Independent director

A board needs someone
with nothing to sell.

Almost every significant board decision now carries a component of information risk: an acquisition, a critical supplier, an artificial intelligence platform, a statement to the market. Around that table there is rarely anyone able to read it who does not have an interest in the answer.

The appointment comes as the security expert supporting the chief executive, on the board, on the risk committee or on an advisory board. It is not training. It is a position, and when it matters it goes in writing so that it stands on the record.

On these matters responsibility no longer belongs to the IT function. It has a name, a surname and a signature.

Since 1995
Thirty years in the trade
First software on the newsstand
Patents
Granted by the USPTO and EPO
Unitary effect in 17 countries
Institutions
European Commission
European Defence Agency
Capital
Co-founder of CyberGrant
Former managing partner of a fund
Why now

Information risk has stopped being a line of spending and become a duty of those who govern.

This is not a forecast. It has already happened, and it is why boards have started looking for a competence inside the room that they used to buy outside it.

Personal liability

The signature is yours

GDPR, NIS2, DORA and the AI Act place the obligation on the administrative body. Delegating is no longer enough: the board must be able to show that it decided knowing what it was deciding about.

In front of a regulator or a court, what counts is what the minutes say.

Irreversible decisions

It goes on the balance sheet

An acquisition, a critical supplier, a migration, the adoption of artificial intelligence tools. Choices that weigh as much as a balance sheet entry and that cannot be unwound.

Whoever brings them to the board almost always has an interest in seeing them approved. The voice the table needs is the one that does not.

Long horizon

Ten years, not twelve months

A board plans in multi-year cycles. The protections it approves are almost always bought on a twelve-month horizon, and the two do not line up.

The question to put to the table is not whether the data is protected today, but whether it will still be protected when that plan runs out. Why the answer today is usually no →

Independent voice

No product to place

An adviser who sells software cannot tell a board that the problem will not be solved by buying software. Someone who does not sell it can, and sometimes that is precisely the right answer.

It is the reason for the call, and the only thing that makes that presence at the table worth anything.

The mandate

A year on a board,
in four moments.

What happens once appointed
01

Taking the seat. It starts with what the board already has and no one has ever lined up: contracts with critical suppliers, audit findings, insurance policies, the continuity plan. In the first few weeks the board receives a single page.

02

The meetings. A seat on the board or on the risk committee. On items with an information component the position is taken before the vote, and it goes into the minutes.

03

Between meetings. A supplier to choose, a due diligence, an AI tool to authorise. Real decisions rarely wait for the calendar: on those days being reachable is part of the appointment.

04

The incident. When it happens, the board needs to know within two hours what to say to the regulator, to customers and to the market. It is the part that is prepared in advance, and not improvised from behind a desk.

At the table

The questions that reach the table.

They are almost always these. And they are almost never technical questions.

  • Can this supplier actually do what it claims, or does it only claim it?
  • If we sign this statement, are we able to prove it?
  • What happens to our data if the supplier is breached tomorrow?
  • Can we authorise this artificial intelligence tool, and on what conditions?
  • Does the plan we were shown cover the risk, or the budget of the person who wrote it?
  • Will what is protected today still be protected in ten years?
  • Under inspection, is the protection demonstrable or merely declared?
  • If something comes out tomorrow, who speaks, when, and in what words?
Forms of appointment

Three ways to sit down.

A

Independent director

A formal appointment to the board for the length of the term. It is the form that gives the opinion the weight of a vote, and gives the board the ability to show that the competence was in the room.

  • Attendance at board meetings
  • Position on the record for matters within the remit
  • Availability between meetings
B

Risk committee and advisory board

A scheduled presence without directorial liability. This is the most common form in groups that already have a full board and want the groundwork, not another vote.

  • Preparatory work on technology items before the board
  • Second opinion on suppliers, plans and investments
  • Crisis simulations for the administrative body
C

Fixed-term engagement

Support on a single decision: an acquisition, a critical supplier, the adoption of artificial intelligence, an incident under way. It starts and it ends.

  • Duration agreed at the outset
  • One document delivered to the board
  • Attendance at the meeting where it has to be defended

Few appointments are accepted each year, and only one per sector: never two tables that compete. The condition is set before the appointment, not after. Appointments move slowly, and nomination committees look at profiles months ahead.

Declaration of interests

I am co-founder and technical director of CyberGrant, and the patents in the record are mine. When I sit on a board my technology is not among the options and does not become one: if an evaluation were ever to reach that point, I recuse myself and ask for the recusal to be minuted. It is the only condition I set before accepting an appointment, and I am the one who sets it.

Valerio Pastore

If your board is about to open a seat, or a decision is already on the table, write to me. I answer personally.

Get in touch