Governance Isn't a Line Item — It's the Job

Two stories broke in the same news cycle. One is about protecting machines from hackers. The other is about a man who protected himself from accountability. Read together, they say the same thing: security is only as good as the governance behind it.
The €234 Million Question
Exein, a Rome-based cybersecurity company, just raised €234 million at a €1.4 billion valuation, making it — reportedly — the most valuable cybersecurity startup in Europe, according to EU-Startups. The company builds what it calls Physical AI security: protection for intelligent machines, from industrial robots to connected vehicles, that face an estimated 5,000 attacks every week.
That's a serious number, and a serious business. Sifted frames it as a sign that European cybersecurity is finally attracting capital at scale, not just attention.
Fair enough. The world needs better defences against external threats. Machines that run factories, cars, and critical infrastructure should not be one firmware bug away from disaster.
But here's the uncomfortable part: no external shield fixes an internal rot. You can encrypt every endpoint and still fail, if the people running the show answer to no one.
What Happens When Governance Fails
The Upper Tribunal's decision to uphold the ban on Crispin Odey is the other half of this story, and it's not really about hedge funds. It's about what happens when internal accountability structures exist on paper but not in practice.
The facts, briefly:
- Odey, founder of Odey Asset Management, was subject to an internal disciplinary process over repeated inappropriate behaviour towards female employees.
- When his firm's executive committee tried to hold him to account, he dismissed them — twice.
- The Tribunal found his justifications were "no more than a smokescreen." His real goal was self-preservation.
- He was also found to have shown a lack of candour in dealings with the FCA, including false assertions and threatening behaviour toward regulatory staff.
- All five FCA allegations were upheld. The ban stands. The fine, adjusted slightly, is £1.53 million.
The FCA's own words are blunt. Therese Chambers, the regulator's executive director of enforcement, said Odey "clearly thought he could act with impunity" and displayed "arrogant entitlement" with "complete disregard for proper governance."
That last phrase is the point.
The Common Thread
Exein sells protection against external attackers. Odey's case is about the absence of internal ones — the checks meant to stop a person with power from simply removing anyone who challenges them.
Both stories point to the same principle: security is a system, not a purchase.
A company can buy the best firewall in the world and still collapse if:
- Leadership can override oversight whenever it's inconvenient.
- Governance bodies exist to be dismissed rather than obeyed.
- Accountability is treated as optional for anyone senior enough.
Exein protects machines from attackers who don't care about their targets. Odey's tribunal shows what happens when the people inside an organisation don't care about the rules either. Different domains, same failure mode: protection without accountability is theatre.
Why This Matters Beyond Finance and Tech
Governance isn't a compliance checkbox you complete once a year. It's the ongoing, sometimes uncomfortable work of letting people below you say no — and having that no actually mean something.
Odey didn't lack governance structures. Odey Asset Management had an executive committee, a disciplinary process, a final written warning already on record. The structures existed. What failed was the willingness to let them function when they produced an inconvenient answer.
That's the real lesson for any organisation, cybersecurity firm or otherwise: building the system is the easy part. Respecting it when it tells you something you don't want to hear is the job.
Key takeaways
- External security and internal governance are not substitutes for each other — a firm can be technically secure and organisationally rotten at the same time.
- Exein's €234 million raise shows real investor appetite for protecting physical and connected systems from external threats.
- The Upper Tribunal's decision on Crispin Odey shows what happens when internal accountability structures are dismantled by the very people they're meant to check.
- Governance only works if it survives contact with someone powerful who disagrees with it.
- Real protection requires both: defend the perimeter, but also make sure no one inside can simply override the rules when it suits them.