Strengthening Cyber Governance
Lydian Technologies, a cloud services and software provider, has suffered a sophisticated breach. Hackers gained access via a software update from a widely used third-party provider, compromising Lydian’s monitoring product across critical sectors. The breach went undetected for months and was revealed by an external cybersecurity firm.
The board was notified only after the public disclosure and is now facing scrutiny from regulators and clients. Directors discover that cyber risk was framed as a compliance item rather than a strategic enterprise risk, and that many felt underprepared to assess these issues.
What should the board do now?