Earlier this year, the UK Government launched its Cyber Resilience Pledge initiative, aimed at encouraging more companies to invest in cyber security. This initiative aims to make those in charge of companies more aware of the challenges that affect their business operations, and how they have to make their systems more resilient.
The challenge around cyber security is making it relevant for board teams. IT is essential to how businesses operate today – according to Accenture’s Pulse of Change report, 71% of leaders rank investment in digital tools as their top strategy for managing operations. At the same time, the company found that 87% of organizations see cyber disruption as a recurring operating reality too.
Security problems are growing
The number of issues is growing too. According to our research, the number of critical vulnerabilities in the CISA Known Exploited Vulnerabilities list has gone up by 6.5 times since 2022, rising to 473 million issues closed in 2025. The other significant change for IT and business teams is around AI. Frontier AI models like Mythos and ChatGPT 5.5 Cyber perform well at finding issues in software. As part of its Project Glasswing initiative, Mythos discovered around 23,000 vulnerabilities, of which around 6,000 were rated as high or critical. AI can also be used to test and link those vulnerabilities together to become more serious attack chains.
In our research, we found more than 1,000 attack paths that took multiple issues and created potential exploits using AI. The attack paths would use issues rated as 7.0 or lower in severity, so they would be more likely to stay unpatched for longer. All of these issues – and there are a lot of them – threaten how security teams manage patching and configuration management. People can’t keep up.
The response to this has to be automation. Deploying updates automatically for low-risk issues can cut a lot of the overhead, leaving more time for humans to work on the issues that need insight or additional testing. The challenge for IT teams is trust around those updates. To solve this level of problem, teams can implement more automated processes for testing issues before deployment. Of more than 150 million patches deployed last year at our customers, 40 million were completed automatically, with only 0.01 percent rolled back.
Understanding risk, not just threats
For management teams and boards, these technical issues might seem like they are not important enough to merit individual attention. They would be right. But each one can also have a huge impact on how a business operates, bringing down IT systems or leading to financial losses.
For boards, understanding cyber risk in context is critical. The Cyber Resilience Pledge includes a commitment that board members should understand cyber security threats through undertaking NCSC Cyber Governance training. The board also has to go through a risk assessment exercise that asks for suppliers to get Cyber Essentials accreditation for themselves, with suppliers rated based on the company’s overall risk appetite.
This exercise should help board members get familiar with how to understand cyber security risk in theory. However, the sheer volume of potential issues that are coming up is overwhelming. Even with this training, board members need help to put these risks into perspective and context. For the IT team, the most effective way to do this is through estimating financial impact for any potential risk alongside the likelihood that this issue can be exploited.
Behind this, security teams can understand what the biggest risks are for the business based on real time insight and threat intelligence. If and when a serious issue does arise, that vulnerability can receive the attention that it needs. For the board, this risk figure should describe how much that vulnerability could cost as well as how effective any existing security controls are at preventing issues. Putting this in terms of cash at risk will make the board pay attention, as well as putting those losses into the same context as their other business decisions.
Once these issues are costed, the cash impact can be judged against each other. The board can then make decisions around potential losses and risk, and decide whether they will invest more to prevent that risk or to use other forms of capital like cyber insurance to hedge against that risk. On top of this, CISOs can take their boards through how they can design business processes to be more resilient.
Resilience involves more than simply protecting IT systems against attack, but where the overall system can carry on running even when something does go wrong. When companies rely on their digital strategies to work and face more threats, they have to invest in the right places to keep their operations functioning. When AI can discover more issues and speed up how fast those issues are exploited, it is impossible to respond to every issue in advance. While CISOs often feel like they carry all the responsibility for cyber and IT security across their organisations, the reality is that directors and board members hold that duty. The solution to this problem is for CISOs to build up more resilience in their company systems, to automate the process around removing issues where possible, and to explain where risk exists in ways that the business can understand and make decisions on.
Matt Middleton-Leal is VP EMEA at Qualys.

