CYBERPLANZ
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Boardroom Guide to Cyber & AI Governance
    • Board Cyber & AI Governance Self-Assessment
    • Cyberplanz Cyber Culture Dashboard
    • Cyberplanz Board Third-Party Cyber & Ai Risk Dashboard
  • About Us
  • Contact Us
  • Blogs
Picture
Picture
“Plans are of little importance, but planning is essential.”
― Winston Churchill

8 September Blog

9/8/2026

0 Comments

 

AI Governance: Turning Innovation into Competitive Advantage Without Increasing Risk

Picture
The biggest risk with AI may not be adopting it too quickly.
It may be allowing your competitors to adopt it better.
Across almost every industry, organisations are experimenting with Artificial Intelligence.
Employees are using generative AI to write documents, analyse information, develop presentations, summarise meetings, research markets, write software and automate routine work.
Business units are purchasing AI-enabled applications.
Existing software providers are quietly adding AI functionality to products organisations already use.
Executives are asking how AI can improve productivity.
Boards are asking about the risks.
And somewhere between the enthusiasm and the concern sits one of the most important governance challenges facing organisations today:
How do we capture the competitive advantage of AI without creating unacceptable risk?
The answer should not be to stop innovation.
It should be to govern it well enough that innovation can accelerate safely.


AI Governance Is Not About Saying No
When organisations first discuss AI governance, the conversation can quickly become dominated by risk.
What information might employees put into AI?
Where does the data go?
Can we trust the output?
What about privacy?
What about intellectual property?
What if employees use unauthorised AI applications?
What happens if AI makes a bad decision?
These are legitimate questions.
But if governance becomes synonymous with restriction, something predictable happens.
People work around it.
Innovation moves underground.
And Shadow AI grows.
Employees who believe approved processes are too difficult may simply use the tools available to them.
The organisation hasn't removed the risk.
It has removed its visibility of the risk.
Good AI governance therefore starts with a different question.
Not:
“How do we stop people using AI?”
But:
“How do we enable our people to use AI safely, responsibly and productively?”
That is a fundamentally different leadership mindset.


The Competitive Advantage Is Already Emerging
AI is not simply another technology project.
It is becoming a capability that can influence how organisations operate.
Used appropriately, AI can help organisations:
  • Improve productivity.
  • Analyse information faster.
  • Automate repetitive activities.
  • Improve customer experiences.
  • Support better decision-making.
  • Identify patterns and opportunities.
  • Accelerate product development.
  • Improve knowledge sharing.
  • Reduce administrative workload.
  • Help employees focus on higher-value activities.
But simply providing employees with AI tools does not create competitive advantage.
Your competitors can buy many of the same tools.
The advantage comes from how effectively your organisation learns to use them.
That means AI capability increasingly becomes a combination of:
Technology + Governance + People + Culture + Judgement
The organisations that combine those elements effectively may create something far harder for competitors to copy than access to another AI platform.
They create organisational AI capability.


The Board's Role Is Bigger Than AI Risk
Boards understandably approach AI through the lens of risk.
But there are two sides to the governance question.
Risk of AI adoption
Privacy.
Cybersecurity.
Data leakage.
Bias.
Inaccurate outputs.
Intellectual property.
Regulatory exposure.
Third-party dependency.
Reputation.
Risk of AI non-adoption
Lower productivity.
Slower innovation.
Higher operating costs.
Loss of talent.
Reduced customer experience.
Competitors moving faster.
Missed strategic opportunities.
Boards therefore need to consider both.
The governance objective should not be minimum AI use.
It should be:
Maximum responsible value within an acceptable level of risk.
That is a business governance question—not simply a technology question.


Start With Visibility
Before a Board can govern AI, the organisation needs to understand how AI is actually being used.
That sounds obvious.
In many organisations, it isn't.
AI adoption frequently happens from the bottom up.
An employee creates an account.
A department subscribes to a service.
A software vendor introduces an AI feature.
A team connects an AI application to business information.
No major technology implementation occurs.
No formal project is launched.
Yet the organisation's risk profile has changed.
Boards should therefore ask:
  • Which AI tools are being used?
  • Who is using them?
  • What are they being used for?
  • What information can they access?
  • Which AI applications have been formally approved?
  • Which business processes depend upon AI?
  • Which third parties are using AI on our behalf?
You cannot govern what you cannot see.
And that makes AI visibility one of the foundations of AI governance.


Not All AI Use Carries the Same Risk
One of the mistakes organisations can make is treating every AI use case equally.
Using AI to brainstorm ideas for a marketing campaign is very different from using AI to assess a customer's financial position.
Using AI to improve the wording of a public document is very different from uploading confidential employee information into an external model.
Using AI to summarise a meeting is different from allowing an autonomous system to make decisions that materially affect people.
Governance should therefore be proportionate to risk.
A simple approach might classify AI use as:
LOW RISK
General productivity and low-sensitivity tasks with human review.
MODERATE RISK
AI interacting with internal business information or supporting meaningful business decisions.
HIGH RISK
AI processing sensitive information, interacting directly with customers, making or materially influencing important decisions, or operating with significant autonomy.
The greater the potential impact, the stronger the governance should be.
This allows low-risk innovation to move quickly while applying appropriate scrutiny where the consequences are greater.


Build Guardrails, Not Roadblocks
Employees need to know what good AI use looks like.
That requires practical guardrails.
For example:
APPROVED TOOLS
Which AI platforms can employees use?
APPROVED DATA
What information may be entered into them?
PROHIBITED DATA
What information must never be entered?
HUMAN REVIEW
When must AI-generated outputs be checked?
DECISION-MAKING
Which decisions must remain human?
TRANSPARENCY
When should customers or stakeholders know AI is being used?
ACCOUNTABILITY
Who owns the outcome when AI contributes to a decision?
ESCALATION
Where should employees go when they are unsure?
The last question is particularly important.
Employees will encounter situations no policy anticipated.
Strong governance therefore does not require people to know every answer.
It requires them to know when to ask the question.


Human Judgement Becomes More Important, Not Less
There is an understandable assumption that increasing automation reduces the importance of people.
In many areas, the opposite may be true.
AI can produce information extraordinarily quickly.
But humans still need to determine:
Is it accurate?
Is it appropriate?
Does it make sense?
Is something missing?
Is the source reliable?
Could there be bias?
Should we act on it?
What are the consequences if it is wrong?
The more organisations rely on AI, the more important human judgement becomes.
This connects directly with what we have previously described as the Human Advantage.
AI can amplify capability.
But judgement, context, ethics, curiosity and accountability remain fundamentally human responsibilities.
The organisations that develop those capabilities alongside AI may be considerably more resilient than those that simply automate as much as possible.


AI Literacy Is Becoming a Governance Control
Many organisations provide cybersecurity awareness training.
AI literacy may soon need to become just as fundamental.
Employees need to understand more than how to use AI.
They should understand:
  • What AI is good at.
  • Where AI can fail.
  • Why outputs can sound convincing while being wrong.
  • Why sensitive information requires care.
  • How AI-generated content should be verified.
  • What tools are approved.
  • When human review is required.
  • How to report questionable AI behaviour.
  • When to stop and ask for help.
Executives and Directors need AI literacy too.
Boards cannot effectively govern something they do not understand.
Directors do not need to become AI engineers.
But they should understand enough to ask intelligent questions about opportunity, risk, accountability and organisational capability.


Your AI Supply Chain Matters
AI governance cannot stop at the organisation's boundary.
Increasingly, suppliers are embedding AI into their products and services.
Your organisation may therefore be exposed to AI risk without directly deploying an AI system itself.
Boards should understand:
  • Which critical suppliers use AI.
  • What organisational data those systems process.
  • Whether information is used to train models.
  • Where information is stored.
  • What other providers support the AI service.
  • How outputs are validated.
  • What happens if the AI service becomes unavailable.
  • Whether the organisation can exit or transition to another provider.
This is where AI governance and third-party risk increasingly converge.
As we have said previously:
You can outsource the service. You cannot outsource accountability for the risk.


Culture Will Determine Whether Governance Works
You can publish an excellent AI policy.
That does not mean employees will follow it.
If approved AI tools are difficult to access, employees may find alternatives.
If employees fear punishment for admitting they used the wrong tool, Shadow AI becomes harder to detect.
If managers ignore the policy themselves, employees will notice.
If nobody explains why the controls exist, governance becomes another compliance exercise.
The organisation therefore needs a culture where employees can say:
“I found an AI tool that could help us—can we assess it?”
Or:
“I've been using this tool and I'm not sure whether I should be.”
Or even:
“I think I may have entered information I shouldn't have.”
The response to those conversations will determine whether future concerns are reported.
Good AI governance depends on trust.


Measure Value as Well as Risk
There is another important Board issue.
If AI governance reporting only discusses incidents, risks and policy compliance, the Board receives only half the picture.
AI governance should also measure whether AI is creating value.
Boards might ask:
  • Where is AI improving productivity?
  • Which use cases are delivering measurable benefits?
  • Where has AI improved customer experience?
  • What tasks have employees been able to automate?
  • What new capabilities has AI enabled?
  • Where have experiments failed—and what did we learn?
  • Which opportunities should we scale?
  • Are competitors developing capabilities we are not?
This changes the Board conversation.
AI stops being viewed purely as another source of enterprise risk.
It becomes something that must be governed for both risk and opportunity.


Give Innovation a Safe Place to Happen
Organisations should consider creating controlled environments where employees can experiment.
An AI sandbox or structured innovation programme can allow teams to:
  • Test new tools.
  • Explore use cases.
  • Develop prototypes.
  • Assess risks.
  • Share lessons.
  • Identify high-value opportunities.
Successful ideas can then move through an appropriate approval process before broader deployment.
This sends an important cultural message:
“We want you to innovate. We simply want to innovate responsibly.”
Governance then becomes an enabler of experimentation, rather than the department that arrives afterwards to say no.


Govern at the Speed of Innovation
Traditional governance processes can be slow.
AI is not.
New tools appear constantly.
Existing platforms change.
Employees discover new applications.
Business models evolve.
Threats develop.
Governance therefore cannot be something reviewed once a year.
Organisations need a more dynamic model.
DISCOVER → ASSESS → ENABLE → MONITOR → LEARN.
DISCOVER
Understand how AI is being used and identify new opportunities.
ASSESS
Evaluate the potential value and risk.
ENABLE
Provide appropriate tools, controls and guardrails.
MONITOR
Understand how AI is actually performing and being used.
LEARN
Improve governance based on incidents, near misses, employee feedback and emerging opportunities.
Then repeat.
This is how governance begins to move at the speed of innovation.


