Assume the Breach: A Board's Guide to Cyber Resilience

We have spent years investing in prevention firewalls, endpoint protection, identity controls, the works. And those things matter. But the premise underneath them, that the right tools will stop a breach is no longer a reasonable operating assumption.
Attackers are using AI to move faster than our defenses can respond. Third-party breaches doubled year over year. The perimeter we spent decades securing no longer exists. A determined adversary will get in.
What Regulators Are Actually Saying in 2026
The current regulatory shift may feel like relief. Boards should be careful about what that signal means for cyber risk.
New leadership at the Fed, OCC, and FDIC has moved away from prescriptive supervision, refocusing examination on material financial risks. The Federal Reserve has directed examiners to ask "What vulnerabilities would lead to the failure of this institution?" rather than "Are the policies properly documented?" — and has begun downgrading MRAs that address process and documentation to nonbinding observations.
But deregulatory pivot does not mean cyber is off the table. Vice Chair Bowman was explicit at the Federal Reserve Banking Outlook Conference in February 2026:
"Let me be clear: emphasizing core and material financial risks to safety and soundness does not mean neglecting nonfinancial risk. Cybersecurity, for example, remains a top priority. Strong risk management remains essential to the safety and soundness of the institutions we supervise, and we will continue to issue findings and examine for it where appropriate." — Vice Chair Bowman, Federal Reserve Banking Outlook Conference, February 2026
The regulatory pull-back doesn't reduce cyber risk. It removes the supervisory scaffolding that masked whether institutions had genuine resilience or just documentation. After the next significant incident, examiners won't ask whether the policy was approved. They'll ask whether the board understood the material risk — and acted.
For cybersecurity, this exposes a hard truth: the compliance-driven posture many institutions built over the last decade was never sufficient to stop a sophisticated attacker. Regulators are now asking the right question. and Boards should be too, not whether the institution is compliant, but whether it can survive a breach.
Three Questions Every Board Should Be Able to Answer
What can't stop, no matter what — and how do we know we can sustain it? Every institution has functions that are non-negotiable during a crisis. If they go down, the result is regulatory exposure, systemic risk, or irreversible harm. The board should know exactly what those are, what systems they depend on, and whether continuity has been tested — not just documented. For our payment stablecoin infrastructure, mint/burn/redemption continuity isn't a business objective. It's a licensing condition. Resilience here isn't optional; it's the floor.
Have we proven we can recover, or just planned for it? There is a meaningful difference between a recovery plan that lives in a document and a recovery capability that has been demonstrated under pressure. Tabletop exercises exist precisely to expose the gap between the two. If this board has never observed one, we are governing a capability we haven't seen in action. Recovery time objectives should be validated against how our systems actually behave — not assumed based on how they were designed.
When it's 2am and the facts aren't in, who decides — and on what authority? Resilience isn't only operational. It's organizational. Incident response breaks down when decision authority is undefined. Regulatory notification timing, public communication, and crisis resource deployment cannot wait for real-time deliberation with incomplete information. Pre-authorized decision frameworks and a board protocol for convening rapidly under uncertainty should exist before we need them — because the moment we need them is the worst time to build them.
The Bottom Line
The shift away from prescriptive supervision is not a signal to reduce vigilance. It's an invitation to govern more seriously. Regulators are stepping back from checking boxes which means the institutions that thrive will be the ones whose boards can demonstrate genuine understanding of cyber risk, not just point to a policy binder.
Cyber resilience isn't a technology problem the security team manages in the background. It's a board-level question about whether the institution can withstand, adapt to, and recover from the inevitable. The organizations that survive the next major cyber event won't be the ones that had the best prevention. They'll be the ones that were prepared for the moment prevention wasn't enough.
Sources: Vice Chair for Supervision Michelle W. Bowman, "Opening Remarks," Federal Reserve Bank of Atlanta 2026 Banking Outlook Conference, February 19, 2026. | Vice Chair for Supervision Michelle W. Bowman, "Opening Remarks," Federal Reserve Bank of Kansas City 2026 Future of Banking Conference, May 14, 2026. | Freshfields, "2025 Bank Regulatory Roundup and What to Look for in 2026," December 23, 2025. | Davis Wright Tremaine, "2025 Wrap-Up of Supervisory Changes at Federal Banking Agencies," November 5, 2025.
The views expressed are my own. This post was written with the assistance of AI.



