Blog Zscaler

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

CXO Insights

The Director's Cut: Cyber is Changing Risk Faster Than Board Oversight Is Adapting

image
ROB SLOAN
settembre 04, 2026 - 5 min read

Board-level cyber risks requiring oversight: AI-enabled attacks accelerating faster than enterprise controls, ransomware fallout persisting even when victims refuse to pay, insider threats exposing governance gaps around trusted access, and quantum risk forcing earlier planning for cryptographic transition.

 

AI Is Advancing Faster Than Most Enterprises Are Governing It

A late-August warning from more than 100 major technology companies argued that AI-enabled cyberattacks are likely to become materially more widespread and sophisticated within months, not years. OpenAI reinforced that point when, according to The Wall Street Journal, it said its forthcoming Astra model showed cyber capabilities strong enough to justify added safeguards, tighter monitoring, and a limited public release after internal testing found it could devise and execute novel attacks with limited human input.

AI is not just giving attackers better tools. It is changing the speed, scale, and cost of attack activity in ways that can outpace management assumptions about readiness, containment, and recovery. Recent Zscaler research points to the same gap inside the enterprise: across more than 400 organizations assessed for AI security readiness, not one had specialized AI access controls, continuous AI asset tracking, or prompt-and-response inspection.

In 87% of cases, the tools needed to close the most critical gaps were already owned and licensed, but had not been fully activated or configured. For directors, the issue looks less like a spending problem than an execution problem. Management should be able to identify the enterprise’s real AI exposures, show whether existing tools can address the most important gaps, and explain how those controls will be activated, configured, and governed in practice.

What Directors Should Ask Management:

  • What AI-related risks are most relevant to our business today, where is our current exposure highest, and which existing security or governance tools do we already own that could address the most important gaps?  

  • How are we identifying and tracking AI use, AI-enabled workflows, and AI-connected assets across the enterprise, including activity outside formally approved channels?  

  • What controls do we have, or need, to inspect prompts and responses so that sensitive information is not exposed through employee or third-party AI use?

 

Ransomware Pressure Keeps Rising as Public-Sector Victims Refuse to Pay

In the U.S., a ransomware group leaked what appeared to be sensitive law-enforcement files stolen from the Justice Department’s Bureau of Alcohol, Tobacco, Firearms and Explosives after the agency disclosed a “major” cyber incident. Similarly, the government of Berlin said it would not pay a roughly $2.3 million extortion demand after attackers claimed to have stolen more than 5TB of data, including personal information, credentials, and internal documents. Together, the cases show that even when operations are contained, downstream consequences can still be severe.

Ransomware.live says there have been 6,937 victims in 2026 to date, up 33.6% from the same point in 2025. The oversight implication is that ransomware resilience cannot rest on recovery plans alone. Zero trust architecture helps reduce risk by shrinking the attack surface, limiting unnecessary access, and making lateral movement harder once an attacker gets in.

What Directors Should Ask Management:

  • How effectively are we limiting lateral movement if an attacker gains an initial foothold somewhere in our environment?

 

Insider Risk Is Still a Governance Problem, Not Just a Security Problem

The guilty plea of former Defense Intelligence Agency employee Nathan Vilas Laatsch is a reminder that insider risk can come from trusted staff with legitimate access and knowledge of internal controls. According to the Justice Department, Laatsch worked in the DIA’s Insider Threat Division, held a Top Secret clearance, and admitted trying to provide classified information to a foreign government after removing sensitive material from secure systems.

The broader lesson is that insider risk is most dangerous where high trust, privileged access, and weak cross-functional escalation intersect. Effective oversight requires more than policy statements. It depends on tightly scoped access, monitoring for unusual behavior and data movement, controls on removable media, and a formal insider threat program spanning security, HR, legal, compliance, and management. This guide from the Cybersecurity and Infrastructure Security Agency (CISA) may be helpful.

What Directors Should Ask Management:

  • Do we have a formal insider threat program that integrates security, HR, legal, and compliance, and does it monitor for unusual access, data movement, and changes in employee risk indicators?

 

Quantum Risk Is Becoming a Board-Level Transition Issue

Quantum computing is not an immediate operational threat for most companies, but it is becoming a governance issue because it could eventually weaken the encryption that protects sensitive data, transactions, and communications. The nearer-term concern is “harvest now, decrypt later”: adversaries can steal encrypted data today and hold it until quantum capabilities improve.

The governance implication is that quantum readiness should be treated as a transition-planning issue, not a distant science project. The National Institute of Standards and Technology (NIST) has already issued post-quantum cryptography standards, and major technology providers are starting migration plans. Zscaler’s *The Quantum Tipping Point* executive plan is useful here because it helps organizations identify vulnerable cryptography, prioritize data exposed to long-term risk, and plan phased migration to quantum-resistant controls.

What Directors Should Ask Management:

  • What is management’s roadmap for migrating to post-quantum cryptography, and where could transition risk be highest?

 


Zscaler is a proud partner of NACD's Northern California chapter. We are here as a resource for directors to answer questions about cybersecurity or AI risks, and are happy to arrange dedicated board briefings. Please email rsloan[@]zscaler.com to learn more.

form submtited
Grazie per aver letto

Questo post è stato utile?

Esclusione di responsabilità: questo articolo del blog è stato creato da Zscaler esclusivamente a scopo informativo ed è fornito "così com'è", senza alcuna garanzia circa l'accuratezza, la completezza o l'affidabilità dei contenuti. Zscaler declina ogni responsabilità per eventuali errori o omissioni, così come per le eventuali azioni intraprese sulla base delle informazioni fornite. Eventuali link a siti web o risorse di terze parti sono offerti unicamente per praticità, e Zscaler non è responsabile del relativo contenuto, né delle pratiche adottate. Tutti i contenuti sono soggetti a modifiche senza preavviso. Accedendo a questo blog, l'utente accetta le presenti condizioni e riconosce di essere l'unico responsabile della verifica e dell'uso delle informazioni secondo quanto appropriato per rispondere alle proprie esigenze.

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Inviando il modulo, si accetta la nostra Informativa sulla privacy.