Featured Faculty
Executive Director, Kellogg Executive Leadership Institute; Clinical Professor of Executive Education

Yevgenia Nayberg
Being the CEO or board member of a large company has never been easy. These leaders are responsible for making critical decisions that impact the health and long-term viability of an organization as well as its employees and their families.
Today, these jobs are harder than ever. The same risks—and potential rewards—hold true, but there are new, highly complex issues related to shifting geopolitical realities, cybersecurity threats, and the rise of AI. These challenges require leaders to have a working knowledge of a growing list of topics and the ability to move incredibly quickly when a crisis arises.
“Before, you used to be able to say, ‘we’ll discuss this at our next quarterly board meeting.’ Now it’s, ‘we need to talk in the next 40 minutes!’” says Robert Apatoff, associate dean of the Kellogg Executive Leadership Institute and Corporate Alliances, who joined the Kellogg School after retiring as president and CEO of FTD Companies Worldwide.
Apatoff spoke with Kellogg Insight after co-chairing this year’s Kellogg Leadership and Governance Conference, which for 33 years has gathered an invitation-only group of top corporate leaders and board members to discuss their biggest challenges and learn from one another.


This year’s conference, held at the Kellogg Global Hub, featured candid conversations with iconic leaders including JPMorgan Chase chairman and CEO, Jamie Dimon, United Airlines CEO, Scott Kirby, Verizon CEO, Dan Schulman, and Brett Leatherman, assistant director of the cyber division at the FBI.
While the conference itself is off the record, Apatoff shared some of the common themes and concerns that emerged as top of mind for these leaders.
Leaders today rarely have the luxury of simply focusing on creating a superior product or service and getting it to customers. While this remains at the core of their work, there are many new layers involved, from supply-chain concerns due to geopolitical shifts or tariffs, to rapidly developing technology and its associated risks.
There’s simply more for leaders to know. But they can’t expect to know all of it.
“You’re not going to be an expert in everything,” Apatoff says. “But you do need to know the right questions to ask.”
To know the right questions, you need to ensure you have at least a good working knowledge of these topics. Apatoff saw this play out at the conference when board members and CEOs were taking pages and pages of notes on topics like AI along with other insights shared by the speakers.
“These are accomplished leaders who are still thirsty for knowledge on how to compete at this level and this speed,” he says. “They know the importance of connecting the dots.”
There’s no playbook for what the next cyberattack or disruptive competing product will look like. But there’s no doubt that crises will arise, and leaders need to be prepared—even overprepared—for all eventualities.
In other words, it pays to avoid self-inflicted wounds from lack of preparation that can generate or worsen crises.
For preventing cyberattacks, that means having the right teams and technical knowledge in place well before something goes wrong. For example, think through how to “harden your shell,” Apatoff says, to close off vulnerabilities to hackers through routes like temporary employees or vendors.
And it helps to keep in mind that not all major technology crises are caused by hackers demanding ransom. An ill-timed software failure can also have huge implications for customers—and a company’s reputation.
Likewise, preparing for disruptive products or technologies means anticipating potential crises well before they appear.
“These are accomplished leaders who are still thirsty for knowledge on how to compete at this level and this speed. They know the importance of connecting the dots.”
—
Rob Apatoff
Kodak is a famous example of a company that did not do this, Apatoff says. The company had digital camera technology well in advance of it being mass-marketed but chose to focus on its cash cow of film instead.
“They totally missed the boat, and it destroyed the company,” Apatoff says. Instead, “when you’ve got cash coming in, the wind at your back, and a well-performing stock, that’s when you need to listen to your customers and continue to innovate. Complacency, lack of foresight, and reluctance to innovate could create a crisis.”
Like much of the rest of the world, the top leaders at this conference had a variety of perspectives on whether AI is ushering in a golden era of growth and possibility or heralding hardship and economic disaster.
“Even with the smartest people out there, there’s no consensus,” Apatoff says. But there was advice on best practices for integrating AI into organizational processes.
“Don’t try and come up with a standalone AI strategy; enable your business strategy with AI,” Apatoff says.
This means being laser-focused on how AI can improve your organization’s strategies for, say, growth or product design, instead of just bringing AI into operations because it seems like the thing to do. This could mean using AI to make existing workflows more efficient or using it to perform rote tasks so employees can focus on innovation.
“It’s saying, here’s our strategy and here’s what can be enabled by AI, versus spending a ton of money building something and then trying to figure out what you’re going to do with it,” Apatoff says.
Large, public companies are often bound by federal regulations that can feel onerous and time-consuming. But many leaders are now recognizing that the rules put in place by the 2002 Sarbanes-Oxley Act are useful governance parameters. So much so that private companies are emulating these regulations in their own firms.
Given the large rise in the number of companies owned by private-equity firms, this means these governance strategies are starting to spread beyond their original purpose of protecting investors in the wake of Enron and other scandals.
“Governance, in general, can have a positive impact for companies and investors,” Apatoff says. “You’re seeing companies self-imposing more rules because they see them as keeping them out of harm’s way.”
Private companies are using more widely accepted public-company governance practices to ensure they are prepared for scrutiny in the event they decide to go public or entertain private-equity investment.
Following these governance regulations, even when they are not required by law, can help companies fend off many issues, including shareholder lawsuits. But they can also protect against other potentially damaging crises, such as cyberattacks, Apatoff says.
“Without certain governance rules in place—such as access control policies, authentication mandates, and software and patch update requirements—cyberattacks could have had a much greater negative impact.”
Emily Stone is a writer based in Chicago.








