05 Feb Leadership in cybersecurity — and cybersecurity in leadership
Leadership in cybersecurity is no longer just a boardroom talking point; Ioannis Fragkoulopoulos, Cybersecurity Consultant, argues that in an AI‑driven, data‑saturated world, cyber leaders must move from servicing the business to actively shaping its strategic direction.
For nearly two decades, I have worked in the cybersecurity domain, largely within multinational cybersecurity providers and alongside global organisations operating across multiple geographies. My work has consistently been situated at the intersection of business strategy, technology and cyber risk. At the same time, I have participated actively in global industry bodies and professional associations, observing patterns that extend beyond individual companies or sectors. Over the years, two ideas have emerged with increasing clarity: first, the rapid and ongoing evolution of cybersecurity itself; and second, the rising expectations placed on leaders to internalise and champion cybersecurity principles. Yet despite the strong emphasis on ‘cybersecurity in leadership’, I have seen far less progress in what I consider the more fundamental requirement: genuine leadership in cybersecurity. This distinction matters. It defines not only how organisations respond to risk, but how they create long-term resilience.
To understand why this distinction is important, let’s look at the evolution of cybersecurity. In the late 2000s, cybersecurity was dominated by compliance. Organisations interpreted regulatory frameworks independently, and cybersecurity effort was heavily tied to the implementation of abstract standards. The outputs were familiar: policies drafted to satisfy auditors, processes mapped to checklists, and system-hardening activities aimed at avoiding non-compliance. Cybersecurity was a governance exercise, anchored in documentation rather than operational capability.
The second phase emerged as digital transformation accelerated and networks became more interconnected. Heterogeneous technologies had to be secured despite limited interoperability, and the expansion of broadband connectivity exposed critical systems to open environments for the first time. Employees, customers and partners were suddenly interacting with corporate systems across porous network boundaries. Cyber risks grew in parallel with the internet itself. The focus shifted toward cybersecurity engineering, building security architectures and deploying real-time monitoring capabilities that could keep pace with the changing threat landscape.
The next phase began as organisations moved the bulk of their operations online. Data volumes soared, business processes became digital end-to-end and exposure to the internet increased proportionally. Cybersecurity teams responded with enhanced awareness programmes and advanced detection and response technologies, such as EDR and XDR platforms. Threat protection matured, but the surface area expanded faster. The profession became more technically sophisticated, but also more reactive, as attackers exploited new opportunities created by digital expansion.
What comes next?
Today, we are entering a new phase shaped by AI and data. Many organisations aim to transform every operational layer into data flows or models, making security not just a question of protecting systems but of safeguarding prompts, training data and the integrity of AI-assisted decision-making. The cybersecurity outcomes required in this era are still emerging. Secure AI prompts, protections against data poisoning and models for trusted AI governance have not yet fully crystallised. Cybersecurity is no longer a discrete function within compliance or IT; it has become a horizontal capability that stretches across the entire enterprise — from cloud protection to brand monitoring, from third-party ecosystems to customer-facing services. The boundaries of cybersecurity have dissolved, leaving organisations with vast and complex responsibilities.
This evolution brings us to the central problem. Despite all progress, cybercrime continues to rise. The sophistication, speed and scale of adversaries increase at a pace that often surpasses defensive innovation. Boards expect resilience, not excuses. Security and privacy programmes are expected to cover protection, detection, response and recovery. They are expected to deliver continuity of operations even under severe stress.
Leading with expectation
This expectation has sparked a surge in interest in ‘cybersecurity in leadership’ — the idea that executives across the business must embrace cybersecurity principles. While this trend is positive, it sometimes masks a subtle dynamic: the redistribution of responsibility. Cybersecurity professionals hope upper management will share the burden, while executives expect security teams to protect the organisation despite mounting challenges. This tension creates a gap between aspiration and reality. What is missing is not more cybersecurity embedded in leadership, but more leadership embedded in cybersecurity.
As cybersecurity becomes more complex, interconnected and mission-critical, the function requires strong leadership in its own right. Cybersecurity now touches data governance, AI ethics, operational resilience, regulatory strategy, supplier ecosystems and customer trust. It influences mergers and acquisitions, product design and organisational culture. It cannot be managed purely as a technical discipline. Instead, it requires leaders who can integrate cybersecurity with business objectives, shape strategic direction and guide organisations through uncertainty.
Shifting mindsets
This shift is accelerated by the increasing adoption of managed cybersecurity operating models. Security capabilities are becoming service-driven, automated and scalable. In some organisations, provisioning cybersecurity will soon resemble provisioning cloud resources: fast, modular and centrally orchestrated. Yet even as cybersecurity becomes more service-oriented, strategic leadership does not disappear; it becomes more important. Someone must decide what to prioritise, how to allocate resources, how to evaluate risks and how to integrate cybersecurity with broader business objectives. That responsibility cannot be outsourced. It must be owned by cybersecurity leaders, supported by executives but not replaced by them.
Leadership in cybersecurity therefore demands a different skill set from that traditionally associated with security teams. Cyber leaders must learn to translate technical issues into business language that boards can understand and act upon. They must articulate a strategic vision that aligns with long-term organisational goals rather than reacting to individual threats or compliance events. They must show calm and clarity during crises, guiding cross-functional teams and providing reliable direction when stakes are high. Their influence must extend beyond their direct reporting lines, shaping decisions in product teams, legal departments, procurement, cloud operations and customer-facing functions. They must empower highly specialised technical teams, creating environments where expertise can scale rather than bottleneck. And they must strike a careful balance between innovation and risk, enabling the organisation to move forward without exposing itself unnecessarily.
United front
Cybersecurity service providers also have a role in this leadership-driven model. The industry cannot limit itself to deploying tools or selling solutions. Providers must help clients envision the future of their security capabilities, accept responsibility for measurable outcomes, communicate effectively and respond to challenges with resilience and creativity. They must collaborate closely with internal teams, understanding business priorities and tailoring services accordingly. Leadership is not a byproduct of technology; it must be engineered into service models.
Ultimately, cybersecurity has evolved faster than the leadership structures designed to manage it. If organisations continue to rely only on cybersecurity in leadership, they will remain reactive. The next decade requires a deeper transformation: cultivating genuine leadership within cybersecurity itself. This is not a shift in tools or frameworks, but a shift in mindset. Cybersecurity must not simply follow the organisation; it must help lead it.
This feature appeared in issue 146 of Security Middle East magazine.
Sorry, the comment form is closed at this time.