Five takeaways from Tobias Jaeger on cyber resilience, AI and executive responsibility, and the questions every organization should be asking before an attack occurs.
On 8 September, the Amsterdam Institute of Finance welcomed alumni, participants and other finance professionals to Capital C in Amsterdam for an evening dedicated to one of today’s most pressing leadership challenges: cybersecurity. Tobias Jaeger, Founder & CEO of Falcone International, challenged executives to rethink how they assess cyber risk, prepare for disruption and take responsibility in the boardroom.
Cybersecurity is no longer simply an IT issue. Growing dependence on digital infrastructure, increasingly interconnected supply chains, AI-enabled threats and new regulation have fundamentally changed the nature of cyber risk.
That was the central message of Tobias Jaeger, expert in risk management and organizational resilience, during his keynote Cybersecurity and the boardroom: what executives need to know. Rather than trying to cover every aspect of cybersecurity, Jaeger structured his presentation around five points executives can use to have a more informed and critical conversation about cyber risk.

Tobias Jaeger, Founder & CEO, Falcone International
“You will not be judged on whether you were breached. You will be judged on how long you were down.”
– Tobias Jaeger, Founder & CEO, Falcone International
From preventing breaches to managing disruption
One of Jaeger’s first challenges to the audience was to reconsider a seemingly obvious question: “Are we secure?”
There is no honest yes-or-no answer, he argued. Organizations should assume that incidents can occur and focus on their ability to withstand and recover from disruption. “You will not be judged on whether you were breached. You will be judged on how long you were down.”
The financial consequences can quickly become significant. Jaeger pointed, among other examples, to Jaguar Land Rover and Marks & Spencer to illustrate the potential cost of prolonged downtime. His broader point was not to predict precisely how much the next cyber incident will cost, but to understand which services are critical and how long the organization can realistically function without them.
For boards, that means defining a maximum tolerable period of disruption for each critical service, assigning ownership and deciding in advance what happens when those thresholds are exceeded.
Your cyber risk does not stop at your organization
A second challenge is that an organization’s own security is only part of the picture. Suppliers, software providers and other parties in the wider digital ecosystem can provide an entry point for attackers.
Jaeger used recent incidents to show why traditional vendor risk management may not be enough. Organizations tend to map the parties they pay and have contracts with. But credentials can remain active after contracts expire, while vulnerabilities may originate with fourth parties that the organization does not directly know or control.
At the same time, regulation is shifting responsibility upwards. Jaeger highlighted how European frameworks such as NIS2 and DORA are moving accountability beyond IT and further into the boardroom.
The implication for executives is clear: cyber risk cannot simply be delegated to the IT department or a risk specialist.
“The money still moves the old way, through a person approving a payment.”
Program spotlight: Cybersecurity for Executives
Cyber risk is now a boardroom issue. This hands-on executive program helps senior leaders engage credibly with cybersecurity, IT, risk, compliance, legal, and communications teams. Learn to assess cyber and information risk at executive level, strengthen governance and oversight, and lead effectively through cyber incidents.
Become boardroom-fluent in cyber in 2 days:
Explore the program or contact AIF for personal advice: +31 20 246 7140 | info@aif.nl
AI changes the attacker, but people still authorize the payment
AI inevitably entered the discussion. Jaeger cautioned against focusing exclusively on futuristic scenarios involving fully autonomous cyberattacks. AI is already making it easier to scale and improve parts of an attack, but many successful frauds still depend on a familiar weakness: a human being making a decision.
He referred to business email compromise and the widely reported Hong Kong deepfake case, in which criminals used convincing video to support a fraud involving approximately US$25 million. The decisive step was still human authorization.
His practical conclusion for executives was therefore deliberately straightforward: “The money still moves the old way, through a person approving a payment.” That makes authorization processes one of the controls organizations can strengthen now.
From presentation to boardroom reality
Following the keynote, Jaeger continued the conversation with Myrthe van der Erve, CEO of Sijthoff Media.
The discussion quickly moved from cybersecurity theory to the decisions executives face in practice. Van der Erve raised a question many business leaders may recognize: is a company of relatively modest size really an attractive target?
Jaeger’s answer was unequivocal. Cybercrime has developed into an industry, and being smaller does not mean being invisible. Organizations with revenue, employees, data and digital systems can all be potential targets.
Their conversation also explored what happens after an incident. How transparent should an organization be with customers? Can the way a company responds to a breach actually rebuild trust?
