Cybersecurity for the C-Suite and Shareholders: Cyber Risk Is Business Risk

By Chuck Brooks, Skytop Contributor & Host of “Intelligence Briefing”, SkytopTV Talk Show Series / August 26, 2026

As President of Brooks Consulting International, he is a leading voice on how AI, quantum, 5G, IoT, and blockchain are reshaping organizational risk, critical infrastructure protection, and national‑security posture.

A two‑time Presidential Appointee, Brooks served as the founding Director of Legislative Affairs at the DHS Science & Technology Directorate and previously advised Senator Arlen Specter on technology and security issues. He has briefed the G20, the Vatican, USTRANSCOM, the FBI, the National Academies, and DHS CISA on global cybersecurity challenges.

Brooks has held senior roles at General Dynamics, Xerox, Rapiscan, SRA International, and Sutherland, driving strategy, government relations, and technology commercialization. He has advised the Bill & Melinda Gates Foundation and serves on multiple boards focused on cybersecurity and digital innovation.

A prolific author with 450+ publications—including contributions to Skytop Media, Forbes, Dark Reading, The Hill, and Homeland Security Today—he writes on emerging threats, AI‑driven risks, quantum disruption, and digital resilience. He is the author of Inside Cyber: How AI, 5G, IoT, and Quantum Computing Will Transform Privacy and Our Security (Wiley).

He is an Adjunct Professor in Georgetown University’s Cyber Risk Management and Applied Intelligence programs, teaching cybersecurity, quantum, blockchain, and disruptive technologies. Georgetown recently honored him with the Tropaia Outstanding Faculty Award.

He holds an MA in International Relations from the University of Chicago, a BA in Political Science from DePauw University, and a Certificate in International Law from The Hague Academy.‍ ‍


For many years, cybersecurity was primarily considered an IT issue. While the CEO, CFO, general counsel, and board concentrated on strategy, operations, sales, and shareholder value, the chief information security officer was concerned with firewalls, malware, vulnerabilities, and updates.

It is no longer possible to maintain that division. Business continuity, enterprise risk management, and corporate governance now all heavily rely on cybersecurity. A hack can disrupt business operations, jeopardize intellectual property, reveal consumer data, draw regulatory attention, harm a company's brand, and reduce shareholder value. A cyber incident may occasionally jeopardize the company's capacity to survive.

As a result, the boardroom must adopt a new perspective on cybersecurity. "Are we resilient enough to continue operating, preserve trust and protect shareholder value when—not if—we are attacked?" should be the main question instead of just "Are we secure?"

As the digital environment is transformed by artificial intelligence, cloud computing, the Internet of Things, 5G, connected infrastructure, and quantum computing, this distinction becomes more crucial. The physical and digital worlds are now intricately linked, as I argued in my book Inside Cyber: How AI, 5G, IoT, and Quantum Computing Will Transform Privacy and Our Security. Since technology today permeates almost every facet of company, cybersecurity and business strategy are inextricably linked.

The Boardroom Should Include Cybersecurity

Computer protection is no longer the only aspect of cybersecurity. It is about safeguarding the business. In addition to financial, operational, legal, geopolitical, and reputational risks, cyber risk is becoming a part of boards' fiduciary duties to stakeholders and shareholders. For years, I have maintained that businesses cannot offshore accountability just because they outsource a portion of their cybersecurity operations.

Part of an organization's security infrastructure may be run by a third-party managed security provider, cloud provider, or technology vendor, but the CEO and board are still in charge of recognizing the risks.

This is especially crucial for publicly traded corporations. Investors, authorities, and the general public are now more aware of cyber incidents because to cybersecurity disclosures. The idea that substantial cyber risk is information pertinent to shareholders and not just an internal IT issue has been strengthened by the SEC's cybersecurity disclosure regulations. This means that discussions about cybersecurity should go beyond technical metrics for directors. Boards ought to inquire:

Which digital assets are the most crucial? Which business operations cannot afford to be offline? How soon could we identify and stop a significant intrusion? To what extent do we rely on other people? What would happen if an AI system was controlled or compromised? How much of our private data would be safe if quantum computing were to someday crack today's encryption? These are business-related inquiries.

The First Line of Protection: Cyber Hygiene

It is easy to think that another advanced technological platform is the solution to cybersecurity in an increasingly complex threat environment. Despite the importance of technology, many successful cyberattacks still take advantage of fundamental flaws. weak passwords. systems without patches. excessive rights. Identity management is inadequate. Phishing. cloud environments that are not properly designed. unprotected endpoints. backups with inadequate security. workers who click on dangerous links.

These vulnerabilities are not unique. They are examples of poor cyber hygiene. Because even the most sophisticated cybersecurity architecture can be compromised by fundamental security flaws, cyber hygiene is the cornerstone of digital resilience. That foundation has grown even more crucial in the AI era.

