Managing cyber risk for boards – the ultimate guide for UK board directors

Image for the ultimate guide to managing cyber risk for boards

Managing cyber risk has become a key issue for boards of directors. 

And although most board members are not cyber experts, and cyber security is a complicated, technical and rapidly changing field, they have an obligation to recognise and monitor this risk. 

While this may appear to be a daunting task, there are some relatively simple steps boards and board members can take. These steps will ensure that they and their organisations are both minimising cyber risk and being seen to do so by their customers and other stakeholders, which we will share.

In addition, we believe reducing cyber risk is a positive value-add for businesses and increasingly a way of increasing competitive advantage. Rather than seeing cyber risk as an unwelcome distraction, we strongly encourage board directors to see it as an area to enhance value.

In this guide to managing cyber risk for boards, we:

  1. outline the questions boards need to address
  2. suggest a 5-step action plan to answer them effectively in a manageable way.

Questions on cyber risk that boards and board members need to address

The National Cyber Security Centre has specified a number of questions that boards and board members should ask themselves.

1. Is a cyber strategy in place?
2. Can board members name the top cyber security threats, and outline the measures that are in place to mitigate their impact?
3. Do we have an effective approach to managing cyber risks?
4. Does the board understand the overarching purpose of the cyber security measures in place?
5. Does your organisation have an incident response plan in place, and do you regularly rehearse it?
6. Are products/services provided by partners/suppliers documented?
7. Do your organisation’s security metrics focus on success rather than failure?
8. Are your HR team identifying – and addressing – any cyber skills gaps in your organisation?

Taking action – how board directors can address these questions and minimise their cyber risk

The questions laid out by the NCSC cover a wide range of topics. However, we believe most boards and board directors can get to grips with their cyber risk by adopting a 5-step approach that addresses the key issues they raise.

The intention with the 5-step approach is to break things down into more manageable chunks so dealing with cyber risk never seems overwhelming. If you can make progress against each step, the cumulative impact on your cyber risk with be significant. And as we said above, not only does that mean reducing cyber risk, it also means boosting competitive advantage.

5 step plan for reducing cyber risk graphic

Here are our recommended 5-steps:

  1. Understand the scope of cyber threats – particularly ones that affect your industry
  2. Understand the reality of where you are now, and what are the biggest cyber risks
  3. Understand what is currently in place to mitigate cyber risks, and whether the risks are being monitored
  4. Understand your responsibilities
  5. Develop a realistic roadmap for improvement, and review regularly

1) Understand the scope of cyber threats – particularly ones that affect your industry

Because cyber crime is growing in scale and scope, every business is now a possible target. 

According to the Ponemon Institute/IBM Security Cost of a data breach 2022 report, the average cost of a data breach in the UK is now £4.14 million (at current exchange rates), with this now the 4th largest figure globally (having risen from 8th in 2021). 

No board can afford to ignore a threat of this scale.

If you need any more persuasion, consider the following statistics from the same Ponemon Institute/IBM Security Cost of a data breach 2022 report:

  • For 83% of businesses surveyed in the report, their latest data breach was NOT their first
  • 60% of businesses that suffered a data breach had to increase prices as a result
  • The average time that elapsed between the first detection of the breach and its containment was 277 days
  • This average rises to 326 days for a ransomware attack
  • Nearly 20% of breaches were caused by a supply chain compromise, and these compromises made breaches more expensive and resulted in longer lifecycles

In order to do this effectively, you first need to understand where you are, which is covered in step 3 below.

2) Understand the reality of where you are now, and what are the biggest cyber risks

In our opinion, this is the most critical step of the five in our action plan. 

If you don’t know exactly where you are, taking action or putting together a meaningful plan to reduce your cyber risk is almost impossible.

It is essential therefore to have an independent review of your situation from a specialised and qualified cyber security company. This is not to be critical of your existing arrangements, but rather to give you a clear assessment of where you are and what issues – including potentially critical ones – you need to address.

In our opinion, such a review should include:

  • Real, valuable, non-technical insights into your potential risks, threats and vulnerabilities, along with details of business or operational impact on the customer
  • A detailed report with your strengths, weaknesses and any urgent issues that require attention
  • A general assessment of the environment analysed

If you need help with this, Securious offers a Cyber Security Audit for boards to provide the information you need, with a full explanation of what it all means for a board (non-technical) audience. Learn more here.

3) Understand what is currently in place to mitigate cyber risks, and whether the risks are being monitored

For example, we might implement and test measures to minimise the damage an attacker could do inside our network?

Can you realistically identify the presence of an attacker within your network – do we have appropriate monitoring? 

How do we defend ourselves against phishing attacks?

  • Do we filter phishing emails
  • Do we mark external emails as ‘External’ 
  • Do we conduct staff security awareness training, so they can be our first line of defence?

4)  Understand your responsibilities

If there is a breach in cyber security, the board and top management may have to explain what they did. 

Board members could be in violation of their fiduciary duties to the company and its shareholders if they don’t put in place the right controls for reporting, system or cyber security, and data protection, or if, after putting these controls in place, they don’t keep an eye on them. 

During and right after a cyber attack or data breach, the board of directors may also be looked at to see how they handle notifying the authorities, the financial markets, and people whose data may have been affected. 

As an illustration, the Ponemon Institute/IBM Security Cost of a data breach 2022 report suggests that companies that had in place a cyber incident response plan and a team that had rehearsed it reduced breach costs by 58% versus those with no incident response plan or team in place. 

So, it’s important for senior management to figure out who is responsible for setting up and managing cyber and data security in a company, both before and after a cyber event, and that the appropriate systems are in place.

5) Develop a realistic roadmap for improvement,  and  review regularly

While having a clear understanding of where you are is crucial, what ultimately matters is that you take action to lower your risk appropriately.

In order to do this, you will need a prioritised road-map that suggests how you should address existing risks, threats, and vulnerabilities.

This will show that you know how important cyber security is and that you are taking steps to fix any holes or weak spots in your infrastructure.

It will also give your board clear visibility of the actions needed, their cost and impact, and the ability to track progress over time.

At Securious, our Cyber Security Audit for boards always includes a roadmap of this type; contact us for more information!

Unfortunately, cyber security, by its very nature, is not something that can just be addressed once and fixed for good. Threats are constantly evolving, and the solutions to yesterday’s problems might not be fit for purpose today or tomorrow.

This means cyber security is an area that your business, and your board, needs to maintain vigilance over on a permanent basis. 

Cyber risk and visibility

One of the most crucial aspects is to ensure visibility of what is actually happening within your organisation’s systems. This enables you to monitor them effectively. After all, if you can’t see what’s actually happening, you have minimal chance of taking effective action against threats. Remember the average threat is live inside an organisation’s systems for 277 days before it is neutralised.

Technology will never be the full answer to cyber security risk. That’s because people are always a crucial factor. But it can definitely help. 

For example, it is now possible and affordable for virtually all organisations to set up live 24/7 monitoring and visibility of their environment. This will let you see everything on your network and devices and flag anything that seems odd so it can be looked into right away.

For an example of how this can work, have a look at the Securious Managed Detection and Response service, here.

The MDR service will also provide regular reports that keep the board updated on key issues. This will further enable them to take control of cyber security oversight on an ongoing basis

Minimising your cyber risk – next steps

If you would like some independent and qualified support, we’d be delighted to talk you through the process.

Based in Exeter, Securious is the region’s leading cyber security consultancy. We work with leading organisations across the South West and beyond to help understand and mitigate their cyber risk. 

We are highly experienced, qualified and well-regarded by our clients. Critically, we provide a completely independent viewpoint. This can give boards confidence without being solely dependent on the opinions of their internal team or external IT support.

With many of our clients, we develop a lasting and ongoing relationship to help them address risk along their journey.

Our services include cyber strategy, cyber risk audits, PCI DSS, PCI 3DS compliance, penetration testing and vulnerability scanning, ISO 27001, Cyber Essentials/Cyber Essentials Plus. Securious also offers a Managed Detection and Response (MDR) service to effectively outsource your cyber risk to us.

We believe reducing cyber risk is a positive way of adding value to organisations and building a competitive advantage. We strongly recommend boards frame it this way rather than as an unwelcome chore.

Would like to find out more about our services or discuss your cyber security requirements with us, in confidence and without any obligation or hard sell? Please give us a call or send an email to our CEO Pete Woodward at pete@securious.co.uk.