1st Edition

Cumulative Effect Cyber Security Guide for Directors and CEOs

By Vladas Leonas Copyright 2026
204 Pages
by CRC Press

204 Pages
by CRC Press

204 Pages
by CRC Press

For years, cyber security was the ‘poor relation’ in many boardrooms: treated as inferior to other priorities, seen as an irritating cost centre and assumed to be money that could be spent ‘better’ elsewhere. That mindset is rarely the result of a single bad decision. It is inertia, the cumulative effect of multiple factors and, above all, a lack of understanding of how dramatically the landscape... Read more
Foreword
Preface: Why you should read this book
About the author
Acknowledgments
Introduction: Personal liability and cyber insurance
1. Cumulative effect
2. CIA, risk appetite, and risk exposure
3. The fifth column
4. Complexity tax
5. Digital revolution (and its consequences)
6. Agile curse
7. Cloud: Who owns the breach?
8. SaaS sprawl
9. Supply chain challenges
10. The fifth column just got bigger: Internet protocols
11. Compliance ≠ Security
12. Standards and frameworks
13. Tyranny of KPIs
14. Gone phishing
15. Emerging threats
Conclusion

Biography

Dr Vladas Leonas is a subject matter expert and specialises in ICT Strategies, their implementation and ICT Operations, gateway reviews and internal audits, enterprise risk management, cyber security, governance, procurement, and compliance. Over the last 25 years, he has held eight CIO and CTO positions.

Dr. Vladas Leonas has written a book that should be read by directors, CEOs, insurers, senior operators, and anyone responsible for cyber governance.
Cumulative Effect: Cyber Security Guide for Directors and CEOs addresses a problem that is still widely misunderstood. Cyber exposure rarely arises from one spectacular failure. It builds through the accumulation of dependencies, assumptions, shortcuts, unmanaged components, cloud services, SaaS platforms, third-party providers, APIs, certificates, domains, and gaps between what an organisation believes it has governed and what actually exists.
After three years of listening to Andy J. Jenkinson and reading the reams of evidence he has assembled, I have come to understand DNS and PKI as the nucleolus of the problem. They sit beneath the public trust layer on which digital commerce, communications, identity, insurance, governance, and institutional credibility increasingly depend. A weak or unmanaged foundation can quietly compromise the value of higher-order controls, certifications, policies, assurance statements, and cyber-insurance assumptions.
Dr. Leonas’s contribution is to place those foundations inside the larger cumulative reality: escalating complexity, cloud and SaaS dependence, supply-chain opacity, fragile accountability, and the persistent distance between compliance and actual security.
Most compliance processes begin with what an organisation says about itself. Policies, questionnaires, control statements, certifications, and internal attestations all have a place. Their value increases substantially when they are grounded in independently observable evidence of the actual condition of the environment.
That is the premise behind Whitethorn: an evidence-led assurance layer capable of examining the public-facing trust infrastructure of an organisation, including domains, subdomains, DNS, certificates, and associated conditions. The aim is to give boards, operators, insurers, and underwriters a more factual starting point for governance, remediation, risk pricing, and accountability.
Cyber governance becomes more credible when it begins with observable condition rather than declared confidence.
Dr. Leonas has provided a clear and valuable framework for understanding why that shift is overdue.

Brian Walls, Founder & CEO