—they are governance issues. Cyber vigilance and responsible AI adoption must start at the top. Why Cybersecurity and AI Are Governance Matters Boards are responsible for overseeing the strategic direction and long-term resilience of an organisation. Historically, this has included oversight of:
A cyber incident can disrupt operations, expose sensitive information, damage trust, and impact revenue. Similarly, poorly governed AI can result in:
Employees may unknowingly upload sensitive information into public AI platforms. AI systems may access, process, or generate business-critical information. Cybercriminals are using AI to create increasingly sophisticated phishing campaigns, deepfakes, and social engineering attacks. Boards must therefore consider cyber governance and AI governance as complementary disciplines that support organisational resilience. Leadership Sets the Tone Organisational culture reflects leadership priorities. Employees pay attention to what boards discuss, what executives measure, and where organisations invest their resources. If cybersecurity and AI governance are regularly discussed at board level, they become embedded within organisational thinking. If they are viewed solely as technology concerns, employees may perceive them as someone else's responsibility. Boards play a critical role in:
Boards Don't Need Technical Expertise Many directors worry that they lack the technical knowledge required to oversee cybersecurity and AI. This concern is understandable—but largely misplaced. Boards are not responsible for implementing technical controls. They are responsible for governance. The board's role is to ask:
What matters most is informed oversight and effective questioning. Questions Every Board Should Be Asking Cybersecurity
Understanding AI usage should be a priority governance activity. The Emerging Risk of Shadow AI Most boards are familiar with the concept of Shadow IT. Today, organisations face a similar challenge: Shadow AI. Employees are increasingly using public AI tools to improve productivity, generate content, analyse information, and automate tasks. While these tools can create significant benefits, they can also introduce risks if used without guidance. Examples include:
Building a Culture of Cyber Vigilance and Responsible AI Use Technology alone cannot create resilience. People remain the most important line of defence. Employees must understand:
Moving Beyond Compliance Many organisations focus heavily on compliance requirements. Compliance remains important, but it should not be the ultimate objective. The goal should be resilience. A board focused solely on compliance might ask: "Have all staff completed cybersecurity and AI training?" A board focused on resilience might ask: "Can our people recognise cyber threats, use AI responsibly, and make sound decisions when faced with uncertainty?" The second question provides far greater insight into organisational capability. Preparing for AI and Cyber Incidents Cyber incidents are no longer a question of if, but when. Similarly, organisations should prepare for AI-related incidents, including:
Cybersecurity and AI as Strategic Enablers Strong governance is not simply about avoiding problems. It is about enabling growth with confidence. Organisations that effectively manage cyber and AI risks often benefit from:
The Board's Most Important Contribution The future of organisational resilience will depend increasingly on how organisations manage both cyber risk and artificial intelligence. Technology will continue to evolve. Threats will continue to change. New opportunities will continue to emerge. Boards do not need to become cybersecurity experts or AI engineers. They do, however, need to provide leadership. By fostering cyber vigilance, supporting responsible AI governance, asking informed questions, and ensuring resilience remains a strategic priority, boards can help their organisations navigate an increasingly complex digital landscape. Cyber resilience and AI governance begin in the boardroom. When boards lead, organisations follow.
0 Comments
Loyalty, Innovation, and Risk: Should You Stay with Your Existing Cybersecurity Supplier or Embrace New Technology?In cybersecurity, there is a constant tension between loyalty and innovation.