What Should the Board Ask?
At the next Board meeting, consider asking:
1. Where is AI currently being used across our organisation?
Not where we think it is being used.
Where is it actually being used?
2. Which AI use cases create the greatest value?
Where could AI materially improve our organisation?
3. Which AI use cases create the greatest risk?
Where could failure cause meaningful harm?
4. Do our employees understand the guardrails?
Could they explain what information they should and should not put into AI?
5. How are we managing Shadow AI?
Do employees have a safe way to disclose unapproved AI use?
6. What AI are our suppliers using?
Could third-party AI create risk for our organisation?
7. Where must human judgement remain?
Which decisions should never be delegated entirely to AI?
8. How are we measuring value?
Can management demonstrate that AI investment is improving business outcomes?
9. What are we learning?
How is our AI governance evolving as the technology changes?
And perhaps the most important question:
“Is our AI governance helping the organisation innovate—or simply helping us say no?”


From AI Governance to AI Advantage
The organisations that succeed with AI may not be those that adopt every new tool first.
Nor will they necessarily be those with the most restrictive controls.
The advantage is likely to belong to organisations that learn how to combine:
Innovation
with
Governance
with
Human judgement
with
Trust
with
Continuous learning.
That creates an environment where people understand the boundaries, feel confident experimenting within them and know when to ask for help.
It allows Boards to support innovation without abandoning oversight.
It allows executives to pursue opportunity without accepting unmanaged risk.
And it allows employees to use AI as a tool rather than seeing governance as an obstacle.


The Boardroom Principle
AI governance should not answer:
“How do we stop AI creating risk?”
It should answer:
“How do we create more value from AI while keeping risk within boundaries we are prepared to accept?”
That is the difference between governing AI defensively and governing AI strategically.
Because responsible AI governance is not the opposite of innovation.
It is what gives organisations the confidence to innovate.
And in an increasingly AI-enabled economy, that confidence may itself become a competitive advantage.


CYBERPLANZ | THE BOARDROOM GUIDE TO CYBER & AI GOVERNANCE
Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.
Helping Boards build secure, resilient and AI-ready organisations.
 

0 Comments

01 September Blog

9/1/2026

0 Comments

 

Preparing Your Organisation for the First 24 Hours After a Cyber Incident

Picture
The first 24 hours of a cyber incident will test far more than your technology.
They will test your leadership.
Your governance.
Your communication.
Your culture.
Your decision-making.
And ultimately, your organisation's resilience.
When a serious cyber incident occurs, information is rarely complete.
Nobody immediately knows the full extent of the problem.
Systems may be unavailable.
Customers may be affected.
Employees want answers.
Suppliers may be involved.
Regulatory obligations need to be considered.
Social media speculation can begin before management understands what has happened.
And somewhere in the middle of all this, leaders must make decisions.
This is why cyber incident preparedness cannot simply be an IT responsibility.
The first 24 hours are a business leadership challenge.
The Incident Starts Before the Board Knows About It
Most cyber incidents don't begin with a dramatic announcement.
They begin quietly.
An employee clicks something suspicious.
Someone notices unusual activity.
A customer reports something strange.
A supplier calls with bad news.
A system behaves unexpectedly.
An employee realises they may have shared information they shouldn't have.
What happens next can significantly influence what follows.
At Cyberplanz, we believe in a simple principle:
The Cyberplanz Five-Minute Rule
The most important five minutes in any cyber incident are the five minutes after someone realises something might be wrong.
People should not waste those minutes worrying about blame.
They should not attempt to hide a mistake.
They should not spend half an hour trying to determine whether the problem is serious enough to report.
They should know exactly how to raise the alarm.
Early reporting creates options.
Delay removes them.
This is why incident preparedness starts with culture.
0–1 Hour: Establish What You Know
The first hour is about creating clarity without pretending you have certainty.
The immediate priorities should include:
  • Activating the appropriate incident response process.
  • Confirming who is leading the response.
  • Bringing together the right technical and business people.
  • Establishing what is currently known.
  • Protecting critical evidence.
  • Containing immediate threats where appropriate.
  • Identifying which business services may be affected.
  • Establishing a reliable internal communication channel.
One of the greatest risks during this period is speculation.
Someone believes customer data has been stolen.
Someone else believes it hasn't.
Another person thinks the incident originated with a supplier.
An executive wants to tell customers immediately.
The technical team is still investigating.
Leadership needs to distinguish clearly between:
What we know.
What we think.
What we don't yet know.
That discipline becomes critical throughout the incident.
Who Is Actually in Charge?
This sounds like a simple question.
During a real incident, it often isn't.
The CISO may lead the technical response.
The CIO may own affected systems.
The CEO may lead the organisational response.
Legal advisers may guide regulatory decisions.
Communications teams manage stakeholders.
Business continuity leaders focus on operations.
The Board provides governance and oversight.
If these roles have not been established before the incident, valuable time can be lost deciding who has authority to do what.
A good incident response plan should therefore define more than technical responsibilities.
It should establish decision rights.
Who can disconnect a critical system?
Who can authorise emergency expenditure?
Who decides whether customers are notified?
Who engages external specialists?
Who communicates with regulators?
Who speaks publicly?
Who briefs the Board?
During a crisis, ambiguity creates delay.
1–4 Hours: Understand the Business Impact
Once the immediate response is underway, leadership needs to move beyond the technical question:
"What has been compromised?"
and begin asking:
"What does this mean for the organisation?"
Which critical services are affected?
Can customers still transact with us?
Can employees work?
Can we access essential information?
Are payment systems functioning?
Could sensitive information have been exposed?
Are suppliers affected?
Do we need to invoke business continuity arrangements?
This is where cybersecurity and business resilience become inseparable.
A technically serious incident may have limited business impact.
A relatively simple technical failure may stop the organisation operating.
Boards and executives need visibility of both.
Protect the Organisation—But Preserve the Evidence
There can be enormous pressure to get systems operating again as quickly as possible.
That is understandable.
But poorly coordinated recovery can destroy valuable evidence or make it harder to understand how the incident occurred.
Technical specialists may need to preserve logs, devices, communications and other evidence before systems are rebuilt or restored.
This can create tension between:
"Get us operating again."
and
"We need to understand what happened."
Those decisions should be anticipated before a crisis occurs.
The organisation may also need external forensic, legal, insurance or specialist incident-response support.
Knowing whom to call before the incident saves precious time afterwards.
4–8 Hours: Communication Becomes Critical
Cyber incidents create an information vacuum.
And information vacuums are quickly filled by rumours.
Employees speculate.
Customers ask questions.
Suppliers become concerned.
Journalists may make enquiries.
Social media can amplify incomplete information.
Good crisis communication therefore matters enormously.
But speed must be balanced with accuracy.
The organisation should communicate what it knows without pretending to know what it doesn't.
A useful principle is:
Be early. Be factual. Be consistent.
Internal communication matters just as much as external communication.
Employees should know:
  • What has happened, where appropriate.
  • What they should do.
  • What they should not do.
  • Where updates will come from.
  • Who is authorised to speak externally.
  • How to report additional concerns.
Employees can become one of the organisation's greatest communication strengths during an incident—or an unintended source of confusion.
Don't Forget Your Customers
When organisations experience cyber incidents, there is an understandable tendency to focus inward.
Systems.
Investigations.
Legal advice.
Technical recovery.
But customers are experiencing the incident too.
They may be unable to access services.
They may be worried about their information.
They may not understand what is happening.
And silence can quickly damage trust.
Customers do not necessarily expect an organisation to have every answer immediately.
They do expect honesty, competence and communication.
How an organisation communicates during uncertainty can influence its reputation long after the technical incident has been resolved.
8–12 Hours: Governance and Regulatory Decisions
As more information becomes available, the governance implications become clearer.
Leadership may need to consider:
  • Privacy obligations.
  • Regulatory notification.
  • Contractual obligations.
  • Cyber insurance requirements.
  • Law enforcement involvement.
  • Customer notification.
  • Material financial impacts.
  • Disclosure obligations.
  • Third-party responsibilities.
These decisions should involve appropriate legal, privacy, risk and governance expertise.
This is another reason Boards should not wait for an incident before discussing cyber response.
The first time directors consider these questions should not be during a crisis.
What Should the Board Be Doing?
The Board's role during a cyber incident is important—but it must be clearly understood.
Directors should provide oversight, challenge and support.
They should not become the incident response team.
A Board that begins directing technical recovery can create additional confusion.
Instead, directors should focus on questions such as:
  • What do we know?
  • What don't we know?
  • What are the most significant business impacts?
  • Are customers or employees at risk?
  • Are critical services operating?
  • What decisions require Board involvement?
  • Are regulatory and legal obligations being addressed?
  • Is management receiving the resources it needs?
  • When will the Board receive its next update?
Perhaps most importantly:
Is management making decisions based on evidence—or pressure?
Good governance during a crisis provides clarity rather than additional noise.
12–24 Hours: From Response to Resilience
By this stage, the organisation should be developing a clearer understanding of the incident.
The priorities begin expanding from immediate containment towards:
  • Recovery of critical services.
  • Ongoing investigation.
  • Customer support.
  • Employee communication.
  • Regulatory engagement.
  • Supplier coordination.
  • Reputation management.
  • Longer-term business continuity.
But uncertainty may still remain.
This is important.
Twenty-four hours after a sophisticated cyber incident, the organisation may still not know everything.
Boards should resist demanding certainty where certainty does not yet exist.
Instead, leadership should demonstrate that:
The response is structured.
Responsibilities are clear.
Evidence is being gathered.
Customers are being considered.
Critical operations are being prioritised.
Decisions are being documented.
And the organisation is adapting as new information emerges.
That is what resilient leadership looks like.
Third Parties Must Be Part of the Plan
Not every cyber incident will begin inside your organisation.
A critical supplier may be compromised.
A cloud platform may fail.
A software provider may experience an attack.
A payroll provider may lose access to its systems.
This creates an additional challenge because your organisation may not control the investigation.
You may depend on someone else to tell you what happened.
Your incident response plans should therefore include third-party scenarios.
As we've discussed previously in the Boardroom Guide:
You can outsource the service. You cannot outsource accountability for the risk.
If a supplier's cyber incident affects your customers or your ability to operate, it becomes your resilience issue too.
AI Is Changing Incident Response
Artificial Intelligence adds another dimension.
An incident may involve:
  • Confidential information entered into an unapproved AI tool.
  • AI-generated fraud.
  • Deepfake executive impersonation.
  • Compromised AI applications.
  • Manipulated AI outputs.
  • Automated attacks operating at greater speed.
AI can also assist defenders by analysing information and identifying patterns more quickly.
But organisations should be careful not to outsource critical judgement to AI during a crisis.
AI can support decisions.
Accountability remains human.
Don't Wait for an Incident to Discover Your Plan Doesn't Work
A beautifully written incident response plan provides very little assurance if nobody has tested it.
Tabletop exercises are one of the most valuable tools available to Boards and executive teams.
Imagine beginning a Board exercise with:
8:07am Monday
Your CFO receives a call.
Several critical systems are unavailable.
IT believes ransomware may be involved.
A journalist has emailed asking whether customer information has been stolen.
Your largest customer wants an explanation.
And your technical team cannot yet confirm what happened.
What do you do next?
That conversation will reveal more about your preparedness than another policy review.
Who takes control?
Who contacts whom?
Who has authority?
What information does the Board need?
How do you communicate?
Where are the gaps?
Exercises turn theoretical plans into organisational capability.
After 24 Hours, Start Asking What We Are Learning
Recovery may take days, weeks or even months.
But learning should begin early.
What worked?
What caused delays?
Were responsibilities clear?
Did employees report quickly?
Were communications effective?
Did suppliers respond as expected?
Did the Board receive the information it needed?
What should change?
A resilient organisation does not simply survive an incident.
It becomes stronger because of what it learns.
The First 24 Hours Are Built Before the Incident
This may be the most important point.
You cannot manufacture trust during a crisis.
You cannot suddenly create clear governance.
You cannot instantly build leadership capability.
You cannot introduce a reporting culture after the attack begins.
And you cannot properly test an incident response plan while you are using it for the first time.
The quality of your first 24 hours is determined by the preparation undertaken during the previous 12 months.
Strong governance.
Clear responsibilities.
Practised leadership.
Trusted relationships.
Engaged employees.
Tested plans.
Reliable suppliers.
Good communication.
These are what create resilience.
The Question Every Board Should Ask
At your next Board meeting, don't simply ask:
"Do we have a cyber incident response plan?"
Ask:
"If a serious cyber incident began at 8am tomorrow, would we know what to do by 8:05?"
Then ask:
Who would lead?
Who would make the critical decisions?
When would the Board become involved?
How would we communicate?
Could we continue operating?
Have we actually practised it?
If those questions are difficult to answer, another policy may not be the solution.
Practice may be.
Because when a serious cyber incident occurs, your organisation will not rise to the quality of the document sitting in a folder.
It will depend on the quality of the decisions its people can make under pressure.
And those decisions are built long before the crisis begins.
Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.

