Imagine a solid, matte black cube sitting on a desk. It is perfectly smooth, entirely uniform, and gives nothing away. There is something comforting about it. No clutter, no warning signals, nothing demanding your attention. Just a calm, unblemished surface.

Now, pick it up and press your hand against it.

The heat from your palm triggers a sudden change. Vibrant colors bleed up from underneath, revealing patterns, sides, and corners you did not know existed. The cube was never empty. It had six distinct sides all along. You had simply only ever touched one of them.

In my daily work with boards, CISOs, and executive teams, I see this object everywhere. That cube is your cybersecurity posture.

the side everyone presses.

Walk into almost any boardroom today, and you will see a familiar scene. A slide goes up with a dashboard that is reassuringly green. A few amber flags are being tracked down, but the overall mood in the room is one of quiet relief. NIS2 compliance is mapped, DORA requirements are logged, ISO 27001 audits are signed off. Green means compliant. Green means covered. Green means leadership can safely move on to the next agenda item.

That green dashboard is completely honest. It represents one real, vital face of the cube: regulatory readiness earned through genuine hard work. The issue is not that this side is fake. The issue is that it is usually the only face anyone ever thinks to press.

That is how the curse of the black cube actively takes hold. The green dashboard traps your focus on a single side, while leaving the other five faces completely unexamined.

the five sides still in the dark.

When we only inspect the compliance face, five-sixths of your actual risk picture remains hidden beneath that matte black surface, waiting for a crisis to expose it. In my conversations with executive leaders, I always encourage them to look at what is lurking on those other five sides.

  1. The first hidden side is board governance and liability. The real question here is whether digital risk actually reaches the boardroom as a defensible business decision, or whether it gets lost in technical translation on the way up.

  2. The second side is third-party and supply chain risk. Every external supplier, software dependency, and M&A integration brings unmapped vulnerabilities onto your balance sheet, regardless of whether they show up on your internal reporting.

  3. The third side is embedded controls and evidence. Having a security policy written down in a document is relatively easy. Producing immediate, audit-ready proof that a control actually holds up the moment real pressure hits it is a completely different story.

  4. The fourth side is resilience and crisis governance. When a critical service fails, and eventually something will, is executive command clear enough for core operations to continue, or does your incident response plan only work on paper?

  5. The fifth side is GRC execution bandwidth. Most security leaders I speak with can name their gaps with precision. Far fewer have the actual hands-on capacity to close them, once daily administrative overhead has consumed the hours meant for fixing things.

Five critical faces, sitting quietly in the dark, right next to the one side that turned green.

compliant is not the same as secure.

This is the core distinction every executive needs to sit with: regulatory readiness confirms that you have met a standard on one face of the cube. It tells you almost nothing about the other five.

These two concepts, being compliant and being secure, certainly overlap. But mistaking one for the other creates a dangerous blind spot. That gap is precisely where five-sixths of your actual risk lives.

pressing the cube on purpose.

Reality has a habit of pressing cubes too. But reality never asks for permission, it always chooses the worst possible moment, and it rarely presses the side you were already watching.

The real work of effective governance is pressing all six sides on purpose, before an attacker or a system failure forces your hand. It means sitting down with someone who knows which faces tend to stay dark, and walking through every single one of them.

In my role leading the Cybersecurity and GRC practice at Randstad Digital, this is where I spend my time. If you are curious about what your other five sides might be hiding, I would be delighted to come by your offices for a coffee and an open discussion. No sales pitch, no endless slide decks, just a fresh look at the full picture.

Your green dashboard might be completely honest. The question worth asking is whether it is the only side of the cube you have ever looked at.

the analogy of the black cube explained by Jan (Dutch)
about the author
Jan De Bondt
Jan De Bondt

Jan De Bondt

practice lead cybersecurity & grc at randstad digital

Jan De Bondt is a cybersecurity, privacy, and AI governance expert at Randstad Digital Belgium. With over a decade of experience across the public and private sectors, he specializes in building organizational resilience by transforming security into a dynamic, people-driven practice through coaching and knowledge sharing.

Jan guides clients through complex regulatory frameworks—including NIS2, GDPR, and the AI Act—translating compliance requirements into business-aligned security strategies. He is also a prominent industry thought leader and commentator, frequently publishing insights on digital risk, board accountability, and long-term cyber resilience.