In this episode of Inside Cybersecurity, former Palo Alto Networks CEO and Chairman Mark McLaughlin joins René Bonvanie to discuss how cybersecurity has moved from a CISO issue to a board-level responsibility. The conversation explores how boards should evaluate cyber maturity, why AI is changing the economics and scale of attacks, and why organizations need to understand how much of their security response still depends on human intervention. Mark also discusses the growing importance of resilience, digital sovereignty, and control as geopolitical fragmentation reshapes how governments and large enterprises think about critical data. Mark draws on his experience leading Palo Alto Networks, serving on the President’s National Security Telecommunications Advisory Committee, and advising companies at the board level to explain why cybersecurity can no longer be treated as a problem that can be solved once and set aside. This episode of Inside Cybersecurity examines the strategic questions boards, CEOs, and security leaders should be asking as AI, regulation, and geopolitical pressure change the operating environment. Mark McLaughlin: You don’t have to solve cyber. I don’t think it is a completely solvable thing. But if you can be better at cyber than your nearest competitor, that is a competitive advantage. Another way to look at it is: can I be as good as I can be, and better than the competition? Because now cyber can be a strategic advantage. It can be a selling advantage. Some of the best CISOs I have worked with understand that their job is not only to protect the organization. It is also to translate that work for the CEO and the go-to-market organization and say: we are good at this, and we should let people know that, because customers care about their data, privacy, and security. René Bonvanie: A lot has been said about the role of AI. Is it giving boards and executives more hope, or more fear? Mark McLaughlin: It is still very early. Some security leaders have treated AI as another application and said, we have been securing applications for a long time, so we will allow it or block it. But that is changing quickly. Organizations are starting to understand that they lack visibility. After that, they are also lacking the ability to apply granular control. What you want to do is harness AI and make it productive, but do it securely. The question is whether your infrastructure and systems allow you to do that. Right now, the answer is: not really. The number of attacks is going to continue to rise, and AI has made it possible to launch sophisticated attacks at very low cost. The question is how many of those attacks can be handled without a human. If humans remain the primary resource, organizations will always fall behind. AI has made that problem more acute, but it also creates the opportunity to bring machines to the defense. We now have algorithms fighting algorithms. Organizations need to lean into that. René Bonvanie: What should boards ask their security leaders? Mark McLaughlin: Ask one question every quarter: how many attacks did we see, and how many required human involvement? If the human ratio is not stable or declining, that tells you where to focus. If it is increasing, the organization may not fully understand the problem, much less the solution. The second question is how the security team views AI. If the answer is simply that AI is another application, I would be skeptical. René Bonvanie: We are also hearing more about digital sovereignty. Why is that becoming more important? Mark McLaughlin: Five years ago, sovereignty was discussed primarily in the context of privacy. Today, it means something broader. The question is whether an organization or a nation knows where its data is, how it is being used, and what level of control it has over that data. In AI, the leading question is who gets to use your data for training. Do you know it is happening? Do you have any say in it? Sovereignty now involves architecture, privacy, national policy, and security. Ultimately, it comes down to control. Geopolitical polarization is also likely to push nation-states and major enterprises toward greater control over critical data. The period of assuming complete globalization is over. Governments and large multinational organizations will increasingly try to control where their data sits, how it is processed, and which infrastructure it depends on. We are already seeing that in regulation and data center investment, and we are likely to see more of it. Thanks for listening. Subscribe for free to stay up to date with Inside Cybersecurity by Cylake. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cylake.substack.com