July 19, 2026
Control as the Main Angle for IT Strategy
By Bruno Sivanandan Roques de Borda, Cybersecurity Consultant
Cybersecurity and compliance as the foundation of transformation
I initially started my career working on IT projects from an architectural perspective. That is, looking at IT systems from above, considering all components and how they interact with each other trying to identify patterns and principles that would enable building a solid and long lasting infrastructure for the system, much like a house would not stand the test of time if built on shallow foundations. Drawing from the parallel, I came to the conclusion that the foundations of a system should be laid specifically on Cybersecurity and Compliance, and experience has not argued with it since.
The reason is simple. Whatever transformation an organisation is contemplating, an ERP programme, a network expansion, a cloud migration, a data platform, a new AI prototype, the same questions surface within days. How is the system secured? Which data is involved? Who has access? Which processes are affected? Which third parties are connected? And how does this new initiative fit into the wider picture of the company's digital estate?
These questions are prerequisites for building, over the long term, a system that is coherent with the business strategy and adaptive to a technological and commercial landscape that will not stop moving.
Digital systems are now a board-level concern
This is why cybersecurity and compliance should not be treated purely as technical or legal constraints. At their best, they force an organisation to understand itself. They oblige the company to map what exists, clarify responsibilities, identify its exposure, document its controls, and produce evidence that the system is genuinely being managed.
Achieving this feat implies something significant: Top management is able to keep control over the entire IT system. Every component, endpoint, data process, network device, third party, application, dependency and responsibility involved.
Only such a comprehensive view is what prevents gaps opening up between teams or suppliers, and what keeps responsibilities clearly delineated. It is also what allows information to be compiled in a form that is intelligible at board level, enabling sound decisions on risk, on budget constraints, and on transformation priorities, in coherence with the business strategy.
Digital systems have become a board-level concern because they now carry operations, finance, customer experience, reporting, compliance, security, intellectual property and, increasingly, AI-enabled capabilities. For many companies, the digital system is no longer a set of tools the business uses but becomes the environment in which the business actually operates.
In the end, what changes is the governance with which the board steers the system’s transformation. Boards and executive committees cannot confine themselves to isolated technical updates and fragmented project reports. What they need is a structured view over the digital operating system: what is critical, what is exposed, what is protected, what is costly, what is obsolete, and what should be transformed next.
At board level, digital control takes shape around three questions.
First: do we know our risk? This means understanding critical assets, sensitive data, regulatory obligations, third-party dependencies, operational weak points, and the likely impact suffered in case an incident occurs.
Second: do we know where the budget goes? Across software, suppliers, cloud infrastructure, licences, cybersecurity, compliance, maintenance, remediation and transformation projects.
Third: are we choosing the right things to transform? Not every modernisation effort carries the same value. The right priorities are those that reduce risk, remove waste, strengthen resilience, improve usability, support the business strategy, and prepare the organisation for requirements that have not yet arrived.
Control as a strategic discipline
This is where control becomes a strategic discipline. It is the bridge between digital risk, digital spending and digital transformation, and it is what creates management confidence.
That confidence works in two directions. Internally, leadership gains the assurance that the company is genuinely harvesting the potential of the technologies it has invested in. Externally, control is the primary means to build trust with: clients, investors, auditors, regulators, insurers and partners increasingly expect a company to demonstrate that it understands and governs its digital environment.
Once that confidence exists, transformation becomes far easier to steer. A company that understands its system can integrate new technology faster, because it knows where the new technology belongs. It avoids accumulating disconnected tools. It consolidates platforms. It reuses evidence across multiple compliance obligations. It anticipates regulatory requirements rather than reacting to them. And it aligns field-level IT engineering with top management priorities.
In that sense, control does not slow transformation down. It is an investment that allows an organisation to move faster without losing coherence.
AI makes digital control more urgent
It is impossible, today, to discuss digital transformation without a word on AI. This technology does not fundamentally change the discipline described above. On the contrary, because it accelerates everything, it makes that discipline more important still.
AI introduces new data flows, new automations paradigms, new third-party dependencies, new cost exposure, and new accountability issues. AI tools and agents must therefore be integrated into the company's control system like any other component. They need clear owners, access boundaries, approved use cases, logs, cost limits, review mechanisms, incident procedures, and human accountability.
The companies that will benefit most from AI are those able to connect experimentation to governance, architecture, security, compliance and business value.
Towards the maturity of digital control
It is taken for granted that companies devote considerable effort to controlling their finances and compiling financial information at board level. An entire ecosystem has grown up around financial control: regulation plays a forceful role, and a great many actors have standardised their practices, tools, audits, reports and professional language.
The digital industry is somehow still at its dawn. The technology continues to evolve rapidly, AI above all. Regulation is still taking shape around the world with industrial players still adapting their operations to integrate these technologies for the long run.
Our goal is to take part in the emergence of a standard way for running digital transformation journeys for our clients, one that aligns top-management control with field IT engineering, and holds the two together rather than letting them drift apart. It is why we approach an engagement by asking what a client is actually running before asking what we could build for them. It is also the thinking behind Baulders, our decision intelligence platform, built to assess critical exposure, surface the risk factors that genuinely matter, and turn a sprawling digital estate into something a leadership team can decide upon.
What we want is to prepare our clients to adopt new technology faster, while keeping coherence with their overall system and anticipating the compliance requirements ahead of them. The result is not merely better security, or better compliance. It is the optimisation of the business, and the future-proofing of value for every stakeholder.




.png)
.png)