Organisations often build long-standing relationships with trusted cybersecurity suppliers who understand their environment, culture, and operational challenges. At the same time, the cybersecurity market continues to evolve at an unprecedented pace, with new vendors introducing innovative technologies that promise greater protection, automation, and efficiency. This raises a difficult question for many business leaders: Should you remain loyal to an existing cybersecurity supplier and wait for them to develop future capabilities, or should you adopt new technologies from emerging providers that may offer advantages today? The answer is rarely straightforward. The Case for Staying with Your Existing Supplier Established cybersecurity partners often bring significant value beyond the technology itself. Institutional Knowledge Long-term suppliers understand your business, your risk profile, and your operational environment. They know your history, your priorities, and often the people responsible for managing security outcomes. This knowledge reduces onboarding time, minimizes disruption, and enables more informed recommendations. Cultural Alignment Cybersecurity solutions succeed when people adopt them. An existing supplier who understands your organizational culture is often better positioned to introduce changes that employees will accept and use effectively. They have already built trust with stakeholders and can often navigate internal resistance more effectively than a new provider. Simplified Training and Adoption Introducing new technology often requires significant training and change management. Existing suppliers may offer enhancements that build upon tools your employees already understand, reducing learning curves and minimizing productivity impacts. Reduced Integration Risk Replacing cybersecurity technologies can create unforeseen challenges:
Relationship Capital Trust has value. A supplier that has consistently delivered results, supported your organization during incidents, and demonstrated commitment to your success has earned a level of credibility that should not be dismissed lightly. The Case for Exploring New Suppliers While loyalty is important, cybersecurity threats evolve rapidly. Loyalty should never become complacency. Innovation Often Comes from Challengers Many cybersecurity breakthroughs originate from newer, more specialized vendors. Emerging suppliers are frequently able to:
Competitive Advantage Organisations that adopt innovative security technologies early can often gain:
Avoiding Vendor Lock-In Long-term relationships can sometimes create dependency. Organisations may become reluctant to evaluate alternatives because switching appears difficult or uncomfortable. A healthy cybersecurity strategy periodically challenges existing assumptions and validates whether current suppliers remain the best fit. Future Promises Are Not Future Guarantees One of the most common arguments for staying with an incumbent supplier is the promise that a comparable solution is coming soon. However, roadmaps are not products. Future capabilities may:
The Often-Overlooked Factor: Technology Fit The best cybersecurity technology is not necessarily the most advanced technology. It is the technology that best aligns with your organization's:
Technology that is theoretically superior but practically unusable creates little real-world value. Culture: The Hidden Driver of Cybersecurity Success Cybersecurity leaders often focus on technical capabilities while underestimating the role of organizational culture. A solution that employees resist, bypass, or fail to understand will struggle to deliver its intended outcomes regardless of how sophisticated the technology may be. When evaluating suppliers, leaders should consider:
The Real Cost Equation Price alone rarely reflects the true cost of a cybersecurity decision. Organisations should evaluate: Direct Costs
Perhaps most importantly, leaders should consider the cost of waiting. If a new solution can significantly reduce risk today, delaying adoption while waiting for an incumbent supplier's future roadmap may expose the organization to unnecessary threats. Finding the Right Balance The decision should not be framed as loyalty versus innovation. Instead, it should be viewed as a question of organizational resilience. Strong supplier relationships remain valuable, but they should not prevent organisations from objectively evaluating new capabilities. Likewise, chasing every new technology trend can create unnecessary complexity and fatigue. The most mature organisations adopt a balanced approach:
Cybersecurity is ultimately about managing risk, not managing vendors. Loyalty has value. Trust has value. Relationships have value. However, innovation, adaptability, and the ability to respond to emerging threats also have value. The best decision is rarely determined by who has been with you the longest or who has the newest technology. It is determined by which solution best supports your people, aligns with your culture, fits your operational environment, and strengthens your organization's resilience both today and tomorrow. The question leaders should ask is not, "Who do we owe our loyalty to?" Instead, it should be, "What decision best protects our people, our business, and our future?" Cyber Vigilance: How to Keep Everyone Engaged – From the Boardroom to the Break Room Cybersecurity is often viewed as an IT problem. Firewalls, antivirus software, multi-factor authentication, and security monitoring are all important components of a strong defence strategy. However, despite billions of dollars invested in technology each year, cybercriminals continue to succeed because they understand one simple truth:
People remain the most targeted and influential part of any organisation's security posture. Whether your organisation employs ten people or ten thousand, creating a culture of cyber vigilance requires more than annual compliance training or occasional phishing tests. It requires leadership, engagement, communication, and the integration of secure behaviours into everyday business activities. The organisations that achieve the highest levels of cyber resilience are not necessarily those with the biggest security budgets. They are the organisations where everyone understands their role in protecting the business. Cybersecurity is a Team Sport Every person within an organisation presents both a potential risk and a valuable line of defence. Board members make strategic decisions that influence cyber risk exposure. Executives allocate resources and set organisational priorities. Managers influence team behaviours and accountability. Employees handle sensitive information and critical business systems. Contractors, interns, and temporary staff often have access to systems and data that cybercriminals seek to exploit. A single click on a malicious email, an unsecured password, or an unreported security concern can have significant consequences. Equally, one vigilant employee can prevent a major breach. The challenge is ensuring cyber vigilance becomes everyone's responsibility rather than someone else's job. Leadership Must Lead by Example One of the most common mistakes organisations make is treating cybersecurity as an operational issue rather than a business issue. Employees pay attention to what leadership prioritises. If board members and executives openly discuss cybersecurity, participate in training, follow security procedures, and ask questions about cyber risk, employees are far more likely to take security seriously. Cyber resilience should be a standing agenda item at board meetings, management discussions, and strategic planning sessions. When leaders visibly engage with cybersecurity initiatives, they send a powerful message: "This matters to everyone." Move Beyond Fear-Based Awareness Campaigns Traditional awareness programmes often focus on worst-case scenarios. Employees are shown examples of devastating breaches, financial losses, and regulatory penalties. While these examples can create awareness, fear alone rarely drives lasting behavioural change. Instead, organisations should focus on:
Cybersecurity awareness should feel empowering rather than intimidating. Make Security Relevant to Individual Roles One-size-fits-all training rarely works. A finance manager faces different cyber risks than a marketing coordinator. A board member has different responsibilities than a customer service representative. Training and awareness programmes should be tailored to reflect the real-world risks associated with specific roles. Examples include: Board Members
Create Continuous Engagement Rather Than Annual Events Cyber awareness is not something that can be achieved through a single annual training session. Threats evolve continuously, and awareness programmes should do the same. Successful organisations create regular touchpoints throughout the year, including:
Think of cybersecurity awareness as fitness. A small amount of regular exercise delivers better results than one intensive workout per year. Recognise and Reward Positive Behaviour Many organisations focus exclusively on mistakes. Employees who click a phishing link receive additional training, while employees who identify and report threats receive little recognition. This is a missed opportunity. Positive reinforcement encourages participation and helps create a proactive security culture. Consider recognising employees who:
People repeat behaviours that are noticed and appreciated. Make Reporting Easy and Safe Employees must feel comfortable reporting mistakes and concerns. Unfortunately, many organisations unintentionally create environments where staff fear embarrassment or disciplinary action if they report an incident. This often leads to delayed reporting, allowing incidents to escalate. A strong cyber culture encourages employees to report:
When employees know they can report concerns without fear, organisations gain valuable early warning capabilities. Integrate Cybersecurity into Everyday Processes Cyber vigilance becomes sustainable when it is embedded into existing business activities. Rather than treating security as a separate function, organisations should incorporate cyber considerations into: Recruitment and Onboarding Introduce cybersecurity expectations from day one. Performance Reviews Include accountability for secure behaviours. Project Management Assess cyber risks during project planning. Procurement Evaluate supplier security practices. Business Continuity Planning Include cyber incidents in resilience exercises. Leadership Meetings Review cyber risks alongside financial and operational risks. The more cybersecurity becomes part of normal business operations, the less it feels like an additional burden. Build Security Champions Across the Organisation One of the most effective approaches for both SMEs and large enterprises is creating a network of Cyber Champions. These individuals act as local advocates within departments, business units, or regional offices. They help:
Measure Culture, Not Just Compliance Many organisations measure training completion rates and assume success. Completion does not necessarily indicate understanding or behavioural change. More meaningful indicators include:
The Human Firewall Technology remains an essential component of cybersecurity, but technology alone cannot protect an organisation. True cyber resilience is achieved when every individual understands their role in protecting the business and feels empowered to act. From the boardroom to the newest intern, every person has the potential to either strengthen or weaken organisational security. The most successful organisations create a culture where cyber vigilance is not an annual exercise, a compliance requirement, or an IT responsibility. It becomes part of how the organisation thinks, operates, and makes decisions every day. When cybersecurity becomes part of the culture, vigilance becomes a habit—and resilience becomes a competitive advantage. Keeping Cyber Vigilance Alive When Employees Have So Much Else to Worry About As winter settles in across New Zealand, many organisations are facing a perfect storm of challenges. Economic uncertainty continues to place pressure on budgets, ongoing geopolitical tensions in the Middle East are impacting global markets and operating costs, and organisations are simultaneously trying to understand both the opportunities and risks presented by Artificial Intelligence (AI).
