No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

How Do You Counter a Threat Actor Who Just Wants to Fight?

The changing nature of geopolitical risk brings a new world of cyber exposure

by Avani Desai
June 29, 2026
in Risk
global risk concept satellite image

Most businesses prepare for a scenario where attackers want something, whether that’s access to proprietary information, money — or both. But what do you do when an attacker has no motive? Avani Desai of Schellman explores how organizations can reorient their risk management approach to prepare for a new age of geopolitical threats.

Fraud, unauthorized access to IT systems, data breaches, there is no shortage of risks for businesses today. Last year, IBM reported that the cost of a data breach was, on average, $4.4 million, and that number isn’t getting lower anytime soon. For business leaders, security professionals and boardrooms, these threats aren’t new. If an attack, like a case of ransomware, did succeed, there were still options to recover. Ransoms can be paid and data or systems can be restored. But now a new problem is emerging. How do you plan for, and respond to, an adversary that has no motive?

Geopolitical considerations have shifted drastically in recent years, meaning businesses could find themselves in the crosshairs of an attack. Whether it’s aimed at critical infrastructure like a power grid or water supply or government agencies that house troves of sensitive data, businesses up and down the supply chain are vulnerable.

Risk is changing, and the strategies that have defined years of security compliance must adapt to keep up with the threat.

Risk modeling for an age of uncertain geopolitical threats

Increasingly, boardrooms are starting to realize the importance of geopolitical threats. A recent survey from the World Economic Forum found that 64% of organizations are now accounting for geopolitically motivated cyberattacks, including disruption of critical infrastructure or espionage.

So, what exactly is changing with that realization? Traditionally, the risk models embraced by business leaders have centered around where a business’ operations are. That means focusing on the specific places where sensitive data and valuable assets lie and the systems intended to secure them.

That approach, while effective in some instances, is proving to be incomplete for the purposes of a more determined attacker. When the motive is just attacking for the sake of attacking, the financial incentives that may make a seemingly more secure organization not worth the trouble to the attacker disappear. Once an attacker sets their sights on a target, they’ll stop at nothing to break through.

And this is where a more comprehensive approach to risk needs to take hold. In this context, dependencies span a few different attack vectors. Everything up and down the supply chain, third-party vendors, partner organizations, even external business relationships all represent dependencies that can be exploited. Couple these vulnerabilities with an organization that holds government contracts or is involved with critical infrastructure and an otherwise innocuous business quickly becomes a major target for state-level actors.

Any one of those dependencies could result in an unauthorized individual gaining entry and unleashing chaos on critical systems. Security posture starts here with identity and access management (IAM) controls.

magritte son of man deepfake
Risk

Deepfakes Are Now a Board-Level Risk & Regulators Are Watching

by Matt Flegg
May 1, 2026

Recent UK regulatory developments are making deepfake risk a board-level disclosure and accountability issue, not just an IT problem

Read moreDetails

Security starts at the management plane

This is where many organizations — even large enterprises with more mature security — run into trouble. While important, IAM is often an issue relegated to IT teams, which are already tasked with a multitude of other important roles and responsibilities to keep the rest of the organization running smoothly.

The longer that misconception and misallocation lingers, the more fragmented ownership over IAM becomes. In reality, identity controls are no different than any other security need. Regulatory compliance and internal governance cannot exist if security teams don’t have a reliable accounting of who has access to what. Taking steps to frequently conduct compliance assessments and restrict or revoke access to individuals is an important first step.

In any business environment, employees, vendors and partners all come and go over time. Even the most up-to-date security systems won’t matter if an attacker gets in from a former employee’s account. Even something as simple as a bad password is all it takes.

The amount of turnover that naturally exists in business presents a perfect opportunity for attackers. Successfully fending them off will take a rigorous strategy built on continuous validation.

Where do boards go from here?

All of the threats we’ve discussed exist on a huge scale and are subject to factors that are largely out of the control of any one organization. We know the stakes are high, we know where the vulnerabilities are, but how should boardrooms actually start planning for these possibilities?

Don’t overthink it, keep any model simple and focused. An overly detailed and elaborate threat model isn’t going to make taking action any clearer — but clarity will. An effective risk management strategy stays dialed into what matters and what the business impact could be.

That’s what really translates into operational impact. Strategy should be built around the answer to questions like how do we respond if a system is completely wiped out? What if a specific region goes offline? Or what if critical operations are disrupted?

Then it’s about creating an action plan with a few focused actions. This should first include strengthening identity and access controls and implementing continuous validation of those credentials to reduce unnecessary risk. Then plans must ensure operational resilience is ready to respond to an attack with adequate backup and recovery capabilities.  

Ultimately, the best plans are those that don’t try to cover every eventuality. Prioritization is vital, focusing on what matters the most helps set the right foundation.

Managing risk in an uncertain geopolitical landscape

How do you win a fight where your opponent wants nothing more than to keep fighting? The business world is entering a new age of ambiguity when it comes to cyber threats. Motivations are blurring and the risk models that have long been in place to counter attacks are becoming outdated. 

Whether you’re a CIO, CSO, a board member or security practitioner, there must be a complete understanding of an organization’s place in the geopolitical landscape from top to bottom. Knowing the connections that exist throughout a business and rigorously controlling the management plane have become the new foundation for understanding threats.

Geopolitical tensions are fueling new attack motives — or rather a lack of one at all. As this shift continues molding the cyber threat landscape, businesses across the board need to be prepared for whatever lies ahead.

Tags: Cyber Risk
Previous Post

2026 Global M&A Trends

Next Post

From the Pitch to the Boardroom: Building a Championship-Level Compliance & Governance System

Avani Desai

Avani Desai

Avani Desai is a partner and president at Schellman & Co., a niche CPA that focuses on technology and security assessments. She is also CEO and co-founder of MyCryptoAlert, a push notification and portfolio app for cryptocurrency. Avani started her career working at a Big 4 accounting firm (KPMG) for over 10 years, where she led a team and oversaw IT risk management and privacy across national service lines.

Related Posts

NRF Litigation Trends Midyear Pulse

2026 Litigation Trends Survey: Midyear Pulse

by Corporate Compliance Insights
June 17, 2026

Norton Rose Fulbright's 2026 midyear litigation pulse examines how dispute exposure is shifting across sectors as cybersecurity, AI and employment...

news roundup green bars

Only 39% of Businesses Meet Recovery Targets After Major Disruption

by Staff and Wire Reports
June 12, 2026

Mid-market companies, AI and governance; European banks’ emissions reporting; AI identity attacks

Ethixbase360 Third Party Cyber Risk

A Practical Guide to Third-Party Cyber Risk Management

by Corporate Compliance Insights
May 8, 2026

A practical, business-focused look at third-party cyber risk as the natural next step in TPRM eBook A Practical Guide to...

magritte son of man deepfake

Deepfakes Are Now a Board-Level Risk & Regulators Are Watching

by Matt Flegg
May 1, 2026

Recent UK regulatory developments are making deepfake risk a board-level disclosure and accountability issue, not just an IT problem

Next Post
world cup

From the Pitch to the Boardroom: Building a Championship-Level Compliance & Governance System

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights