In April 2025, Marks & Spencer (M&S) faced a significant cyberattack that disrupted its online shopping services for over 15 weeks. The breach compromised personal customer data, including names, addresses, and contact details, though payment information remained secure. The company’s leadership, including CEO Stuart Machin and Managing Director John Lyttle, were thrust into crisis management, balancing technical recovery with customer communication and brand reputation.
In 2024, it was reported that Irish SMEs lost nearly €10 million to email-based scams in the previous year alone, while almost nine in ten companies experienced disruption or financial loss from cyberattacks in the past five years. The average large enterprise in Ireland paid €683,000 in cyber ransoms in 2024 while some have put indirect costs to the economy as result of cyber-attacks at €10 billion.
The scale and frequency of these incidents serve as a reminder that cybersecurity challenges are as much about leadership, culture and strategy as they are about technology. Decisions on verification, escalation and response determine whether a breach is contained or becomes a full-blown crisis.
But as we approach 2026, the convergence of AI-driven threats, human vulnerabilities and geopolitical instability necessitates a comprehensive leadership approach that aligns cybersecurity with broader business objectives.
AI: Innovation, Risk and the Digital Advantage
Artificial intelligence represents both an opportunity and a threat. AI can enable faster threat detection, predictive analytics and automated response, with platforms like Microsoft’s Security Copilot demonstrating how AI can streamline security operations and reduce the burden on technical teams. Yet the same technologies are being weaponised by cybercriminals through autonomous AI tools capable of launching AI-enhanced credential stuffing attacks and bypassing multi-factor authentication.
The question for leaders is not whether to adopt AI, but how to seize the digital advantage while maintaining high levels of trust and organisational resilience.
In Ireland, the adoption curve is steep. A report by AWS indicates that 63% of Irish startups have adopted AI, with 36% embedding it at the core of their business models, significantly outperforming the European average. However, only 7% of Irish businesses feel “very confident” in their organisation’s AI capabilities and only 8% of organisations have taken a truly “AI-first approach,” highlighting a gap between adoption and readiness
Even more concerning is the governance gap. Most Irish organisations still lack formal frameworks for secure and responsible AI deployment. The rise of “Shadow AI” — where employees use unapproved AI tools without oversight — compounds the risk. Eight in ten organisations report employees using free AI tools with no enterprise security controls, while 61% of managers acknowledge AI use even in workplaces where it is formally prohibited.
For leadership, this is the moment to move from awareness to execution. Seizing the digital advantage requires more than just technical investment. Leaders must build cross-functional teams that can interpret AI outputs, challenge assumptions and connect insights to business outcomes. While it might be a stretch to say the future “belongs” to organisations that combine innovation with disciplined governance, at the very least those that treat cyber and AI as integrated components of strategy rather than parallel streams of risk management are giving themselves a critical advantage.
The Human Factor: Culture, Retention and Capability
Despite technological advancements, human error remains a significant vulnerability. Phishing, social engineering and operational errors remain primary sources of cyber incidents, while cybersecurity teams face high stress, burnout and turnover. Technical tools alone cannot secure a business because they cannot mitigate against the human factor.
This challenge mirrors broader business issues. Leaders are expected to cultivate cultures of psychological safety where employees feel able to raise concerns and contribute ideas. Those same practices—encouraging openness, collaboration and accountability—directly impact innovation, employee retention and organisational performance.
Far from being related to “soft” leadership, psychological safety is a performance multiplier. It fuels creative problem-solving in innovation teams and proactive risk mitigation in cyber teams. Teams that feel safe to share ideas or flag mistakes are faster to innovate and quicker to contain breaches. Conversely, a lack of psychological safety can lead to underreporting of issues, stifling of creativity and increased risk exposure.
Unfortunately, the cybersecurity talent gap in Ireland is widening. The National Cyber Security Centre reported 721 confirmed cybersecurity incidents last year, with 309 investigations initiated. Yet demand for cybersecurity professionals exceeds supply, with entry-level roles taking three to six months to fill for 52% of companies.
This shortage is further exacerbated by the lack of leadership training for technical professionals. Many individuals with deep technical expertise are promoted into leadership roles without the necessary management training, leading to a disconnect between technical capabilities and strategic leadership.
