Skip to content

15 February, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board Expertise
      • finance
      • Technology
    • board decisions

      How to take decisions in uncertain times

      Instability is no longer a temporary disruption but a permanent state, so boards must govern...

      ethnic diversity FTSE 350

      Are US anti-DEI policies affecting global boards?

      Chairs must be alert to the issues raised by a shifting picture in diversity, equity...

      mindset

      Transformation begins with board mindset

      Boards cannot lead meaningful change without being prepared to examine and adjust how they think,...

  • Comment
      • View all
    • mindset

      Transformation begins with board mindset

      Boards cannot lead meaningful change without being prepared to examine and adjust how they think,...

      growth in a volatile year

      5 strategies for growth in a volatile year

      A survey of the C-suite in Europe reveals the practical and pragmatic approaches being taken...

      audit reform

      This is the worst time to abandon audit reform

      High-quality audit, accurate corporate reporting and strong governance give investors confidence and help companies operate...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • ethnic diversity FTSE 350

      Are US anti-DEI policies affecting global boards?

      Chairs must be alert to the issues raised by a shifting picture in diversity, equity...

      2026 OUTLOOK

      Are you ready for 2026?

      Buckle up: it looks like boards are in for a turbulent time. We interviewed key...

      sustainability report audit

      Thinking of sidelining sustainability? Think again

      Boards that embed sustainability into strategy will be ready to face today’s complex environment, the...

  • Board Careers
      • View All
    • female CEO

      Number of women in leadership stays unchanged

      In 2021, there were only eight female CEOs in the FTSE 100—a figure that is...

      female NED

      UK female non-executives earn £73k less than male NEDs

      Although the UK’s average gender pay gap on boards is shrinking, it is still one...

      directors duties

      3 top tips on directors’ duties

      When directors fall short of their responsibilities, the consequences can be devastating. How can board...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • Governance Outlook 2026: Governance in transition across Asia-Pacific

      Diligent partnered with the Governance Institute of Australia and the Singapore Institute of Directors for...

      Allianz Risk Barometer 2026

      Allianz Risk Barometer 2026

      For this report, Allianz sought the views of 3,338 respondents from 97 countries and territories,...

      forvis mazars ceo 2026

      C-suite barometer: outlook 2026

      Forvis Mazars collected the views of more than 3,000 C-suite executives across 40 countries, for...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

Do company boards need an expert in cybersecurity and technology?

by Stephen Bonner on February 24, 2017

Cybersecurity is at the top of boardroom agendas. Stephen Bonner of Deloitte asks whether boards need a member who is a dedicated cyber expert.

Cybersecurity

Photo: Shutterstock

Favorite

Deloitte recently completed an analysis of FTSE 100 companies’ most recent annual reports, ending September 2016, to review company disclosures concerning cybersecurity. The results show that top companies are trying to reassure investors that they are taking these issues seriously.

These firms are revealing many details about their approach to this risk and being transparent about how such risks might impact on them. There was near consensus that cyber is important to discuss, with 87% identifying it as a principal risk.

In a surprising statistic, just 5% disclose in their annual report that a board member has expertise in cybersecurity or technology.

However, in a surprising statistic, just 5% disclose in their annual report that a board member has expertise in cybersecurity or technology. Whilst it is likely that many more of these boards do have this experience, or access to it, many simply did not disclose this time.

Now the precedent to disclose has been set by these outlying companies, we’d expect that the next set of reports will have a dramatically increased rate of expertise revealed. As the number climbs from an anomaly to the norm, it will be fascinating to see what happens to those boards that do not have access to this capability and, in the meantime, it raises a number of questions.

Will we see increasing pressure from investors to ensure boards have sufficient skills to navigate potentially treacherous waters of cybersecurity? Should a significant cybersecurity incident occur, will the ability of the board, with oversight of management, be called into question? The only answer to these questions is “yes”.

Buzzwords

To date, it has been a goal of the unitary board for all directors to decide company policy by consensus. A diverse set of backgrounds and experience reduce the risk of “group think” and allow each member to bring their own insight and experience to the discussion. But there is a risk, if a board member is seen as the expert on the topic, that other members may attempt to abdicate responsibility to them.

There is clearly a balance to be struck here to ensure the entire board can contribute, while recognising the different strengths and experiences that each member brings. Non-executives may have some knowledge in cyber, but without formal training or tangible experience, it is difficult to get to the nub of the issue.

There is a judgement to make about which areas need to shine from the CVs of the non-executives, and which can be covered with quick wit and sharp minds.

A key principle of corporate governance is that the board needs sufficient relevant skills and understanding to review and challenge management performance. It is unrealistic to expect the board to have representatives with deep experience on every topic, so there is a judgement to make about which areas need to shine from the CVs of the non-executives, and which can be covered with quick wit and sharp minds.