Cyber hygiene should be seen by the C-suite as an ongoing organizational discipline, much like physical safety in other businesses. This entails upholding robust identity and access management, multifactor authentication, prompt patching, endpoint security, secure configurations, employee education, phishing awareness, tested backups, vulnerability management, and incident response protocols.

It also entails knowing who has access to the most important data for the business and why. The organization as a whole should practice cyber hygiene. A compromised account, an unmanaged device, or the weakest credential can serve as a gateway to a much larger company. It also goes beyond the company itself more and more.

Your Attack Surface Includes the Supply Chain

Seldom do modern firms run on their own. They rely on a wide range of third parties, including cloud providers, software suppliers, shipping firms, managed service providers, contractors, manufacturers, payment processors, consultants, and many more.

Although this interconnection generates significant economic benefit, it also increases the risk of systemic cyberattacks. Even with strong internal security, a corporation could still be penetrated by a weak supplier. When we consider dependencies between fourth, fifth, and nth parties, the cybersecurity problem becomes even more complex. A business might be aware of its main supplier, but it might not have much insight into the suppliers that help that supplier. One of the key cybersecurity issues facing the digital economy is this.

AI is simultaneously increasing supply-chain efficiency and raising the potential repercussions of breach, according to a recent report I published on supply-chain cybersecurity. Because manipulating AI-enabled logistics, manufacturing, software, and vendor-management systems can impact operations on a scale, they may become appealing targets.

Thus, supply-chain security must be a permanent governance concern for boards. It is important for organizations to be aware of which third parties have access to privileged systems, sensitive data, or essential operational functions. They should be aware of software dependencies, assess vendor risk, demand suitable security controls from suppliers, and have backup plans in case a vital source is compromised. The concern is whether the ecosystem that your business depends on is sufficiently safe, not just whether your business is secure.

AI: The New Force Multiplier for Cybersecurity

One of our generation's biggest opportunities—as well as one of the biggest cybersecurity challenges—is artificial intelligence. Cybersecurity can be significantly enhanced by AI. AI can be used by security teams for threat hunting, anomaly detection, behavioral analytics, malware analysis, vulnerability discovery, identity protection, automated monitoring, and incident response. AI can assist security teams prioritize threats by analyzing massive amounts of data considerably more quickly than human analysts.

This can be revolutionary for companies dealing with growing attack surfaces and a lack of cybersecurity personnel. However, AI is also turning into a multiplier of attacking power. AI can be used by criminals and nation-state actors to automate reconnaissance, produce convincing phishing messages, make deepfakes, find holes, alter malware, and speed up attacks. Because autonomous systems may be able to perform multi-step tasks with significantly less human interaction, agentic AI raises the stakes even more.

As a result, the cyber arms race is getting faster. The conventional belief was that a sophisticated campaign required a great deal of time and expertise on the part of the attacker. AI lowers both obstacles. Because of this, cybersecurity tactics must stop being only reactive and start being proactive. The pace of AI-enabled attacks renders conventional methods more insufficient. Organizations require resilience incorporated into the architecture, automated defenses, predictive analytics, and ongoing monitoring.

However, AI itself needs to be regulated. Boards should be aware of the applications of AI, the data it accesses, the decisions it affects, and the consequences of manipulating its output. Appropriate human oversight, access controls, data governance, model security, testing, and monitoring should all be part of AI security. The idea should be straightforward: Intelligence should never be used without responsibility.

The issue of deep fakes is also a business issue.

Another new issue facing business executives as a result of AI is the deterioration of trust. Synthetic media and deepfakes can mimic more realistically mimic identities, voices, and faces. The political and national security contexts will undoubtedly be affected, but the corporate ramifications could be just as dire.

Imagine the CEO authorizing a multimillion-dollar transfer through what looks to be a video conversation with the CFO. Let's say an employee gets a voicemail that seems to be from the general counsel of the organization. Let's say an executive gives a supplier a seemingly legitimate order to change payment details. Protecting networks is only one aspect of cybersecurity; another is figuring out whether the person or machine on the other end of a transaction is legitimate.

As a result, identity-centric security, continuous authentication, multifactor authentication, behavioral analytics, and verification processes are all becoming more crucial. The cybersecurity perimeter now includes trust itself.

Q-Day Is a Boardroom Problem

Boards shouldn't wait until quantum computers are strong enough to crack current encryption to address another issue. Q-Day is that threat. The term "Q-Day" describes the moment when widely used public-key encryption systems, such as those based on RSA and elliptic-curve cryptography, could be compromised by sufficiently powerful quantum computers. Q-Day's precise date is still unknown. However, it's important to distinguish between ambiguity about the timing and confusion about the necessity of preparation.

