Skip to main content
Cyber Governance for Boards

Cyber Governance for Boards

Resources to enable Boards to govern cyber risks with confidence.

Technology and digital systems are at the heart of modern business, driving innovation, growth, and competitiveness. As organisations adopt emerging technologies, they also introduce new risks - cyber risk being one of the most significant.

Cyber threats can disrupt operations, damage reputation, and weaken competitiveness, making cyber risk a principal business risk. As with any major risk, Boards and directors have a critical responsibility to govern it effectively. However, many organisations are still not addressing this challenge with the urgency it demands.

69% of large organisations reported a cyber security breach or attack in the last year

69% of large organisations reported a cyber security breach or attack in the last year

Just 48% of large organisations review cyber risks from their immediate supplier

Just 48% of large organisations review cyber risks from their immediate supplier

Only 24% of large organisations assess wider supply chain risks

Only 24% of large organisations assess wider supply chain risks

57%

Only 57% of medium organisations have an incident response plan

38% of medium businesses have not undertaken cyber security risk assessments in the last year

38% of medium businesses have not undertaken cyber security risk assessments in the last year

57%

Just 57% of medium organisations have a formal cyber strategy in place

CYBER BREACHES SURVEY 2026

These Cyber Governance resources have been created to support boards and directors in governing cyber security risks. They also clarify the government’s expectations for Board accountability in overseeing cyber security risk management in medium and large organisations. 

Who are these Cyber Governance Resources for?

These resources are tailor-made for Boards and directors of both public and private organisations across the UK.

That could be:  

  • Non-Executive Directors or a Board of Trustees 
     
  • A Board of Directors 
     
  • A Board of Governors/Advisors  

Although not specifically designed for smaller organisations, they offer valuable benefits and practical insights that can help strengthen their approach to governance.


Cyber security risks demand Board-level attention. While directors don’t need to be technical experts, they must understand cyber governance principles so they can ask the right questions, evaluate preparedness, and ensure cyber security measures align with the business’s goals.