Cyber security: checks are still sporadic in more than half of all companies
Cybersecurity must be integrated into corporate governance, extending beyond IT functions to protect the value of the business
The digital age is over. Or rather, it has entered a new phase. IT infrastructure has become the nervous system of organisations, business processes and relationships with customers, suppliers and institutions, but this consolidation has not been matched by equivalent progress in security, which has historically been treated as a separate function, delegated to a technical department and assessed using criteria that date back to when the Internet was, albeit very promising, still just one channel amongst many. But if everything is digital today, cybersecurity cannot remain confined to a single department; it must be embedded in the organisation’s processes, decision-making and governance.
Cybersecurity unfortunately suffers from an original sin, namely that it has always been a discipline focused on protecting data, databases and networks, and confined to IT departments. Companies, managers and boards of directors have always treated it as a technical issue, and anything perceived as technical rarely features among business priorities. Consequently, two parallel worlds have developed — the world of security, which talked about firewalls, vulnerabilities, patches and compliance, and the world of management, which talked about growth, customers, markets and results — which at a certain point ceased to communicate with one another. But in doing so, we have built giants with feet of clay.
Cybersecurity: checks in companies remain sporadic
A study we have just completed as Strategic Management Partners involving 80 large Italian companies confirms just how wide the gap between awareness and operational governance really is. In more than half of the companies, cyber risk assessments are carried out sporadically: 45 per cent conduct assessments only once a year, and one in ten does not even have a set frequency for such assessments. In two out of three cases, there are no KPIs to measure the level of security achieved — which means that boards discuss cybersecurity without having any metrics to assess it.
The most critical finding, however, concerns the supply chain: only 12 per cent of businesses regularly check the security of their suppliers, 25 per cent carry out no checks at all, and 63 per cent do so only occasionally. This is despite the fact that the European regulatory framework — NIS2, DORA, AI Act — has shifted responsibility across the entire supply chain, making the supply chain the effective perimeter of security. The problem is that many organisations continue to view security as a necessary cost, if not a bureaucratic burden, and merely as a function for protecting data. Yet the reality tells a different story. Over 80 per cent of the most damaging incidents in Europe are linked to ransomware and digital extortion, the aim of which is not the data itself, but rather to disrupt the organisation’s ability to operate. Data is not the end goal, but the means; the real target is business continuity and the value generated by the organisation: in a word, the business in its entirety.
This is all the more urgent with the advent of iartificial intelligence, which acts as a catalyst for the problem: integrating AI and cloud models into business processes means multiplying the attack surfaces, yet our research shows that awareness of this specific risk is still lagging behind. Companies invest in cybersecurity primarily to comply with regulations, without turning compliance into a tool for governance and organisational efficiency. This is why we must stop viewing cybersecurity as an IT function and start integrating it into business strategies, shifting from data protection to value protection, and from technological control to organisational resilience.

