August 24, 2026

Cyber Resilience: A Board Responsibility Redefined

How are Artificial Intelligence and the Next Cryptographic Shift Redefining the Board's Mandate?

In boardrooms today, two common conversations exist side by side, but are regularly treated separately from each other. One is about artificial intelligence (AI): how quickly a company is adopting it and where AI will create value. The other is about cyber risk: how exposed the company is and how much an incident cost. In fact, these are part of the same conversation, and the market is already valuing that difference. The UK Treasury has measured this directly: more cyber resilient organizations recover more shareholder value after a serious disruption and grow faster afterward than less prepared companies.1

The forces now reshaping cyber risk, machine-speed AI, and an approaching cryptographic shift, do not affect every organization equally. They act as a market filter, separating companies that treat resilience as a strategic capability from those that treat it as a cost to deal with later. Below, we explain why this filter is closing faster than most boards assume, and why delaying the incorporation of AI risk considerations is itself a competitive decision.

Why Do Sophisticated Attacks No Longer Require Rare Skills?

For decades, cyber defense assumed a rough balance of effort: A sophisticated attack required highly developed, and therefore rare, human skills. That assumption no longer holds. AI is industrializing the most labor-intensive stages of a cyberattack, from reconnaissance and vulnerability discovery to social engineering. This allows a single operator to run campaigns that once required a full team. In 2026, IBM recorded a 44% year-on-year rise in attacks that begin by exploiting a public-facing application, driven by AI-accelerated vulnerability discovery.2 More than eight in 10 phishing emails now show signs of AI use.

Until recently, the strongest evidence for the use of AI in cyberattacks came from controlled academic research. In April 2026, as widely reported, a major AI company revealed that one of its models had independently discovered thousands of previously unknown vulnerabilities in operating systems, browsers, and open-source projects, including a flaw that had gone unnoticed for almost three decades.3 Three decades of undetected exposure is not just a line item: That flaw sat on the balance sheet the entire time, unseen and unpriced. What matters even more: over 99% of the vulnerabilities identified remain unpatched, largely because those responsible for maintenance have not caught up.4

Finding vulnerabilities is no longer the bottleneck; validating, prioritizing, and fixing them at the same speed is. The gap between a vulnerability being identified and used at scale, once measured in months, is now close to zero.

Can a Human Defender Keep Up With an Attacker Who Moves in Seconds?

Most incident-response protocols still assume a human face on both sides: an intruder who takes days to move through a network, a defender with time to detect and respond. Autonomous systems break that balance. Security professionals now rank agentic and autonomous AI as the top attack vector, ahead of deepfakes. According to several vendor studies, autonomous agents are already involved in roughly one in eight AI-related breaches, a share growing at close to 90% a year.5

In tests published this year, a frontier model completed a simulated 32-step corporate attack chain in three out of 10 attempts, something no model had achieved before.6 A defense built around a person reading an alert and deciding how to respond will not work against an attacker that moves in seconds. However, there is a real counterpoint: organizations that have adopted AI-powered detection have reduced the average time needed to contain a breach to its lowest level in almost a decade. Speed works both ways, but only for organizations that have already built that capability.

Is the Company's Own AI an Asset or a Liability?

The third shift is the easiest to miss. Every model built in-house, every foundation model licensed, every AI feature added to a SaaS product, or every autonomous agent deployed is both a source of value and a new way in for attackers. Each one carries identities, permissions, and access that traditional security models were not built to manage.

Governance has not kept pace with adoption. According to IBM’s Cost of a Data Breach Report 2025, nearly two-thirds of organizations have no policy on AI use, or do not apply one consistently.7 Shadow AI employees using unauthorized tools outside official control, adds an average of USD 670,000 to the cost of a breach. 13% of organizations have already reported a breach linked to AI, and 97% of those cases had no proper access controls.8 This also introduces attack techniques with no equivalent in traditional model. This could include hiding malicious instructions in documents that an agent is asked to process or corrupting a model's training data. The same pattern repeats across all three shifts: AI is being adopted before governance is developed to control it.

What if the Damage Has Already Happened Before It Becomes Known?

