The (multi) million-dollar question: what your board needs to know before the breach

Getting cybersecurity wrong costs millions of dollars, customer trust, and sometimes the business itself.

At the NH Tech Alliance’s recent Cybersecurity Summit at Manchester Community College, I moderated a panel we called “The (Multi) Million Dollar Question.” The name was deliberate. Getting cybersecurity wrong costs more than IT tickets. It costs millions of dollars, customer trust, and sometimes the business itself.

I was joined by Lisa King, Senior Account Executive at Cross Insurance; Paige Yeater, CISO and COO of Mainstay Technologies; Katarina Overberg, Associate at McLane Middleton; and Ron Wright, Founder of Pinnacle Logistics Advisors. Between them they covered insurance, technology, legal, and supply chain. Our goal was to help leaders ask the right questions about their security posture before they have to explain what went wrong.

Cybersecurity isn’t an IT problem

The panel agreed on this immediately. Security isn’t something you hand off to IT or your managed service provider. Just as everyone in a company owns the customer experience, everyone owns security. Technology partners are essential, but ownership can’t be outsourced, and it starts with leadership setting priorities and being accountable for results.

Paige addressed a familiar complaint. Long passwords, slow VPNs, and blocked websites are real annoyances, but they’re nothing compared to your company being shut down. Training and phishing simulations are worth the time, because most breaches trace back to human error. Your employees are your greatest asset, and they can be your weakest link if they aren’t prepared.

Your supply chain is part of your security

Ron put it simply: there’s a reason the word “chain” is in supply chain. Your business is one link among suppliers, vendors, distributors, and customers. You can have an excellent security program and still be hit hard by someone else’s incident.

He asked leaders to consider some scenarios. What if your biggest customer is shut down and depends on you to keep operating? What if a competitor goes offline and you’re flooded with demand overnight? What if your vendor’s vendor goes down? Incidents like the Colonial Pipeline attack showed how one compromised link can ripple across an entire industry.

You can’t transfer your accountability

Katarina raised a common and costly misconception: that handing data to a third party also hands off the liability. It doesn’t. Even when a vendor causes the incident, customers and regulators usually hold your organization accountable for the information it collected. Vendor due diligence and strong contract terms are core responsibilities.

She also noted that every company holds personal data, even without customer information, because you have your employees’ records. And a breach isn’t only an outside hacker. It includes any unauthorized access, loss, or disclosure. That’s why least-privilege access matters. Employees and vendors should reach only the information their role requires.

Cyber insurance is one part of the plan

Lisa challenged the idea that a business without customer data doesn’t need cyber insurance. If you have employees, email, a website, or handle financial transactions, you have exposure. Losses often come from ransomware, business interruption, and fraud like invoice manipulation, not just data breaches. A strong policy also connects you with forensics teams, breach coaches, and notification services.

Insurance doesn’t prevent incidents, though, and it only works if you understand it. Policies have specific reporting requirements, and missing them can put your coverage at risk.

What to do today

I closed by asking the panelists what the audience should do right away. They agreed on these steps:

  • Map your dependencies. Could one vendor bring down your business? Find where you rely most on a partner and examine their security practices. Don’t assume they have a strong program.
  • Plan for a manual fallback. Could you operate without your core systems, or process orders without the data feeds you take for granted? Could you support a customer who had to go fully manual?
  • Put governance in place. Set up committees for cybersecurity, risk, technology, or AI governance, with at least one board member and one member of management on each.
  • Minimize what you store. Create a retention policy, delete what you no longer need, and collect only what’s required. Less data means a smaller target and less damage if a breach happens.
  • Know your insurance policy. Understand what it covers and how to report an incident. If you don’t have coverage, talk to your agent.

The panel’s main message was that cybersecurity isn’t a department. It’s a chain, and your resilience depends on the links around you as much as on your own defenses. The million-dollar question is whether you’ll ask these hard questions before a breach or answer them afterward.

Julie Demers is the executive director for the NH Tech Alliance.

Categories: Cybersecurity