Warren O’Driscoll, Head of Security Practice, NTT DATA UK & Ireland, on why cyber resilience is now a matter of board accountability and why organisations must act before regulation or a major incident forces change.
Cyber resilience is no longer an IT issue that boards can delegate and revisit only after an incident. The UK Government has made that abundantly clear.
In October 2025, an unprecedented coalition of senior leaders – including the chancellor, two secretaries of state, the security minister, the CEO of the National Cyber Security Centre (NCSC) and the director general of the National Crime Agency (NCA) – issued a joint ministerial letter calling on boards to take direct responsibility for strengthening their organisations’ cyber resilience.
The message could hardly have been stronger: cyber security is now a matter of corporate governance and board accountability. Directors have a responsibility not only to protect their own organisations but also to safeguard customers, supply chains and, collectively, the resilience of the UK economy. Boards can no longer view cyber as a specialist technical concern that sits solely with CIOs, CISOs or IT departments.
The timing of the letter was significant. It followed the cyber attack on Jaguar Land Rover, an incident that the Bank of England’s November 2025 Monetary Policy Report found had a measurable impact on UK GDP growth.
The implications are stark. Cyber attacks are no longer isolated operational disruptions; they have the potential to affect economic performance, public trust and national resilience.
For boards, the question is no longer whether cyber belongs on the agenda but whether they are prepared to exercise the leadership and oversight that the threat environment now demands.
Awareness is certainly increasing. More than 90% of boards already recognise cyber security as a strategic priority. Yet recognition is not the same as accountability and concern does not automatically translate into action.
Awareness is not accountability
The first step is to build understanding. For years, the nature and scale of the cyber threat meant that IT departments – aided by all-staff training on attack techniques such as phishing – were largely able to manage the risk. Cyber security sat well outside the board’s responsibilities, typically with CISOs, and was rarely embedded in strategic governance alongside topics such as finance, safety and operational risk.
Even today, CISOs do not typically sit on boards. The further they operate from the board – whether under the CIO, within a risk function or inside a directorate such as Digital Transformation – the greater the risk that the security message becomes diluted before it reaches those who need to act on it. It is little surprise, then, that few board members possess an understanding of cyber risk comparable to their knowledge of accounting, brand reputation or strategic workforce management.
Both the nature and scale of the threat have, however, increased dramatically. Boards that continue to delegate cyber downward are now personally exposed, with the ministerial letter placing legal and reputational accountability squarely on directors and board members.
Inevitably, much of this accountability will ultimately land with CIOs, who now have both heightened influence and greater responsibility for the careers and reputations of their fellow board members.
The challenge is even greater for CIOs in UK Critical National Infrastructure (CNI) organisations, where responsibility often extends beyond enterprise IT into operational technology (OT) – the industrial control systems that underpin essential services such as energy, water and transport.
The pitch has therefore been rolled. Board members should be ready to listen to their CIOs on cyber issues. It is now for technology leaders to educate their fellow board members on how the threat manifests within their own organisations and how resilience is best achieved.
The commercial case for resilience
One key message is that cyber resilience, when handled well, is increasingly a source of commercial advantage rather than simply a cost centre. As more procurement teams and regulators make cyber posture a condition of contract, organisations with demonstrably strong governance frameworks will be better placed to win business than less rigorous competitors.
The reverse is equally true. Organisations that suffer breaches compromising customer or client data risk losing both trust and their reputation as secure partners, presenting an existential threat to their businesses.
The commercial case for acting is, in that sense, inseparable from the security case.
One practical step is to make cyber security and cyber resilience standing board agenda items, using the government’s Cyber Governance Code of Practice. This sets out specific actions for both executive and non-executive directors and is supported by free training for board members.
Boards must also recognise the need to plan and practise how they would continue operations and rebuild following a major incident or crisis. The NCSC’s Cyber Security Toolkit for Boards advises leaders to ensure that incident response plans are in place so that organisations can minimise the impact of incidents and resume normal operations as quickly as possible.
In my many years as a military reservist, I have learned a principle that holds just as true in business as it does in the Armed Forces: in a crisis, you will typically sink to the level of your training.
You do not get lucky without effective planning and regular exercises.
Supply chain risk is another critical consideration. According to the ministerial letter, just 14% of UK businesses assess the cyber risks posed by their immediate suppliers, despite the fact that cyber attacks disproportionately exploit the weakest link in the chain. An attacker does not need to breach your defences directly. They simply need to find a supplier with lower standards and use that relationship as their route in.
Boards must also recognise that if they become the entry point for an attack on a customer, the consequences extend far beyond operational disruption. They affect customer trust, commercial relationships and future growth opportunities.
A cyber attack that takes down your production line may frustrate your customers; losing their data to cyber criminals may lose them permanently.
One obvious action is to require Cyber Essentials certification across the supply chain, as the government already demands of its own suppliers. This establishes a minimum standard and sends a positive signal to regulators and investors. The ministerial letter notes that certified organisations are 92% less likely to make a claim on their cyber insurance.
The controls within Cyber Essentials Plus should be considered the baseline for any organisation, although applying them consistently across multinational businesses remains challenging, not least because it is currently a UK-only certification.
Similarly, registering for the NCSC’s Early Warning service requires minimal implementation effort and gives organisations valuable time to detect and contain incidents before they escalate. The service encourages intelligence sharing between government and industry so that both can outpace attackers, with its value increasing as information flows in both directions. It is one of the lowest-cost, highest-impact actions available to any board today.
Move before regulation forces the issue
Organisations should also be preparing for the passage of the Cyber Security and Resilience Bill, which will bring significant change to the UK landscape by expanding the scope of regulation and giving regulators much sharper enforcement powers. This emerging legislation presents both another set of responsibilities for CIOs and another powerful means of demonstrating the strategic importance of cyber resilience to boards.
Just a few years ago, relatively few boards included a CIO. Today, they are central to almost every organisation’s operations.
Now CISOs are increasingly recognised as equally critical to organisational resilience and future success, and the government’s strong messaging should help technology leaders bring their fellow board members fully into the cyber agenda.
The question is no longer whether cyber belongs at the board table. It is whether boards are prepared to lead on cyber resilience before legislation or a major incident forces their hand.
The government is giving CIOs and CISOs powerful support in securing board-level commitment to the cyber agenda, and digital leaders should use every bit of that leverage.
Organisations that bring their boards on side and implement the standards, practices and certifications outlined above will be significantly better placed to withstand an increasingly hostile cyber threat environment.
Those that do not will ultimately be compelled to act – either by regulation or, far worse, during the clean-up after a successful attack.