At the same time, cybersecurity teams are operating under extraordinary strain. High alertness, constant change and chronic understaffing have created burnout rates that mirror those in healthcare and emergency response sectors, compounded by the constant promotion of highly technical professionals into leadership roles without preparing them for the transition from technical excellence to people leadership.
For Irish businesses, particularly SMEs and rapidly scaling tech companies, the scarcity of cyber talent highlights a wider leadership challenge: how to develop teams with both technical expertise and strategic perspective. Investing in leadership development, coaching and structured career pathways is critical for maintaining organisational resilience and competitive advantage.
Building resilience therefore means reimagining what high performance looks like in technical environments: not relentless availability or heroics, but sustainable, psychologically safe and strategically aligned teams that can balance innovation with vigilance.
Geopolitics: Complexity Without Borders
Cyber risk has become inseparable from geopolitics. Over the past year, state-backed attacks have targeted critical infrastructure, financial systems and global supply chains, often as extensions of political or economic conflicts. Incidents involving Chinese-linked groups exploiting vulnerabilities in enterprise hardware and Russian-affiliated actors targeting European energy networks reveal how digital conflict now operates alongside traditional diplomacy.
For Irish organisations, these global events can feel distant, yet they are anything but. Ireland’s economy is one of the most globally integrated in Europe, hosting more than a thousand multinational firms and relying on deeply connected digital and data supply chains. A single breach in a global vendor or cloud platform can cascade locally within hours. This is what risk experts describe as complex contagion: the way interconnected systems can amplify small shocks into widespread disruption. A ransomware attack on a logistics provider in Germany might delay pharmaceutical shipments in Dublin; a breach in a U.S. partner network could expose Irish customer data before a local business even realises it’s been compromised.
In this environment, traditional approaches to risk management are no longer sufficient. The volatility of the geopolitical landscape demands that leaders think in scenarios — anticipating, rehearsing and stress-testing their responses before crises occur. Increasingly, organisations are adopting red teaming and scenario planning — methods long used in military and intelligence settings — to test their strategic and operational resilience.
A red team acts as a simulated adversary, deliberately probing for weaknesses in systems, processes and decision-making. In cybersecurity, it means simulating a real attack to reveal how a company would respond under pressure, revealing not just technical vulnerabilities but also leadership blind spots: how decisions are made under pressure, how communication flows in a crisis and how competing priorities — between transparency, continuity, and reputation — are managed.
Similarly, scenario planning helps leadership teams explore how emerging threats — from AI-driven disinformation and data sovereignty disputes to sanctions and cyber conflict — could impact their operations and partners. The goal isn’t prediction, but preparedness: developing the strategic agility to adapt when the unexpected happens.
This is where the need to lead through uncertainty becomes most visible. In a world where global instability, technological disruption and information warfare intersect, leadership is less about control and more about adaptability — creating clarity where there is none, making decisions amid incomplete information and communicating with confidence through volatility.
For Irish business leaders, the global system is now so tightly coupled that events far beyond Ireland’s borders — a cyber skirmish in Eastern Europe, a regulatory ruling in Washington or an AI supply chain disruption in Asia — can reshape local markets overnight. Leading through uncertainty, in this context, means recognising that cybersecurity is not a technical niche but a lens through which to understand complexity, resilience and strategy itself.
Leadership and Business Strategy
Organisations that view cybersecurity solely as a technical necessity miss the opportunity to leverage it as a strategic asset. Effective cybersecurity leadership can enhance brand reputation, build customer trust, and ensure compliance with regulatory requirements. Leaders who understand the strategic value of cybersecurity can drive initiatives that align security with business objectives, turning potential risks into competitive advantages.
Cybersecurity reflects wider challenges for leadership: managing complexity, balancing risk with innovation and integrating technology into organisational strategy. Crucially, leadership development can bridge the gap between technical expertise and organisational impact. Leaders who understand AI, human factors and global cyber risk can create organisations that are resilient, agile and capable of turning security challenges into competitive advantage.
The stakes are not hypothetical. Cyber decisions influence innovation pipelines, talent retention and market trust. Organisations that integrate cybersecurity into broader business strategy will be better equipped to navigate 2026 and beyond.
Of course, that’s not a guarantee. But to avoid the guarantee of what happens when leaders don’t do this, there really is little choice.