Not all breaches are caused by cyber attacks. In fact, many of the most damaging incidents I see have nothing to do with technical vulnerabilities, and everything to do with how organisations send information out.
It’s tempting to think of cybersecurity and compliance as “IT problems” or “data protection problems,” but they are organisational responsibilities. Every business area, from HR to research, from finance to student services, generates and handles information. And it’s senior leadership that sets the tone for how it's managed.
Governance isn’t the most glamorous part of cybersecurity or data protection. It doesn’t make headlines like a breach or turn heads like a shiny new AI tool. But if it’s not in place, even the best technology can’t save you.