KUALA LUMPUR, Sept 5 —Cybersecurity can no longer be treated as a technology issue confined to the IT department but must be recognised as a core business risk requiring direct board-level oversight, cybersecurity expert and Chief Executive Officer of Vortiq <X> Jane Teh said.

Teh, a cybersecurity, AI and change management specialist with more than 20 years of experience, said organisations must fundamentally change how they approach digital security as threats become increasingly sophisticated, professionalised and interconnected.

“Cybersecurity is no longer a technology risk discussed in the boardroom. It is a business risk that happens to run on technology,” she said in her Cybersecurity in the Boardroom: Leading the Digital Defence presentation, part of the session in She Leads, She Defends, Law, Risk and Governance Forum 2026.

She said the traditional approach of treating cybersecurity as an IT cost centre or regulatory compliance exercise was no longer sufficient.

Instead, cyber risk should be evaluated alongside financial and legal exposure and become a standing item on the board agenda.

Teh said boards did not necessarily need to understand the technical details of encryption or cybersecurity systems, but must understand the potential business impact.

This includes direct financial losses, ransom costs, lost revenue and recovery expenses, as well as operational disruption, reputational damage, loss of customer trust and regulatory or legal exposure.

She also highlighted the changing threat landscape, pointing to ransomware, supply-chain vulnerabilities, geopolitical spillover and insider risks as major concerns for organisations that need to be seriously taken into the context.

AI Creates New Opportunities — and New Risks

Teh said the rapid adoption of artificial intelligence was further changing the cybersecurity equation.

While AI can strengthen defence through faster detection, automated responses and large-scale pattern recognition, the same technology can also enable deepfakes, large-scale social engineering and faster exploitation of vulnerabilities.

The emergence of agentic AI, she said, represents an important shift because AI systems are increasingly moving from recommending actions to taking them.

Under the emerging model, data can feed into an AI system that makes decisions and initiates action, with humans moving into a supervisory role.

This creates new governance challenges, particularly when organisations deploy AI faster than they develop policies, ownership structures and oversight mechanisms.

Teh also warned of data risks arising from unsanctioned “shadow” AI use and potential data leakage through third-party tools.

“Every AI capability an organisation adopts is also a new attack surface, a new vendor relationship, and a new governance question,” she said.

Boards Must Test Their Readiness

Teh said effective board oversight should extend beyond receiving periodic cybersecurity presentations.

Boards should assess whether cyber exposure is within the organisation’s stated risk appetite, whether incident response plans have actually been rehearsed, and whether third-party and AI vendor risks receive appropriate scrutiny.

She also urged boards to focus on meaningful measures of exposure and outcomes rather than metrics such as the number of attacks blocked.

“ When your CISO gives a twenty-minute update once a quarter, is that oversight — or theatre?” she asked, challenging boards to examine whether their current cybersecurity governance is genuinely effective.

She said cybersecurity resilience should also be viewed as a portfolio covering prevention, detection, response and recovery, with investment calibrated according to the organisation’s risk appetite.

Crisis Preparation Must Come Before the Crisis

Teh stressed that organisations should rehearse cyber incidents before they occur, including establishing decision-making processes for dealing with regulators, the media and customers.

Clear authority should be established over who speaks, what information is disclosed, how quickly responses are made and how customer trust is protected.

Without such preparation, boards can become paralysed when a major breach occurs, particularly when ransom decisions, regulatory notifications and public disclosures have to be addressed simultaneously.

“A board that has never rehearsed a breach scenario freezes on the decisions that matter most — while the clock is running,” she said.

Teh also called for a transformation in the role of the Chief Information Security Officer, from a technologist and systems owner into a business translator and strategic board partner who helps shape organisational decisions.

She said digital trust would increasingly determine relationships between organisations and their customers, regulators and investors.

Ultimately, she said, resilience in the age of AI should not be viewed simply as a technical achievement.

“In the age of AI, resilience is not a technical achievement. It is a leadership choice,” she said.

Leave a Reply

Designed with WordPress

Discover more from Press KL: Your Voice, Your Vision

Subscribe now to keep reading and get access to the full archive.

Continue reading