0 Comments

24 August Blog

8/24/2026

0 Comments

 

Third-Party Risk: Your Suppliers Can Become Your Biggest Cyber Vulnerability

Picture
Your organisation may have strong cybersecurity controls.
Your suppliers may not.
And increasingly, that matters.
Modern organisations rarely operate independently.
We depend on cloud providers, software vendors, accountants, payroll providers, marketing agencies, IT companies, contractors, logistics partners, consultants and countless other third parties.
Each relationship creates efficiency and expertise.
But each can also create another pathway into your organisation.
A supplier may have access to your systems.
They may hold your customer information.
They may process confidential data.
They may connect remotely to your network.
And increasingly, they may be using Artificial Intelligence to process information on your behalf.
This creates a fundamental governance challenge for Boards:
You can outsource a service. You can outsource technology. But you cannot outsource accountability for the risk.
Your Security Perimeter Has Changed
There was a time when organisations could think about cybersecurity largely in terms of protecting their own network.
That world has disappeared.
Today's organisation is an interconnected ecosystem.
Data moves between cloud platforms.
Applications communicate through APIs.
Employees collaborate with external partners.
Suppliers access organisational systems remotely.
Information is shared across multiple platforms and jurisdictions.
And AI services are increasingly being incorporated into business processes.
Your cyber environment therefore extends far beyond your own organisation.
Your suppliers have effectively become part of your security perimeter.
The problem is that you don't necessarily control how well they protect it.
Attackers Understand the Supply Chain
Why attack a large organisation directly if one of its smaller suppliers provides an easier route?
Cybercriminals understand this very well.
A major organisation may have sophisticated security controls, dedicated cybersecurity teams and substantial budgets.
One of its suppliers may have:
  • Limited cybersecurity resources.
  • Weak access controls.
  • Poor password practices.
  • Outdated systems.
  • Limited staff awareness.
  • Inadequate incident response processes.
  • Little understanding of AI-related risk.
If that supplier has privileged access, holds sensitive information or connects directly into the larger organisation's systems, it can become an attractive target.
Your cybersecurity may only be as strong as the weakest trusted connection into your organisation.
Third-Party Risk Is More Than Cybersecurity
Boards should resist viewing supplier risk as simply another technical cybersecurity issue.
Consider what happens when a critical supplier experiences a major incident.
Can you continue operating?
Can you access your data?
Can you serve customers?
Can you pay employees?
Can you communicate with stakeholders?
Can you move quickly to another supplier?
Who must notify customers or regulators?
How much reputational damage could flow back to your organisation?
These are questions about business resilience, not simply cybersecurity.
A cyber incident affecting a supplier can quickly become your business interruption.
Not Every Supplier Presents the Same Risk
One of the mistakes organisations make is treating every supplier equally.
The company supplying office furniture clearly does not create the same cyber exposure as the company hosting your customer database.
Boards should expect management to understand which suppliers are critical.
That means asking questions such as:
  • What information does the supplier hold?
  • What systems can they access?
  • How critical are they to our operations?
  • Could we continue operating without them?
  • How quickly could they be replaced?
  • What would happen if their systems were unavailable for a week?
  • Do they use subcontractors?
  • Where is our information stored?
  • What AI systems are they using?
The objective is not to create unnecessary bureaucracy around every supplier.
It is to identify where dependency creates material organisational risk.
The AI Supply Chain Is Creating a New Risk
Artificial Intelligence adds another dimension to third-party governance.
A supplier may be using AI even when your organisation isn't.
Imagine engaging an external marketing agency, legal adviser, recruitment company, software developer or consultant.
Are their employees using public AI tools?
Could your confidential information be entered into those systems?
Are AI-generated outputs being checked?
Does the supplier use AI models or services provided by another organisation?
Where does your information go?
Who retains it?
Could it be used for training?
This creates what we might call an AI supply chain.
Your organisation may therefore have excellent internal AI governance while still being exposed through suppliers with very different practices.
Boards increasingly need visibility not only into their own AI usage, but into how critical third parties are using AI when handling organisational information.
Due Diligence Must Happen Before the Contract Is Signed
Third-party cyber risk is much easier to manage before a supplier becomes embedded within the organisation.
Procurement therefore plays an important role in cyber and AI governance.
Before appointing a critical supplier, organisations should understand:
  • Their cybersecurity practices.
  • How they protect information.
  • Their incident response capability.
  • Their business continuity arrangements.
  • Their use of subcontractors.
  • Their AI governance practices.
  • Their history of significant incidents.
  • Relevant certifications or independent assurance.
The level of due diligence should reflect the level of risk.
A small supplier should not necessarily face an enormous security questionnaire simply because it is company policy.
Equally, a critical technology provider should not be approved solely because they offered the best price.
Good governance should be proportionate to risk.
Contracts Matter—But Contracts Don't Create Resilience
Contracts should clearly define expectations around areas such as:
  • Information security.
  • Privacy.
  • Incident notification.
  • Access control.
  • Data ownership.
  • Data location.
  • AI usage.
  • Subcontractors.
  • Business continuity.
  • Termination and data return.
But having clauses in a contract does not automatically make an organisation resilient.
A contract may tell you that a supplier must notify you of an incident.
It doesn't tell you whether they are capable of detecting one.
A contract may require appropriate security controls.
It doesn't prove those controls are operating effectively.
This is why governance must continue throughout the relationship.
Supplier Risk Doesn't End After Onboarding
Too many organisations assess suppliers once.
The questionnaire is completed.
The contract is signed.
The supplier is approved.
And then everyone moves on.
But organisations change.
Suppliers change.
Technology changes.
Ownership changes.
Subcontractors change.
AI usage changes.
Cyber threats change.
A supplier considered low risk three years ago may now be providing a critical service or processing substantially more information.
Third-party risk therefore requires ongoing review.
The greater the dependency, the greater the need for continuing assurance.
Don't Forget Fourth-Party Risk
There is another question Boards should increasingly ask:
Who do our suppliers depend on?
Your organisation may contract with Supplier A.
Supplier A may rely on a cloud provider, data processor, software platform or AI service.
That organisation may rely on another provider.
Your organisation can therefore become exposed to companies with which you have no direct contractual relationship.
This is sometimes called fourth-party risk.
Boards do not need a detailed map of every company in every supplier's ecosystem.
But for critical services, management should understand significant dependencies and concentrations of risk.
Concentration Risk Deserves Board Attention
Suppose ten of your critical suppliers all rely on the same cloud provider.
Individually, each supplier may appear resilient.
Collectively, the organisation may have a significant concentration risk.
The same issue can arise with:
  • Cloud infrastructure.
  • Identity providers.
  • Telecommunications.
  • Payment platforms.
  • Software providers.
  • Data centres.
  • AI platforms.
This is where individual supplier assessments can miss the bigger picture.
Boards need to understand not only who their critical suppliers are, but also where dependencies overlap.
Incident Response Must Include Suppliers
Imagine one of your critical suppliers calls tomorrow morning and says:
"We've had a cyber incident."
What happens next?
Who receives that call?
Who determines what information may have been compromised?
Who decides whether systems should be disconnected?
Who communicates with customers?
Who considers regulatory notification?
Who communicates with the Board?
And perhaps most importantly:
Have you ever tested this scenario?
Third-party incidents should be included in tabletop exercises and incident response planning.
A plan that assumes every incident originates inside your own organisation is no longer realistic.
Your Suppliers Can Also Strengthen Your Resilience
Third-party risk should not become an exercise in distrust.
Strong supplier relationships can actually improve organisational resilience.
Good suppliers bring expertise.
They identify emerging threats.
They share lessons.
They help organisations recover.
They provide capabilities that would be difficult or expensive to maintain internally.
The objective is therefore not to eliminate third-party relationships.
It is to create trusted, well-governed relationships.
Good governance should strengthen partnerships rather than simply add compliance requirements.
The Human Element Still Matters
Third-party risk ultimately comes back to people.
Someone selects the supplier.
Someone approves access.
Someone shares information.
Someone reviews the contract.
Someone notices unusual behaviour.
Someone receives the incident notification.
Someone makes the decision to continue or suspend the relationship.
Technology can help monitor third-party risk.
But judgement, communication and trust remain essential.
This is why third-party risk fits naturally into a human-centric approach to cybersecurity.
Questions Every Board Should Ask
Boards don't need to review hundreds of supplier security questionnaires.
They do need confidence that management understands the organisation's material third-party dependencies.
Some useful questions include:
Who are our most critical suppliers?
Which suppliers have access to our most sensitive information or systems?
What would happen if one of them became unavailable tomorrow?
How do we assess their cyber and AI governance practices?
How frequently are critical suppliers reassessed?
Do we understand their important subcontractor dependencies?
Are there concentrations of risk across our supplier ecosystem?
Are third-party incidents included in our response exercises?
Could we replace a critical supplier if necessary?
And perhaps most importantly:
Would we know quickly if one of our suppliers had been compromised?
From Supplier Management to Ecosystem Resilience
The language we use matters.
If third-party risk is treated purely as supplier compliance, the objective becomes collecting questionnaires and contracts.
If it is treated as ecosystem resilience, the conversation changes.
Now we ask:
Where are we dependent?
Where could disruption spread?
Where is information flowing?
Where do we have concentration risk?
Which relationships are essential to our ability to operate?
How do we strengthen resilience together?
Those are Board-level questions.
Trust, But Verify
Organisations depend on trust.
We trust employees.
We trust technology.
We trust business partners.
And we trust suppliers.
But good governance does not rely on trust alone.
It creates appropriate assurance.
Not because every supplier should be viewed with suspicion.
But because strong relationships are built on clear expectations, transparency and shared responsibility.
Boards should therefore expect management to know which third parties matter most, understand the risks they create, test critical dependencies and maintain appropriate oversight.
Because your organisation can have excellent cybersecurity controls and still experience a significant cyber incident through someone else's systems.
Your suppliers are part of your resilience.
Treat them that way.
And remember:
You can outsource the service.
You cannot outsource accountability for the risk.
Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.

