Skip to main content
Guidance

Cyber Security Toolkit for Boards

Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.

Page 27 of 27

Engaging with Boards to improve the management of cyber security risk

Magnilion via Getty Images

How to communicate more effectively with board members to improve cyber security decision making.

Cyber security is a critical risk for boards and executive teams. Cyber security leaders (such as CISOs) play a crucial role in describing and mitigating the risks. This guidance helps those leaders to communicate effectively with Boards, and to better engage with their members.


Note:

This guidance does not aim to increase cyber security understanding amongst board members. The NCSC has produced separate guidance designed to help Boards ‘get a grip on cyber’, and includes briefings, guidance and training material directed at non-technical decision makers.


Note:

The Financial Reporting Council - UK Corporate Governance Code gives a more detailed view of the role of a Board (and its members).

Understand how YOUR Board works (and who is on it)

We tend to think of ‘The Board’ as a single entity, but it is of course made up of individual humans just like any other group, each with their own knowledge, skills, styles and preferences. 

As well as who is on the Board, it's important to understand the mechanisms and practicalities of how your Board operates. How often do they meet? What format do the meetings take? What committees are there? Find out who manages the Board in your organisation. Larger companies will have a Company Secretary team who will be able to support you. Responsibility sometimes falls to a Chief of Staff role. In particular, seek advice on their ‘ways of working’, such as how they like sessions to work, and what style of papers and presentations work best. Read what Board output might be available to you.

Cyber is a risk - talk about it as such

Boards understand risk. Many Boards will have a Risk Committee possibly combined with other functions such as Audit, Governance or Compliance. 

Whilst cyber risks may be notably different from other risks (the adversarial nature, the potential for catastrophic impact, their often very technical nature - and more generally how ‘new’ cyber risk is), it is helpful to align it with the framework and language of risk the Board are already familiar with. It allows you to locate ‘cyber’ in what should be familiar territory for board members. Your role is to help them understand how the cyber risks manifest as business risks, their potential impact and what you (with their support) will do to avoid or mitigate them.

In practice this means decomposing the threat landscape into clearly stated risks, in natural language, then grading the likelihood and impact of those risks.

Where possible, quantify and make the risks tangible, using precise language. You should reserve ‘doomsday scenario’ language and hyperbole for risks that really really warrant it. Equally Boards expect honest, matter-of-fact assessments of risks and your current position. Trying to gloss-over the risk (or overstate the mitigation) is not helpful.

Recent research commissioned by the NCSC revealed that 80% of Boards do not realise that the accountability for cyber risk rests with them, even when cyber aspects are outsourced. Remember, it’s your job to advise; you can’t set the appetite for risk. That has to be done by the Board.

Engage outside of Board meetings

Board meetings aren’t the best place for you to ask questions, or to have in-depth discussions. 'Cyber' is more likely to be allocated a 15-minute session, rather than a two-hour workshop. It is much easier to have longer discussions between individuals and smaller groups. You may also find Board members are more comfortable asking questions about things they are unsure about in these smaller groups, something that’s hard for anyone to do in a formal setting. 

You’ll soon be able to identify the individuals on the Board who have a particular interest or knowledge of your area, so try and develop regular communication with them outside the regular Board agenda. Work with your executive management to achieve this.

High-profile incidents present an opportunity to inform, update and advise. When cyber hits the news, which it frequently does, use the story to put a short briefing together for executive teams and Boards. This should cover the potential impact on your organisation, the steps you're taking to protect against similar incidents, and anything within your organisation that might heighten the risk or block progress in mitigating it. It may not be appropriate for you to send this directly to the Board, but share these thoughts with executives for them to share, if they see fit.

Answer the most important questions first

Make sure that you understand what is most important from the Board’s perspective. This might include:

  • What are the key risks and mitigation plans that you need to show progress against?
  • What are the KPIs and metrics that are most relevant to your organisation?
  • What impacts are your Board most worried about? Downtime? Client impact? Regulation? 
  • What are the critical questions the Board wants answering? 
  • What operational data can you surface to show activity and the benefits being achieved by investments made? 

A ‘one-page’ summary dashboard maybe called for here. Your organisation or Board meetings may have a preferred format and approach to routine reporting which you should work with.

Expect to be asked about the big picture

Part of Board’s role in governance and oversight is to make sure experts don’t get lost in the weeds at the expense of the bigger picture. One way Board members will do this is by ‘stepping back’ and asking broad questions. Questions you can expect to be asked may include: 

  • Do we understand the cyber security threat, and how it might impact our business strategy and plans?
  • How do we benchmark against other organisations? Our peers? Our sector?
  • How do we consider cyber security implications when we take decisions?
  • Have the critical assets for protecting our key business objectives been identified?
  • Are we managing the risks in an effective way?
  • Are we executing against the mitigation actions?
  • Are responsibilities clear?
  • Are we working with our supply chains and customers on this?
  • Do we have incident and contingency plans in place? Have they been tested?

The NCSC’s ‘Cyber security 101’ for board members (PDF) gives insights into the types of questions Boards should and might reasonably be asking. Note that these aren’t technical questions; these are governance & assurance questions that Board members will feel comfortable asking, and to test the answers to.




Published

Publish date

Reviewed

Version

3.0