Quick answer: Cyberattack losses could hit $20 trillion a year, and cyber risk has moved from the server room to the boardroom. Why directors who still treat it as an IT problem now carry personal legal exposure.
Originally published on LinkedIn: 23 July 2026.
Cyber risk has stopped being a technical problem for the CIO and become a core fiduciary duty for the board. Global cyberattack losses are projected to approach $20 trillion annually, more than double the $8 trillion lost in 2022.
The end of the "IT problem" era
A single supply chain breach can now erase a third of a major retailer's annual profit. Cyber risk is a business risk and business opportunity, not a briefing item to be delegated to the basement.
Legacy systems are a ticking time bomb
Many organisations still run critical functions on legacy systems never designed to withstand modern adversaries. Boards routinely defer modernisation because the return is harder to quantify than a new product launch.
AI as weapon, vector and value
Attacks have already moved from AI-assisted to AI-generated and managed cyberattacks. A growth strategy built on AI, running on a security framework built on old assumptions, is growth built on sand.
From check-the-box to personal legal liability
SEC Item 106 now requires public companies to describe how the board supervises cyber risk. Delaware courts are expanding Caremark liability, signalling cybersecurity failures may constitute a "mission-critical" risk requiring heightened board attention.
The cyber expert fallacy
Relying on a lone cyber expert on the board is a dangerous single point of failure. Effective oversight demands foundational literacy across the whole board.
Directors now face decision points spanning M&A integrations, cloud architecture approvals and ransom payment escalation thresholds.
Tony Ridley, MSc, CSyP, FSyI, SRMCP, advises boards and executive teams on integrating cyber risk into enterprise governance, from director literacy and committee oversight structures through to defensible decision records and third-party risk frameworks. Contact him to strengthen your board's cyber governance before the next incident forces the conversation.