0 Comments

11 August Blog

8/11/2026

0 Comments

 

How Boards Should Measure Cyber Culture (Not Just Compliance)

Picture
A 100% cybersecurity training completion rate does not mean you have a cyber-aware organisation.
It means everyone completed the training.
Those are two very different things.
For years, Boards have been presented with cybersecurity dashboards containing reassuring numbers.
Training completion: 98%.
Policies acknowledged: 100%.
Phishing simulation failure rate: 4%.
Critical patches completed: 97%.
These metrics have value.
They provide evidence that important activities are taking place.
But they don't necessarily tell a Board whether people will make good decisions when confronted with a real cyber threat.
They don't tell you whether an employee will challenge an unusual payment request.
Whether someone will question an AI-generated answer before acting on it.
Whether a manager will report a potential data breach immediately.
Or whether an employee who accidentally clicks a malicious link will feel safe enough to tell someone within five minutes.
Those behaviours are influenced by something much harder to measure.
Culture.
And if Boards want to understand how cyber resilient their organisations really are, they need to start measuring it.
Compliance Matters—But It Isn't the Destination
Let's be clear.
Compliance is important.
Policies matter.
Training matters.
Technical controls matter.
Regulatory requirements matter.
The problem occurs when organisations mistake evidence of compliance for evidence of resilience.
Consider two organisations.
Both have 100% cybersecurity training completion.
In the first organisation, employees rarely discuss cybersecurity, hesitate to report mistakes, don't understand the organisation's AI policy, and assume security belongs to IT.
In the second, employees regularly report suspicious activity, managers discuss cyber risks with their teams, Cyber Champions encourage questions, and staff feel confident challenging unusual requests.
On a compliance dashboard, these organisations may look almost identical.
Culturally, they are worlds apart.
Which organisation would you rather lead during a cyber incident?
What Is Cyber Culture?
Cyber culture is the collective set of behaviours, attitudes, beliefs and expectations that influence how people respond to cyber and AI risks.
It answers questions such as:
Do people think before they click?
Do they challenge unusual requests?
Do they understand why security matters?
Do they know how to use AI responsibly?
Do they feel safe reporting mistakes?
Do managers reinforce good cyber behaviours?
Does leadership demonstrate that cybersecurity matters?
Culture is what happens when nobody is checking whether the policy is being followed.
Boards Need to Measure Behaviour, Not Just Activity
Traditional cyber metrics often measure activity.
How many people completed training?
How many phishing simulations were sent?
How many policies were acknowledged?
Culture metrics should go further.
They should help Boards understand how people actually behave.
For example:
1. Reporting Rates
How many suspicious emails, unusual requests, mistakes and potential incidents are employees reporting?
Interestingly, an increase in reporting can be a positive sign.
A Board looking purely at incident numbers might see more reports and conclude that risk is increasing.
A mature Board might ask whether employees have simply become better at recognising and reporting concerns.
Context matters.
2. Time to Report
This may be one of the most valuable human-centric cyber metrics an organisation can measure.
How long does it take between someone noticing something unusual and reporting it?
At Cyberplanz, we believe:
The most important five minutes in any cyber incident are the five minutes after someone realises something might be wrong.
If employees report concerns quickly, incident response teams have more opportunities to contain potential damage.
If employees wait because they fear blame, embarrassment or disciplinary consequences, small incidents can become much larger ones.
Boards should therefore consider time to report alongside traditional technical metrics.
3. Employee Confidence
Ask employees simple questions.
Do you know how to report a cyber concern?
Would you feel comfortable reporting a mistake?
Do you know which AI tools you are permitted to use?
Would you challenge an unusual request from a senior executive?
Do you understand your role during a cyber incident?
These questions reveal far more about organisational resilience than training completion alone.
4. Leadership Participation
Cyber culture is heavily influenced by what leaders do.
Boards should ask:
Are executives completing the same awareness activities expected of employees?
Do managers regularly discuss cyber and AI risks?
Are leaders following security policies themselves?
Are cyber incidents and near misses discussed openly?
When leaders bypass controls because they are inconvenient, employees notice.
Culture follows behaviour.
5. Near-Miss Reporting
Near misses are one of the richest sources of information available to an organisation.
A finance employee questions an unusual invoice before payment.
An employee nearly uploads confidential information into an unapproved AI platform but checks first.
Someone receives a convincing deepfake call supposedly from an executive and verifies it independently.
Nothing bad happened.
But something valuable happened.
The organisation learned.
Boards should encourage near-miss reporting because it provides insight into emerging threats before they become incidents.
Measure the Questions People Ask
There is another cultural indicator that rarely appears on cybersecurity dashboards.
Questions.
Are employees asking:
"Is this AI tool approved?"
"Can I share this information?"
"Does this email look right?"
"Should we verify this payment request?"
"Who should I report this to?"
Questions demonstrate engagement.
Silence doesn't necessarily demonstrate security.
Sometimes it demonstrates uncertainty.
A healthy cyber culture encourages curiosity.
Don't Turn Phishing Simulations Into Punishment
Phishing simulations can provide useful insight.
But they can also damage culture when handled badly.
If employees who click simulated phishing links are publicly embarrassed, punished or repeatedly labelled as security risks, the organisation may unintentionally teach people something dangerous:
Don't admit mistakes.
The objective of simulations should be learning.
Boards should therefore look beyond click rates and ask:
Did reporting increase?
Did people recognise the warning signs?
Did teams discuss what happened?
Did behaviours improve over time?
A phishing simulation should create learning, not fear.
AI Governance Needs Cultural Metrics Too
As Artificial Intelligence becomes embedded across organisations, Boards need visibility into AI culture as well as cyber culture.
Traditional compliance measures might tell you whether an AI policy exists.
Cultural measures tell you whether anyone understands it.
Boards should ask:
  • Do employees know which AI tools are approved?
  • Do they understand what information should not be entered into public AI platforms?
  • Are AI-generated outputs being challenged and verified?
  • Do employees know how to report inappropriate AI use?
  • Are teams discussing the ethical implications of AI-supported decisions?
An AI Governance Framework without an AI-aware culture is simply another document.
Cyber Champions Provide Valuable Cultural Intelligence
Cyber Champions can provide Boards and leadership teams with insights that dashboards often miss.
Because Champions operate within departments, they hear the questions people ask.
They see where policies create friction.
They identify emerging AI usage.
They recognise where employees lack confidence.
And they can highlight positive behaviours worth reinforcing.
This creates a valuable feedback loop:
Board → Leadership → Cyber Champions → Employees → Cyber Champions → Leadership → Board
Good governance should not simply flow downward.
Insight must flow upward.
Build a Board Cyber Culture Dashboard
Rather than presenting Boards with dozens of technical metrics, organisations could develop a simple Cyber Culture Dashboard.
For example:
Employee confidence in reporting cyber concerns
Average time to report potential incidents
Suspicious activity reporting trends
Near-miss reporting
Cyber Champion engagement
Leadership participation
AI governance awareness
Employee confidence challenging unusual requests
Lessons implemented following incidents
The objective is not to create another complicated reporting exercise.
It is to give Directors a clearer picture of whether secure behaviours are becoming embedded across the organisation.
Look for Trends, Not Perfect Scores
Culture cannot be reduced to a single percentage.
Nor should organisations aim for artificial perfection.
A healthy cyber culture may actually produce more reported incidents, more questions and more near misses because employees are increasingly engaged.
Boards should therefore look for trends.
Is reporting becoming faster?
Is employee confidence increasing?
Are people asking more questions?
Are lessons being implemented?
Are departments discussing cyber and AI risks more frequently?
Is leadership becoming more visible?
These trends tell a story.
And that story matters more than a single score.
The Questions Boards Should Ask
At the next Board meeting, instead of simply asking:
"Has everyone completed their cybersecurity training?"
Try asking:
"Do our people know what good cyber behaviour looks like?"
Instead of:
"How many employees failed the phishing test?"
Ask:
"How quickly did people recognise and report it?"
Instead of:
"Do we have an AI policy?"
Ask:
"Do our people understand how to use AI responsibly?"
Instead of:
"How many cyber incidents did we have?"
Ask:
"What did we learn from them, and what changed as a result?"
Different questions create different conversations.
Different conversations create different behaviours.
And behaviours shape culture.
What Gets Measured Gets Discussed
Boards influence organisations through the questions they ask and the measures they prioritise.
If the Board focuses exclusively on compliance, management will naturally focus on compliance.
If the Board asks about behaviours, confidence, trust, reporting and learning, those things become organisational priorities too.
This does not mean abandoning traditional cybersecurity metrics.
It means complementing them with human metrics.
Because technology can tell you what your systems are doing.
Compliance can tell you whether your processes are being followed.
But culture tells you what your people are likely to do when something unexpected happens.
And that is when resilience matters most.
From Compliance to Capability
The most cyber-resilient organisations will not necessarily be those with the highest training completion rates.
They will be the organisations where people:
Recognise unusual behaviour.
Challenge assumptions.
Ask questions.
Use AI responsibly.
Report concerns quickly.
Learn from mistakes.
And feel empowered to protect the organisation.
That is why Boards must move beyond asking whether the organisation is compliant.
They need to understand whether the organisation is capable.
Because ultimately:
Compliance tells you what the organisation has done.
Culture tells you what your people will do.
And when the next cyber incident occurs, it is what people do that can make all the difference.
Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.