For Jaeger, preparation, execution and communication all matter. An incident immediately exposes how seriously an organization has prepared beforehand. Companies that have flexible plans, know who is responsible and communicate effectively can potentially emerge from a crisis with customer trust intact, or even strengthened.
Van der Erve then made the scenario concrete: what if you discover a breach at 7 a.m.? What should an executive do in the first 60 minutes?
Jaeger’s first recommendation was strikingly simple: call the specialist you have already lined up to help you. If an organization only starts looking for professional support after discovering an incident, valuable time is already being lost.
The first challenge is often establishing what has actually happened. Which systems or data are affected? Does the attacker still have access? Is the incident contained or still developing? That makes preparation crucial. Organizations should know whom to call, have a communication approach ready and work through scenarios before a real incident forces them to make those decisions under pressure.
The discussion also highlighted that recovery is about more than getting systems running again. An organization has to catch up on what was missed while simultaneously resuming normal operations. The consequences can therefore extend to customers, employees, company culture and strategic plans.
“Your board minutes are your defense, and most boards cannot write them.”
Questions from the audience: what does cyber resilience mean in practice?
The audience then brought another layer to the conversation. Questions ranged from regulation and board expertise to investment decisions and cyber resilience. Two exchanges in particular captured the practical dilemmas in the room.
How much cybersecurity is enough?
One audience member used a particularly fitting Amsterdam analogy: securing an organization is a little like locking a bicycle. You may not need the best lock on every bicycle in the city, but you do not want yours to be the easiest target.
Jaeger agreed with the underlying principle. Attackers looking for opportunities may move on when their initial probing reveals a sufficiently strong security posture. The catch is that such a posture has an expiry date if an organization does not continuously maintain it.
Rather than starting with the question “How much should we spend?”, Jaeger suggested starting from the inside: mindset, internal standards, controls and regular checks that those standards are actually being upheld. Once those fundamentals are understood, the required investment becomes easier to determine.
Does a board need cybersecurity experts, or executives who know which questions to ask?
Another audience member questioned the relatively low level of disclosed cybersecurity expertise on boards. Jaeger’s presentation showed that only 14.7% of a sample of 1,000 Russell 3000 proxy statements disclosed a director with cybersecurity expertise, compared with 100% disclosing a financial expert.
But the discussion went beyond simply adding an IT specialist to the board. Cyber literacy matters across leadership. Directors need to be able to ask the right questions, challenge specialists and make informed decisions about issues such as acceptable downtime, customer communication and incident response.
A CISO or risk executive can advise the board, but cannot assume its responsibility. As the discussion concluded: the adviser advises; the executive remains responsible for the risk and the decision.
Five takeaways for the boardroom
Jaeger brought the evening back to the five messages that had formed the backbone of his presentation:
- You are judged on how long you were down, not on whether you were breached.
- An attack comes through someone you have no contract with.
- There is no longer one map, and the liability moved rather than left.
- AI changed the attacker first. What breaks is authorization.
- Your board minutes are your defense, and most boards cannot write them.
Behind those five points sits a broader governance question. Regulation increasingly requires boards not simply to approve cybersecurity policies, but to demonstrate that they understood what they approved. As Jaeger put it in his presentation, the question is whether executives can show that understanding.
His closing advice to the audience was more personal and practical: keep your eyes open in your daily activities, keep learning about a field that continues to evolve rapidly, and trust your instincts when something does not feel right.
The conversation continued afterwards over drinks at Capital Kitchen, giving AIF alumni, participants and guests the opportunity to exchange experiences and continue discussing the challenges raised during the session.
Thank you to Tobias Jaeger, Myrthe van der Erve and everyone who joined us at Capital C for an insightful evening of discussion, questions and networking. We look forward to welcoming the AIF community again at our next Alumni Network Event.
Read more:
The Firewall Fallacy: Tobias Jaeger on why cyber risk belongs in the boardroom
Meet the expert
Tobias Jaeger, Founder & CEO, Falcone International
Tobias Jaeger is an expert in risk management and organizational resilience, with more than 15 years of international experience across finance, energy, software, media, and other sectors. He is the Founder and CEO of Falcone International.
Read more about Tobias Jaeger’s expertise and programs.
Program spotlight: Cybersecurity for Executives
Cyber risk is now a boardroom issue. This hands-on executive program helps senior leaders engage credibly with cybersecurity, IT, risk, compliance, legal, and communications teams. Learn to assess cyber and information risk at executive level, strengthen governance and oversight, and lead effectively through cyber incidents.
Become boardroom-fluent in cyber in 2 days:
Explore the program or contact AIF for personal advice: +31 20 246 7140 | info@aif.nl
![]()