21 August 2026

Keith Barnes – The importance of balancing innovation, governance and risk

FSP are a specialist in advisory-led enterprise transformation delivered through integrated capabilities – Data & AI, Cyber Security, Enterprise Cloud and Change Delivery. Over the next couple of months, we’re running a series interviewing leaders from each area, to explore the trends, challenges and opportunities shaping enterprise transformation today from their perspective.

In this article, we interview our Group Director of Cyber Security, Keith Barnes. From embedding cyber security into enterprise transformation from day one, to balancing innovation with security and governance and building resilience into business strategy, Keith shares his perspective on what organisations need to do to make cyber security a strategic enabler of successful transformation.

Read the article below to discover Keith’s key takeaways and expert perspectives.

How has the role of cyber security evolved within enterprise transformation? 

Keith:

Cyber has fundamentally shifted over the past decade. Cyber teams used to be considered as back-office, performing a reactive role, patching vulnerabilities, managing perimeters, and perceived by the business as the “department of no!”  

Fast forward to now, cyber teams must be embedded in transformation from day one. Being at the table to support business change, when new platforms are adopted, when M&A activity happens. This evolution isn’t just technical, it’s cultural and organisational. Cyber can no longer speak its own language, we must speak the language of business value, risk appetite, and competitive advantage.  

Why is cyber increasingly becoming a strategic business issue rather than just a technology concern? 

Keith:

“Cyber risk has become a critical component of organisational resilience and long-term business success.”

Cyber security is increasingly being recognised as a strategic business issue rather than solely a technology concern. As organisations become more reliant on digital systems, data and connected supply chains, the potential consequences of a cyber incident extend far beyond operational disruption. 

A ransomware attack, for example, can impact customer trust, attract regulatory scrutiny, disrupt business operations and, in some cases, affect market value and brand reputation. 

What may begin as a technical incident can quickly evolve into a broader business challenge with financial, legal and reputational implications. Boards must be placing greater emphasis on cyber risk as part of their wider governance and risk management responsibilities. 

This shift is also being reinforced by evolving regulatory frameworks, organisations are going have to navigate EU Cybersecurity Regulations such as the NIS2 Directive, Cyber Resilience Act (CRA), and the Digital Operational Resilience Act (DORA), along with the increasing number of cyber-related disclosure requirements, so we are constantly encouraging organisations to view cyber resilience through an enterprise-wide lens. 

The growing focus on cyber security from boards, regulators, investors and insurers reflects a broader reality: cyber risk is no longer confined to the IT function. It has become a critical business issue and a key component of organisational resilience, requiring organisation-wide attention to support long-term success.

What are the biggest challenges organisations face when balancing innovation with security and governance? 

Keith:

The core tension is speed versus rigour. Innovation thrives on iteration and velocity. Traditional governance frameworks were built for stability and control. The challenge is that many organisations haven’t modernised their governance models to match the pace of change, so unfortunately, security becomes a bottleneck rather than a guardrail intended to enable and support the business.  

The other significant challenge is shadow IT and ungoverned adoption, particularly with AI tools right now. Businesses are deploying capabilities faster than cyber teams can assess them. 

The answer isn’t to slow innovation down; it’s to build security into the design & delivery pipeline so it moves at the same speed, working in collaboration, being an enabler, aligning to and supporting the business objectives. 

Why do organisations still struggle to integrate cyber effectively into transformation initiatives? 

Keith:

Organisations struggle primarily because cyber is still too often treated as a workstream rather than a focused lens. Some transformation programmes bring in strategy consultants, technology partners and change managers and then bolt cyber on at the end as a compliance retrospective checkbox. By that point, re-engineering for security is expensive and disruptive, resulting in corners getting cut and risks getting implicitly accepted.  

There’s also a skills and communication gap. Cyber professionals historically haven’t been trained to engage with business stakeholders, and business leaders haven’t been expected to understand risk in cyber or technical terms. Closing that gap by building genuine shared ownership of security outcomes is where most organisations are still falling short. 

What does “secure transformation” look like in practice? 

Keith:

“Security debt should be tracked and managed like technical debt.” 

Secure transformation starts with involving cyber security from the very beginning, not treating it as a checkpoint at the end. In practice, this means considering security requirements alongside business and technology objectives from day one. Threat modelling should take place as solutions are being designed, with secure-by-design principles embedded throughout the development process. 

It also means ensuring that security frameworks, controls and governance are built into cloud and AI adoption programmes by default, rather than being added retrospectively. When security is treated as an integral part of transformation, organisations can innovate more confidently while reducing risk and avoiding costly rework. 

