Looking for cyber risk in the wrong places
Mon, 21st Sep 2026 (Today)
Cyber risk hasn't just grown. It's moved. And our conversation needs to shift. While most organisations are securing the right things, they're doing so in the wrong place. For years, cybersecurity has been built around a simple idea: protect the system, reduce the risk. This logic made sense when most of the value and exposure sat inside those systems - but it is no longer the case.
Today, a significant portion of risk lies in the processes that surround them, particularly with how software is developed, tested and deployed. The pipelines that move code from idea to production have quietly become part of the attack surface. In many cases, they are also the least governed and understood.
This is a growing blind spot. Gartner predicted that 45% of organisations would experience an attack on their software supply chain by 2025. The reality, as reported by various industry research analysts, consistently shows that software supply chain incidents are rising and in some reports exceeded the prediction. At the same time, development environments and automation pipelines continue to expand, often without the same level of oversight applied to production systems.
Businesses need to move fast to adapt with market and technology changes, and these environments are designed for speed. Automation removes friction. Workflows trigger automatically. Code is pushed, tested and deployed in continuous cycles. That speed is a genuine advantage - but it comes paired with exposure that grows just as quickly.
The systems and internal processes organisations trust most are now viable entry points for attackers. Not because they are inherently insecure, but because they are built to prioritise speed, collaboration, and ease of use. In many cases, they operate with elevated permissions and implicit trust. That changes the nature of the problem.
Cyber risk is no longer just about keeping attackers out; it's also about understanding how trusted processes can be used in unintended ways. Modern infrastructure is often deployed quickly, with default settings left in place and rarely revisited. Permissions are broader than they need to be. Access controls evolve over time. What begins as a practical decision during development becomes a persistent exposure. This is not a failure of technology. It is a failure of governance.
A default permission here, or an automated trigger there, may seem minor in isolation. Together, they create a level of exposure that is difficult to see, and even harder to quantify. This is where the conversation needs to shift.
Cybersecurity is still largely framed as a technology problem, addressed through better tools and more detailed dashboards. But the next phase of maturity will be defined by whether organisations can understand where their exposure actually sits - across systems, processes and dependencies - and translate that into business risk. Because the real issue is structural.
A vulnerability in a development pipeline does not stay contained. It moves downstream into the software being built, the organisations using it, and ultimately the customers relying on it. That is what makes software supply chain risk so consequential. It scales quietly, and it propagates quickly.
And yet, most governance frameworks are still catching up to this reality.
Boards are being given more cyber data than ever before, but often without the context needed to interpret it. They can see alerts, incidents and vulnerabilities, but not necessarily how those risks connect to core business functions or where the most material exposures actually sit. The result is a gap between perceived risk and actual risk.
Closing that gap requires a shift in mindset. Not just asking "are our systems secure?", but also "where does risk now live within the business?" Because in many cases, it is no longer where it used to be.
The organisations that move first will have an advantage because they understand risk well enough to manage it as part of the business, not separate from it. But for now, most enterprises are still looking in the wrong place.