Security News

Cybersecurity news aggregator

INFO News Dark Reading

What Boards Need to Know About Tech Risk

  • What: Discussion on tech risk for boards
  • Impact: Organizations and IT leaders
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Vulnerabilities & Threats Global Threat Campaign Hits Critical VMware vCenter Flaw Global Threat Campaign Hits Critical VMware vCenter Flaw by Rob Wright Aug 13, 2026 4 Min Read Sponsored Content AI-powered cyberattacks require a hybrid and adaptive approach to AppSec. AI-powered cyberattacks require a hybrid and adaptive approach to AppSec. by Joan Goodchild Aug 13, 2026 World Related Topics DR Global Asia Pacific Europe Latin America Middle East & Africa See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyber Risk Cybersecurity Operations Vulnerabilities & Threats What Boards Need to Know About Tech Risk Why do so many boards underestimate technology risk until it becomes a crisis? Chris Drumgoole , President of Global Infrastructure Services (GIS) , DXC Technology August 14, 2026 8 Min Read Source: FangXiaNuo via Getty Images OPINION Most boardrooms are built to evaluate opportunity, growth initiatives, tech acquisitions, and operational improvements. The discussion centers on a familiar equation: investing in X to generate Y return. That mindset is essential for scaling a business. But it often creates dangerous blind spots in digital infrastructure. Unlike revenue-generating projects, many of the most important technology investments don't produce visible upsides. Modernizing infrastructure, reducing technical debt, building redundancy, improving recovery capabilities, and strengthening governance don't necessarily translate into quarterly earnings reports. It comes through in the avoidance of system and organizational failure. It is an investment that only becomes visible when it's not made. Similarly, technology risks accumulate slowly and quietly in the background of your organization. I've seen this pattern repeat throughout my career. In almost every case, the risks causing — or likely to cause — the most disruption weren't the ones executives were actively discussing. They were the ones that had become accepted as normal, that teams actively worked around every day. They build slowly over time, only to be noticed when they become seemingly insurmountable. Related: 'GhostJacking' Exposes Identity Governance Gaps in AI Agents That reality is becoming increasingly dangerous as digital transformation accelerates. AI adoption, cloud concentration, vendor dependencies, and increasingly interconnected business operations mean a single technology failure can have wide-reaching consequences. The board member s who manage technology risks most effectively aren't passive overseers. They’re active participants, making technology governance a board-level responsibility long before systems begin to fail. That’s where the real return on investment becomes visible. Technology risks don’t behave like most business risks. If a factory roof starts to leak, the water on the floor is evidence of a needed repair. If a supply chain disruption occurs, businesses immediately seek alternatives or follow preset plans. If equipment begins to falter, owners call for a fix or an upgrade before it breaks down completely. Hidden Technology Risks Boards Should Be Most Concerned About I’ve noticed that many enterprises today simply accept or ignore the complex web of core business risks that threaten their long-term sustainability. Some of the risks boards should pay close attention to include: Deferred modernization. No software or piece of equipment will last forever. As your infrastructure ages, risks such as system outages, failures, and corruption become more likely. Technical debt accumulation. Every delayed update, temporary workaround, or postponed improvement creates future obligations. Technical debt is rarely catastrophic at first. But as it accumulates, so do vulnerabilities, complexity, and performance issues. Reduced AI governance. As organizations adopt AI more aggressively, governance has become increasingly important. Without robust frameworks and human oversight, businesses risk inaccurate outputs, compliance challenges, and data exposure. Supply chain dependencies. When you're reliant on a single route, vendor, or component, supply chain disruptions can have damaging ripple effects, affecting everything from production to costs to external relationships with suppliers and customers. Cloud concentration. Using only a small array of software may reduce complexity for your team. But it has its risks, including, as Investopedia notes , mass extended downtime in the event of a system outage. Diminished operational resilience and recovery capability. Without strong risk management frameworks, IT infrastructure, team guidelines, and system backups, your organization is at risk of a delayed recovery in the event of an outage or breach. Related: Sherlock Holmes Was the 'OG' Social Engineer Bridging the gap between your awareness of these technology risks and your preparedness for them is the key to operational longevity. I’ve found boards gain much better visibility when they stop relying exclusively on green dashboards and start asking operational questions. Related: AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking Some of the most valuable include: What operational dependencies could keep the organization nonfunctional for an extended period in the event of a service interruption? Are we making the right technology investments for our current needs, growth plans, and systems? Do we have the guidelines and backups in place to operate through an active crisis? What percentage of the organization's data and operating systems are invisible to our monitoring tools, and how can we increase the boundaries of our internal visibility? How often should our various systems, structures, and equipment be patched, updated, or replaced? The resulting conversations often uncover risks that traditional dashboards never surface. Why Is Technical Debt a Board-Level Issue? As Accenture reported in 2024 , tech debt in the United States costs companies nearly $2.5 trillion per year, and would require just over $1.5 trillion to resolve. Deloitte's 2026 Global Technology Leadership Study found that technical debt likely accounts for about 21% to 40% of a company's IT spending. Yet technical debt remains difficult to discuss at the board level because its consequences often feel distant. The business continues to function. Employees patch and adapt. External parties don't notice. Revenue remains stable. Boards continue to divert funds to projects with clear ROI rather than to mitigate potential technology risks. It creates the illusion that the problem can wait. Eventually, the technical debt becomes too large to pay off. At that point, it becomes much more than an IT concern. It becomes a business risk. You can address technical debt early by: Regularly auditing assets. When you regularly review the age, technical health, and support history of software, particularly legacy applications, you can more easily identify potential risks and areas for improvement. Comparing costs. Calculate the cost of maintaining aging and damaged systems and compare it to the estimated costs and long-term savings of technology investments. Clarifying the numbers gives you a transparent look into the benefits of reducing risks rather than simply managing them. Establishing regular maintenance schedules. When you consistently update, back up, test, and replace systems, you gain a clear view of your organization's inner workings. Debt can't be eliminated. But you can prevent this technology risk from becoming large enough to threaten operational performance. Building operational resilience. Modernizing infrastructure. Establishing rapid recovery capabilities. While these systems, and the tech behind them, don't generate revenue, they serve an equally important purpose: keeping your organization functional and reliable. Boardroom conversations tend to focus first and foremost on the ROI of growth opportunities rather than on the risk-adjusted value of defensive planning. A prolonged breakdown in digital infrastructure that renders customer-facing platforms unusable for days at a time doesn't just stall revenue; it damages relationships. Data losses resulting from system vulnerabilities or insufficient redundancy can invite legal penalties and external scrutiny. Outages caused by vendor dependencies can incur high costs and regulatory investigations. As the digital world becomes increasingly interconnected, technology risks carry greater business consequences. Passive oversight isn't an option. You must actively reshape your investment priorities, turning resilience spending from a bottom-tier option into a core policy to ensure the business's survival. How Can Boards Create Better Technology Risk Conversations? Before you can effectively defend against risks, you need to build stronger relationships with your CIOs and CISOs. These executives know the company's systems better than anyone else. It's their job to think in technical terms: the software vulnerabilities, compliance frame

Share this article