63% of boards say their cyber governance isn’t good enough
Cyber risk has become continuous. The governance that oversees it, however, is still periodic.
The result: 63% of boards consider their current practices insufficient to oversee this risk. Five structural causes explain why.
1. Periodic oversight for a continuous risk
Review cadence hasn’t caught up with how the risk actually behaves. In fact, 29% of French companies review cyber risk only once a year, at ExCo or board level.
Attackers don’t wait for the next quarterly meeting. Increasingly, neither can oversight. The World Economic Forum’s 2026 Global Cybersecurity Outlook confirms this shift: threat landscapes now move in near real time. AI drives that speed, on both the offensive and the defensive side.
2. Silos that don’t cover their own seams
Blind spots rarely form inside a single team. Instead, they form in the gap between teams.
Here’s an example: 79% of French companies already use AI internally, but only 42% do so with a formalized security strategy. That 37-point gap is exactly where risk hides.
This isn’t just a French pattern, either. Globally, 87% of organizations named AI-related vulnerabilities their fastest-growing cyber risk last year (WEF, 2026). Meanwhile, security teams are catching up: the share of organizations that assess AI tools before deployment jumped from 37% to 64% in just one year.
3. A skills gap that keeps widening
54% of organizations lack the skills to deploy AI securely. This gap doesn’t close on its own — it widens as AI adoption outpaces upskilling.
So which roles are missing? Globally, three stand out: threat intelligence analysts, DevSecOps engineers, and identity and access management specialists (WEF, 2026). These are exactly the profiles you need to secure AI at scale, not generalist security hires.
4. Regulatory fragmentation that redirects the effort
NIS2, DORA, ReCyF, ISO: each framework brings its own lens, its own evidence requirements, its own audit cadence. As a result, 76% of CISOs say this multiplicity hurts their ability to stay compliant.
So effort shifts from protection to regulatory paperwork. And the scope keeps expanding: 59% of French companies already consider themselves in scope for NIS2 alone, ahead of DORA (32%) and the Cyber Resilience Act (30%). Three overlapping regimes, three separate compliance tracks, one finite security budget.
5. Third-party risk managed by declaration, not by control
30% of French cyber incidents originate with a third party. Yet only 23% of companies monitor their attack surface continuously. The rest relies on a contract clause. In other words, it relies on trust, not on control.
A model built for a pace that no longer exists
The takeaway is simple: boards built cyber governance for a pace of risk that no longer exists.
Getting out of this impasse follows a four-step path:
Ad hoc GRC → Standardization → Centralization → Automation
Each step corrects one of these five causes, in order. Standardization closes the gaps between silos (#2). Centralization turns periodic reporting into continuous visibility (#1), and it also cuts through regulatory duplication (#4). Automation closes the skills gap (#3) last, and it’s what finally makes continuous third-party monitoring (#5) realistic instead of aspirational.
So, where does your organization sit on that path today — still running ad hoc GRC, or already automating?
#SharpenCISO #CISO #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #RiskManagement