The Blogging Edge · Digital & AI
Cyber-safe and Digitally Mature
Board Governance, Cyber Security & Business Continuity
What if your CEO’s browsing history (including visits to adult content websites) leaked during a board meeting? What if your daughter called you, sobbing for help, and only later did you realise it wasn’t her but a deepfake designed to manipulate you?
If that sounds far-fetched, you haven’t been paying attention. The real world is catching up with our darkest imaginations, and unfortunately, most companies are playing defence without a playbook.
When the Hackers Came for Us
During my time at a large multinational consumer goods company, we faced a direct hit. Hackers locked us out of our external database and demanded a ransom for access. Quickly, we realised this wasn’t just about files. It became an uncomfortable conversation with our partners and a significant operational disruption.
We had underestimated the risk. Suddenly, we had to evaluate:
a) the true value of our data,
b) how deeply business continuity would be impacted,
c) the reputational risk with partners, and d) our lack of a contingency plan.
Out of every crisis comes an opportunity. For us, it fast-tracked our digital maturity and forced a long-overdue expansion of digital governance beyond IT. In hindsight, we were lucky for the wake-up call.
Could This Happen to You?
Years have passed. AI and digital adoption have exploded. The nightmare scenarios aren’t just possible; they’re probable. Boards today must act like guardians and secret agents; ready for any threat.
Here are some disturbingly plausible scenarios. Some are fictional, others allegedly real:
The Porn-Stained Presidency
A global leader’s private browser history leaks: unfiltered, unredacted, humiliating. Niche adult content, hate forums, shadowy interactions. Trade deals collapse, alliances unravel, trust vanishes overnight.
Lesson: Digital governance must protect even the most unexpected weaknesses. Reputation is your most valuable asset.
The Deepfake Daughter Hostage
Your NED receives a video of their son injured in a car crash. Your CEO gets a call from their daughter begging for help. Voices shake. Eyes plead. "Please, send the money." They’re fine. The video is synthetic.
Lesson: Hackers no longer target systems. They target hearts.
Real-Life Abduction Meets Data Ransom
A senior exec is kidnapped after fitness app data reveals daily routines. The ransom? Internal IP and customer data.
Lesson: Leaked data doesn't just float in the cloud. It manifests in the real world.
The Dead Employee Who Sends Emails
Weeks after an executive passes away, their email account starts issuing instructions, releasing confidential data, firing staff. A calculated deepfake campaign.
Lesson: Protect digital identities, especially posthumously.
The Total Blackout
Silence. No internet. No emails. No servers. No phones. Backup systems sabotaged. Your entire business, offline.
Lesson: If your crisis plan assumes power and signal, it's already outdated.
The Whisper Network Leak
A document of internal complaints leaks. Misconduct, bias, affairs. Some true, some AI-generated. The reputational damage is immediate.
Lesson: In an AI-driven world, perception outpaces evidence.
Customer Data for Sale
Hackers steal CRM data: purchases, complaints, private details. They threaten exposure. "Shall we show your clients what you know about their insecurities?"
Lesson: Data is a critical asset. Privacy is now your brand equity.
The Internal Breach
HR systems are breached. Staff addresses, salaries, corporate card usage extracted. Phishing scams follow. Then, a leak reveals a senior exec’s extravagant expenses.
Lesson: Employee data is a corporate asset. Protect it accordingly.
Where Do the Hackers Come From?
Hackers see systems, countries, and people as open doors. Digital preparedness is a business issue, and also a national security concern.
Do you know where your apps are developed? Where your data flows? Are your teams and their families digitally literate enough to stay secure?
Major sources of cybercrime include:
- Russia: Ransomware and infrastructure attacks (REvil, Sandworm)
- China: IP theft and corporate espionage (APT41, Hafnium)
- North Korea: Cybercrime for funding (Lazarus)
- Iran: Retaliation and sabotage
- Eastern Europe: Non-state actors providing RaaS and phishing kits
Attackers are invisible but methodical. When you’re targeted, ignorance won’t save you, and it won’t protect you legally.
Can You Even Pay the Ransom?
In many countries, the answer is no.
- In the US, payments to sanctioned cybercriminals can violate OFAC.
- In the UK, ransom payments may breach the Proceeds of Crime Act.
- Australia and parts of the EU are tightening laws to restrict or ban such payments.
The decision often rests with the Board. It falls under fiduciary duty, and it requires clear governance.
Do You Actually Have a Backup Plan?
Two types of backups are essential:
- Data Backups: Offline, immutable, tested. Ironically, printing out critical ledgers may feel safer than a digital-only plan.
- Infrastructure Resilience: Can your business function without the cloud? Can your Board communicate in a blackout? Hope is not a strategy.
Governance Is the New Cybersecurity
This is no longer a tech issue. It’s leadership.
Effective governance includes:
- Ownership of cyber risk at Board level
- Crisis simulations grounded in political and psychological warfare
- AI detection monitored by trained humans
- Board training on how to operate under digital siege
Cyberattacks don’t just steal data. They weaponise it against you: your employees, your customers, your country. They destroy reputations and trust in hours.
My Conclusion: Digital Maturity Is Inevitable
As my own experience shows, digital maturity is not optional. The question is whether your organisation can evolve fast enough.
The endgame of digital transformation is a truly customer-centric business. Budgets shouldn’t be split by function, but driven by outcomes. Organisations must evolve structurally to ensure security across both digital and physical environments. For example, traditional companies operating with yearly budget cycles per department, will most likely deal with cyber security as a budget discussion between IT and Marketing or Sales. Don't do that please anymore.
Digital maturity isn’t a differentiator. It’s the cost of survival. With AI evolving faster than governance structures, it is vital that organisational development accelerates alongside. Cyber risk belongs in the Boardroom, under Risk & Audit.
Because in a world this volatile, the companies that will survive aren’t the ones with the best firewalls. They’re the ones who can see the fire before it starts.
Final note: The urge to write this blog came after attending my sixth (!) event on cybersecurity readiness for Boards. This one, refreshingly, was dominated by women board directors and hosted by Ashurst. After the event, we were treated to a private tour of St Paul’s Cathedral—a building rich with symbols, hidden knowledge, and reverence. I’m deeply grateful to have experienced that. I took the picture of the famous staircase, and I am enchanted that is looks like an eye. Talking about privacy in a place full of eyes.
If you enjoyed reading this, check out another of my pieces with information on useful cyber security frameworks