Make boards legally liable for cyber attacks, security chief warns
Steve Durbin
- Published
- Opinion & Analysis, Technology

Cyber security is now a boardroom responsibility, with the Information Security Forum calling for directors to face a legal duty to protect their organisations from attack
Company boards should be placed under a legal duty to understand and manage cyber risk, as attacks become more automated, more complex and more damaging to businesses heading into 2026, according to the head of a leading global security body.
Steve Durbin, chief executive of the Information Security Forum (ISF), said cyber threats have reached a point where voluntary oversight and delegated responsibility are no longer sufficient.
Speaking at an ISF webinar, he warned that boards which fail to treat cyber resilience as a core governance issue are exposing their organisations to systemic risk.
“I would almost like to see it become a statutory requirement that boards look at and understand the risk they’re facing,” he said, arguing that cyber exposure should be governed with the same seriousness as financial risk and regulatory compliance.
Durbin said the call reflects a sharp upturn of risk in the threat landscape, where cyber attacks are no longer isolated technical events but are increasingly tied to supply chains, geopolitics and human behaviour.
His warnings were set out during the ISF’s annual Emerging Threats outlook for 2026, delivered in a one-hour webinar titled Emerging Threats 2026: Shaping the Future of Cyber Security.
Cyber attacks, he warned, are becoming “much more complex and much more automated” than in the past, driven by four key risk factors that will shape the year ahead.
He said artificial intelligence sits at the centre of the emerging threat landscape. As tools become cheaper and more accessible, attackers are using AI at scale to conduct synthetic identity attacks, deepfake impersonation and automated social engineering, changing the focus of cybercrime from systems to people and the relationships they rely on.
The second risk is supply-chain dependency, including reliance on cloud infrastructure and external service providers. As organisations become more interconnected through cloud services, outsourced operations and third-party providers, attacks are increasingly originating several steps removed from the primary target. He said many of the most serious incidents now exploit assumed trust between organisations, making board-level visibility and oversight essential.
The third driver, Durbin said, is quantum computing. While quantum-enabled attacks are unlikely to materialise in the immediate future, he warned that the long lead times involved mean preparation must begin now. Government bodies, he noted, often take around a decade to migrate systems to quantum-resistant environments.
Geopolitical tension represents the fourth key risk factor, as nation states, proxy groups and organised criminal gangs increasingly operate in overlapping spheres. Durbin said this convergence is blurring the line between cybercrime, espionage and political pressure, and is “not going away any time soon”.
Taken together, these forces are creating what the ISF describes as “entangled risks”, where digital threats intersect with physical disruption, political instability and human vulnerability. In such an environment, familiar signals of legitimacy — a known supplier, a recognised voice, a routine request — can be fabricated with speed and precision, turning trust itself into a liability.
The warning follows a spate of high-profile cyber incidents in recent months, including cases involving Jaguar Land Rover and Marks & Spencer.
Durbin said this makes it impossible for organisations to defend everything equally. Instead, boards must be directly involved in identifying and protecting “mission-critical information assets”: the data, systems and processes without which the organisation cannot function, even in a degraded state.
He also called for wider use of independent cyber audits, saying external scrutiny is essential if boards are to understand their true exposure.
“I look forward to the day when cyber audits are as important as financial audits,” he said.
READ MORE: ‘ISF warns of a ‘corporate model’ of cybercrime as criminals outpace business defences‘. Cybercrime has matured into an industry that mirrors legitimate enterprise, complete with supply chains and customer service. The industrialisation of hacking, amplified by artificial intelligence, demands a total rethink of how organisations manage people, technology and risk, warns Steve Durbin of the Information Security Forum.
Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.
TOP STORIES
-
Gamers face gridlock as latest Grand Theft Auto download 'nears two days' -
Samsung profits soar ninefold to record £61bn amid AI chip boom -
New Springer books put the UN’s struggling sustainability goals to the real-world test -
Europe’s solar boom set for two-year slowdown after record growth -
Let it pea. Musicians turn vegetables into instruments at Beatles' Abbey Road studios -
Golden naked Trump statue unveiled at European Parliament -
Jaguar puts controversial rebrand on the road with £130K 1,030PS Type 01 -
Deepfakes and identity fraud drive new wave of post-hire background checks -
Spain crowned Europe’s top retirement destination -
More than half of UK professionals report workplace burnout -
More than 1.2m English drivers may have eyesight too poor for the road, study finds -
David Reuben, Britain’s second richest person, leaves London for Monaco -
UK prisoner release plan faces a major lag as tougher rules risk sending inmates back to jail -
Brits trust AI with their health but not their money -
Britain still hungry for Italian food as exports hit €4.56bn despite Brexit -
Women who earn more than their partners still pay the price at work, landmark study finds -
Vape expectations go up in smoke as new UK tax sparks fury -
Robot sales rocket 24% as 250,000 machines snap up jobs in warehouses, hotels and hospitals -
New-build homeowners should not be left with ‘mud and a fence’, campaigners warn -
Bank of England governor warns AI poses growing ‘increasingly significant’ threat to financial stability -
UK economy grows faster than first thought as household incomes bounce back -
UK unveils ‘Great British Grid’ in bid to cut energy bills -
British Chambers unite against 'Made in Europe' rules amid fears for UK industry -
Bouncy castle firms urged to sign new safety pledge following child deaths -
Remembering Matthew Jukes, The European’s Wine & Fine Drinks Correspondent
Make boards legally liable for cyber attacks, security chief warns
Steve Durbin
- Published
- Opinion & Analysis, Technology

TOP STORIES
-
Rethink AI governance or risk an uncontrolled intelligence explosion -
Young people are living through a rights crisis -
Strong leaders know when to make a U-turn -
Life’s last expedition should not be made alone -
If the NHS can’t be a place of psychological safety for staff, where can? -
Under fire, Iran’s carpet weavers fight to keep an ancient art alive -
How COVID silenced my music and taught me to listen to my body -
Marisa Papen – the naked truth behind one of the world's most controversial models -
The blame game – why Britain can't stand losing -
As hospitals shut out fresh air, common sense goes out the window -
The law must catch up with the sexual exploitation risks posed by wearable cameras -
Who governs 900 billion AI agents? -
Why disabled musicians are still struggling to get a fair hearing from record labels -
The five types of masculinity and what they reveal about modern men -
Who let the bots out? The disturbing truth behind rogue AI -
Palm oil steals a march on rivals ahead of new EU food safety rules -
Who pays the price when men withdraw from society? -
Smart glasses and AI are opening a new route to sexual exploitation -
Europe risks losing its cleantech stars to the US -
Lost in translation: can Europe's publishing industry sustain its linguistic diversity? -
No, Elon, AI won't make money obsolete -
Brussels’ sustainability rollback has exposed a crisis of corporate belief -
AI regulation has a knowledge problem -
Why men are increasingly withdrawing from society -
Chris Packham launches campaign to rid Britain of ‘frankenchicken’





















































