For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge.
Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organisations continue to suffer major cyber incidents with alarming regularity. Every week seems to bring news of another ransomware attack, supply chain compromise or data breach affecting organisations that many would have assumed were well protected.
The obvious conclusion is that we are asking the wrong questions.
Too many executive teams remain preoccupied with the latest threat actor, the newest security product the CISO wants to buy or the latest vulnerability making headlines. Those issues matter, but they are not what should be keeping CEOs awake at night.
In my view, there are three far more fundamental issues that deserve the attention of every chief executive.
-
Corporate complexity, and the widening gap between business leadership and cybersecurity reality
Perhaps the biggest cybersecurity risk facing large organisations today is not technical at all.
It is the growing disconnect between executive perception and operational reality.
Many boards genuinely believe their organisations are reasonably well protected. They receive regular dashboards showing improving maturity scores, increasing compliance levels, falling vulnerability counts and reassuring traffic-light reports.
Unfortunately, cyber attackers do not read dashboards.
Behind those executive reports often lies an increasingly complex technology landscape, thousands of unmanaged digital assets, ageing infrastructure, rampant shadow IT, fragmented ownership, inconsistent governance and security teams struggling to keep pace with relentless business change.
The problem is rarely a lack of effort.
It is that corporate complexity has reached a level where traditional governance mechanisms are no longer capable of providing an accurate picture of organisational resilience.
Executives believe they understand the level of cyber risk they face because they receive regular reports. In reality, those reports often measure activity rather than resilience.
Governance committees end up debating around another percentage point of phishing awareness or vulnerability remediation, while fundamental issues remain unaddressed in the background.
-
Organisational inertia, and the need for executive structure to evolve faster
Cyber criminals continue to evolve rapidly. Large organisations generally do not.
This is the second issue that should concern every CEO.
Throughout my career, I have observed organisations repeatedly responding to new cyber threats by adding another technology platform, another monitoring capability, another compliance framework or another governance committee.
Very rarely do they stop to redesign how cybersecurity actually operates.
The result is what I described several years ago as the “Cybersecurity Spiral of Failure”.
- As complexity and regulation increase, organisations invest in more security products.
- More products create more complexity.
- More products and greater complexity generate more alerts.
- More alerts require more analysts.
- More analysts produce more reports.
- More reports continue to build up executive confidence.
- Meanwhile, the underlying structural weaknesses remain largely unchanged, technical debt piles up and costs escalate.
And when the inevitable breach eventually happens, reality reveals itself but distrust also sets in between senior executives and security teams.
This is not a funding problem. Nor is it a skills problem. It is fundamentally an operating model problem.
Many organisations continue trying to solve twenty-first century challenges using governance, accountability, organisational and reporting structures designed twenty-five years ago.
The cybersecurity function itself has evolved dramatically. Many executive structures have not.
This organisational inertia extends beyond technology: It affects budgeting cycles, investment priorities, procurement processes, accountability models and decision-making speed.
Cyber attackers innovate every day. Organisational change often takes years.
That imbalance should worry every CEO.
-
Accelerating technological disruption, and how it challenges organisations in areas where they are intrinsically weak
The third issue is potentially the most significant over the coming decade.
- Artificial intelligence, autonomous agents and machine identities
- Software supply chain complexity.
- Quantum computing, and post-quantum cryptography
Each of these developments represents far more than another technical trend.
Together, they fundamentally change the dynamics of cybersecurity.
Artificial intelligence is transforming countless business processes. At the same time, it is also increasing both the speed and sophistication of cyber-attacks while simultaneously transforming defensive capabilities.
Organisations have become increasingly dependent on software ecosystems that extend far beyond their own direct control. Engaging with the supply chain in ways that lead to a genuine appreciation of the risks involved has become a key challenge for most cybersecurity practices.
Quantum computing may eventually invalidate much of today’s cryptographic algorithms, forcing organisations into one of the largest technology effort since Y2K—but without the benefit of a fixed deadline and faced by a problem that is considerably more complex and hyperconnected IT estates that have little to do with those of the late 90s.
None of these challenges can be solved overnight: They require clear governance, sustained investment over a number of years and cross-functional organisational coordination.
Most large organisations are weak on those three fronts: This is precisely why CEOs should be focusing on them now.
Waiting until some of those risks become obvious will almost certainly be too late.
Businesses naturally prioritise immediate commercial pressures. Cybersecurity often involves preparing for risks whose timing remains uncertain.
But one of the greatest leadership failures I keep seeing remains the inability of organisations to act decisively on known unknowns.
That tension explains why many organisations delay action until external events force them to respond. Unfortunately, cybersecurity rarely rewards late action.
Leadership will determine who succeeds
Cybersecurity discussions still frequently focus on technology. I believe they should focus far more on leadership.
Technology will continue evolving. Threat actors will continue adapting. Regulations will continue expanding. Those developments are inevitable.
What remains within the control of every CEO is how their organisation responds.
Does cybersecurity remain an IT issue? Or is it recognised as an integral part of business resilience?
How is cybersecurity accountability assigned at executive level? Or does it still rest largely with a CISO hidden in the organisation?
Does the board spend sufficient time discussing resilience? Or does cybersecurity appear only when approving budgets or reviewing incidents?
These questions will increasingly determine organisational success.
The companies that navigate the next decade successfully will not necessarily be those spending the most on cybersecurity. Nor will they be those deploying the latest security technologies first.
They will be the organisations whose leadership recognises that cybersecurity has become a permanent business capability—embedded into governance, strategy, operational decision-making and organisational culture.
That transformation cannot be delegated. It begins with the CEO.
And perhaps that is the single biggest issue that should keep every chief executive awake at night: Not when the next cyber-attack will happen, but whether their organisation is evolving quickly enough on those matters to meet a threat landscape that is changing much faster than the business itself.
JC Gaillard
Founder & CEO
Corix Partners
Contact Corix Partners to find out more about developing a successful Cyber Security Practice for your business.
Corix Partners is a Boutique Management Consultancy Firm and Thought-Leadership Platform, focused on assisting CIOs and other C-level executives in resolving Cyber Security Strategy, Organisation & Governance challenges.
An edited version of this article was published on CIOonline on 24th July 2026 and can be found here.
