Cybersecurity and AI Urgency: Francisco Gaffney Calls for Boardroom Action

F

Francisco Gaffney

LinkedIn Author

Board Advisor | Chairman| ex-SAP & Teradata | PLC, SME & Mid Market Firms

In a recent LinkedIn post, Francisco Gaffney discusses the accelerating pace of cybersecurity and artificial intelligence advancements, urging business leaders and boards to take immediate action. Gaffney highlights a critical gap in board-level expertise, pointing to a statistic that underscores the need for greater focus on these evolving threats.

The Growing Disconnect Between Technology and Board Oversight

Francisco Gaffney emphasizes that the speed at which cyber threats and AI capabilities are evolving significantly outpaces traditional board meeting cadences and established governance routines. This rapid advancement creates a dangerous lag in strategic decision-making and risk mitigation. As Gaffney notes,

Cyber and AI advance faster than most board routines.

This disparity means that by the time a board fully grasps a current threat landscape, new and potentially more sophisticated challenges have already emerged. Gaffney reinforces this point with a concerning statistic about the lack of dedicated cybersecurity representation at the highest levels of corporate governance.

Addressing the Cybersecurity Board Member Deficit

Gaffney presents data that illustrates a significant shortfall in dedicated cybersecurity expertise within boardrooms. According to the post, a mere 27% of businesses had a dedicated cybersecurity board member by 2025. This statistic is particularly alarming given the increasing sophistication and impact of cyberattacks on businesses of all sizes.

By 2025, only 27% of businesses had a dedicated cybersecurity board member.

The implications of this lack of specialized oversight are profound. Without individuals at the board level who possess a deep understanding of cybersecurity risks, organizations are more vulnerable to breaches, data loss, and operational disruptions. Gaffney argues that this is not merely a matter of resource limitation but a conscious operational choice.

The Choice Between Action and Inaction

Francisco Gaffney makes a strong case that organizations failing to prioritize cybersecurity and AI governance are making an active decision to accept the associated risks. He states,

If your organization hasn’t prioritized this, it’s an operational choice, not a limitation.

This perspective shifts the narrative from one of external constraints to internal accountability. Gaffney suggests that the necessary expertise and frameworks can be developed or acquired, and the delay in doing so reflects a lack of strategic will rather than an insurmountable obstacle. He further extends this concern to executive teams, noting that even those operating without a formal board structure face similar challenges.

Executive Teams Face Parallel Complexities

Gaffney’s analysis extends beyond traditional corporate boards, recognizing that leadership structures vary. He points out that executive teams, whether formally constituted as a board or not, grapple with the same intricate issues and constraints related to cybersecurity and AI. The fundamental need for proactive, informed decision-making remains consistent, regardless of the specific governance model.

In conclusion, Francisco Gaffney’s LinkedIn post serves as a critical call to action for business leaders. He urges a faster, more informed approach to cybersecurity and AI governance, emphasizing that the time for deliberation has passed and the era of decisive action is now.

📝 About This Content

This article is based on insights shared by Francisco Gaffney on LinkedIn.

📅 Originally posted on April 17, 2026 | View original post on LinkedIn →