Boards have accepted responsibility for cyber risk. Now they must focus on the place where so many breaches actually begin: identity.
Kim Stewart Smith’s recent article makes an important argument. Cybersecurity and artificial intelligence are no longer operational IT concerns. They are governance issues. Boards are accountable for enterprise risk, and cyber now sits alongside financial, legal, regulatory, and operational risk as one of the most significant threats facing an organization.
That is an important and overdue shift. But there is another question boards should now be asking. It is not simply whether cyber belongs in the boardroom. It is whether the board is spending enough time on the part of cyber that determines whether an attacker gets into the organization in the first place.
Most board discussions about cybersecurity still revolve around firewalls, endpoint protection, ransomware recovery, threat detection, incident response, cyber insurance, resilience, and disaster recovery. All of those investments matter. But they share one uncomfortable assumption: the attacker has already made it inside.
That is increasingly where the cybersecurity conversation has gone wrong, because today’s attackers often do not need to break through the walls of an enterprise. They simply walk through the front door using what appears to be a legitimate identity.
Many of today’s most damaging attacks begin with identity. Attackers steal credentials through phishing, manipulate help desks, relay MFA requests, overwhelm users with authentication prompts, hijack sessions, or simply convince an employee to authenticate the attacker.
The result is enormously difficult for traditional security tools to recognize because, from the system’s perspective, the attacker appears to be a legitimate employee. Attackers are no longer necessarily breaking in. They are logging in, and that should fundamentally change the boardroom conversation.
If identity has become one of the primary attack surfaces, boards should be asking why so much cybersecurity spending is devoted to detecting and containing attackers after compromise while comparatively little attention is paid to making unauthorized authentication impossible in the first place.
This shift toward identity based attacks is already well documented. Stolen credentials, phishing, social engineering, MFA fatigue, and session hijacking have become standard attack techniques, while generative AI is making phishing campaigns and fake login environments increasingly convincing and scalable.
Organizations spend enormous sums on technologies designed to detect attackers once they have entered the environment. Endpoint detection, extended detection and response, security information and event management, threat hunting, behavioral analytics, and incident response platforms are all necessary components of modern security architecture.
But think about the underlying economics. Imagine applying the same strategy to physical security. Instead of installing a secure front door, an organization would allow intruders into the building and then hire hundreds of guards, cameras, investigators, and response teams to find them after they entered.
No board would consider that a sensible physical security strategy. Yet the cybersecurity industry has spent years building increasingly sophisticated systems for identifying attackers once they are already moving around inside the organization. That makes prevention at the identity layer a board level economic issue as much as a technical one.
Kim Stewart Smith is right that directors cannot simply delegate cyber accountability to the IT department. That same principle should apply specifically to authentication.
Boards should understand how employees prove their identity before they are granted access to corporate systems. They should also understand whether that authentication mechanism can be manipulated remotely through phishing, social engineering, credential theft, an MFA relay attack, or a compromised recovery process.
This does not require directors to understand cryptography or authentication protocols. It requires them to ask better governance questions. One of the most important is remarkably simple: what evidence do we have that the person accessing our most critical systems is actually the authorized person?
That question deserves the same level of scrutiny as financial controls, regulatory compliance, succession planning, and operational resilience. Because if the answer is simply a password, an SMS message, a six digit authentication code, or a push notification on a phone, the organization may not actually know who is authenticating.
Legacy MFA increasingly leaves exactly that gap. Phishing and real time relay attacks can trick users into authenticating an attacker because many traditional authentication systems verify possession of a code or approval of a request rather than establishing strong assurance of the actual human identity involved.
Passkeys are an important improvement over passwords and legacy MFA. At the protocol level, FIDO2 and WebAuthn were designed to resist traditional phishing by cryptographically binding authentication to the legitimate service.
But boards should not assume that every passkey implementation delivers the same level of security. In practice, many passkeys are synchronized through consumer cloud accounts, live on general purpose phones or laptops, and exist alongside account recovery mechanisms, device replacement processes, fallback authentication, help desk procedures, and other systems that attackers can target.
That means the core cryptography may be strong while the overall implementation still contains weaker paths around it. A cloud account takeover, compromised endpoint, social engineering attack against account recovery, or weak fallback process can undermine an otherwise strong authentication architecture.
The question therefore cannot simply be, “Do we use passkeys?” The better board question is, “Can our identity system still be bypassed through another device, account recovery process, cloud account, help desk intervention, or fallback method?”
That distinction matters enormously. Passkeys are progress, but for high value enterprise access, boards should be looking for identity assurance that extends beyond a cryptographic credential and establishes with much greater certainty that the authorized human being is physically present and approving access.
For many years, cybersecurity strategy depended heavily on training employees to recognize suspicious activity. That becomes harder every year as generative AI makes it possible to produce highly convincing phishing emails, executive impersonations, voice calls, fake login pages, and social engineering scripts at enormous scale.
Attackers no longer need exceptional language skills, design ability, or deep technical expertise to create believable attacks. Security awareness training remains useful, but expecting every employee to correctly identify every sophisticated attack is not a security architecture. It is an increasingly fragile dependency.
The stronger approach is to build authentication systems in which an employee can make a mistake and the attacker still cannot gain access. That is the fundamental difference between trying to make humans impossible to fool and making authentication impossible to steal.
At Token, our view is that enterprises need to move beyond simply asking whether a user possesses something or knows something. The stronger question is whether the system can establish that the correct human being is physically present and authenticating to the correct destination.
Token approaches that problem using dedicated biometric hardware, FIDO2 cryptography, domain binding, and proximity. The authentication credential is tied to the legitimate destination, the user must provide a fingerprint match on the device, and the device must be physically present with the person authenticating.
There is no authentication code for an attacker to steal or relay, no push notification that an employee can accidentally approve, and a spoofed domain cannot simply request authentication successfully. Unlike many consumer passkey implementations, the identity credential also does not need to float between personal devices through a consumer cloud account.
That creates a fundamentally different security model. Rather than relying primarily on what the employee knows, what their phone contains, or whether they make the right decision when presented with an authentication request, the system requires physical biometric proof tied to dedicated hardware and the legitimate destination. That is much closer to identity assurance than traditional authentication.
Boards do not need to select authentication products. Management and security teams should still evaluate and deploy the appropriate technologies. But directors should absolutely be asking whether the organization’s identity architecture reflects the threat environment that exists today rather than the one that existed five years ago.
They should be asking how easily an attacker can impersonate an employee, whether MFA can be phished or socially engineered, whether help desk procedures can bypass authentication controls, whether a passkey can be recovered or synchronized through a compromised cloud account, whether fallback mechanisms quietly undermine stronger primary authentication, and whether privileged administrators are protected differently from ordinary users.
Most importantly, boards should ask whether the organization can prove that the actual authorized individual approved access to a critical system or transaction.
Those are no longer technical implementation questions buried deep inside an IT report. They are questions about enterprise risk, and enterprise risk belongs to the board.
Kim Stewart Smith describes a board meeting where the cybersecurity update received four minutes while a property lease received forty. That comparison should make directors uncomfortable.
But there is an even deeper issue. Even when boards give cyber more time, much of the discussion still focuses on what happens after an attacker gets in. The next evolution in cyber governance is to move the conversation closer to the front door.
Identity should become one of the first cybersecurity questions boards ask, because nearly every other security control becomes more difficult and more expensive once an attacker has successfully authenticated as someone the organization trusts.
Cyber belongs in the boardroom. AI belongs in the boardroom. And increasingly, identity belongs there too, because attackers do not always need to break into the enterprise anymore. They can simply log in.
The board’s job is to make sure they cannot.