Based on experience and networking, I would say your position is not isolated although different organisations can be at different stages of maturity. Having separate and specialised functions for Cyber, Fraud, Business Resilience especially in larger businesses is common and not necessarily a bad thing.
What is important is that they they do talk to each other where subjects intersect and that such interaction is structurally built into the system and not ad hoc and solely dependent on people's personalities.
I was recently a part of an organisational project to map out the roles of the 3 lines (of defense), where they overlap, where there are gaps and what needs to be done to make the approach more cohesive. I would recommend such an exercise for any medium or large organisation which has not already done it. Ideally with sponsorship from the Board, Audit Committee and/or Senior Leadership Team. That will put the spot light on (expectations) of Finance, Compliance, Legal, Operations and what challenges are faced including any missing links when priorities/strategies are made for a business or function.
I hope this is useful to you.
------------------------------
Shehan Goonewardene
The Hague
------------------------------
Original Message:
Sent: 05-24-2026 12:58
From: Gerrit Wilhelmij
Subject: Cyber, fraud and resilience
Great to hear Jason that Finance in your company has been setting the agenda for cyber and taking the lead.
My experience in various finance and governance roles at corporate and operational levels in an international energy company has been varied, with plenty of silos and inconsistencies. In the international investment business, Finance took the lead for business resilience and risk while cyber was addressed by IT. In the corporate area, Finance only led on risk management with cyber left to a specialist IT team, while compliance and addressing fraud was a legal responsibility. In operating entities Finance generally had little to do with cyber which was left to IT, and little to do with resilience and risk except to bear the consequences of data process failures.
This situation does not align with the expectation that Finance should provide some level of reassurance on the integrity and reliability of data underpinning corporate performance, financial reporting and associated decisións. This expectation implies it has the right to set priorities and requirements for data process and technology resilience, and for compliance controls. Finance also has the appropriate professional competencies and critical mindset.
However Finance seems pushed to the side with an overall agenda set by others.
Is this the experience of others? If so, what are blockers and challenges for Finance, and what steps should we in Finance be taking? Are there examples of organisational approaches where the data integrity priorities and emerging concerns of Finance and other functional áreas are addressed in a balanced and agile way? Is anyone aware of moves towards something like a multi-disciplinary "resilience (or risk) operations centre"?
Original Message:
Sent: 5/14/2026 6:45:00 AM
From: Jason Knox
Subject: RE: Cyber, fraud and resilience
Cybersecurity started with finance because I identified the risk and then made it a priority to get done.
I came in at the early stage of my company's development so I ended up sponsoring and directing the build out of my firms cybersecurity infrastructure which included selection of the cybersecurity vendor to get a Managed SIEM, Penetration test, and Cyber Essentials and Cyber Essentials Plus audits done. Getting third party backup in place, mandating the use of VPN's since my company is largely remote, and implementing a vulnerability and patching system to ensure people's systems are up to date.
------------------------------
Jason Knox
London
+4407954243429
------------------------------