In practical terms, I’ve seen it work best when you embed cyber subject matter experts e.g. architects, governance, risk and assurance specialists, directly within transformation delivery teams, with a clear mandate to enable rather than obstruct.  

Secure transformation also means building resilience into the target operating model from the outset. Organisations need confidence that the capabilities they deploy can withstand attack, continue operating under pressure and recover quickly when disruption occurs. Achieving this requires robust testing and validation, ensuring that systems are not only secure, but also resilient when faced with real-world threats. 

How critical is resilience within modern enterprise strategy? 

Keith:

“Our Governance, Risk and Assurance team are working with multiple clients to support their journey to achieve Defence Cyber Certification (DCC), DCC’s primary focus is for organisations to be resilient, secure and risk aware.”

Resilience is increasingly recognised as a strategic business priority. While prevention remains important, organisations understand that some level of disruption is inevitable. The ability to withstand attacks, maintain critical operations and recover quickly has therefore become just as important as the ability to prevent incidents in the first place. 

The questions that need to be answered are: 

  • Can you detect fast?  
  • Can you contain effectively?  
  • Can you recover with minimal business disruption?  

Organisations that have invested in resilience, clear incident response playbooks, tested recovery capabilities and crisis communication frameworks, will consistently outperform those that focus purely on prevention. Resilience is also increasingly a commercial differentiator. Major clients, partners, and regulators want to see it demonstrated, not just asserted. 

What are the risks of approaching cloud, AI and cyber in isolation? 

Keith:

The risks are significant and compounding. Cloud without cyber gives you scale and agility with an exposed attack surface. AI without cyber governance introduces data leakage, model manipulation, and ungoverned access risks at speed. Cyber without cloud and AI fluency produces a security function that’s always playing catch-up with the threats it’s supposed to be managing.  

These three domains are deeply interdependent. AI is now a tool for both attackers and defenders. The common theme from most of the conversations we are having with clients, is that AI is moving faster than the security controls built to govern it. 

Cloud is the infrastructure underpinning almost every transformation. When organisations manage them through separate strategies, separate budgets, and separate leadership conversations, they create dangerous blind spots.

How should organisations think about governance in an increasingly complex technology landscape? 

Keith:

Governance needs to be adaptive, proportionate, and outcomes-focused, not heavy in process and procedures for its own sake.  

The complexity of modern technology environments means it’s challenging to govern everything to the same level of rigour. Risk-tiered governance is essential – applying the strongest and stringent controls to the most critical assets and accepting managed risk elsewhere.  

As technology landscapes become more complex, governance must become more adaptive. Manual, point-in-time governance activities still have a role to play, but on their own they are unlikely to provide the visibility and responsiveness modern organisations require. 

Many organisations are therefore exploring more automated approaches, including continuous compliance monitoring and automated assurance, to help keep pace with rapidly changing environments. The goal is not simply to reduce administrative effort, but to provide more timely insight into risk and control performance. 

Governance should be seen as a capability that enables innovation, resilience and trust. Organisations that view it solely as a compliance exercise often miss its wider value as a tool for making better decisions and supporting sustainable growth. 

What do leadership teams often underestimate when it comes to cyber and transformation? 

Keith:

“In a highly interconnected, cloud-native, API-driven world, your risk extends to every supplier, partner, and platform you depend on.” 

Most successful cyber attacks still exploit human behaviour, phishing, social engineering and insider risk. Organisations will invest heavily in technology controls and chronically under commit and underinvest in culture, awareness, and behavioural change.  

Secondly, the third-party and supply chain risk surface. Leadership teams tend to think about cyber in terms of their own estate. However, in a highly interconnected, cloud-native, API-driven world, your risk extends to every supplier, partner, and platform you depend on.  

A significant proportion of major incidents in recent years have originated in the supply chain. Boards need to be asking hard questions about third-party assurance and providing support towards addressing gaps in visibility and management.

What do you think the future of cyber-enabled enterprise transformation looks like? 

Keith:

The future of cyber is not greater visibility but greater integration – becoming so intrinsically embedded in design, inherent in operations of technology that it is ever-present, yet largely unseen. 

AI-driven security operations will handle the majority of routine detection and response. Security engineering is a core competency of every development team. These are primary focus areas within our Secure Management Services Capability currently.  

The CISO role must continue to evolve from being less of a gatekeeper to more of an enterprise risk strategist with a seat at the executive table. 

The organisations that will thrive are those that see cyber, not as a cost of doing business, but as an enabler of trust that underpins every digital interaction they have with customers, partners, suppliers and regulators.