Your current Chief Information Security Officer built their career defending perimeter networks. Your Chief Technology Officer grew up in cloud architecture. Neither has deep experience governing AI systems in production. The board needs to appoint one executive to lead both disciplines. Where do you even start?
Does this apply to you?
ASX-listed: Yes. The board is accountable to shareholders for executive appointments that affect material technology and cyber risk. A poor hire in this role creates direct exposure to disclosure obligations under the ASX Listing Rules. [1]
APRA-regulated: Yes. APRA expects boards to be satisfied that management has the capability to execute on information security and technology obligations. [2] [3] The competence of the executive you appoint is a governance matter, not just an HR one.
NFP / SME: Partially. You may not be hiring a C-suite tech executive, but you are likely appointing someone, whether a contractor, a virtual CISO, or a senior manager, to own technology risk. The same scrutiny applies at whatever level that sits.
The Competence Gap Is Real and the Board Owns It
Boards have spent years being told they need better technology literacy. Most have made some progress. The sharper problem right now is not the board's own literacy. It is whether the executive sitting in the technology chair actually has the combined skill set the organisation needs.
AI and cyber are not the same discipline. A candidate with fifteen years in enterprise security may have little practical experience governing large language model deployments, data pipeline integrity, or the specific failure modes of AI-assisted decision systems. The reverse is equally true. A candidate who built AI products in a fast-growth technology company may have never operated under the kind of regulatory pressure that APRA or the Cyber Security Act 2024 places on critical infrastructure operators. [4]
The board's duty of care under the Corporations Act requires directors to act with reasonable diligence. [5] Appointing a technology executive whose actual competence does not match the role's demands is a governance failure, not just a hiring mistake. The AICD, as the professional body for Australian directors, is clear that boards must critically assess the capability of management against the risks the organisation faces. Accepting a candidate's self-assessment without independent verification does not meet that standard.
What Combined AI and Cyber Competence Actually Looks Like
Before a board can assess candidates, it needs a clear picture of what genuine combined competence looks like. This is not a checklist exercise. It is a substantive conversation the board or its nomination committee must lead.
On the cyber side, the executive needs demonstrated experience with incident response at scale, security architecture decisions, and board-level risk reporting. They need to understand what the Cyber Security Act 2024 requires of the organisation right now, not in theory. If the organisation is a critical infrastructure asset holder, experience with the obligations that flow from that is not optional.
On the AI side, the required experience is more recent and harder to verify. Look for candidates who have governed AI in production environments, not just piloted it. Governance of AI means owning the decisions about model selection, data quality, bias risk, human oversight requirements, and what happens when an AI system produces a harmful or incorrect output. A candidate who can describe those decisions in specific operational terms, with real examples, has the experience. A candidate who speaks in vendor frameworks and conference language probably does not.
The ACS, as the professional body for Australian technology practitioners, has been working to define what professional competence in this space looks like. That work is worth engaging with when the board is building its assessment criteria, though it does not replace the board's own judgment about fit for the specific organisation.
Does the Federal Government's CyberPath Help?
The federal government's CyberPath initiative is designed to grow the pipeline of cyber-skilled workers in Australia. It matters for the long run. It does not solve the board's immediate hiring problem.
CyberPath addresses workforce development at a broad level. It supports training pathways, credentials, and career entry points. That is valuable work. But a board hiring a technology executive is not looking for someone at the start of a career pathway. It is looking for someone with ten or fifteen years of hard operational experience, ideally across both disciplines, who can walk into a board meeting and give directors a clear, honest assessment of where the organisation sits.
The talent pool with that specific profile is genuinely small. CyberPath will help replenish it over time. Right now, the pool the board is drawing from is limited, which means two things. First, the assessment process must be rigorous, because the margin for a bad hire is low. Second, the board may need to accept that the perfect combined candidate does not exist and structure the executive team accordingly, whether that means a technology executive with strong cyber credentials who has a direct AI governance reporting line, or a CISO and a Chief AI Officer operating as peers with clear accountability boundaries.
Who Really Has the Experience?
This is the question boards avoid asking directly, and it is the most important one.
Most candidates for senior technology roles in Australia today built their careers before AI governance became a board-level issue. That is not a criticism. It is a structural reality. The discipline of governing AI systems at an enterprise level is less than five years old in any meaningful sense. The number of executives in Australia who have done it, survived the hard lessons, and can translate that experience into board-level accountability is small.
Boards should probe specifically for failure. Ask candidates to describe an AI deployment that went wrong and what they did about it. Ask them to describe a cyber incident they managed and how they reported it to a board or senior leadership. Ask them what they got wrong and what they changed. Candidates who have real experience have real failures to discuss. Candidates who have been managing impressions rather than managing risk will give polished, general answers.
Reference checking must go beyond the names the candidate supplies. Talk to people who reported to them, not just people who managed them. The board's perspective on a technology executive's competence is only as good as the honesty of the assessment that produced the appointment.
What the Board Should Actually Do
Governance red flags
- The board is relying entirely on the CEO or an external recruiter to define the competency requirements for the technology executive role, with no independent input from the board itself.
- The role description separates cyber and AI into different reporting lines with no mechanism for integrated risk reporting to the board.
- The interview process does not include a structured board-level conversation that tests the candidate's ability to communicate technology risk clearly to non-technical directors.
- The board has accepted a candidate's credentials and self-reported experience without independent reference verification that goes beyond the candidate's own supplied contacts.
- The appointment decision is being driven by speed or scarcity rather than fit, with the board aware of gaps but proceeding anyway without documenting the risk acceptance.
Questions to ask management
- What specific competency framework is management using to define the requirements for this role, and has it been validated against our actual AI and cyber risk profile rather than a generic job description?
- Can you give the board the names and contact details of three referees the candidate did not supply, including at least one person who reported directly to them?
- How will we assess whether this candidate has governed AI systems in a live production environment, not just in a pilot or advisory capacity?
- If we cannot find a single candidate with genuine combined AI and cyber depth, what executive structure are you recommending and how will you ensure integrated risk reporting to the board?
- How does this appointment address our current obligations under the Cyber Security Act 2024, and what gaps in management capability remain after the hire?
The board that waits for the perfect candidate will wait a long time. The board that appoints a candidate without genuinely testing the depth of their experience will pay a different kind of price. The discipline here is building a proper assessment process, owning the competency criteria at board level, and being honest about what a single executive can and cannot cover. Boards that treat a technology executive appointment as primarily an HR function are outsourcing a governance decision they are not permitted to outsource.
Suitable for board minutes or a risk register entry
Frequently Asked Questions
Can one executive realistically cover both AI governance and cyber security at board level?
Some can. The honest answer is that true depth in both disciplines is rare right now because AI governance at the enterprise level is a relatively new field. When assessing candidates, the board should look for genuine operational experience in both areas rather than theoretical familiarity with both. Where a single executive cannot credibly cover both, a structured dual-reporting arrangement with clear accountability boundaries is a defensible governance model, provided the board is receiving integrated risk reporting rather than two separate views.
Does CyberPath certification or participation tell the board anything useful about a candidate?
It signals a commitment to the discipline and engagement with the government's workforce development agenda. It does not, by itself, tell the board whether the candidate has the senior operational experience required for an executive role. Use it as a positive data point in assessing professional currency, not as a substitute for rigorous competency assessment against the specific demands of your organisation.
What is the board's liability if the technology executive appointment turns out to be a poor one?
Directors have a duty of care and diligence under the Corporations Act. If a board appointed an executive without adequately assessing competence, and a material cyber or AI failure followed, the quality of the appointment process is directly relevant to whether directors met that duty. The protection is not in the outcome. It is in demonstrating that the board applied a rigorous, documented process appropriate to the risk. Boards that treated this as a routine HR matter rather than a governance decision face greater exposure if things go wrong.
How should the board handle the situation where no candidate meets the full requirement?
Document the gap and the decision explicitly. If the board appoints a candidate who has strong cyber credentials but limited AI governance experience, the board should record that it identified the gap, assessed the residual risk, and put in place a specific mitigation, whether that is a named advisory resource, a defined review date, or a structured capability development commitment from the executive. Silence on a known gap is the problem. Boards that acknowledge and manage known limitations are in a far stronger governance position than boards that pretend the gap does not exist.
If this resonates, I would welcome a conversation about the Cyber Governance Deep Review, or get in touch directly.
Sources
- [1] ASX Guidance Note 8: Continuous Disclosure: Listing Rules 3.1, 3.1B (effective 27 May 2024)
- [2] Improving cyber resilience: the role boards have to play | APRA
- [3] Prudential Standard CPS 234 Information Security (July 2019)
- [4] Cyber Security Act 2024, Federal Register of Legislation
- [5] Corporations Act 2001, SECT 180 Care and diligence (civil obligation only)
