
Is your company the weakest link?
Mark Kandborg, Group Chief Risk Officer at Nordea, on why cybersecurity must be a standing board priority, and how understanding your company's unique exposure is the first step to being prepared.
Mark Kandborg, Group Chief Risk Officer (CRO) at Nordea, explains why boards must treat cyber risk as a business-critical issue – and what they can do to prepare before an attack happens.
We live in a world where cybercrime generates more revenue than the illegal drug trade. These are not opportunistic hackers working from their basements. It is organised crime on a vast scale, targeting the weakest link – whether a large corporation, a small business or a sole trader. If criminals find a way in, they will exploit it. The consequences can be devastating.
That is why cybersecurity must be at the top of the board's agenda – not delegated to IT or reviewed only once a year. It must remain a priority.
Everyone is exposed – but the least prepared are targeted first
A common misconception is that cyber risk primarily concerns large companies with complex digital infrastructure. It does not. Cybercriminals strike wherever they find an opportunity – and the least prepared make the easiest targets.
If criminals encounter strong defences, they are likely to move on. That is the key insight for any board: you do not need to be impenetrable, but you do need to be better prepared than the next target.
The board's role – understand your unique exposure
The starting point is not technology, but the business. The board needs to understand the company's specific exposure. Which technologies and online services does it use? Which third-party providers does it depend on, and how prepared are they? How reliant is the company on digital channels to serve its customers?
With that understanding, the board should define a clear risk appetite. What level of risk is acceptable? Which systems must remain operational under all circumstances? The answers should guide decisions on backups, data resilience and how quickly the company can switch to alternative systems after an attack.
Three pieces of advice
- Understand your unique exposure
Map the vulnerabilities in your business model, the technology you use, the services you depend on and the third parties with access to your systems. You cannot manage a risk you have not defined. - Train, train, train
Train employees to practice good cyber hygiene. Test contingency plans so everyone knows how to respond if an attack succeeds. Prepare the board and management to act, ensuring that they know which third-party specialists can help contain an attack quickly. A contingency plan that has never been tested is not a plan. It is just a document. - Make cybersecurity a standing agenda item
Cybersecurity is not a one-off exercise. The board needs regular reporting: Are systems being patched and updated? When were contingency plans last tested? The conversation must be ongoing, because the company's preparedness needs to keep pace with the threat.
Want to hear more from Mark Kandborg?
Watch the full conversation (5 min) on Boardway Academy – sign up for free to get access.


