The Role of the Board in Managing Cybersecurity: Where the cyber buck stops!

In an era where digital has reshaped industries, cybersecurity has emerged as a critical business risk, in banking its often cited as the most important risk type. The role of the board in overseeing cybersecurity is no longer optional—it is an imperative. Boards must ensure that their organizations are not only protected against cyber threats but also resilient in the face of inevitable incidents.
Cyber threats are not just IT issues; they are enterprise-wide risks that can impact reputation, financial stability, and operational continuity. High-profile breaches, such as those experienced by Equifax (2017), SolarWinds (2020), and Colonial Pipeline (2021), have demonstrated the consequences of inadequate cybersecurity oversight. According to a 2023 IBM report, the average cost of a data breach globally reached $4.45 million, a 15% increase over three years. Key statistics make sober reading …
60% of small businesses fold within six months of a cyber-attack. (National Cybersecurity Alliance)
83% of organisations have experienced more than one data breach. (IBM Security, 2023
Human error is a factor in 95% of cybersecurity breaches. (World Economic Forum, 2024)
The board must establish a culture of cybersecurity awareness and become involved in the active management of cyber security policy implementation. To do so, board members should set the tone from the top, understanding the threat landscape and be prepared to allocate the resources and expertise needed. On a day-to-day basis, the board should give oversight of Cybersecurity strategy and policies, and the board must ensure that the organisation has a comprehensive cybersecurity strategy aligned with business objectives. Boards can adopt different governance models for:
Full Board Oversight: The entire board is responsible for cybersecurity. About 45% of organisations sampled
Dedicated Committee: A risk or audit committee takes the lead. About 40% of organisations sampled
Hybrid Model: A combination of full board and committee oversight. About 15% of organisations sampled
There are case studies of where a board acted around cyber security. The Maersk (2017 NotPetya Attack) resulted in a $300 million in losses due to a global ransomware attack. The Board action was to prioritise cybersecurity post-attack, investing heavily in resilience and recovery. Similarly, Capital One (2019 Breach) had 100 million customer records were exposed. In this case, the Board overhauled cybersecurity governance, including the appointment of a new CISO and increased budget allocation.
The board’s role in managing cybersecurity is proactive and non-negotiable. Is that the case in your organisation? If not, then ask yourself should I change? If not now, then when (and why)?
To talk about cyber security contact Jeremy Bryson on jeremy.bryson@velesconsulting.co.uk

Jeremy Bryson
View on LinkedIn
