Cyber Resilience Starts with Mindset, Especially at Board Level
“It is not a question of whether we will be attacked, but when.”
You hear this line at every cyber conference. It is rarely lived. At the annual event of the SwissBoardForum, in a workshop called “Cyber Resilience Without Illusions,” I saw again why. In a small group, we spoke openly about real worst-case scenarios, emergency plans, crisis teams, the difference between illusion and genuinely tested preparation, architecture and governance. Of all these themes, I want to single out one, because it precedes all the others: mindset.
What flying teaches about reacting under pressure
I explain this through an experience from my work as a flight instructor. During a winch launch, a glider hangs from a cable and is catapulted, like a kite, from 0 to 100 km/h in 2.5 seconds. The critical phase comes just after lift-off, during the rotation into a steeper climb angle. If the cable snaps at that moment, if the winch loses power, or if the pilot pulls the aircraft off the ground too hard, the situation turns dangerous very fast, close to the ground. The options are minimal, and you get exactly one attempt to save it.
As a young flight instructor, I drilled my students and pilots above all on the procedures for saving that situation. In training, though, I noticed that reactions often came too late. The closer to the ground, the more pilots hesitated to act, even though they knew the procedures and had trained them. My own reactions, before I became a flight instructor, were no different. The reason is not a lack of knowledge. It is the moment of shock. As long as the pilot secretly hopes nothing will happen, the realisation that “it has actually happened” costs precious seconds before the procedure is retrieved.
What helped was not an additional procedure. It was a reframing, a mental preparation for the real event, one none of us wants. I taught that in launch preparation, the cable break is the normal case, not the successful launch. The cable will break, as a default assumption! That is not meant to create fear. It is meant to make the decision consciously, before the launch: do I want to launch under these conditions, am I fit for this flight, and can I bring the aircraft safely to the ground at every phase under the prevailing conditions (weather, wet ground, tall grass, crosswind, and so on)? A pilot who launches with this mindset is prepared for the real event and stays capable of acting in any situation. This shift in mindset eliminated exactly the delay that had cost pilots their ability to act. The side effect is notable: the vast majority of launches (by my own count, roughly one genuine cable break per 1,000 launches) become a moment of relief, because the expected emergency does not happen.
The same mechanism plays out on the board
In many boardrooms, the opposite mindset prevails. A cyberattack is seen as unlikely. We are supposedly too small, too unimportant, our industry no attractive target. Or IT is outsourced and everything sits in a well-protected cloud. These assumptions came up at the event too, and they are widespread. They do not hold up to reality, but that is not the real point. The real point is that they serve the same function as wishful thinking in the cockpit. They allow the real event to go unimagined. That is exactly what costs the decisive hours, or even minutes, once an incident hits.
The question of whether to invest further in software, audits, penetration tests or a CISO function usually answers itself quickly. A well-founded risk assessment, one that quantifies the cost of a single serious incident, ends that discussion within minutes. But as long as the underlying mindset, “it won’t happen to us, and if it does, we have backups,” remains in place, every investment stays piecemeal.
The data shows resilience is led, not bought
This observation matches current figures. The World Economic Forum’s Global Cybersecurity Outlook 2026 shows a telling difference:
- Leaders of low-resilience organisations name lack of funding (63 per cent) and lack of skilled staff (56 per cent) as their biggest obstacle on the path to greater resilience.
- Leaders of highly resilient organisations, by contrast, mostly name supply chain and third-party risk (78 per cent). Anyone still stuck on budget and staffing is, as a rule, less resilient.
- Organisations that are resilient have moved past that stage and now manage the ecosystem around them. The budget question is rarely the real obstacle; it is often an expression of mindset.
Fittingly, the same report does not place the traits of resilient organisations primarily in technology. Its Cyber Resilience Compass lists seven fields, among them leadership and people and culture, ranked equally alongside technical systems. Resilience, in other words, is not a product you procure. It is a trait that is led.
What this means in practice for the board
In the cockpit, the individual is responsible. In a company, it is the board. Mindset at board level cannot be left to sentiment; it has to be institutionalised. Concretely, that means:
The board pre-empts the real event in its preparation, rather than treating it as an exception.
The board tests the emergency plan through a run scenario, not just on paper. It confirms that the crisis team has clear roles, and that the board and the executive team actually accept those roles in a crisis. And it turns the question of whether the organisation would be able to act in a real event into a recurring agenda item, not a topic that only comes up after the first incident. Especially in the current phase, as technologies advance at breakneck speed (AI systems and agents, quantum computing, robotics), these risks need continuous assessment and reappraisal.
This is not optional. It is part of the duty of care. Responsibility for risk management falls, under Art. 716a para. 1 no. 1 OR, among the board’s non-delegable duties. Responsibility for cyber risk can be outsourced no more than that overall direction itself can.
This mindset costs no budget, only leadership attention, and in many boardrooms that is scarcer than money. It often achieves more than additional software or external mandates. I am deliberately not writing that it prevents damage. That would be neither truthful nor in keeping with this mindset. But the serious, realistic preparation it triggers can limit damage and shorten outages, and sometimes avert the worst entirely.
From my experience in sport, leadership and, above all, cybersecurity, I am convinced that resilience under pressure rests on the mindset of the individual, the team and the organisation. Without that foundation, neither tools nor processes help. On the board, it starts with a single shift in perspective: the real event is not the exception you hope will never come. It is the normal case you are prepared for.