0 Comments

4 August Blog

8/4/2026

0 Comments

 

Why Cybersecurity is Really About Business Resilience

Picture
"Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people."
For too long, organisations have viewed cybersecurity as an IT issue.
When cyber threats increased, they purchased new technologies.
Firewalls.
Endpoint protection.
Email security.
Multi-factor authentication.
Threat detection platforms.
While these technologies remain essential, they represent only part of the solution.
Because when a cyber incident occurs, the question quickly changes from:
"How do we stop the attack?"
To:
"How do we keep the business operating?"
That is not a technology question.
It is a business resilience question.
And that is why cybersecurity has become one of the most important governance responsibilities facing Boards and executive teams today.
Cybersecurity Is a Means, Not the End
Many organisations unintentionally measure success by the number of security controls they have implemented.
How many policies exist?
How many phishing emails were blocked?
How many vulnerabilities were patched?
These are important indicators.
But they don't answer the question that matters most.
Can the organisation continue to operate when something goes wrong?
Because cyber resilience isn't measured on the day everything works perfectly.
It is measured on the day it doesn't.
Every Organisation Will Face Disruption
Cyber incidents are no longer rare events.
They have become part of the operating environment.
Whether it's ransomware, a compromised supplier, accidental data disclosure, AI misuse, or a major system outage, every organisation should assume disruption will occur at some point.
The organisations that recover fastest are rarely those with the most technology.
They are the organisations that prepared their people, tested their plans, and built resilience into their culture.
Resilience is not about avoiding every disruption.
It is about responding effectively when disruption occurs.
Business Resilience Is Built Before the Crisis
The most important decisions during a cyber incident are often made long before the incident occurs.
Before the first phishing email.
Before the first ransomware demand.
Before the first AI-related mistake.
Boards influence resilience by asking questions such as:
  • Have we clearly identified our critical business services?
  • What would happen if they became unavailable tomorrow?
  • Have we tested our incident response plans?
  • Does every executive understand their role during a cyber crisis?
  • Have we considered AI-related risks alongside traditional cyber risks?
  • How quickly could we continue serving our customers?
Resilience begins with preparation.
Technology Alone Cannot Create Resilience
Technology detects threats.
Technology blocks malicious activity.
Technology automates responses.
But technology cannot:
  • Reassure customers.
  • Lead employees during uncertainty.
  • Make strategic decisions.
  • Balance competing priorities.
  • Protect organisational reputation.
  • Restore stakeholder confidence.
Those responsibilities belong to leaders.
This is why governance matters.
Resilient Organisations Think Differently
Many organisations ask:
"How do we stop cyber attacks?"
Resilient organisations ask:
"How do we continue operating if an attack succeeds?"
That subtle difference changes everything.
Instead of focusing solely on prevention, they invest in:
  • Business continuity.
  • Incident response.
  • Crisis communications.
  • Leadership capability.
  • Staff engagement.
  • AI governance.
  • Organisational culture.
They recognise that resilience is created through preparation, not optimism.
People Are the Difference
Every cyber incident eventually becomes a people issue.
A manager deciding whether to disconnect a critical system.
A finance team verifying an urgent payment request.
An employee reporting suspicious activity.
A customer service representative communicating with concerned customers.
A Board making strategic decisions under pressure.
Technology supports these decisions.
People make them.
This is why organisations that invest in leadership, culture and trust consistently recover more effectively.
AI Has Expanded the Resilience Challenge
Artificial Intelligence is transforming organisations.
It is also changing the nature of organisational resilience.
AI can improve productivity, automate decisions and enhance customer experiences.
It can also introduce new risks.
Confidential information may be shared unintentionally.
AI-generated content may be inaccurate.
Critical decisions may rely on incomplete or biased information.
Deepfakes and AI-assisted fraud are becoming increasingly convincing.
Business resilience now requires organisations to govern AI with the same discipline applied to cyber risk.
Responsible AI governance is no longer optional.
It is an essential component of organisational resilience.
Culture Is the Hidden Strength
Resilient organisations share one characteristic.
People trust each other.
Employees feel safe reporting concerns.
Managers encourage learning.
Cyber Champions promote good practices.
Boards discuss cyber resilience regularly.
Leaders communicate openly during uncertainty.
This culture cannot be purchased.
It is built.
Every conversation.
Every decision.
Every day.
The Board's Responsibility
Boards are not expected to become cybersecurity experts.
They are expected to provide leadership.
Their role is to ensure the organisation is prepared to withstand disruption, make informed decisions under pressure and recover with confidence.
Boards should regularly ask:
  • Are we building resilience or simply buying more technology?
  • Do we understand our most critical business services?
  • Are our people prepared to respond?
  • Have we tested our plans?
  • Are we governing AI as carefully as we govern cyber risk?
  • What lessons have we learned from recent incidents and near misses?
These are governance questions.
And governance shapes resilience.
Measuring What Really Matters
Traditional cyber metrics often include:
  • Number of blocked attacks.
  • Patch compliance.
  • Training completion.
  • Vulnerability counts.
These remain useful.
But resilient organisations also measure:
  • Time taken to report incidents.
  • Time to recover critical services.
  • Staff confidence.
  • Cyber culture.
  • AI governance maturity.
  • Board engagement.
  • Lessons learned from near misses.
  • Customer confidence after an incident.
These measures reflect organisational capability rather than technical activity.
Resilience Creates Competitive Advantage
Customers trust organisations that continue delivering services during disruption.
Investors value organisations with mature governance.
Employees remain engaged when leadership communicates with confidence.
Business partners prefer organisations that manage risk responsibly.
Resilience therefore creates value.
It protects reputation.
Strengthens relationships.
Supports innovation.
Builds confidence.
And enables sustainable growth.
Cybersecurity is not simply about preventing loss.
It is about enabling success.
The Future Belongs to Resilient Organisations
Technology will continue to evolve.
Artificial Intelligence will reshape every industry.
Threats will become faster, more sophisticated and increasingly unpredictable.
The organisations that succeed will not necessarily be those with the most advanced technology.
They will be those with the strongest leadership.
The clearest governance.
The most engaged people.
And the greatest ability to adapt.
Because cybersecurity has never really been about technology.
It has always been about protecting the organisation's ability to achieve its purpose.
Ultimately, cybersecurity is really about business resilience.
And business resilience is created when leadership provides direction, governance enables good decisions, and people are empowered to respond with confidence.
That is how organisations build lasting trust.
That is how organisations create resilience.
And that is how organisations thrive in an increasingly digital world.
0 Comments

28 July Blog

7/28/2026

0 Comments

 

