Why cybersecurity is now a boardroom topic

Technology · 2026-07-10 · 9 min read

By Arjun Mehta, Engineering & product

Boards started asking about security when it stopped being downtime and started being disclosure, liability and lost revenue.

An outage used to be an engineering embarrassment. A ransomware event is a business continuity failure with a regulator attached: disclosure timelines, customer notification, insurance conditions and, increasingly, personal accountability for named officers.

The threat model moved too. Most serious incidents no longer begin with an exotic exploit; they begin with a valid credential belonging to a real employee or a contractor whose access was never revoked. Identity, not the network perimeter, is the boundary that matters.

Vendors are the soft edge. Your security posture is the union of every supplier holding your data, and the smallest one with the weakest login is the one that gets used. Ask for their incident history, not their certification badge.

A board does not need a threat briefing. It needs four numbers reviewed quarterly: percentage of accounts on phishing-resistant multi-factor authentication, median time to patch a critical vulnerability, the date backups were last restored in a test, and the count of third parties with production access.

The unglamorous truth is that the controls preventing most losses have been the same for a decade. What changed is that the cost of skipping them is now visible on the income statement, which is exactly why the conversation moved upstairs.

Tags: security, enterprise, risk

Arjun Mehta — Arjun writes about web performance, developer tooling and applied AI for ESPYCRUX. He has spent the last decade building and maintaining production web apps, and most of his articles start from something that broke in one of them.