Cybersecurity

3 things leaders can do to resolve the cybersecurity governance gap

A woman is on her laptop next to a server room: To bridge the cybersecurity gap, leaders must address it as a governance issue

Closing the cybersecurity governance gap means turning boardroom awareness into accountability. Image: Unsplash/Christina@wocintechchat.com

Melonia da Gama
Director of Training and Learning Programs, Fortinet
Natasa Perucica
Lead, Initiatives and Growth, World Economic Forum
This article is part of: Centre for Cybersecurity
  • While 73% of organizations consider cybersecurity a business priority, only 59% of boards back this up with financial resourcing – and just half appreciate the cyber risks associated with AI.
  • The skills needed to address today's cyber threats are evolving, with organizations increasingly turning to AI tools for help, which, if executed correctly, opens up new development opportunities.
  • Leaders can close the cybersecurity gap by strengthening board-level accountability, investing in workforce skills and adopting AI with clear governance and human oversight.

Cybersecurity has made its way into the boardroom – recent research shows that 73% of organizations now see it as a business priority rather than just a technical function. This is an important mindset shift as executives increasingly understand that cyber incidents can affect revenue, reputation and long-term business stability.

That said, recognition has not fully translated into action. Organizations are increasingly aware of the problem but not yet fully structured to manage it.

Only about 59% of boards treat cybersecurity as a financial priority backed by proper investment. There is, therefore, a significant gap between what leaders say is important and what is actually resourced.

This gap between awareness and investment is one of the clearest signs that governance has not kept pace with the reality of modern cyber risk.

A similar issue appears when it comes to new and emerging risks. Only around half of leaders today say their board fully understands cyber risks associated with artificial intelligence (AI), despite its rapid deployment across businesses and security environments, often faster than governance structures can keep pace.

Compounding the challenge, reports have found that AI and automation allow attackers to move faster and at greater scale, using cloud services and stolen identities to break into systems before most security teams can respond.

Organizations that invest in continuous learning and clear upskilling pathways are not only improving retention, they're also building stronger internal capability to manage increasingly complex, AI-driven security environments.

How the talent crisis gives rise to an AI paradox

The cyber risks challenge is made more complex by how quickly skill requirements are evolving. Many organizations now struggle to find professionals with combined cybersecurity expertise and AI knowledge.

As a result, organizations are increasingly turning to AI tools to help fill the gap and improve efficiency. In many cases, this is working in the short term but it also creates a reinforcing cycle.

A shortage of skilled people leads to greater reliance on AI, which in turn increases the need for even more specialized skills. Instead of solving the problem, technology and talent gaps amplify each other.

While AI can significantly improve speed, scale and detection capabilities, it cannot replace human judgment, especially in situations that are new, unclear or rapidly evolving. When systems behave unexpectedly or when attackers use novel techniques, experience and intuition still matter.

This is why better tools alone are not enough. What matters is whether organizations are resourced to make good decisions about cyber risk, invest in people, processes and technology in the right places, and are equipped to respond quickly when problems arise.

Why talent retention is a cybersecurity challenge

At the same time, leaders must also contend with talent retention, with the biggest reason cybersecurity professionals leave their roles being a lack of training and development opportunities.

This is a critical point because it shifts part of the solution directly into leadership responsibility. Organizations that invest in continuous learning and clear upskilling pathways are not only improving retention; they are also building stronger internal capability to manage increasingly complex, AI-driven security environments.

The most resilient organizations will be those able to strike the right balance. They will use AI to strengthen their teams and make sure that human expertise remains strong enough to step in when automation reaches its limits.

Organizations that acknowledge cyber risk without structuring governance, investment and talent development around it – are building on a fragile foundation.

3 things leaders can do to bridge the cybersecurity governance gap

1. Move boards from awareness to accountability

Cybersecurity should not only be discussed as a risk but embedded into how organizations are governed. That means structured cybersecurity education at the board level, cyber expertise represented in governance and a willingness to fund resilience as a strategic priority rather than acknowledge it rhetorically.

2. Treat talent strategy as risk management

Cybersecurity capability depends on people, not just tools. This means investing in reskilling existing practitioners, building diverse pipelines with genuine follow-through and creating AI learning pathways that are structured and role-relevant rather than compliance-driven.

3. Adopt AI with a governance, not just a technology posture

Clear ownership, validated use cases and deliberate design for human oversight are what separate organizations that benefit from AI from those that become dependent on it. AI should, therefore, be integrated into decision-making in a controlled and intentional way, not treated as a plug-in solution.

Have you read?

How leaders can successfully navigate the next era of cyber risk

The gap between boardroom awareness and accountability is not a technology problem. It is a governance problem and it is one that leaders can close.

The organizations best positioned to navigate the next era of cyber risk will be those that have built the governance structures, talent strategies and decision-making capabilities needed to use technology effectively and responsibly.

They will be the ones where leadership understands what those tools can and cannot do, where human judgment is still valued and developed and where accountability for cyber outcomes sits clearly at the top.

The reverse is also true. Organizations that acknowledge cyber risk without structuring governance, investment and talent development around it are building on a fragile foundation.

Closing the governance gap starts with a decision: to move from acknowledging cyber risk to owning it. That shift, from awareness to accountability, is what defines cyber-resilient leadership today.

Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

Why cyber resilience depends on trust

Mark Orsi, Keri Pearlson and Luna Rohland

August 3, 2026

Why a sustainable finance mechanism for cybersecurity is key to securing the global economy

3:29

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum