Boards Need to Change the Question from “Are We Secure?” to “Are We Ready?”

What boards and governing bodies must focus on during Cybersecurity Awareness Month 2026 and beyond.

table of contents

Cybersecurity Awareness Month 2026 comes with a long-term challenge. CISA’s theme, “Securing the Next 250,” marks America’s 250th anniversary by asking how we secure the digital systems and critical infrastructure the next era will depend on. For boards, that challenge goes beyond awareness to whether the enterprise is actually built to withstand an attack.

Adversaries no longer need months to turn a newly found flaw into a working attack. AI now finds weaknesses, writes the exploit, and moves through a network faster than most security teams can open a ticket. In that world, “are we secure?” is a comforting question with no useful answer.

The better question for every boardroom is simpler and harder: when, not if, we are breached, how much of our business will keep running?

Attackers, human or humans with powerful machines, are opportunists. They go where the door is already open: a reused password, a vendor with standing access, a flat network where one compromised laptop reaches everything, an end-of-life server nobody owns.

Most boards have never decided how much damage is too much. Governance is where the effort to make attacks hard truly begins. And it depends upon the Architecture. You cannot govern what you have not architected.

That is where boards should focus.


See ColorTokens in Action: Containing an AI-Assisted Attack


Decide How Much Material Impact Is Acceptable

Every board sets a risk appetite for credit, markets, and safety. Few have done the same for a cyber event. Define, in money, days of downtime, regulatory exposure, and lost customers, the worst disruption the enterprise can absorb and remain viable. I call it the Maximum Acceptable Material Impact, or MAMI. You may call it something else. But write it down. Review it every year. Expect it to shrink as defenses mature.

Regulators have moved. Disclosure rules now require reporting material cyber incidents within days, and frameworks like NIS2 place accountability squarely on management bodies. “I was not briefed” is no longer a defense. A board that cannot state its acceptable material impact cannot judge whether its security program is working.

Grow the Part of the Business That Stays Unaffected

Traditional cyber resilience plans protect and restore the critical 15 to 20 percent of systems first. On the other hand, most CFOs and CEOs do not want to accept more than 10% loss in revenue. That leaves the enterprise staring at at least a 70% gap, with a recovery plan stapled on top.

Instead, ask for the smallest set of capabilities, processes, and assets that must stay unaffected during an attack, designed so a breach in one place cannot spread to the next. Then ask management to grow that percentage every year. I call it the Minimum Viable Digital Enterprise, or MVDE. You might call it something else. Write this down too. And direct the organization to align it to the MAMI. Resilience is not how fast you rebuild; it is how little you have to.

Treat Identity, Access, and Authority as Board-Level Risk

Most serious breaches involve a stolen or misused identity. Now add AI agents, service accounts, and partners, all holding keys to systems they rarely need. Every standing privilege is an invitation.

Boards should expect a clear answer to three questions. Who and what can access our critical systems? On what authority? And how quickly can we revoke it? Phishing-resistant authentication, no permanent administrator rights, and strictly bounded permissions for AI agents are no longer technical niceties. They are governance.

Access the eBook: Enable AI Without Expanding the Blast Radius

Fund Outcomes, Not Tools

Global security spending keeps rising, and so do successful attacks. With the advent of frontier AI models that continue to show the potential to autonomously find zero-day vulnerabilities and exploit them, patching them on time is becoming a massive challenge.

More products are not the answer. Direct funding toward three outcomes that measurably reduce material impact:

  • Reduce what attackers can reach by removing unnecessary connections and paths between systems.
  • Restrict access to outdated and unsupported technology or replace it before it becomes the easiest way in or the source of difficult-to-patch systems.
  • Recover by design, with rehearsed plans, isolated backups, and the ability to contain an attack in minutes.

Tie every budget request to one question: how much does this shrink our acceptable material impact, or grow the unaffected enterprise? That is language a finance committee understands.

Build Cyber Fluency Among Non-Technical Leaders

A crisis is a business decision under pressure: whether to shut a plant, pay nothing, call a regulator, or speak to customers. The CEO, general counsel, CFO, and communications make those directives, not the SOC or the CISO.

And most decisions are supported by information from non-technical leaders like the Head of Manufacturing or Sales or Legal, etc. In organizations where these leaders don’t understand how cybersecurity can drive business innovation, decisions are usually risk-averse, with the caveat that “you never know what the attacker can do.”

Directors and executives should rehearse breach scenarios at least annually, with AI-enabled deepfake and impersonation attacks on the script. Leaders who have practiced decide faster and better. Leaders who have not tend to freeze. Remember, ideally the organization must know how an attacker can exploit digital systems and not the attacker. If there is a technology debt, that is what needs immediate funding.

Watch: The Academician’s View of Being Breach Ready for a discussion on leadership, security drills, survivability, and preparing the enterprise before an attack occurs.

Own the Skills Gap, Not Just the Headcount

The global shortage of security professionals runs into the millions and will not close soon. Boards cannot hire their way out. They can insist on architecture that needs fewer people to defend, automation that contains threats at machine speed, trusted partners for specialist depth, and investment in upskilling the teams they already have.

The skills gap is also a security culture gap. Everyday habits across the whole workforce, such as verifying unusual requests, reporting suspicious messages, and using strong authentication, are the cheapest defense any enterprise owns. Boards set the tone that makes those habits normal. Only then can you do more with skilled cybersecurity professionals.

Five Questions for Your Next Board Meeting

  1. What is our maximum acceptable material impact, and when did we last validate it?
  2. What percentage of our digital enterprise is designed to remain unaffected during a breach, and is that number growing?
  3. Which identities, human and machine, employee or third party, hold standing access to our crown jewels, and how often are they reviewed?
  4. What technology debt needs funding to determine which unsupported systems are still running, and when will we replace them?
  5. When did this organization last present the improvements from findings of a major cyber incident rehearsal?

The Cybersecurity Awareness Month 2026 theme, “Securing the Next 250,” is a reminder that we are building digital enterprises that must endure for decades, not quarters. The organizations that thrive will not be the ones that were never attacked. They will be the ones that made their digital landscape difficult to breach, contained the inevitable, and kept serving customers while others went dark.

Build breach readiness. Plan to be unaffected. Begin by assessing your Breach Impact.

If you want to understand how much of your enterprise can remain unaffected during an attack, contact us.