For many years, cybersecurity was viewed as primarily a technical responsibility, carried by IT teams and security leaders.
That view no longer aligns with the reality of modern organizations.
The consequences of a cyberattack now extend far beyond the information systems perimeter: they affect the company’s reputation, regulatory compliance, financial valuation, and, in some cases, its ability to continue operating.
This evolution is fundamentally changing how organizations must think about cybersecurity accountability. While CISOs identify risks and propose strategies to mitigate them, they do not decide budgets, nor business trade-offs, nor the level of risk the organization is truly prepared to accept.
Cybersecurity has become a governance issue as much as a technology issue.
Coupang Case: When Responsibility Reaches the C-Suite
In December last year, Park Dae-jun, Coupang’s General Manager for Operations in South Korea, resigned. A data breach exposed the personal information of nearly 34 million customers, essentially the entire user base. Park Dae-jun said he was stepping down to assume the “heavy responsibility” for this data breach.
His resignation followed government investigators’ conclusion that it was neither an unprecedented attack nor an unavoidable event. A former engineer, who knew the system’s weaknesses, had simply returned through a virtual door the company had forgotten to close. Authorities characterized this incident as a managerial failure rather than a technical one. Responsibility was attributed to the company’s leadership, not the CISO.
In other words, this case illustrates how a lapse can flow up the chain of command to directly implicate the CEO. In such situations, the board’s gaze no longer stops at the security heads alone.
The Limits of the CISO’s Role
For years, leaders have instinctively blamed the CISO when a security incident occurred. After all, he leads the company’s cybersecurity strategy. Yet this reasoning quickly hits its limits.
The CISO does not make the decisions that determine the organization’s actual exposure. He does not set budgets. He does not decide the level of risk the company is prepared to accept. He cannot force various business units to enforce security policies when they pursue other priorities. His role is to present the risks and the different reduction options to the executive committee. It is then up to that committee to decide the way forward.
The consequences of a cyber incident reflect these decisions. If an organization underinvests in cybersecurity, it is not a failure of the CISO. It is a governance choice. When a breach occurs, responsibility should logically trace back to the decision-making power. In most organizations, that power rests with the Chief Executive Officer.
Cyber Failure as a Governance Shortcoming
For a long time, boards treated data breaches as an IT problem. That has always been a mistake. And for many companies, this perception remains today.
However, when the financial and reputational consequences become impossible to contain, that distance disappears. A breach affecting tens of millions of customers creates not only a legal issue: it permanently damages the company’s reputation, affects its stock market valuation, and immediately draws regulatory scrutiny. All of these consequences fall under leadership responsibility.
Just as boards now ask more questions before an incident occurs, regulators are now far more precise after a cyberattack. In the most high-profile cases, regulators view cybersecurity failings not as mere bad luck but as potential evidence of governance negligence.
This pressure is gradually redefining expectations of the CISO’s role. His mission is to provide management with a clear view of risks and the trade-offs they entail. The decisions that follow are then the company’s responsibility. Without top-level impetus, cybersecurity strategies often remain at the level of recommendations.
Aligning Executives’ Bonuses with Overall Security
Embedding this sense of accountability into how an organization functions is far from simple and remains uneven across companies. Much of the issue depends on how leadership performance is assessed and rewarded.
When the CEO’s objectives are primarily tied to revenue growth and pay little attention to cybersecurity outcomes, that naturally shapes the priorities of the entire organization.
In the few companies where cyber accountability is clearly integrated into governance, change typically starts with the expectations set for leadership rather than with technical measures. Boards do not manage daily security operations, but their influence is felt through how risks are discussed, the trade-offs evaluated, and the actions expected of leadership over time.
The challenge is less about naming a culprit and more about clarifying where ultimate responsibility lies when known risks go unaddressed.
When a government investigation concludes that a major data breach primarily stems from governance failure, and a CEO resigns to take responsibility, it marks a subtle yet deep shift in how responsibilities are allocated. In such cases, it becomes evident that a governance problem cannot be solved by a simple technical fix, nor can it be shouldered by the security function alone.
The True Role of Executive Leadership
Organizations rarely change simply because risks are well understood. They evolve when the consequences of their decisions become impossible to ignore. In cybersecurity, that link remains more the exception than the rule. But in the gravest incidents, avoiding it becomes increasingly difficult. Regulatory pressure, market reactions, and public scrutiny now converge on executive leadership more than ever.
The evolution of threats, the tightening of regulatory requirements, and the growing financial impact of cyber incidents make this clarification essential. The CISO’s role is not to bear the organization’s cyber risk alone, but to provide leadership with the visibility needed to make informed decisions.
The real question, therefore, is no longer who will be held responsible after a cyberattack, but how companies today organize the sharing of that responsibility. For when a risk becomes strategic to the business, governance must itself become strategic.
*John Kindervag is Chief Evangelist at Illumio