This reality puts regulation and leadership at the heart of the discussion, as responsibility for decisions and risks is increasingly shifting towards management. Having policies and controls in place is no longer enough: organisations must be able to demonstrate who makes decisions and how risks are monitored and managed.
The need for clarity also extends to identity and access management. The challenge is no longer limited to controlling employee access, but also includes suppliers, service accounts, application programming interfaces (APIs) and AI agents. Every access should have a clearly defined owner, purpose and timeframe.
At the same time, growing reliance on third parties requires a deeper approach to risk. The entity posing the greatest risk is not necessarily the largest, but the one whose failure could disrupt a critical service. Understanding these dependencies and anticipating the impact of a failure has become an essential part of risk management.
Security must also be embedded from the outset. This approach is particularly important when it comes to data security: organisations need to know where sensitive information actually resides and ensure that its protection follows the data wherever it is used.
When assessing and validating exposure, organisations must also move beyond traditional approaches. Rather than simply identifying individual vulnerabilities, it is essential to understand the routes an attacker could exploit and determine where the organisation is genuinely exposed. In security operations, the growing use of AI adds another dimension to this challenge: how much autonomy are we prepared to give our own defences, and where should human oversight remain?
All these questions converge on a common goal: cyber resilience. Rather than trying to prevent every incident, organisations must be able to recover from an attack, protect backup systems, rebuild critical systems and continue to meet their commitments to customers, partners and regulators.