From a theoretical idea, quantum computing has developed into increasingly complex commercial and governmental systems. Adversaries, on the other hand, are motivated to gather encrypted data now that might be decrypted later—a tactic known as "harvest now, decrypt later." For information whose value endures for years or decades, this poses a more severe issue. Intellectual property, trade secrets, strategic plans, information related to mergers and acquisitions, sensitive customer records, government data, healthcare data, and national security data should all be considered.

The damage might still be substantial if that data is stolen now and decoded years later. Panic is not the proper reaction. It's getting ready. Businesses should start figuring out where cryptography is used, whose data needs to be kept secret for a long time, inventory cryptographic assets, evaluate dependencies, and create a plan for moving to post-quantum cryptography.

Crypto agility, or the capacity to modify cryptographic methods without completely rebuilding the technological environment, becomes crucial in this situation. It is not necessary for boards to become quantum scientists. However, they must inquire with management as to whether the business has a solid quantum-readiness plan.

Cybersecurity should be viewed as an investment issue by shareholders.

A significant cyber event can have far-reaching financial repercussions that go far beyond the initial expense of system restoration. Revenue loss, fines from regulations, lawsuits, client attrition, higher insurance premiums, intellectual property losses, business disruption, and long-term brand harm are all possible outcomes.

Uncertainty might also be penalized by the market. Investors want to know if management is aware of the company's risks and if it has a solid plan in place to manage those risks. For this reason, rather than being handled as a separate technology budget, cybersecurity should be integrated into enterprise risk management.

The essential issue is not: How much are we spending on cybersecurity? Instead, the board should comprehend cybersecurity investments in terms of risk reduction, resilience, and business enablement. It is: How much risk are we taking , and is that amount in line with our fiduciary duties and commercial goals?

Cybersecurity to Cyber Resilience

The realization that prevention is not enough is one of the most significant shifts in cybersecurity thought. Vulnerabilities will eventually be discovered by attackers. Resilience must therefore be the goal.

A resilience-centric framework based on predicting dangers, tolerating disruption, recovering quickly, and upholding stakeholder confidence must replace the prevention-centric strategy.

An organization that is resilient anticipates disruptions and makes appropriate preparations. It is aware of its vital systems. It is capable of redundant functions. It keeps safe and verified backups. It is aware of who makes decisions in a crisis and has an incident-response plan. It has practiced communicating with staff, clients, investors, regulators, and the media. It also knows how quickly vital business operations can be resumed. The ability of an organization to carry on after defenses are breached should be used to assess cyber resilience rather than just the quantity of attacks that are thwarted.

What the Board and C-Suite Should Do Right Now

Leadership is needed in the new cybersecurity landscape, not just technology. The board and C-suite should include cybersecurity in the organization's strategic dialog. They ought to guaranty that the CISO has significant access to the board and senior leadership. Business-continuity planning and enterprise risk management should incorporate cyber risk. They ought to demand significant supply-chain and third-party risk visibility.

Clear governance for AI, including security, privacy, data protection, and human monitoring, should also be established. And instead of waiting for Q-Day to make headlines, they ought to start getting ready for the quantum shift right away.

Above all, executives should foster a culture where everyone is accountable for cybersecurity. In the end, cybersecurity is a process, people, and technology issue. Inadequate leadership cannot be made up for by a firewall. Human mistake cannot be completely eliminated by any AI platform. Resilience cannot be guaranteed by any compliance certification.

Corporate Security: A New Definition

We are approaching a time where corporate resilience will be determined more and more by digital resilience. AI will alter how businesses function. The core presumptions of modern cryptography will be altered by quantum computing. Connected gadgets will keep increasing the attack surface. Digital integration will increase in supply chains. Additionally, the speed, automation, and difficulty of differentiating cyberattack from legal operations will all increase.

Organizations that recognize cybersecurity as an essential part of strategy, governance, innovation, and trust will be the ones that thrive, not necessarily those that spend the most on it. This entails considering cybersecurity as a fiduciary and governance responsibility for boards and making cyber risk a business conversation for the C-suite. It entails assessing whether management possesses the resilience required to safeguard enterprise value for shareholders. It also entails realizing that maintaining good cyber hygiene is more than just a technological task. It serves as the cornerstone for the development of digital trust.

As I have stressed throughout my book Inside Cyber, technological innovation brings exceptional potential, but every new capability also generates new vulnerabilities. This lesson is still very true today.

Stopping innovation is not the aim. It is to develop resilience ahead of time, manage risk wisely, and innovate securely. There could not yet be a date set for Q-Day. The next big cyberattack doesn't either. For this reason, leadership needs to start preparing for both. IT expenses no longer include cybersecurity. It is an investment in the company's long-term viability, resiliency, and worth.

Next
Next

ISA: Announces CISO Based, Cross Sector Study on AI in Critical Infrastructure