Skip to content

7 September, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • data

      Every board needs a scientist or engineer

      STEM professionals are trained to work with incomplete data, and in business you rarely have...

      climate risk

      Now is the time to take action on climate risk

      Whatever direction national policies take, nature and climate remain as drivers of value and risk...

      AI risk

      AI is about strategy, not technology

      Clients are judging how professional services firms are performing against their AI expectations, but most...

  • Comment
      • View all
    • data

      Every board needs a scientist or engineer

      STEM professionals are trained to work with incomplete data, and in business you rarely have...

      climate risk

      Now is the time to take action on climate risk

      Whatever direction national policies take, nature and climate remain as drivers of value and risk...

      ai skills gap

      Don’t forget to price up the AI skills gap 

      With AI set to be biggest force reshaping organisations, it is time to put workforce...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

      female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • Georgeson 2026 European AGM Season Review

      Georgeson’s deep dive into the evolving dynamics of investor voting across nine major European markets in...

      2026 MidYear Executive Benchmark Survey: The Verification Gap

      AI enthusiasm is running into reality: 1 in 4 executives in this Workiva survey say...

      Seven Steps for Futureproofing Business

      This guide from Business in the Community aims to help businesses build a practical strategy...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

Crime fighters

by Peter Swabey

With cyber-crime hitting the headlines, it’s time for tech-savvy non-executives to take note. Peter Swabey explores the big questions boards need to address.

Cybercrime, data protection, GDPR, cybersecurity

Cybercrime. Photo: European Parliament – Audiovisual Unit

Favorite
Cybercrime. Photo: European Parliament - Audiovisual Unit
Cybercrime. Photo: European Parliament – Audiovisual Unit

Boards have had to pay closer attention to cyber-security as attacks become increasingly complex and more frequent.

Technological expertise around the boardroom table, however, has not advanced at the same rate and therefore does not match the sophistication of cyber-crime.

Hackers are more likely to be millennials, yet boardrooms tend to be populated with older, non-tech-savvy individuals whose careers predate the internet and who consider cyber-security to be arcane. With cyber-crime costing industry billions of dollars, it is time that Generation Y was given a seat at the top table.

According to research by Ortus, the average age of FTSE 100 board members in 2013 was 57, with one in six board members aged 65 or over. In Australia, the technology sub-committees of the largest ASX 200 companies in 2014 comprised males with an average age of 60 to 69, without tech sector experience or even any specific technical training. Cyber-security, it would seem, is beyond most board directors’ personal experience.

Reputational damage can be the biggest cost and, once consumer trust is lost, it is very difficult to win back.

Traditionally, cyber-security has fallen under the remit of the chief technology officer (CTO) and chief information security officer (CISO), but it is now considered a direct responsibility of the board of directors and the audit committee in particular.

There is a good reason for this. Cyber-crime is one of the top threats facing businesses. Data can be destroyed (as in the case of Sony Pictures), intellectual property stolen to gain a competitive edge, customer data compromised, and information that companies would rather remain secret can be used to shame and embarrass companies and individuals.

Reputational damage can be the biggest cost and, once consumer trust is lost, it is very difficult to win back. Non-executive directors and other board members, therefore, need to fully understand the business implications of cyber-crime.

Perpetrators

The first thing to grasp is that not all cyber-crime is committed by outside criminals. Disgruntled employees can cause as much damage as external hackers, as in the case of Morgan Stanley, which suffered a security breach when an employee posted information about 900 of its wealthy clients online.

The first thing to grasp is that not all cyber-crime is committed by outside criminals. Disgruntled employees can cause as much damage as external hackers…

The board should consider whether strict controls are in place to prevent client data and passwords getting into the wrong hands. When an employee leaves, organisations should change their passwords and clients should be advised to change theirs.

Non-executive directors could also pose unforeseen problems. Often they are privy to highly confidential information, but as they mainly work off-site the information stored on their mobile devices might be not as strongly protected as it should be.

The same is true of third-party vendors and service providers. Third-party vendors’ usernames and passwords have been used to access a company’s network and cause chaos, as was the case in the Home Depot security breach in the US. The liabilities that third-party providers and company suppliers bring should be analysed in the assessment of an organisation’s risk profile.

Implications

The financial implications of losing customer information are huge and third-party assurance is set to grow as companies seek to protect themselves against lawsuits for loss of data or revenue.

Think how costly it would be to eBay if the 145m users who had their personal records hacked in 2014 brought a class action against the company. The security breach on Sony’s PlayStation network in 2011 is estimated to have cost the company $170m, and that was for just 12m account holders.

An ICSA guidance note places cyber-crime firmly at the top of the UK boardroom agenda. The report identifies four key challenges for board members:

  • Understand cyber-risks particular to the company;
  • Allocate a budget to cyber-crime prevention;
  • Focus on building resilience to attacks that get through the system, rather than preventing all attacks;
  • Identify a director responsible for the oversight of the company’s cyber-crime strategy.
The digital age is here. Boards need to ensure that they are properly equipped to meet it.

Appointing a non-executive director to lead a special cyber-risk task force is a good idea for high-risk companies.

Senior security and technology experts within the business should report into a non-executive so that the board has one formally identified place to go with any technology and information concerns. This would also ensure that cyber-risk remains firmly on the board’s radar.

Boards need to be thinking about appointing technologically savvy non-executives. Not only will their direct experience be of benefit, their ability to help other board members understand and assess cyber-risks is priceless in terms of striking a balance between digital innovation and risk avoidance.

The digital age is here. Boards need to ensure that they are properly equipped to meet it.

The big questions

The top-ten questions that non-executives ought to be asking themselves about cyber-security:

  1. How confident are you that your company’s most important information is being properly managed and is safe from cyber-threats?
  2. Do you know your company’s specific cyber-risks and do they appear on the company’s risk register?
  3. Are budgets reviewed and risk assessment carried out on a regular enough basis?
  4. Do you have a full and accurate picture of the impact on your company’s reputation, share price or future survival if sensitive internal, or customer, information were to be lost or stolen?
  5. Is the board receiving reports on breaches and IT risks regularly enough? For example, do you know who may be targeting your company, their methods and their motivations?
  6. What would the impact on the business be if online services were disrupted for a short or sustained period?
  7. Have you taken the time to understand the company’s systems? Is there a strong privacy policy in place, for example?
  8. Do you know your company’s cyber policies and procedures, and are all employees made fully aware of cyber-risk? Is staff training provided in digital do’s and don’ts?
  9. Could you be a key target? Is the confidential information that you hold adequately protected?
  10. How could cyber-security insurance limit your liability?

Peter Swabey is policy and research director at ICSA, the professional body responsible for governance and the qualifying body for chartered secretaries.

 

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Cyber criminals chase ransomware insurance money
    April 18, 2023
    ransomware insurance

    Specialist ransomware criminals are investigating victims’ insurance capacity—sometimes by blatantly asking companies outright.

  • Technology, cyber risk and ESG top list of business leaders' concerns
    June 8, 2022
    Digital code on skycrapers

    Mazars survey reveals 82% of executives plan to increase investment in IT systems, while 75% plan to boost spending on sustainability.

  • FBI warns ransomware gangs are targeting M&A transactions
    November 18, 2021
    ransomware threat

    US crime agency says the hard deadlines involved in M&A transactions pressures victims to pay up for fear of affecting stock values.

  • Are cyber disclosure demands too high?
    August 15, 2022
    cyber disclosure

    Organisations increasingly struggle with cybersecurity as they balance fear of reputational damage against cyber disclosure requirements.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy