In September 2025, a cyberattack against a technology provider used by dozens of airlines to manage check-in and boarding disrupted Europe’s air travel operations. Airports in Brussels, London and Berlin had to abandon their digital systems and return to pen and paper, while dealing with the frustration of thousands of passengers and delayed flights.

Neither the airports nor the airlines had been the direct targets of the attack. The target was a shared provider whose vulnerability ultimately affected an entire network of organizations and people, triggering a crisis with operational and reputational consequences.

This example reveals how cyber risk has changed. Today, it can extend beyond an organization and become systemic, spreading rapidly through providers and supply chains. Digital transformation, the accelerated adoption of artificial intelligence (AI) and the dependence on third parties have expanded the reach and consequences of these risks. In this context, cybersecurity is no longer exclusively a technological issue; it has become a strategic and governance challenge.

According to Check Point Research’s Cyber Security Report 2026, organizations had an 18% increase in cyberattacks over the previous year. The World Economic Forum’s Global Cybersecurity Outlook 2026 revealed that “87% of respondents identified AI-related vulnerabilities as the fastest-growing cyber risk.” In addition, 65% of companies consider “third-party and supply chain vulnerabilities are their greatest challenge” in strengthening cybersecurity resilience.​

For this reason, managing cyber risks requires a cross-functional approach, integrated into strategy and overseen at the highest level. To achieve this, I would like to share five key recommendations.

 

1. Cybersecurity decisions belong at the strategic table:

The board must take an active role in overseeing cyber risk, incorporate it into strategic decisions and define the risk appetite that guides those decisions. In the face of more sophisticated threats and greater technological dependence, prevention must be at the heart of the business. However, organizations must also be aware that incidents can still occur and be prepared to respond and recover. To do so, formal oversight mechanisms should be established through a specialized committee, with clear accountability and periodic reporting.

Likewise, the board should require that every initiative involving the implementation of automation or the addition of new providers evaluate its cybersecurity implications from the outset. Investing in cybersecurity means investing in operational continuity, data protection and stakeholder trust.

 

2. The board oversees while management manages:

Cybersecurity requires shared responsibility, but with clearly differentiated roles. The board is responsible for overseeing cyber risk, while management—led by the CEO—must manage it, translating those definitions into resources and actions and integrating cybersecurity into strategy. The CISO, in turn, provides the technical expertise needed to protect critical assets and strengthen corporate resilience. Given the scope of these risks, their management must be coordinated across the different areas of the organization. The success of the model will depend on this.

To exercise effective oversight, the board needs clear, comparable information that is connected to the business. Reports should show trends, flag emerging risks and translate technical metrics into potential operational, financial and reputational impacts, allowing the board to assess how the risk is evolving and guide decisions in a timely manner.

 

3. Cybersecurity extends to third parties:

An organization may have strong controls but still be exposed because of its dependence on third parties. The board must identify which providers, platforms or services are critical to operations and what impact their disruption would have. This makes it possible to identify risks that may remain outside the organization but can nevertheless compromise its continuity and generate cascading effects. In addition, it should require third parties to have cybersecurity controls proportionate to the risk they represent to the organization.

 

4. Governing AI also means managing risk:

AI offers significant opportunities for productivity and innovation, as well as for strengthening cybersecurity. But it also expands exposure to cyber risks. For this reason, effective AI governance is essential, with policies, processes and controls that enable its responsible use in alignment with strategy. This means periodically reviewing potential risks, overseeing the effectiveness of controls, monitoring automated decisions and ensuring appropriate data management, both for the organization’s own data and third-party data.

For example, an AI agent that is capable of accessing emails and databases or performing tasks autonomously. If there are no clear controls over its permissions or accountability mechanisms, it can amplify existing risks or create unforeseen vulnerabilities. This creates new challenges. Governing AI does not mean slowing its adoption but rather ensuring that its use is consistent with strategy, risk appetite and regulations.

 

5. Resilience is the competitive advantage:

It is essential to be prepared for a cybersecurity incident and, for that reason, the question is not whether the company will be attacked, but how capable it is of responding and recovering. Preparing is more valuable than reacting, and that means the board should not only review preventive controls, but also require, oversee and update contingency plans to manage a potential crisis, ensuring operational continuity.

This also means participating in simulation exercises that test decision-making under pressure. Resilience is a collective effort that requires the entire organization to be aligned and prepared. It is not something that can simply be declared; it is the result of continuous preparation, and that is what makes the difference.

**

In an environment where cyber threats will continue to evolve and spread through increasingly interconnected ecosystems, the difference will lie in the ability to anticipate, respond and recover.

Cybersecurity must be viewed as a corporate governance challenge. Boards should make it a strategic priority to manage risks, protect their assets, strengthen stakeholder trust and create sustainable value over the long term.

Because resilience is not built during a crisis; it is built long before one occurs.​​

By Susana Sierra
Published in Forbes Business Council