The new cybersecurity playbook
Cybersecurity has decisively moved out of the server room and into the boardroom. As attacks increasingly threaten operations, revenue, reputation and customer trust, organisations are being forced to rethink who owns cyber risk — and how resilience should be funded, measured and managed. Keyur Shah, Sophos “Cybersecurity has moved beyond the IT department. When an attack can stop operations,…
Cybersecurity has moved beyond being solely the responsibility of the IT department and has become a critical concern for the entire boardroom. As cyber attacks pose threats to operations, revenue, reputation, and customer trust, organizations are reevaluating how they manage cyber risk and allocate resources for resilience. Keyur Shah, Associate Field CISO at Sophos, emphasizes that cyber risk has become a business risk and a responsibility that falls on the boardroom.
He highlights the need for a "connected defense" strategy that integrates prevention, detection, threat intelligence, and response into a cohesive system.
Shah argues that simply deploying more tools is not enough; instead, the focus should be on the efficiency of the response process—seeing, deciding, containing, and recovering swiftly, as well as being prepared before an attack occurs. This shift in perspective affects how CISOs communicate with the boardroom about investment and accountability in cybersecurity measures.
Jan D’Herdt, a SANS Institute Certified Instructor, agrees that cyber risk is indeed business risk. He advises IT leaders to communicate technical concerns in plain business terms, avoiding jargon, to make a compelling case for budget allocation and to demystify the long-term risks posed by cyber threats to the board.
D’Herdt stresses that cybersecurity responsibility extends beyond the IT department, particularly as shadow IT expands the attack surface. Measuring success in cybersecurity should not revolve around technology investment but rather on a mindset where resilience becomes the norm, appearing unremarkable and boring. When incidents occur, a disciplined approach to decision-making becomes crucial.
D’Herdt advises focusing on understanding why an attack happened rather than getting stuck on how it happened, to prevent recurrence. Shah concludes by noting that in the age of artificial intelligence, speed of decision-making and coordinated response will be the defining factors in achieving cyber resilience.
Written by urgent.news from Gulf News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.