Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 4 of 27
What is cyber security?

Explains the Board’s role in cyber security, why organisations are at risk, and the factors behind cyber attacks.
What is cyber security?
Cyber security is how individuals and organisations reduce the risk of cyber attack. Its core function is to protect the devices we all use and the services we access - both online and at work - from theft or damage. It's also about protecting the vast amounts of data we access from cyber attacks or compromise, which could disrupt businesses and cause financial loss or reputational damage.
As a Board Member, it's important to view cyber security strategically. Cyber security is crucial to safeguarding your operational resilience to ensure that your business can continue to function during an incident. When it's done well, cyber security can be an enabler of positive change within your organisation, rather than simply being the reaction to a breach. For example, organisations with a pro-active approach to cyber security were able to quickly pivot to adapt to the challenge of providing secure homeworking in response to the COVID-19 pandemic.
Cyber security and cyber resilience both have an equal part to play in reducing the cyber risk to organisations:
- cyber security focuses on preventing hackers penetrating your IT systems1
- cyber resilience is the ability of an organisation to protect itself from, detect, respond to and recover from a cyber attack
Taking a methodical and proactive approach to cyber security, and putting in place basic safeguards can greatly reduce the risk to your organisation.
Your responsibility as a board member
The Board is responsible for ensuring that risks to delivering the strategy are identified, evaluated, and mitigated in line with the business risk appetite. This includes:
- understanding the risk that cyber incidents present to delivery of the business strategy
- ensuring that the business has adequate cyber resilience to prevent, detect and respond to cyber attacks
Board members don't need to be technical experts, but you do need to know enough about cyber security to have constructive discussions with key staff, so you can be confident that cyber risk is being appropriately managed.
Encouragingly, the 2024 Cyber Breaches Survey notes that cyber security is rightly seen as high priority for directors, trustees and other senior managers. However, it also notes that "There is a lack of understanding or interest in cyber security relative to the day-to-day operations of the organisation, a lack of training, a lack of time and a perception that their kind of organisation was not facing an especially high risk from cyber attacks".

Percentage of organisations over time where cyber security is seen as a high priority for directors, trustees and other senior managers (Source 2024 Cyber Breaches Survey, Figure 2.2).
Board members can ensure that cyber security is given appropriate investment against other competing business demands. The Board should rely on its cyber security experts to provide insight, so that the board can make informed decisions about cyber security, aligned to business risks. A senior leader with good understanding of cyber security can improve the knowledge of other board members, increase awareness amongst the wider body of staff, and make the business case for more targeted cyber security spending.
As a board member, you may be targeted
Senior executives or board members are an attractive target for cyber criminals because of their access to valuable assets (usually money and information). Attackers may try and directly target your IT accounts, or they may try and impersonate you by using an email address that appears the same as your own. These attacks work by exploiting the reluctance of staff to challenge requests from someone senior in the organisation. Security policies that are fit for purpose, a positive cyber security culture and well-understood reporting processes will all help to mitigate this risk. You should also consider how personal information about you that is available online (known as your 'digital footprint') could assist an attacker who is trying to impersonate you.
Cyber security: what you need to know
The Board Toolkit briefing packs are an excellent way to introduce cyber security to board members. They are written for a non-technical audience and include slides and presenter’s notes for those who wish to deliver the presentations themselves.
- You can download the presentations and read them in your own time, or watch the NCSC's videos that talk you through the content.
Why is your organisation at risk?
It's important to realise that any organisation relying on digital technology is at risk of a cyber incident. The majority of cyber attacks are untargeted and opportunistic in nature. Cyber criminals will attempt to exploit a weakness (or vulnerability) in a system, without any regard for whom that system belongs to, or the size of the organisation. This means cyber risks need to be proactively identified and mitigated. For example, the WannaCry ransomware attack in 2017 was largely possible because software was not being kept up to date, as the following video demonstrates.
This trend of untargeted attacks is unlikely to change because every organisation - including yours - has something of value to an attacker. It is not just the money you might be asked to pay in a ransomware attack to recover your data. It's also the cost of service disruption, lost business, the damage to your reputation and the cost of investigating and recovering from the attack.
Who is behind cyber attacks?
Despite how they are frequently described, most cyber breaches are not a result of 'complex and sophisticated attacks'. The vast majority of attacks are still based upon well-known techniques (such as phishing emails) which can be defended against. The video below summarises the people and groups behind cyber attacks, their capabilities and their motivations.
Whilst it's true that some attacks are highly sophisticated, these are usually conducted by hostile foreign states who have the money (and motivation) to fund them.
1 Organisations that have cyber-physical systems will also need to consider Operational Technology (OT) and Industrial Control Systems (ICS) security and resilience.


