Digital security as a governance issue
Most cyber incidents do not begin with a sophisticated attack. They start with a simple phishing email and a human error. The consequences, however, can be significant: financial fraud, operational disruption, data breaches, reputational damage and statutory notification obligations.
Shadow AI, meaning the use of unauthorised AI applications outside the organisation’s oversight, also creates tangible security risks. These may include the sharing of confidential information with AI providers and their subcontractors, uncontrolled access to data, and dependence on unknown or insecure suppliers.
While shadow AI can never be eliminated entirely, it is often a symptom of policies that are unclear or impractical to implement. Boards should ensure that policies not only provide protection but are also workable in practice and encourage compliance. Ideally, this is achieved not through punishment, but by making the secure option the easiest option.
Where an incident reveals that known risks were ignored, recommendations were not followed up, or digital security was never discussed at board level, questions regarding directors’ liability may quickly arise.