Open Forum Nabi Darryl S. Gomo
Leadership firewall: The vulnerability leaders create before hackers arrive
IF EVERY hacker on earth disappeared tonight, would your organisation still be digitally vulnerable tomorrow morning?
For many institutions, the uncomfortable answer is yes. The reason is that some of the most dangerous weaknesses in an organisation are not created by malicious outsiders. They are created internally, over time, through decisions that once appeared reasonable.
A senior executive needs urgent access to a system while travelling. A temporary privilege is granted. A service provider cannot meet the normal security requirement, but a deadline is approaching, so an exception is approved. A former employee’s credentials remain active because nobody is certain which process still depends on them. An assistant is given standing authority to approve payments because it is administratively convenient.
None of these decisions necessarily begins as misconduct. Each may be defensible in the moment. The danger begins when the exception is not documented, assigned to an owner, reviewed or closed. A temporary solution quietly becomes part of the institution’s permanent operating environment.
The accumulation of discretion
I call this discretion debt: the accumulation of institutional risk created when leaders make legitimate, reasonable exceptions to normal governance, but those exceptions are never properly recorded, revisited or retired.
Like financial debt, discretion debt is not automatically bad. Organisations need judgement. Rules cannot anticipate every crisis, commercial pressure or operational reality. Leadership exists partly because someone must decide when the normal rule cannot apply.
But every exception creates an obligation. The organisation must remember what was changed, why it was changed, who authorised it, who now owns the risk, what evidence supports the decision, and when the arrangement must be reviewed. If that obligation is ignored, discretion stops being agility and becomes vulnerability.
This is the leadership paradox of cybersecurity: the people with the greatest authority to protect an institution often also have the greatest ability to bypass the controls designed to protect it.
The attacker is often not the origin
Cybersecurity discussions naturally focus on hackers, malware, phishing, ransomware and artificial intelligence. Those threats are real and increasingly costly. IBM’s 2026 Cost of a Data Breach Report places the global average cost of a breach at US$4,99 million and reports a sharp rise in AI-driven attacks. Yet technology and malware are frequently the methods of exploitation, not the original source of vulnerability.
The original weakness may be an old access right, an unreviewed vendor account, a shared password, an undocumented approval, an abandoned cloud service, an exception made for a powerful office, or a process that nobody feels authorised to question.
Verizon’s 2025 Data Breach Investigations Report found that the human element remained involved in about 60 percent of breaches, while third-party involvement doubled from 15 percent to 30 percent. These figures should move the boardroom conversation beyond whether the organisation has bought enough security technology. Boards must also ask whether authority, exceptions and dependencies are being governed with the same discipline as systems.
Attackers rarely need to invent every weakness they exploit. They are often patient enough to find the ones an institution has already accumulated.
Silent compliance
One of the most dangerous indicators of discretion debt is silence. An organisation may have policies, committees and reporting structures, yet junior employees still feel unable to challenge a senior decision. Security staff may recognise that an access arrangement is unsafe but conclude that questioning it would damage their careers. Internal auditors may record an exception but lack the authority to force a review.In such an environment, the policy is not necessarily stronger than the culture. If saying no to a chief executive is treated as disloyalty, the institution’s controls are conditional. They work only until hierarchy decides otherwise.
This does not mean cybersecurity teams should obstruct leadership or treat every exception as a violation. It means organisations must create a legitimate path for professional refusal, escalation and review. Ethical refusal should be recognised as an institutional safeguard, not insubordination.
Dependency debt is also cyber debt
The same problem appears in outsourced technology. Cloud platforms, payroll systems, payment services, artificial-intelligence tools and specialist vendors can improve performance, but every outsourced capability creates an inherited attack surface.
The key question is not only whether the supplier is secure today. It is whether the organisation remembers who approved the dependency, what information the supplier can access, which controls were accepted or waived, what would happen if the supplier failed, and who has authority to reconsider the arrangement.
A vendor contract is not a substitute for institutional memory. Nor is procurement documentation evidence that the risk remains understood. When leadership changes, the reasons behind a decision can disappear even though the technical dependency remains.
Five disciplines for a leadership firewallOrganisations do not need to eliminate discretion. They need to govern it. Five disciplines can create what I call a leadership firewall.
First, review executive exceptions on a fixed cycle. Every exception should have an owner, a rationale, an expiry or review date, and evidence of the decision. No standing privilege should survive simply because everyone has become accustomed to it.
Second, protect principled dissent. Employees must have a credible route to question unsafe decisions without fear of retaliation. The board should be concerned when the security team never disagrees with senior management.
Third, govern third-party dependencies as leadership decisions. Vendors, consultants and platforms should be reviewed not only for price and performance, but also for access, data exposure, continuity and exit risk.
Fourth, improve board-level cyber literacy.
Gomo is Executive Director and Security Strategist at Swatech Security. He works at the intersection of leadership, institutional resilience, security risk and organisational continuity. This article develops ideas presented at the Leadership Symposium held on 7 August 2026.
