Edna Conway: Boards Must Move Beyond Cyber Compliance
Edna Conway urged boards and executives in a recent podcast to treat cybersecurity as governance, not checklist compliance, and to prioritize supply-chain resilience, AI risk planning and workforce training.
Edna Conway, a cybersecurity leader with more than 40 years in law, engineering and security roles, warned in a recent podcast that compliance alone will not protect organizations. She urged boards and senior executives to shift from checkbox audits to active risk governance.
Conway described governance as setting strategy, defining risk appetite and ensuring the organization can adapt. Compliance, by contrast, verifies whether specific controls meet standards. Many boards treat security as an item to audit rather than a program that requires ongoing oversight and trade-offs; that approach, Conway argued, increases exposure to sophisticated attackers and to supply-chain disruption tied to geopolitical changes.
On supply chains, Conway recommended that organizations map critical suppliers, test alternative sources and build resilience into procurement and vendor-review processes so that outages or sanctions do not cascade into major service failures. She said those steps require targeted investment and clearer accountability at the board level.
Conway addressed emerging technologies that will reshape digital infrastructure, including artificial intelligence, blockchain and quantum computing. She noted that AI can add capabilities for threat detection and automation while also creating new attack surfaces and raising ethical questions. Conway called on leaders to include AI risk planning in regular budget cycles and to weigh resources between new development and protection.
Workforce planning featured in Conway’s remarks. She urged focused upskilling so staff can manage modern tools, from secure coding and cloud operations to AI governance. Conway recommended training programs and tighter alignment between engineering, legal and security teams to reduce gaps attackers often exploit.
Conway described collaboration among industry, academia and government as a way to share threat intelligence and develop standards. “Compliance alone won’t protect organizations,” Conway warned, and she said security operations focused primarily on detection need reassessment as AI speeds attack cycles.
On budgeting, Conway advised that boards reframe security spending as risk management rather than cost. That includes funding resilience exercises, supplier audits and modernization of legacy systems, along with scenario planning and tabletop exercises to test incident response and guide capital allocations.
Conway contrasted past technology shifts with future change, noting tools often move from single-use capabilities to global infrastructure and that governance must adapt as technical systems scale. She encouraged executives to ask specific, risk-focused questions about exposure, readiness and recovery plans. Conway’s recommendations reflect discussions across the industry about moving from compliance checklists to integrated governance and preparing for the operational and ethical challenges of advanced technologies.








