Almost every significant board decision now carries a component of information risk: an acquisition, a critical supplier, an artificial intelligence platform, a statement to the market. Around that table there is rarely anyone able to read it who does not have an interest in the answer.
The appointment comes as the security expert supporting the chief executive, on the board, on the risk committee or on an advisory board. It is not training. It is a position, and when it matters it goes in writing so that it stands on the record.
On these matters responsibility no longer belongs to the IT function. It has a name, a surname and a signature.
Information risk has stopped being a line of spending and become a duty of those who govern.
This is not a forecast. It has already happened, and it is why boards have started looking for a competence inside the room that they used to buy outside it.
GDPR, NIS2, DORA and the AI Act place the obligation on the administrative body. Delegating is no longer enough: the board must be able to show that it decided knowing what it was deciding about.
In front of a regulator or a court, what counts is what the minutes say.
An acquisition, a critical supplier, a migration, the adoption of artificial intelligence tools. Choices that weigh as much as a balance sheet entry and that cannot be unwound.
Whoever brings them to the board almost always has an interest in seeing them approved. The voice the table needs is the one that does not.
A board plans in multi-year cycles. The protections it approves are almost always bought on a twelve-month horizon, and the two do not line up.
The question to put to the table is not whether the data is protected today, but whether it will still be protected when that plan runs out. Why the answer today is usually no →
An adviser who sells software cannot tell a board that the problem will not be solved by buying software. Someone who does not sell it can, and sometimes that is precisely the right answer.
It is the reason for the call, and the only thing that makes that presence at the table worth anything.
Taking the seat. It starts with what the board already has and no one has ever lined up: contracts with critical suppliers, audit findings, insurance policies, the continuity plan. In the first few weeks the board receives a single page.
The meetings. A seat on the board or on the risk committee. On items with an information component the position is taken before the vote, and it goes into the minutes.
Between meetings. A supplier to choose, a due diligence, an AI tool to authorise. Real decisions rarely wait for the calendar: on those days being reachable is part of the appointment.
The incident. When it happens, the board needs to know within two hours what to say to the regulator, to customers and to the market. It is the part that is prepared in advance, and not improvised from behind a desk.
They are almost always these. And they are almost never technical questions.
A formal appointment to the board for the length of the term. It is the form that gives the opinion the weight of a vote, and gives the board the ability to show that the competence was in the room.
A scheduled presence without directorial liability. This is the most common form in groups that already have a full board and want the groundwork, not another vote.
Support on a single decision: an acquisition, a critical supplier, the adoption of artificial intelligence, an incident under way. It starts and it ends.
Few appointments are accepted each year, and only one per sector: never two tables that compete. The condition is set before the appointment, not after. Appointments move slowly, and nomination committees look at profiles months ahead.
I am co-founder and technical director of CyberGrant, and the patents in the record are mine. When I sit on a board my technology is not among the options and does not become one: if an evaluation were ever to reach that point, I recuse myself and ask for the recusal to be minuted. It is the only condition I set before accepting an appointment, and I am the one who sets it.
Valerio Pastore
If your board is about to open a seat, or a decision is already on the table, write to me. I answer personally.
Get in touchPatents filed and granted, appointments, institutions, companies. Not claims but acts: things filed with an office, awarded by a jury or entered in a register.
Open the record →Why protecting the network is no longer enough, and what happens when an artificial intelligence agent reads your information. With the demonstration performed live.
Read the thesis →The examination that reaches an investment committee before a deal is the same one that later reaches a board table. Technology, patents, security, people.
How it works →