The first three shifts share something rarely said out loud: The damage is often done long before it becomes visible. An attacker can exploit a vulnerability long before a patch exists. With the same speed that AI tools find, sort, and move data faster than any human team, attackers can also quietly collect the data that a quantum computer will one day be able to read even if it cannot today. Increasingly, attackers are copying encrypted data with the intention of reading it later. The history of cryptography itself offers a warning: It took the world three decades to learn that Allied codebreakers had spent much of World War II reading German codes believed to be unbreakable. Classified capability has a consistent record of staying ahead of public knowledge, sometimes by years, sometimes by decades.

This pattern has a name: harvest now, decrypt later. Attackers can collect data even if quantum computers cannot break today's encryption. It is easy to store data for later use when there is a chance it could be decrypted in the future. What matters for organizations is how long their protected data needs to stay confidential, because sophisticated actors are already collecting encrypted traffic and files at scale, betting that quantum computing will make them readable. For any data with a confidentiality lifespan of 10 years or more (intellectual property, board minutes, M&A documents, patient data, and so on), that battle has already been lost the moment the file was intercepted, regardless of when a computer capable of decrypting it becomes available.

The risk posed by Q-Day is not merely speculative, although its timing remain uncertain. NIST finalized its first post-quantum standards in 2024.9 The transition timeline is now set: New US national-security systems must support resistant algorithms from 2027, and NIST's plan removes RSA and elliptic-curve cryptography by 2035. How much will it cost to rebuild a company's cryptographic foundation, and who has budgeted for it? Judging by the numbers, very few organizations have. Only a small minority has moved post-quantum cryptography into production, while most have not even started migration, even though simply finding where cryptography lives inside a large company usually takes 12 to 24 months.

Regulators on both sides of the Atlantic are reaching the same conclusion, although through different paths. The EU's DORA and NIS2 rules, together with the upcoming Cyber Resilience Act, place non-transferable responsibility for operational and cryptographic resilience with the board. In the UK and the US, the mechanism is different, mandatory disclosure in one case, ministerial pressure and financial supervision in the other, but the outcome is the same: This is no longer a technical matter. Boards need to understand this risk.

Brake or Accelerate?

None of this is an argument for caution. As the evidence at the start shows, resilience is not a brake on how fast a company can put AI to work. On the contrary, it is what allows a well-prepared organization to move faster than competitors without the same foundation. The organizations most at risk today are not the ones adopting AI aggressively, rather they are the ones doing so without asking whether their defenses, inventories, and cryptography can keep up.

For boards, resilience is not, above all, a question of cost. Boards should understand the answers to the following questions: Do we know, with confidence, every AI system and every cryptographic dependency we are exposed through? Can we contain an AI-driven attack faster than it can move? When we look at the risks we cannot yet see (the vulnerability not yet disclosed, the data already harvested for a decryption that has not happened yet), do we treat them as someone else's problem, or as already ours?

That is what it means to redefine the board's responsibility for cyber resilience: acting on the damage before it is visible, not after.

The views and opinions expressed in this article are those of the authors.

Read Past Raising the Bar Issues


References

  1. The Value of Resilience: Cyber Resilience in Financial Services,” HM Treasury, July 2026.
  2. X-Force Threat Intelligence Index 2026,” IBM
  3. Assessing Claude Mythos Preview’s Cybersecurity Capabilities,” Anthropic, April 7, 2026.
  4. Assessing Claude Mythos Preview’s Cybersecurity Capabilities,” Anthropic, April 7, 2026.
  5. 2026 AI Threat Landscape Report,” HiddenLayer, March 18, 2026
  6. Our Evaluation of Claude Mythos Preview’s Cyber Capabilities,” AI Security Institute, April 13, 2026.
  7. 2025 Cost of a Data Breach Report: Navigating the AI Rush Without Sidelining Security,” IBM Think, July 30, 2025
  8. IBM Report: 13% Of Organizations Reported Breaches Of AI Models Or Applications, 97% Of Which Reported Lacking Proper AI Access Controls,” IBM Newsroom, July 30, 2025.
  9. Post-Quantum Cryptography,” National Institute of Standards and Technology
Authors
FOLLOW & CONNECT WITH A&M