Iain Cox - 4 Feb 2026
Digital resilience will be judged after the breach and at the board level
At the board level, digital resilience has become less about preventing incidents and more about how decisions are judged once a breach has occurred. Because scrutiny is retrospective, controls, audits and frameworks offer limited protection unless they clearly inform deliberate board-level judgments about risk, trade-offs and acceptable impact. When expert views diverge, reasonable care is assessed through how uncertainty was handled and revisited, not whether the “right” answer was chosen. Regulation increases the visibility of these judgments without removing ambiguity, reinforcing that digital resilience ultimately depends on board judgment under uncertainty.


