Presented by Okta
Cyber security is much more than just a technology issue. As AI tools become increasingly powerful and cyber threats grow more sophisticated, boards are being challenged to think differently about risk, resilience and organisational culture.
In this episode, Ben King, Vice President for Security, Trust and Culture at Okta, explains why an organisation's people remain one of its greatest strengths and vulnerabilities. He discusses how attackers exploit trust, urgency and human behaviour, why deepfakes and AI-generated scams are becoming more convincing, and what leaders can do to create an environment where employees make better security decisions.
Ben shares practical insights on measuring cyber culture, identifying meaningful indicators beyond training completion rates, and encouraging behaviours that strengthen organisational resilience. He also explores how AI agents are creating new governance challenges, including questions around visibility, access, accountability and oversight.
The conversation examines the role of directors before, during and after a cyber incident, the importance of scenario planning and rehearsal, and why organisations that recover most effectively are those that establish clear responsibilities and regularly test their response plans. Ben also outlines the questions boards should be asking as AI adoption accelerates and the boundary between human and digital workforces continues to blur.
Key takeaways
Key Takeaways:
Culture is a frontline defence — cyber resilience depends not only on technology, but on the everyday decisions employees make when faced with risk
Social engineering is becoming more sophisticated — AI is enabling more convincing phishing campaigns, impersonation attempts and deepfake-based attacks.
Look beyond compliance metrics — measures such as employee reporting, engagement in voluntary security initiatives and behavioural trends can provide stronger insights into cyber culture.
Leadership behaviour shapes outcomes — when boards and executives consistently prioritise security, those expectations flow throughout the organisation.
Preparation drives resilience — clearly defined accountabilities, response playbooks and regular crisis exercises help organisations respond more effectively when incidents occur.
Cyber threats come from a range of actors — financially motivated criminals, nation states, activists and opportunistic attackers all present different challenges.
Ask the right questions — boards should focus on visibility, governance, access controls and whether the organisation can rapidly disable AI systems or accounts when required.
Explore more conversations
Already a member?
Login to view this content