Cybersecurity has a myriad of complex terminologies that can seem impenetrable; those presenting to the board might hide behind that jargon to avoid difficult questions. Even with that dense industry language, someone with a background in a range of fields can probe effectively. Digital or deep technology skills can cut through buzzwords, as can mature risk skills, such as credit or market risk. Members from a senior intelligence or military background often are credible here.

Horror stories

Our analysis showed that 10% of the FTSE 100 disclose that they have trained their board members on cybersecurity. However, it is likely that the number getting this training is actually higher and we will start to see more firms disclose the nature of training across a number of technical issues.

At the very least, this provides comfort to investors. If it can be demonstrated that generalist board members are being kept current on the issues du jour, perhaps this means boards will not need to add members with specific expertise.

Given the nature of the information they need to carry out their duties, board members need to know how to protect their systems and the confidential information they handle.

The horror stories of highly sensitive, and potentially market-moving, information being sent unencrypted to cloud-based email accounts designed for mass market retail use must be left in the past.

Even if you are a non-executive without cyber experience, your computer needs to be updated and protected. It is possible to do this yourself, or ensure the company you oversee provides you a secure way to operate. Either way, the responsibility is down to the individual. For companies, too, there are still some things to learn about providing these environments. Having a different tablet for each board you sit on, for example, is as much a risk to those companies as it is impractical for the non-executive.

Acceleration

Cyber-risks are rising and investors, regulators and customers continue to care about these issues. Boards must be able to understand and effectively challenge these topics.

Cyber-risks are rising and investors, regulators and customers continue to care about these issues. Boards must be able to understand and effectively challenge these topics.

There are a number of ways for them to do this. Ensuring the board can demonstrate their understanding and capability will be key. The largest organisations have defences at scale, and have deep pockets, allowing them to weather these cybersecurity events. It will be interesting to watch how both the big and medium-sized firms mitigate the cyber-threat at board level.

There may be much to learn about how best to do this, but it may be the object lessons of the mid-tier teaching the big firms the right answers, through the painful and destructive lessons learned.

The pace of change is accelerating and vital decisions need to be made at senior levels regarding digital business models, artificial intelligence/machine learning and big data.

What other risks are happening now, on the boards’ watch, on which they haven’t already been briefed? Can the board really carry out its duties effectively without understanding the core of these critical changes to our world? And what other topics do you need insight into to be effective?

For boards themselves, it is prudent to be horizon planning, and not just on cyber.

Stephen Bonner is a partner, FS Cyber Risk at Deloitte.

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Are you serious about cybersecurity?
    October 3, 2023
    cybersecurity chatbot

    Artificial intelligence chatbot hackers are just the latest in a long list of cyber threats, which are not going away any time soon.

  • Experts urge vigilance on cybersecurity amid Russian invasion of Ukraine
    February 28, 2022
    Russian flag in code

    UK and US cybersecurity agencies are among the specialists recommending that companies "bolster their defences" against cyber attacks.

  • Home front: how digitalisation is moving cybersecurity boundaries
    October 20, 2021
    Man working remotely

    The pressure for digital transformation in the wake of Covid-19 is creating new cybersecurity challenges and responsibilities.

  • Business concern over cyber attacks rises in wake of Ukraine conflict
    February 28, 2022
    Ukraine flag with coding

    Geopolitical uncertainty is leading firms to boost their defences against cyber attacks. But true digital resilience is a continuous process.

Search


Follow Us

Most Popular

Featured Resources

wef global risks 2025

The Global Risks Report 2025

The 20th edition of the Global Risks Report reveals an increasingly fractured global...
Supply chain management cover

Strategic Oversight in Supply Chain Management: A Guide for Corporate Boards 2025

Supply chains have become complex, interdependent and opaque and—according to research...
OB-Cyber-Security

Cyber Security: What Boards Need to Know

Maintaining firewalls, protecting servers and filtering malicious emails rarely make...

C-suite barometer: outlook 2025 - UK insights

Forvis Mazars draws UK insights from its global study and looks at UK executives’...

The IA’S Principles Of Remuneration 2024 2025

This guidance from the Investment Association is aimed at assisting remuneration...
Diligent 2024 leadership tech cover

Leadership, decision-making & the role of technology: Business survey 2024

This research report by Board Agenda and Diligent sheds light on how board directors...

Director Reference Guide: Navigating Conflict in the Boardroom

The 'Director Reference Guide' on navigating conflict in the boardroom provides practical...
Nasdaq 2024 governance report cover

Nasdaq 2024 Global Governance Pulse

This Nasdaq survey gathered data from more than 870 board members, executives, and...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...
art & science brainloop new cover

The Art & Science of Creating an Effective Board

Boards are coming under more scrutiny and pressure than ever before from regulators,...
SAA First time NED guide

First Time Guide for Non-Executive Directors

The role of the non-executive director has never been more vital: to advise, support,...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy