Back to top

The Security Gap Hiding in Plain Sight on the Boardroom Agenda

The Security Gap Hiding in Plain Sight on the Boardroom Agenda Cybersecurity has finally earned its place in the boardroom.…

The Security Gap Hiding in Plain Sight on the Boardroom Agenda

28th August 2026

The Security Gap Hiding in Plain Sight on the Boardroom Agenda

Cybersecurity has finally earned its place in the boardroom. After a decade of high-profile breaches, ransomware headlines, and tightening regulation, most business leaders now understand that security is not merely an IT concern but a matter of corporate survival, reputation, and trust. Yet for all this hard-won awareness, a curious blind spot persists. Boards scrutinise firewalls, cloud security, and phishing defences, while overlooking one of the oldest and most reliable routes an attacker can take: the physical device someone plugs in.

This is the security gap hiding in plain sight. It is not exotic, and it does not require a sophisticated adversary. It relies on nothing more than a USB drive and a moment of ordinary human behaviour. For organisations that handle sensitive data or operate in regulated sectors, it is a risk that deserves far more attention than it typically receives.

Why the obvious threats get all the attention

There is a natural bias in how organisations think about cyber risk. The threats that dominate the headlines, and therefore the boardroom conversation, are the ones that arrive over the network: the phishing campaign, the ransomware outbreak, the data breach traced to a stolen password. These are real and serious, and the security industry has built an enormous arsenal to counter them, including firewalls, email filtering, endpoint detection, and continuous monitoring.

The trouble is that all of these defences share a common assumption. They are designed to inspect traffic that travels across a network. They watch the digital front door. And they are largely blind to a threat that does not use the network at all, but instead walks in through the side entrance, carried by hand.

Removable media, the USB sticks, external drives, and portable devices that move data between systems every day, bypasses this entire apparatus. A firewall cannot inspect a USB drive. Email security never sees a file that arrives on a memory stick. When a device is physically plugged into a computer, it is already inside the perimeter that most of an organisation’s security budget is spent defending.

An old threat that never went away

It would be comforting to think of USB-borne attacks as a relic of an earlier era, but the evidence points the other way. The most famous example remains instructive: the Stuxnet worm, which sabotaged Iranian nuclear centrifuges, reached its targets not over the internet but on infected USB drives, crossing an air gap that was supposed to make those systems untouchable.

The technique endures because it works. Attackers have posted malicious USB devices to target organisations disguised as gift cards or promotional items. Penetration testers routinely scatter drives in car parks and reception areas, and reliably find that a percentage of them are picked up and plugged into corporate machines. And departing employees have used the humble USB stick to walk out with intellectual property, customer data, and trade secrets, because it is fast, offline, and almost impossible to trace after the fact.

What makes these attacks so effective is precisely their ordinariness. There is no dramatic breach of the firewall, no alarm on the monitoring dashboard. A trusted person plugs in a device, and the damage, whether malware entering or data leaving, happens quietly, outside the view of the tools built to catch it.

The problem is worse where the stakes are highest

For an ordinary office, the removable-media risk is a manageable concern. But for organisations in critical and regulated sectors, it becomes acute, and for a reason that is easy to miss.

The systems that matter most in these environments are often deliberately isolated from the internet. Industrial control systems, utilities, defence programmes, healthcare equipment, and financial infrastructure frequently run on air-gapped networks, cut off by design to keep threats out. That isolation is a genuine strength, but it creates an unavoidable dependency: if a system is not on the network, the only way to get data, updates, and files onto it is by physical media carried in by hand.

In other words, the very systems that are most protected from network attacks are the ones most dependent on removable media, and therefore most exposed to it. The air gap that keeps hackers out is the same reason a USB drive becomes the primary route in. This is why sectors such as energy, manufacturing, defence, and healthcare treat removable-media control not as an optional extra but as a fundamental security requirement, and increasingly a regulatory one.

Why this belongs on the board’s agenda

It is fair to ask why a topic this operational should concern the board rather than simply the IT department. The answer lies in how the consequences land, and where accountability now sits.

Regulation is tightening across the board. Frameworks governing critical infrastructure, healthcare data, financial services, and defence supply chains increasingly require organisations to demonstrate control over how data moves in and out of sensitive systems, including on removable media. Compliance is no longer a matter of writing a policy and filing it away; auditors and customers alike now expect evidence that controls are genuinely in place and working.

The commercial stakes are just as real. Enterprise customers conducting due diligence ask pointed questions about data handling, and a convincing answer can win a contract while a vague one loses it. A breach traced to something as avoidable as an unchecked USB device carries a reputational cost that lands squarely at board level, alongside the regulatory and financial fallout.

Handled well, controlling removable media is one of the more addressable items on the security agenda. It is a defined problem with defined solutions, of the kind boards like: a clear risk, a clear control, and a clear way to demonstrate diligence. Organisations that need to protect sensitive or isolated systems increasingly turn to dedicated removable media security measures that inspect and clean every device before it is allowed to connect, closing the gap that network defences cannot reach and producing a record that the control is being applied.

Closing the side entrance

The maturing of cybersecurity as a boardroom issue is a genuine achievement, but maturity means seeing the whole picture, not just the parts that make headlines. The network-borne threats deserve the attention they get. The point is that they are not the only way in, and the routes that attract the least attention are often the ones an attacker finds most inviting.

Removable media is the classic example: a decades-old threat, entirely preventable, that persists precisely because it is so easy to overlook. For the organisations with the most to protect, particularly those running the isolated systems that keep critical services and infrastructure running, closing this side entrance is not a technical footnote. It is part of taking security seriously all the way through, rather than only where the spotlight happens to fall.

The businesses that treat it that way gain more than protection. They gain the ability to look a regulator, an auditor, or a major customer in the eye and demonstrate that they have thought about the whole problem, not just the visible half of it. In an environment where trust is increasingly the currency of commercial success, that is a boardroom concern by any definition.

This article is for general information and does not constitute specific security, legal, or compliance advice. Organisations should assess their own risks and seek professional guidance where appropriate.

Categories: Tech

Our awards

Discover Our Awards.

See Awards

You Might Also Like