At the same time, employees are feeling the strain. Rising living costs, concerns about job security, increasing workloads, and the shorter, darker days of winter can all contribute to fatigue, stress, and disengagement. Unfortunately, these same factors can also reduce cyber vigilance at a time when cybercriminals are becoming more sophisticated and leveraging AI to scale their attacks. The challenge for leaders is clear: How do we keep cybersecurity front of mind without creating yet another burden for already stretched employees? Understanding the Human Factor For many years, organisations approached cybersecurity awareness through compliance-driven training, annual courses, and periodic reminders. While these activities remain important, they often fail to account for a simple reality: People are not security systems. Employees are human beings balancing professional responsibilities, personal commitments, financial concerns, and their own wellbeing. When people become overwhelmed, their ability to identify suspicious emails, question unusual requests, or follow security procedures naturally declines. Cybercriminals understand this. Modern phishing campaigns are specifically designed to exploit distraction, urgency, and emotional responses. Increasingly, AI is helping attackers create highly convincing emails, voice messages, and fake communications that are far harder to identify than the scams of previous years. The question is no longer whether employees know what phishing is. The question is whether they can consistently apply that knowledge when under pressure. The Impact of Economic Pressure Periods of economic uncertainty often create conditions that increase cyber risk. Employees may be working longer hours, covering multiple roles, or managing higher workloads following cost-cutting measures. Leaders may be focused on financial sustainability and operational efficiency. In these environments, cybersecurity can unintentionally become viewed as an obstacle rather than an enabler. When productivity becomes the primary focus, employees may be more likely to:
None of these actions are typically malicious. They are often the result of good people trying to meet competing demands. This is why cybersecurity culture matters. Organisations that successfully maintain cyber vigilance focus on making secure behaviours easy, practical, and relevant to employees' daily work. AI: Both Friend and Foe Artificial Intelligence is changing the cybersecurity landscape on both sides of the battle. Attackers are using AI to create more convincing phishing emails, generate realistic fake websites, automate reconnaissance, and even clone voices. What once required significant technical expertise can now be achieved with widely available tools. However, AI also provides organisations with powerful defensive capabilities, including:
The danger lies in assuming that technology alone will solve the problem. No matter how advanced defensive systems become, employees remain the final decision-makers when approving payments, sharing information, or granting access. Human judgement continues to be one of the most critical layers of defence. Organisations should therefore position AI as a tool that supports employees rather than replaces their role in security. Winter Blues and Cybersecurity Winter can have a surprisingly significant impact on cyber resilience. Research consistently shows that seasonal changes can affect mood, energy levels, concentration, and motivation. Employees may experience increased fatigue, reduced engagement, and greater levels of stress during colder months. These factors directly influence cybersecurity behaviours. A tired employee is more likely to click a malicious link. A distracted employee is more likely to overlook a warning sign. A disengaged employee is less likely to report suspicious activity. This does not mean organisations need to launch major security campaigns every winter. Instead, leaders should recognise that employee wellbeing and cybersecurity are closely connected. Supporting staff wellbeing is not separate from cyber resilience—it is part of cyber resilience. Five Practical Ways to Maintain Cyber Vigilance 1. Keep Security Messages Short and Relevant Employees are already overwhelmed with information. Rather than lengthy awareness campaigns, provide concise and practical guidance that relates directly to current threats and business activities. A two-minute reminder about AI-generated phishing attacks may have more impact than a thirty-minute presentation. 2. Focus on Culture Rather Than Compliance People engage more effectively when they understand why security matters. Help employees see how their actions protect customers, colleagues, and the organisation's future rather than simply meeting compliance requirements. Cybersecurity should feel like a shared responsibility, not an imposed obligation. 3. Celebrate Positive Behaviour Many organisations only discuss cybersecurity when something goes wrong. Instead, recognise employees who report suspicious emails, challenge unusual requests, or identify potential risks. Positive reinforcement encourages ongoing engagement far more effectively than fear-based messaging. 4. Connect Cybersecurity to Wellbeing Encourage employees to take breaks, manage workloads, and seek support when needed. An employee who feels supported is more likely to remain alert and engaged. Human performance and cyber resilience are closely linked. 5. Make Reporting Easy Employees should never feel embarrassed about reporting something suspicious. Create an environment where reporting a concern is viewed as a positive action, even if the threat turns out to be harmless. The faster employees report potential issues, the faster security teams can respond. Leadership Sets the Tone Ultimately, cyber vigilance is not a technology problem—it is a leadership challenge. Employees pay close attention to organisational priorities. If leaders consistently demonstrate that cybersecurity, wellbeing, and business resilience are interconnected, employees are more likely to adopt the same mindset. In today's environment, organisations are navigating economic pressures, geopolitical uncertainty, rapid technological change, and workforce wellbeing challenges simultaneously. Expecting employees to remain constantly vigilant without support is unrealistic. The organisations that succeed will be those that recognise a fundamental truth: Cybersecurity is not about creating a workforce that is constantly fearful of making mistakes. It is about building a culture where people feel informed, supported, and empowered to make good decisions, even when pressures are high. When organisations invest in both their people and their security culture, cyber vigilance becomes not another task on the to-do list, but a natural part of how the organisation operates every day. |
AuthorPatrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate Archives
July 2026
Categories |
RSS Feed