Advertisements
Home » Leadership firewall: The vulnerability leaders create before hackers arrive

Leadership firewall: The vulnerability leaders create before hackers arrive

0 comments

Open Forum Nabi Darryl S. Gomo

Leadership firewall: The vulnerability leaders create before hackers arrive

IF EVERY hacker on earth disap­peared tonight, would your organ­isation still be digitally vulnerable tomorrow morning?

For many institutions, the uncom­fortable answer is yes. The reason is that some of the most dangerous weak­nesses in an organisation are not cre­ated by malicious outsiders. They are created internally, over time, through decisions that once appeared reason­able.

Advertisements

A senior executive needs urgent access to a system while travelling. A temporary privilege is granted. A ser­vice provider cannot meet the normal security requirement, but a deadline is approaching, so an exception is ap­proved. A former employee’s creden­tials remain active because nobody is certain which process still depends on them. An assistant is given standing authority to approve payments because it is administratively convenient.

None of these decisions necessari­ly begins as misconduct. Each may be defensible in the moment. The danger begins when the exception is not doc­umented, assigned to an owner, re­viewed or closed. A temporary solution quietly becomes part of the institution’s permanent operating environment.

The accumulation of discretion

I call this discretion debt: the accu­mulation of institutional risk created when leaders make legitimate, reason­able exceptions to normal governance, but those exceptions are never properly recorded, revisited or retired.

Like financial debt, discretion debt is not automatically bad. Organisations need judgement. Rules cannot antic­ipate every crisis, commercial pres­sure or operational reality. Leadership exists partly because someone must decide when the normal rule cannot apply.

But every exception creates an obligation. The organisation must re­member what was changed, why it was changed, who authorised it, who now owns the risk, what evidence supports the decision, and when the arrange­ment must be reviewed. If that obliga­tion is ignored, discretion stops being agility and becomes vulnerability.

This is the leadership paradox of cybersecurity: the people with the greatest authority to protect an institu­tion often also have the greatest abil­ity to bypass the controls designed to protect it.

The attacker is often not the origin

Cybersecurity discussions naturally focus on hackers, malware, phishing, ransomware and artificial intelligence. Those threats are real and increasing­ly costly. IBM’s 2026 Cost of a Data Breach Report places the global aver­age cost of a breach at US$4,99 million and reports a sharp rise in AI-driven at­tacks. Yet technology and malware are frequently the methods of exploitation, not the original source of vulnerability.

The original weakness may be an old access right, an unreviewed vendor account, a shared password, an un­documented approval, an abandoned cloud service, an exception made for a powerful office, or a process that no­body feels authorised to question.

Verizon’s 2025 Data Breach Inves­tigations Report found that the human element remained involved in about 60 percent of breaches, while third-party involvement doubled from 15 percent to 30 percent. These figures should move the boardroom conversation beyond whether the organisation has bought enough security technology. Boards must also ask whether author­ity, exceptions and dependencies are being governed with the same disci­pline as systems.

Attackers rarely need to invent ev­ery weakness they exploit. They are often patient enough to find the ones an institution has already accumulated.

Silent compliance

One of the most dangerous indica­tors of discretion debt is silence. An or­ganisation may have policies, commit­tees and reporting structures, yet junior employees still feel unable to challenge a senior decision. Security staff may recognise that an access arrangement is unsafe but conclude that questioning it would damage their careers. Internal auditors may record an exception but lack the authority to force a review.In such an environment, the policy is not necessarily stronger than the culture. If saying no to a chief executive is treated as disloyalty, the institution’s controls are conditional. They work only until hierarchy decides otherwise.

This does not mean cybersecurity teams should obstruct leadership or treat every exception as a violation. It means organisations must create a le­gitimate path for professional refusal, escalation and review. Ethical refusal should be recognised as an institutional safeguard, not insubordination.

Dependency debt is also cyber debt

The same problem appears in out­sourced technology. Cloud platforms, payroll systems, payment services, ar­tificial-intelligence tools and specialist vendors can improve performance, but every outsourced capability creates an inherited attack surface.

The key question is not only whether the supplier is secure today. It is whether the organisation remem­bers who approved the dependency, what information the supplier can ac­cess, which controls were accepted or waived, what would happen if the sup­plier failed, and who has authority to reconsider the arrangement.

A vendor contract is not a substi­tute for institutional memory. Nor is procurement documentation evidence that the risk remains understood. When leadership changes, the reasons behind a decision can disappear even though the technical dependency remains.

Five disciplines for a leadership firewallOrganisations do not need to eliminate discretion. They need to gov­ern it. Five disciplines can create what I call a leadership firewall.

First, review executive exceptions on a fixed cycle. Every exception should have an owner, a rationale, an expiry or review date, and evidence of the decision. No standing privilege should survive simply because every­one has become accustomed to it.

Second, protect principled dissent. Employees must have a credible route to question unsafe decisions without fear of retaliation. The board should be concerned when the security team nev­er disagrees with senior management.

Third, govern third-party depen­dencies as leadership decisions. Ven­dors, consultants and platforms should be reviewed not only for price and performance, but also for access, data exposure, continuity and exit risk.

Fourth, improve board-level cyber literacy.

Gomo is Executive Director and Security Strategist at Swatech Secu­rity. He works at the intersection of leadership, institutional resilience, se­curity risk and organisational conti­nuity. This article develops ideas pre­sented at the Leadership Symposium held on 7 August 2026.

Leave a Comment

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More