Columns
- The Board’s Strategic Role in Operationalizing Innovation
- When AI Algorithms Control Earnings Reactions
- Point/Counterpoint: To Go Public or to Stay Private?
- Why Mergers Fail When Strategy Is 'Right'
- Transforming Governance into a Growth Strategy
- How the Board Can Get the COO Position Right
- Beyond ROI: A Conversation with Purvee Kondal
- Onboarding
Director Advisory
- Human Capital Governance and the Compensation Committee’s Remit
- Strengthening Board Engagement as Volatility Tests Strategy
- Four Overlooked AI Signals Every Director Should Watch
- A Mid-Cycle Guide for Compensation Committees
- How Boards Influence Successful Carve-Outs
- The Hidden Costs of CEO Succession
-
Governing the Convergence of AI and Cyber Risk
Directorship Magazine
Governing the Convergence of AI and Cyber Risk
Key Points
- AI has fundamentally compressed cyberattack timelines from weeks to hours, requiring boards to shift their focus from basic security oversight to comprehensive resilience.
- The rapid adoption of AI introduces a new, often ungoverned attack surface, including data pipelines and third-party AI models, that boards should ask management to assess to prevent exploitable vulnerabilities.
- Effective governance requires boards to treat AI and cybersecurity as a singular, intertwined strategic agenda rather than separate concerns.
This AI-generated summary, based on content on this page, was reviewed by NACD editors for accuracy.
Artificial intelligence has fundamentally altered cybersecurity. It is no longer just a business tool; it is a force multiplier for cyber-threat actors that can collapse attack cycles into a matter of hours. In addition, when AI tools are integrated without proper security assessments, they open new channels for exploitation that human teams alone cannot manually match.
This article examines the emerging vulnerabilities created by rapid AI adoption, from AI-accelerated social engineering to the post-quantum data risks looming on the horizon. By aligning oversight of AI innovation with cybersecurity governance, boards can turn defensive readiness into a distinct competitive advantage.
Thank you for your interest in this page.
Member-Only Content
For full access, please log in, or explore membership options.

Tiffany Kleemann is a managing director in the Deloitte & Touche LLP cyber board governance practice.

Andrew Morrison is a principal in the Deloitte & Touche LLP cyber board governance practice.
Deloitte is a NACD partner, providing directors with critical and timely information, and perspectives. Deloitte is a financial supporter of the NACD.
As used above, Deloitte refers to a US member firm of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (DTTL). This article contains general information only and Deloitte is not, by means of this article, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This article should not be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this article. Copyright © 2026 Deloitte Development LLP.
Explore All Directorship Issues