​From Human Firewall to Human Advantage

Picture
For years, organisations have been encouraged to think of their employees as the human firewall.
The idea was simple.
Technology cannot stop every cyber-attack.
Eventually, every suspicious email, unusual request or unexpected phone call reaches a person.
Employees become the final barrier between attackers and organisational systems.
While this concept has helped organisations recognise the importance of people in cybersecurity, it also has an unintended consequence.
It frames employees as the last line of defence.
A barrier.
A control.
Something that stands between the organisation and a cyber incident.
Today's organisations need to think differently.
People are not simply a firewall.
They are an organisation's greatest competitive advantage.
A Firewall Doesn't Learn
Traditional firewalls follow rules.
They inspect traffic.
They block known threats.
They do exactly what they have been programmed to do.
People are different.
People learn.
They adapt.
They collaborate.
They ask questions.
They recognise unusual behaviour.
They solve problems.
They make decisions in situations that technology has never encountered before.
Artificial Intelligence may process information faster than people.
But it still depends on human judgement, context and values.
The organisations that succeed in the future will not simply have better technology.
They will have better people, supported by better leadership.
The Human Advantage
The Human Advantage is created when employees are empowered to become active contributors to organisational resilience.
Rather than seeing cybersecurity as someone else's responsibility, people understand that they have an important role in protecting customers, colleagues and the organisation.
This doesn't happen because employees fear making mistakes.
It happens because they feel trusted, informed and supported.
The Human Advantage combines knowledge with confidence.
Technology with judgement.
Governance with culture.
Why Technology Alone Is Not Enough
Cybersecurity technology has advanced dramatically.
Artificial Intelligence can identify anomalies.
Security platforms can detect threats in seconds.
Automated tools can isolate compromised devices.
Yet many successful cyber-attacks still begin with a human interaction.
An employee approves a fraudulent payment.
A manager shares information with an impersonated executive.
A supplier receives a convincing AI-generated email.
A customer service representative resets an account after being deceived.
Technology provides important protection.
People provide context.
Together they create resilience.
Leadership Creates the Advantage
Employees rarely become engaged because of policies.
They become engaged because of leadership.
Leaders influence how people think about cyber risk.
They determine whether cybersecurity is viewed as:
An IT problem.
Or everyone's responsibility.
When leaders regularly discuss cyber resilience, recognise positive behaviours and demonstrate responsible use of AI, employees are more likely to follow.
Culture is shaped by what leaders consistently reinforce.
Trust Unlocks Potential
People perform at their best when they feel trusted.
When organisations create a Just Culture, employees are more likely to:
  • Report suspicious activity.
  • Admit mistakes quickly.
  • Ask questions before taking action.
  • Challenge unusual requests.
  • Share ideas for improvement.
  • Help colleagues stay safe.
Trust transforms cybersecurity from a compliance exercise into a shared organisational responsibility.
Every Conversation Matters
Cyber resilience is rarely built during annual awareness training.
It is built through everyday conversations.
A manager asking whether an unusual email looks legitimate.
A colleague reminding someone not to upload confidential information into a public AI platform.
A Cyber Champion discussing a recent phishing attempt during a team meeting.
A Board reviewing lessons from a recent near miss.
These conversations create awareness.
Awareness shapes behaviour.
Behaviour creates culture.
AI Makes Human Judgement More Important
Artificial Intelligence is changing the workplace faster than many organisations expected.
Employees increasingly rely on AI to improve productivity.
AI can generate reports.
Summarise meetings.
Write software code.
Analyse data.
Create content.
But AI also creates new risks.
It can confidently produce incorrect information.
It can reflect hidden bias.
It can generate convincing phishing emails.
It can be used to create deepfake voices and videos.
This is why organisations need more than AI capability.
They need human judgement.
The Human Advantage recognises that people remain responsible for questioning, validating and making ethical decisions.
Technology can recommend.
People remain accountable.
Cyber Champions Build the Human Advantage
One of the most effective ways to strengthen organisational resilience is to empower people throughout the business.
Cyber Champions encourage conversations.
Share practical guidance.
Promote responsible AI use.
Support colleagues.
Identify emerging risks.
They demonstrate that cybersecurity is not owned solely by IT.
It belongs to everyone.
Every department contributes to resilience.
Measuring What Matters
Many organisations continue measuring awareness through:
  • Training completion rates.
  • Phishing simulation results.
  • Policy acknowledgements.
These measures have value.
But they tell only part of the story.
A true Human Advantage can be seen through different indicators.
How quickly are suspicious activities reported?
Do employees challenge unusual requests?
Are near misses shared openly?
Do teams discuss cyber and AI risks regularly?
Do leaders actively promote cyber resilience?
These behaviours provide a far richer picture of organisational maturity.
The Board's Role
Boards have a critical role in creating the Human Advantage.
Directors should ask:
  • Do our people understand why cybersecurity matters?
  • Do employees feel safe reporting concerns?
  • Are leaders reinforcing positive behaviours?
  • Is AI being adopted responsibly?
  • How are we measuring cyber culture?
  • Are we investing in people as much as technology?
These questions shift the conversation from compliance to capability.
A Competitive Advantage
Customers increasingly trust organisations that demonstrate responsible governance.
Investors look for organisations that manage risk effectively.
Employees want to work where leadership values openness, learning and innovation.
The Human Advantage strengthens all three.
It improves resilience.
Builds trust.
Supports innovation.
Creates stronger organisational culture.
Enhances reputation.
These are outcomes that extend well beyond cybersecurity.
The Future Belongs to People
Artificial Intelligence will continue to evolve.
Technology will become faster.
Automation will become more sophisticated.
Cybercriminals will continue finding new ways to exploit organisations.
The organisations that succeed will not simply deploy the latest security technologies.
They will develop workplaces where people think critically.
Speak openly.
Challenge assumptions.
Learn continuously.
And work together to protect what matters most.
The future of cybersecurity is not about building a stronger human firewall.
It is about creating a Human Advantage.
Because technology may detect threats.
But it is people—guided by leadership, empowered by trust and supported by good governance—who create truly resilient organisations.

0 Comments

20 July Blog

7/20/2026

0 Comments

 

Creating a Just Culture: Why Employees Must Feel Safe Reporting Cyber Mistakes

Picture
Imagine this scenario.
An employee receives an email that appears to come from a trusted supplier.
Everything looks legitimate.
The branding is correct.
The language is professional.
The request seems routine.
Without realising it, they click a link and enter their credentials.
Within seconds, they suspect something isn't right.
Now they face a decision.
Do they report it immediately?
Or do they hope nobody notices?
That decision may determine whether the organisation experiences a minor security event—or a major cyber incident.
The greatest cyber risk is often not the mistake itself.
It is the delay in reporting it.
We Are All Human
Every employee makes mistakes.
Directors make mistakes.
CEOs make mistakes.
IT professionals make mistakes.
Cybersecurity specialists make mistakes.
Even experienced security professionals occasionally click suspicious links or overlook warning signs.
Cybercriminals understand this.
Modern cyber attacks are no longer crude or obvious.
They use Artificial Intelligence.
They research social media.
They impersonate trusted colleagues.
They exploit urgency, curiosity and human emotion.
Their objective is not to defeat technology.
It is to exploit perfectly normal human behaviour.
Organisations should not expect perfection.
They should expect humanity.
The Cost of Silence
In many organisations, employees hesitate to report cyber mistakes because they fear:
  • Embarrassment.
  • Blame.
  • Disciplinary action.
  • Damage to their reputation.
  • Looking incompetent.
  • Letting colleagues down.
These fears are understandable.
Unfortunately, they can significantly increase organisational risk.
An email reported within five minutes may affect one employee.
The same email reported six hours later may affect hundreds.
Time matters.
The sooner an organisation knows about an incident, the more options it has to contain it.
What Is a Just Culture?
A Just Culture recognises an important truth.
People should not be punished for making honest mistakes.
Instead, organisations should seek to understand:
What happened?
Why did it happen?
How can we reduce the likelihood of it happening again?
A Just Culture does not remove accountability.
Deliberate misconduct, reckless behaviour and intentional policy violations still require appropriate action.
However, honest mistakes become opportunities for learning rather than occasions for blame.
High-performing industries such as aviation and healthcare have embraced this approach for decades because they understand that learning depends on openness.
Cybersecurity should be no different.
Fear Is the Enemy of Resilience
Many organisations invest heavily in security technology while unintentionally creating cultures where employees fear speaking up.
This creates a dangerous contradiction.
Leaders ask employees to report incidents immediately.
Employees worry they will be criticised if they do.
The result is predictable.
Problems remain hidden.
Opportunities to contain incidents are lost.
Resilience suffers.
Trust is built when people believe they can admit mistakes without fear of unfair consequences.
Boards Set the Tone
Culture starts in the boardroom.
Boards influence organisational behaviour through the questions they ask, the behaviours they recognise and the values they reinforce.
Directors should ask:
  • Do employees feel psychologically safe reporting cyber incidents?
  • How quickly are potential incidents reported?
  • What have we learned from recent near misses?
  • Are we recognising good reporting behaviours?
  • Are leaders modelling openness and accountability?
The objective is not to eliminate mistakes.
It is to ensure mistakes become learning opportunities.
Managers Shape Everyday Behaviour
While Boards establish expectations, managers influence daily culture.
Employees watch how leaders respond when something goes wrong.
If the first response is:
"Who made this mistake?"
Employees quickly learn to remain silent.
If the response becomes:
"What can we learn from this?"
The conversation changes completely.
Managers should thank employees for reporting concerns.
Recognise honesty.
Focus on solutions.
Celebrate transparency.
People repeat behaviours that are acknowledged and valued.
Shadow AI Makes Trust Even More Important
Artificial Intelligence has introduced new reporting challenges.
Imagine an employee accidentally uploads confidential information into a public AI platform.
Will they immediately report it?
Or will they hope nobody notices?
As AI becomes more common, organisations will inevitably experience accidental misuse.
The organisations that respond most effectively will be those where employees feel safe admitting what happened.
AI governance depends as much on culture as it does on policy.
Near Misses Are Valuable Intelligence
One of the most overlooked sources of organisational learning is the cyber near miss.
Examples include:
  • A phishing email identified before anyone clicked it.
  • An employee questioning an unusual payment request.
  • Suspicious AI-generated content being challenged.
  • An accidental disclosure quickly reported.
  • A supplier requesting unusual information.
Every near miss provides valuable insight.
Rather than asking,
"Who was responsible?"
Leaders should ask,
"What can this teach us?"
Near misses often reveal weaknesses before they become major incidents.
Building a Reporting Culture
Creating a Just Culture requires deliberate effort.
Organisations should:
  • Make reporting simple.
  • Thank employees for speaking up.
  • Share lessons learned across the organisation.
  • Focus on improvement rather than blame.
  • Encourage curiosity.
  • Regularly discuss cyber and AI risks.
  • Recognise positive security behaviours.
When reporting becomes normal, resilience improves.
Cyber Champions Can Help
Cyber Champions play an important role in building trust.
Because they work within individual teams, colleagues often feel more comfortable discussing concerns with them than approaching IT directly.
Cyber Champions encourage conversations.
Answer questions.
Support colleagues.
Promote responsible AI use.
Most importantly, they help create an environment where seeking advice becomes normal rather than something to avoid.
Trust Is a Competitive Advantage
Customers trust organisations that respond openly to incidents.
Employees trust leaders who support learning.
Investors trust Boards that demonstrate strong governance.
Trust is built long before an incident occurs.
It is built every time an employee feels confident enough to say:
"I think I've made a mistake."
Without fear.
Without blame.
With confidence that the organisation will help solve the problem.
The Future Belongs to Learning Organisations
Technology will continue to improve.
Artificial Intelligence will continue to evolve.
Cyber threats will become even more sophisticated.
The organisations that remain resilient will not be those with the most advanced technology alone.
They will be those where people feel trusted.
Where leaders encourage openness.
Where reporting is recognised as a strength rather than a weakness.
Because in cybersecurity, silence is often far more dangerous than mistakes.
The most resilient organisations understand that culture is not simply another security control.
It is the foundation upon which every other control depends.
Creating a Just Culture is not about accepting failure.
It is about creating an organisation that learns faster, responds sooner, and becomes stronger because its people are confident enough to speak up.
In today's digital world, that may be one of the greatest competitive advantages any organisation can build.

