Deloitte Sri Lanka brought together board directors and business leaders for “Cyber Resilience Starts at the Top: The Board’s Strategic Role in Building a Resilient Organization,” a discussion on how boards can better prepare organisations for complex cyber disruption. The programme explored organisational resilience, cyber readiness, risk quantification and crisis response, and included an interactive cyber wargaming exercise designed to simulate a real incident and help leaders test decision-making and preparedness before a crisis occurs.
Opening the discussion, Malinda Boyagoda, Partner – Audit and Assurance, Assurance Leader and Industry Leader for Financial Services, Deloitte Sri Lanka and Maldives, placed cyber resilience within the wider context of disruption. His session considered risks arising from geopolitical uncertainty, cyber incidents, AI-enabled fraud, vulnerabilities in suppliers and partners, and growing regulatory expectations.
Malinda distinguished risk management from resilience: while risk management aims to reduce exposure, resilience is about keeping essential services running and recovering effectively when disruption occurs. He noted, “Cyber resilience is not simply about preventing disruption. It is about ensuring that critical services can continue, decisions can be made with confidence, and the organisation can recover and learn when disruption occurs.” Board members were advised to clarify responsibilities, test severe scenarios and seek evidence of preparedness rather than rely only on reassurance.
Building on this, Mayuran Palanisamy, Partner and Leader, Digital Trust and Privacy, Deloitte South Asia, focused on the difference between confidence and genuine readiness. He highlighted that confidence in an organisation’s cyber preparedness, including assurances provided by management, should be tested and questioned by the Board of Directors. By seeking evidence that response and recovery plans work in practice, boards can gain greater comfort that the organisation is genuinely prepared for a cyber incident.
Highlighting the role of leadership in strengthening cyber readiness, Mayuran said, “Cyber resilience requires boards to go beyond oversight and take a more active role in execution. This means asking management the right questions about the cyber strategy, ensuring there is flexibility in funding when risks emerge, and making cyber oversight a consistent part of the board agenda.”
The discussion then moved to the financial impact of cyber risk. Rukshan Bharatha, Partner, Controls Assurance, Deloitte Sri Lanka and Maldives, introduced Cyber Risk Quantification (CRQ) as a way of translating technical cyber threats into financial terms for board and leadership decisions. Rather than relying only on high, medium or low ratings, CRQ helps organisations understand what a cyber event could mean in monetary terms.
Rukshan explained, “If we want to understand cyber risk, we need to quantify it. Cyber Risk Quantification converts qualitative measures into financial values, giving boards a more tangible view of potential impact and a stronger basis for decisions on investment and the level of risk the organisation is prepared to carry.” He outlined how business exposure, incident scenarios and existing security controls can be used with statistical modelling to estimate potential losses and support decisions on cyber investment, regulatory requirements and insurance.
The final segment, led by Bhawna Pahuja, Associate Director, Cyber Defense & Resilience, Deloitte India, brought the earlier discussions to life through an interactive cyber crisis exercise. Participants were placed in a fictional financial institution facing an escalating cyber incident and asked to make time-sensitive decisions on containment, business continuity, communications, regulatory engagement and ransom response.
The exercise was designed to reflect the uncertainty and pressure leadership teams may face during a real cyber incident, with participants making decisions based on limited information as the situation evolved. It demonstrated how quickly a cyber issue can develop into an organisation-wide crisis, affecting customers, regulators, investors, reputation and operations. The session highlighted the importance of clear crisis roles, tested recovery plans and leadership teams that are prepared to make informed decisions under pressure.
Together, the sessions highlighted that cyber resilience is an organisation-wide responsibility, supported by informed board involvement, clear measures of risk, tested response plans and decisive leadership. Reflecting on the broader message, Vengadasalam Balagobi, Cyber and Technology Risk Head, and Information Security Leader, Deloitte Sri Lanka and Maldives, noted, “Cybersecurity is about protecting the organisation. Cyber resilience is about ensuring it can continue to operate, recover and adapt when disruption occurs. Organisations that prepare, test and learn before an incident are better positioned to respond with speed, confidence and clarity.”
About Deloitte Sri Lanka and Maldives
Deloitte Sri Lanka and Maldives is a multidisciplinary professional services firm that is part of the Deloitte network. Deloitte offers a range of services, including Audit & Assurance, Tax, Strategy, Risk & Transactions and Technology & Transformation.
Deloitte is among the largest professional services networks globally, with a presence in over 150 countries and comprising more than 450,000 professionals.
Tracy
