Cybersecurity is no longer solely the domain of the IT department – with an increasingly complex threat landscape, chief executives now recognise that it is undeniably intertwined with business resilience, governance and organisational performance.
Yet this is leading to something of a disconnect – the World Economic Forum (WEF) Global Cybersecurity Outlook 2026 reports a divergence between the priorities of chief executives and chief information security officers (CISOs) relating to cyber risk, including cyber-enabled fraud.
“The WEF finds chief executives now rank cyber-enabled fraud and AI-driven attacks as their top concerns, while security teams remain focused on ransomware and supply chain disruption – a gap we see in boardrooms,” says Will O’Brien, director, cybersecurity, PwC Ireland.
The PwC 2026 Digital Trust survey echoes this, he says. 57 per cent of Irish firms are increasing cyber investment, yet globally fewer than half (48 per cent) feel “very capable” of withstanding a big attack.
RM Block

When the chief executive and security team see different priorities, O’Brien says, the business ends up protecting against the wrong things. “Investment gets misdirected, blind spots open up, and response times slow,” he says. “Accountability blurs and crisis decisions become harder under pressure.” In a landscape shaped by AI, geopolitics and complex supply chains, that misalignment is often the difference, he believes, between a contained incident and one that damages revenue, reputation and customer trust.
The WEF report also shows that in the most resilient organisations, 99 per cent have active board involvement and clear ownership at the top. “Chief executives should challenge their teams to explain cyber risk through the lens of revenue, operations and reputation,” O’Brien says.
Greater awareness

David McNamara is the founder of CommSec, an IT security company based in Dublin. He says the WEF report largely mimics what he is seeing as greater awareness of cybersecurity builds.
“Yet many organisations still view cybersecurity as an IT or compliance issue rather than a business risk,” McNamara says. That mindset needs to change. “Cybersecurity should be treated like any other business risk, with ownership at leadership level, not just within IT.”
McNamara believes Government has a role to play in continuing to raise awareness and helping organisations understand that resilience is just as important as compliance.

Jan Carroll is the founder of Fortify Institute, a Meath-based cybersecurity and AI governance training consultancy. She also lectures on AI governance, risk and cyber at UCD Professional Academy. In her experience of working with organisations, she believes it is less of a divergence between chief executives and CISOs, and more of a fundamental difference in perspective.
“Chief executives naturally focus on financial loss, fraud, reputation and growth, while CISOs see ransomware, supply-chain exposure and operational disruption at closer range.”
Both perspectives are valid, she says. “The problem arises when they are never brought together into one coherent view of business risk.”
If leadership is crucial, then the biggest risk to businesses, McNamara says, is a lack of ownership. “Boards often understand ransomware, but they do not always understand the wider business impact, from operational disruption and customer trust to regulatory obligations,” he says.
Into the boardroom
Governance, he says, cannot be outsourced. “The most mature organisations have moved cybersecurity out of the server room and into the boardroom,” McNamara says. These typically have a CISO or security leader reporting directly to senior management, maintain a business risk register, align with recognised frameworks such as NIS2, DORA or ISO 27001, and regularly test their incident response plans.
Yet a study of 894 Irish SMEs by Munster Technological University and the NCSC found that 63 per cent of businesses rely solely on the SME owner for cybersecurity responsibility, often without dedicated expertise.
“When one person is carrying both the strategic worry and the technical one, some form of disconnect is almost guaranteed,” Carroll says. “Business leaders understand that cyber risk matters, although many remain unsure about what effective oversight looks like or what questions they should ask.”
Education is central to this, she says, noting that leaders “do not need deep technical expertise”.
“They need enough knowledge to ask informed questions, assess trade-offs and understand the consequences of their decisions. Effective leaders establish clear responsibilities, give security leaders appropriate access and authority, invest in education and rehearse difficult decisions before an incident occurs.”

According to Richard O’Dwyer, managing director at insurance firm Hiscox Ireland, the WEF report findings echo those of the firm’s own research. “One of the clearest findings from our regular Cyber Readiness research is that organisations increasingly recognise cybersecurity as a business-critical issue rather than simply an IT concern.”
Successful organisations, O’Dwyer says, are encouraging greater collaboration between senior leadership, operational teams and technical specialists. “From our perspective as a specialist commercial insurer, this is particularly important for SMEs, many of which do not have extensive in-house cybersecurity resources but face many of the same threats as larger organisations,” he says. “Increasingly, we are seeing cyber resilience incorporated into wider discussions around governance, operational planning, business continuity and organisational risk.”
For SMEs, this does not necessarily require complex governance structures. “What matters most is that cyber risk is understood, owned at leadership level and incorporated into everyday business planning.”
A small SME does not need the same infrastructure as a large multinational, O’Dwyer says, “but it does need controls that are proportionate to its exposure”.
O’Dwyer says Hiscox Ireland’s experience reinforces that cyber resilience is an ongoing process rather than a one-off investment. The threat landscape continues to evolve, and organisations need to ensure their governance, processes and response capabilities evolve alongside it.
“The key point is that successful businesses do not treat cybersecurity as a fixed checklist. They adapt the balance of people, technology and process to the complexity of their own organisation.”



