0 Comments

14 July Blog

7/14/2026

0 Comments

 

The Rise of Shadow AI: What Every Board Should Know

Picture
Artificial Intelligence is transforming the way organisations operate.
Employees are using AI to write reports, analyse spreadsheets, prepare presentations, summarise meetings, write software code, create marketing campaigns, and automate repetitive tasks.
For many organisations, this is increasing productivity, improving customer service, and creating new opportunities for innovation.
But there is another side to this transformation.
It is happening quietly, largely unnoticed, and often without Board oversight.
It is known as Shadow AI.
Just as organisations once discovered employees were using unauthorised software and cloud services—known as Shadow IT—many are now discovering that staff are using AI tools every day without clear governance, policies, or understanding of the risks involved.
The question for Boards is no longer:
"Should our organisation use AI?"
The question is:
"Do we know how AI is already being used across our organisation?"
For many Boards, the honest answer is: probably not.
What is Shadow AI?
Shadow AI refers to the use of Artificial Intelligence tools or services that have not been approved, governed, or adequately monitored by an organisation.
It often begins with good intentions.
An employee wants to save time writing a report.
A manager uses AI to analyse customer feedback.
A marketing team generates campaign ideas.
A developer uses AI to accelerate coding.
A finance team asks AI to summarise complex spreadsheets.
None of these actions are necessarily inappropriate.
In fact, many deliver genuine business value.
The problem is that they often occur without anyone considering:
  • What data is being shared?
  • Where is that information stored?
  • Who owns AI-generated content?
  • How accurate are the results?
  • Are regulatory obligations being met?
  • Could confidential information be exposed?
Without governance, innovation can unintentionally become organisational risk.
Why Boards Should Care
Artificial Intelligence is no longer confined to technology teams.
It is being adopted across every department.
That means AI-related decisions are influencing:
  • Business strategy
  • Customer experience
  • Financial reporting
  • Human Resources
  • Marketing
  • Procurement
  • Operations
  • Risk management
Poorly governed AI can lead to:
  • Confidential information being entered into public AI platforms
  • Privacy breaches
  • Incorrect or fabricated information influencing decisions
  • Intellectual property leakage
  • Biased or discriminatory outcomes
  • Reputational damage
  • Regulatory scrutiny
  • Loss of stakeholder trust
Ultimately, these are governance issues—not just technology issues.
Shadow AI Is Often Invisible
One of the greatest challenges with Shadow AI is that organisations frequently don't know it exists.
Employees are not trying to bypass governance.
They are simply trying to work more efficiently.
AI tools are often:
  • Free
  • Easy to access
  • Available from any web browser
  • Integrated into existing software
  • Recommended by colleagues
Without clear guidance, employees naturally adopt the tools that help them perform their jobs.
The risk isn't that people are using AI.
The risk is that leadership has no visibility over how it is being used.
Banning AI Isn't the Answer
Some organisations have responded by attempting to ban AI altogether.
This is rarely effective.
Employees who see clear productivity benefits are unlikely to abandon AI simply because policies prohibit it.
Instead, AI usage often becomes even less visible.
History has shown this before.
When organisations banned cloud storage, employees found alternatives.
When organisations restricted mobile devices, staff brought their own.
The same applies to AI.
Effective governance is built on enablement, not prohibition.
The objective should be to create an environment where employees can use AI safely, responsibly, and confidently.
Questions Every Board Should Be Asking
Rather than focusing solely on technology, Boards should ask strategic questions.
For example:
  • Where is AI currently being used across our organisation?
  • Which AI tools have been approved?
  • Do we have an AI Governance Framework?
  • What information should never be entered into public AI platforms?
  • How are AI-generated outputs reviewed?
  • Who is accountable for AI-related decisions?
  • How are we educating employees about responsible AI use?
  • Are AI risks included in our enterprise risk register?
These conversations shift AI from an operational issue to a governance priority.
AI Governance Is About Trust
Good AI governance is not about slowing innovation.
It is about building trust.
Employees need confidence that they understand organisational expectations.
Customers need confidence that their information is protected.
Boards need confidence that AI supports business objectives without introducing unnecessary risk.
Trust becomes a competitive advantage.
Organisations that demonstrate responsible AI governance are increasingly viewed as more reliable by customers, regulators, investors, and business partners.
Building an AI-Aware Culture
Policies alone are not enough.
AI governance must become part of organisational culture.
This means:
  • Providing practical AI guidance rather than lengthy policy documents.
  • Helping employees understand both opportunities and risks.
  • Encouraging questions before problems occur.
  • Creating safe reporting channels.
  • Celebrating responsible AI use.
  • Updating governance as technology evolves.
Culture always moves faster than policy.
Strong organisations recognise this and invest in both.
The Role of Cyber Champions
Cyber Champions can play an important role in helping organisations manage Shadow AI.
Because they work within different departments, they often identify emerging AI use before leadership becomes aware of it.
They help colleagues understand:
  • Approved AI tools
  • Safe information handling
  • Responsible prompting
  • Verification of AI-generated content
  • Organisational AI expectations
Cyber Champions become trusted advocates for responsible innovation.
AI Governance Is a Leadership Opportunity
The organisations that gain the greatest value from AI will not necessarily be those using the most sophisticated tools.
They will be the organisations with the strongest governance.
Boards that embrace AI thoughtfully can encourage innovation while maintaining trust, protecting information, and meeting their governance responsibilities.
This requires curiosity.
Leadership.
Clear accountability.
And a willingness to ask better questions.
The Future Belongs to Governed Innovation
Artificial Intelligence will continue to evolve.
Employees will continue discovering new ways to use it.
Customers will increasingly expect organisations to use AI responsibly.
The question is no longer whether AI belongs in your organisation.
It almost certainly already does.
The real question is whether your Board has the visibility, governance, and leadership to ensure AI is being used safely, ethically, and in ways that strengthen—not weaken—your organisation.
Shadow AI should not be viewed as a hidden threat waiting to be eliminated.
It should be viewed as a signal.
A signal that innovation is happening.
The role of the Board is to ensure that innovation is guided by governance, supported by culture, and aligned with the organisation's values.
Because in the age of Artificial Intelligence, organisations will not be defined simply by how quickly they adopt AI.
They will be defined by how well they govern it.

0 Comments

6 July Post

7/6/2026

0 Comments

 

Building Cyber Champions: Why Every Department Needs a Security Advocate

Picture
For many organisations, cybersecurity still sits within the IT department.
When employees have a security question, they contact IT.
When a phishing email arrives, they forward it to IT.
When a cyber incident occurs, everyone expects IT to fix it.
This mindset creates a significant problem.
Cybersecurity is no longer simply an IT function.
It is an organisational capability.
The most resilient organisations recognise that cyber vigilance cannot be delivered by one department alone. It must be embedded throughout the business, with people at every level understanding their role in protecting the organisation.
One of the most effective ways to achieve this is by building a network of Cyber Champions.
What is a Cyber Champion?
A Cyber Champion is not another IT support person.
They are not expected to investigate cyber incidents, configure security systems or become cybersecurity experts.
Instead, they act as a trusted advocate for cyber resilience within their own team.
Cyber Champions help connect organisational security objectives with everyday business activities.
They encourage conversations.
Promote good security practices.
Support colleagues.
Provide feedback.
Identify emerging risks.
Most importantly, they help make cybersecurity part of everyday work rather than something that only appears during annual awareness training.
Why Every Department Needs One
Cyber risks exist across every part of an organisation.
Finance teams face invoice fraud and business email compromise.
Human Resources manages highly sensitive employee information and is increasingly exposed to AI-generated recruitment fraud.
Marketing teams use AI tools to create content while managing brand reputation and social media risks.
Operations teams rely on business systems that support day-to-day service delivery.
Customer service teams regularly verify identities and manage personal information.
Legal teams oversee contracts, privacy obligations and intellectual property.
Every department faces different risks.
A Cyber Champion understands how cyber and AI risks affect their own team and helps translate organisational policies into practical behaviours.
Creating a Human Firewall
The phrase "human firewall" is often used in cybersecurity.
While it conveys an important message, people are much more than a barrier between attackers and systems.
People are decision-makers.
Problem-solvers.
Communicators.
Leaders.
Cyber Champions help create an environment where secure decision-making becomes a normal part of everyday business.
They encourage colleagues to ask questions before sharing sensitive information.
They promote responsible AI use.
They reinforce good cyber habits.
Over time, these small conversations help create lasting behavioural change.
Bridging the Gap Between IT and the Business
One of the biggest challenges facing many organisations is communication.
Security teams often understand technical risks.
Business teams understand operational priorities.
Cyber Champions help bridge the gap.
Because they work within the business, they understand both the pressures their colleagues face and the importance of protecting organisational information.
They help explain security requirements in language that makes sense to their team.
Equally important, they provide valuable feedback to security and leadership teams about practical challenges, emerging concerns and opportunities for improvement.
This two-way communication strengthens governance and supports continuous improvement.
Cyber Champions and AI Governance
Artificial Intelligence has introduced a new dimension to organisational risk.
Employees increasingly use AI tools to:
  • Draft emails
  • Summarise reports
  • Analyse information
  • Generate presentations
  • Write software code
  • Improve productivity
These technologies create enormous opportunities.
They also create new governance challenges.
Cyber Champions can play an important role in helping colleagues understand:
  • Which AI tools are approved.
  • What information should never be entered into public AI platforms.
  • How to verify AI-generated outputs.
  • Ethical considerations when using AI.
  • Organisational AI policies and expectations.
As AI adoption accelerates, Cyber Champions become valuable advocates for responsible AI use.
What Makes a Great Cyber Champion?
The best Cyber Champions are not necessarily the most technical people.
They are people who are:
  • Trusted by their colleagues.
  • Good communicators.
  • Curious and willing to learn.
  • Positive role models.
  • Influential within their teams.
  • Passionate about helping others.
They encourage conversations rather than enforce rules.
They build confidence rather than fear.
They create engagement rather than compliance.
Supporting Your Cyber Champions
Simply appointing Cyber Champions is not enough.
Organisations should provide them with:
  • Regular updates on emerging threats.
  • AI governance guidance.
  • Practical discussion topics for team meetings.
  • Access to security specialists when needed.
  • Opportunities to share ideas with other Champions.
  • Recognition for their contribution.
When Cyber Champions feel supported, they become powerful advocates for organisational resilience.
The Board's Role
Boards and executive leaders have an important role in ensuring Cyber Champion programmes succeed.
They should ask:
  • Do we have Cyber Champions across the organisation?
  • Are they supported by leadership?
  • How do we measure their impact?
  • Are they helping improve our cyber culture?
  • Are they promoting responsible AI use?
Cyber Champion programmes should not be viewed as another awareness initiative.
They are a leadership investment.
They strengthen organisational culture, improve communication and increase resilience.
Measuring Success
Success should not be measured by the number of Cyber Champions appointed.
Instead, organisations should ask:
  • Are employees reporting suspicious activity sooner?
  • Has confidence in identifying cyber threats improved?
  • Are departments discussing cyber and AI risks more regularly?
  • Are security behaviours improving?
  • Are AI tools being used more responsibly?
  • Has collaboration between business teams and security improved?
These indicators provide a much better picture of organisational resilience than attendance records or training completion rates.
Every Organisation Can Benefit
You do not need thousands of employees to build a Cyber Champion programme.
For a small business, the owner or a senior team member may naturally become the Cyber Champion.
Medium-sized organisations may appoint one Champion for each department.
Larger organisations may build networks of Champions across offices, regions and business units.
The model is flexible because every organisation is different.
The principle remains the same.
Cyber resilience is strongest when responsibility is shared.
Turning Awareness into Action
Technology will continue to evolve.
Artificial Intelligence will continue to reshape the workplace.
Cyber threats will continue to become more sophisticated.
The organisations that succeed will not simply invest in better technology.
They will invest in better conversations.
Cyber Champions create those conversations.
They turn policies into behaviours.
Awareness into action.
Compliance into culture.
And colleagues into confident advocates for organisational resilience.
Building a network of Cyber Champions is not simply another cybersecurity initiative.
It is one of the most effective ways an organisation can embed cyber vigilance, strengthen AI governance and build a resilient culture that protects the business long into the future.

