Cyber Risk Is in the Boardroom. Are Boards Ready to Govern It? – By Sanchay Joshi

Cyber Risk Is in the Boardroom. Are Boards Ready to Govern It? – By Sanchay Joshi

Cybersecurity is now firmly in the boardroom, but board attention alone does not equal effective oversight. This article traces how cyber risk evolved from an IT operational concern into a strategic governance issue shaped by major breaches, ransomware disruption, disclosure obligations, resilience expectations, AI-related risks, and growing legal accountability. The central problem is that many boards now receive cyber updates, but those updates often remain too technical, too compliance-focused, or too disconnected from business impact to support real oversight.

The article proposes four practical shifts for boards and executive teams. Boards need stronger cyber-risk capability so directors can challenge management without becoming technical specialists. Oversight must move from prevention alone to resilience, with tested incident response and business continuity plans. Board and management responsibilities must be clearly defined so cyber risk does not fall between committees, executives, and technical teams. Finally, cyber reporting must be aligned with board decision-making by translating technical risk into business consequences, financial exposure, investment priorities, disclosure obligations, and long-term enterprise value. The article argues that organisations that govern cyber risk well will be better positioned to withstand disruption, protect trust, and turn secure digital capability into competitive advantage.

Sanchay Joshi is a techno-legal cybersecurity and privacy risk advisor with over eight years of experience across Deloitte U.S. Offices in India, KPMG India, and PwC India. He is currently pursuing a Master of Cyber Security, specialising in Cyber Defence, at The University of Queensland, Australia.