0 Comments

1 July Post

7/1/2026

0 Comments

 

Why Security Awareness Training Often Fails (And What Boards and Leaders Should Do Instead in the Age of AI)

Picture
Every year, organisations invest millions of dollars in cybersecurity awareness training.
Employees complete online modules.
They answer multiple-choice questions.
A certificate is issued.
The compliance box is ticked.
Yet organisations continue to fall victim to phishing attacks, business email compromise, ransomware, insider threats, and increasingly sophisticated AI-enabled cybercrime.
If awareness training is so widespread, why do so many organisations continue to experience preventable cyber incidents?
The answer is surprisingly simple.
Most organisations measure participation.
Very few measure behavioural change.
Cybersecurity awareness is not a training programme.
It is an organisational culture.
Compliance Does Not Equal Resilience
For many organisations, cybersecurity awareness has become a compliance exercise.
Staff are required to complete annual training because regulations, insurers, or auditors expect it.
Completion rates become the primary measure of success.
"We achieved 98% completion."
That sounds impressive.
But it tells us very little.
It does not tell us whether employees:
  • Recognise sophisticated phishing emails.
  • Know how to safely use AI tools.
  • Feel confident reporting suspicious activity.
  • Understand how their everyday decisions affect organisational risk.
  • Would know what to do during a cyber incident.
Compliance measures attendance.
Resilience measures capability.
The two are not the same.
The Threat Landscape Has Changed Faster Than Training
Traditional awareness programmes were designed for a different era.
Today, employees face threats that barely existed a few years ago, including:
  • AI-generated phishing emails that are almost impossible to distinguish from legitimate communications.
  • Deepfake voice and video scams targeting executives and finance teams.
  • Shadow AI, where employees unknowingly expose confidential information to public AI platforms.
  • AI-assisted social engineering attacks.
  • Supply chain compromises affecting trusted vendors.
Meanwhile, many organisations are still delivering the same annual training they have used for years.
Cybercriminals innovate daily.
Training often changes annually.
That imbalance creates risk.
People Are Not the Weakest Link
One of the most damaging phrases in cybersecurity is:
"People are the weakest link."
People are not the weakest link.
They are the most targeted.
When employees receive thousands of emails, constant Teams or Slack messages, phone calls, and AI-generated content every week, expecting perfect decision-making every time is unrealistic.
Instead of blaming employees, organisations should ask:
  • Have we given them the knowledge they need?
  • Have we created simple processes to follow?
  • Do they feel safe reporting mistakes?
  • Have we designed systems that support secure behaviours?
The goal should be to build confidence, not fear.
Boards Set the Tone
Cybersecurity culture starts long before an employee receives awareness training.
It starts in the boardroom.
If boards treat cybersecurity as an annual compliance exercise, management often does the same.
If boards instead ask:
  • How are we improving cyber behaviours?
  • How are we measuring our security culture?
  • Are employees confident in identifying cyber threats?
  • How are we preparing staff for the responsible use of AI?
...the entire organisation begins to think differently.
Culture follows leadership.
Awareness Should Be Continuous
Learning is most effective when it is ongoing.
The same applies to cybersecurity.
Rather than relying on a single annual training session, organisations should create continuous engagement throughout the year.
Examples include:
  • Five-minute monthly security updates.
  • AI awareness briefings.
  • Department discussions.
  • Short video messages from executives.
  • Phishing simulations followed by coaching.
  • Security tips aligned with current events.
  • Quarterly cyber resilience workshops.
  • Incident reviews that focus on learning rather than blame.
Cyber awareness should become part of everyday work—not an annual interruption.
AI Literacy Is the New Security Awareness
Artificial Intelligence has fundamentally changed the way people work.
Employees increasingly use AI to:
  • Draft emails.
  • Summarise reports.
  • Analyse data.
  • Generate marketing content.
  • Write code.
  • Improve productivity.
Yet many organisations have provided little or no guidance on its safe use.
Without governance, employees may:
  • Upload confidential information into public AI tools.
  • Trust inaccurate AI-generated outputs.
  • Accidentally expose intellectual property.
  • Create regulatory compliance issues.
  • Introduce bias into business decisions.
Security awareness programmes must now include AI literacy.
Employees need to understand not only how to use AI effectively, but also how to use it responsibly.
Make Cybersecurity Relevant
Generic awareness programmes often fail because employees struggle to relate them to their daily work.
The risks faced by a finance manager differ from those faced by a software developer, HR advisor, receptionist, or board member.
Training should reflect those differences.
Examples include:
Finance Teams
Business email compromise, invoice fraud, executive impersonation.
Human Resources
Sensitive personal information, recruitment scams, AI-generated CV fraud.
Marketing
Brand impersonation, AI-generated content, social media attacks.
Executives
Whaling attacks, deepfake communications, strategic decision-making.
Board Members
Cyber governance, AI governance, organisational resilience, regulatory oversight.
People engage when learning feels relevant.
Build a Culture Where Reporting Is Encouraged
One of the strongest indicators of cyber maturity is how quickly employees report concerns.
Unfortunately, many organisations unintentionally discourage reporting.
Employees worry about:
  • Looking incompetent.
  • Being blamed.
  • Disciplinary action.
  • Embarrassment.
This delays incident response.
Instead, organisations should celebrate reporting.
An employee who reports a suspicious email—even if it turns out to be harmless—has demonstrated the exact behaviour leaders should encourage.
Reporting should be recognised as a positive contribution to organisational resilience.
Measure Behaviour, Not Attendance
If awareness programmes are to improve, organisations must rethink what they measure.
Useful indicators include:
  • Phishing reporting rates.
  • Time taken to report incidents.
  • AI usage awareness.
  • Employee confidence surveys.
  • Security culture assessments.
  • Participation in discussions.
  • Lessons learned from near misses.
  • Trends in security-related behaviours.
These metrics provide a far more accurate picture of organisational resilience than training completion rates alone.
Leadership Must Participate
Nothing undermines an awareness programme faster than leaders who fail to participate.
When executives ignore security policies or directors bypass governance processes, employees notice.
Leadership should:
  • Attend awareness sessions.
  • Follow the same security practices expected of staff.
  • Talk openly about cyber and AI risks.
  • Share lessons from incidents.
  • Celebrate good security behaviours.
Culture is built through visible leadership.
Security Awareness Is Really Organisational Awareness
The most resilient organisations understand that cybersecurity is not simply about technology.
It is about decision-making.
Communication.
Trust.
Leadership.
Behaviour.
And increasingly, it is about how people use artificial intelligence responsibly.
Technology can block many threats.
But it cannot replace informed judgement, ethical leadership, or a workforce that understands its role in protecting the organisation.
The question boards and executives should ask is no longer:
"Have our people completed cybersecurity training?"
It should be:
"Have we created a culture where our people think securely, act responsibly, and feel empowered to protect the organisation every day?"
That is the difference between compliance and resilience.
And in today's rapidly evolving digital landscape, resilience is what truly matters.

0 Comments
<<Previous

    Author

    Patrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate

    Patrick combines deep business experience, including an MBA with up-to-date cybersecurity expertise, including certification as a PECB ISO/IEC 27001 Lead Implementer. He helps businesses grow while staying secure—bridging the gap between cybersecurity and real-world operations with clear, human-centric solutions. Passionate about culture, clarity, and resilience, Patrick champions the belief that cybersecurity is everyone’s business—not just IT’s.

    Archives

    September 2026
    August 2026
    July 2026
    June 2026
    May 2026
    April 2026
    March 2026
    February 2026
    January 2026
    December 2025
    November 2025
    October 2025
    September 2025
    August 2025
    July 2025
    June 2025
    May 2025
    April 2025
    March 2025
    February 2025
    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    August 2024
    July 2024
    June 2024
    January 2024

    Categories

    All

    RSS Feed

Human-Centric Cyber Governance & AI Security for NZ Organisations

Picture
A Corna Consulting Company
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Boardroom Guide to Cyber & AI Governance
    • Board Cyber & AI Governance Self-Assessment
    • Cyberplanz Cyber Culture Dashboard
    • Cyberplanz Board Third-Party Cyber & Ai Risk Dashboard
  • About Us
  • Contact Us
  • Blogs