Skip to content

18 November, 2025

  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board Expertise
      • finance
      • Technology
    • directors duties

      3 top tips on directors’ duties

      When directors fall short of their responsibilities, the consequences can be devastating. How can board...

    • CFO

      How to build trust between the CFO and the board

      The chief financial officer’s relationship with the board is critical and requires work on both...

    • permacrisis

      How to lead through permacrisis

      In an era of constant disruption, leaders must rethink culture and embrace empathy, purpose and...

  • Comment
      • View all
    • directors duties

      3 top tips on directors’ duties

      When directors fall short of their responsibilities, the consequences can be devastating. How can board...

    • permacrisis How to lead through permacrisis

      In an era of constant disruption, leaders must rethink culture and embrace empathy, purpose and...

    • polycrisis Business must adapt to survive the polycrisis

      The risk landscape is changing drastically, and it is only through investing in a new...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • Evangelos Mytilineos Metlen Metlen: a governance journey from Athens to London

      The energy and metals multinational joined the FTSE 100 this summer, well prepared to adopt...

    • ai C-suite challenges can need ‘substantive input’ from board

      Challenges such as the introduction of artificial intelligence should be strategic issues for the board,...

    • volatile times Boards look to short-term development to find stability in volatile times

      Nimble business, diversification to make supply chains less fragile and shorter timeframes are key moves,...

  • Board Careers
  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • Reimagining the Way the World Works 2025

      Forum for the Future sustainability report, showcasing examples of organisations or communities that are reimagining...

    • UN SDG Trailblazers cover

      Trailblazers & Transformers:  UK business sectors redefining sustainability 2025

      This UN Global Compact report examines six sectors that will shape the UK’s progress on...

    • KPMG 2025 Global CEO Outlook

      The KPMG CEO Outlook, conducted with 1,350 CEOs in Aug/Sept 2025, provides insight into the...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

Board preparation is key to fighting the ransomware threat

by Kamal Bechkoum on August 5, 2019

Board members must be clear on how their organisation’s data and IT infrastructure is being protected from the growing ransomware threat—and whether to pay up in the event of an attack.

ransomware threat

Image: Nawadoln/Shutterstock

Ransomware is one of the most debilitating forms of cyber-attack, often catching companies unaware and ultimately causing them long-term financial and reputational harm. Unfortunately, in 2019 there has been a massive upsurge in large companies being targeted.

In one recent example a virus hit Johannesburg’s City Power, the primary electricity supplier for South Africa’s economic hub, encrypting all of its databases, applications and network. In another, Norsk Hydro announced that it is facing a price tag of £75m after recovering from a ransomware attack that froze staff computers and halted production lines.

Once ransomware takes hold of a single device entire networks can quickly become infected. Just one click is all that’s needed for confidential information and other crucial aspects of a company’s operations to be made inaccessible.

Ransomware will often make its way onto a system as a malicious weblink or email attachment. If a network is not properly protected an entire organisation’s IT infrastructure will end up becoming infected.

Just one click is all that’s needed for confidential information and other crucial aspects of a company’s operations to be made inaccessible

There are two main types of ransomware: crypto and locker. If an illegitimate application is opened, crypto-ransomware will seek to encrypt all of the files, folders and hard drives, promising to reinstate data only after a ransom has been paid. As the name suggests, locker-ransomware poses a similar threat by locking users out of devices and systems.

In the face of these developments, boards cannot afford to be complacent over organisational security strategies.

Top teams should have a detailed view of what the impact of a breach will be and understand who will take the lead if service as normal is interrupted. They should also be prepared to lead long-term strategic planning to protect operations against the continually evolving ransomware threat.

To pay or not to pay?

One of the biggest challenges to confront is the ethical dilemma of whether an organisation should pay a ransom or not. This is no easy decision. Average ransom amounts are currently in the region of around £10,000, often with a 24-hour countdown attached to them before all data or access is irretrievably lost.

This means the board debate over whether to pay a ransom needs to be had long before an IT network is held hostage.

At the same time transparency can be vital. Business leaders need to prioritise security while insisting that all frontline employees do the same. People are inevitably the weakest link in cybersecurity and so they need to know when there has been a breach, what action is being taken and how their work will be impacted.

Cybersecurity cannot be solved by simply buying in more technology as a quick fix. It is about taking a strategic approach to budget allocation and decision-making that delivers genuine improvement.

Be prepared to ask the difficult questions of your IT team. If they believe they have the necessary expertise and software to deal with any ransomware threat, then put this to the test. Bring in a third-party company that is fully qualified and capable of pushing process and practise with an unannounced attack.

The board debate over whether to pay a ransom needs to be had long before an IT network is held hostage

A culture of security should be fostered throughout the workplace. Staff need to be educated and trained to keep software applications and systems updated; backup files regularly; and segment networks to ensure sensitive data is only accessible as necessary.

The ideal organisational culture sees managers and staff taking a second-nature approach to keeping information safe and viewing security as a positive force. This necessitates a check-list that boards can become familiar with and adhere to as part of their regular order of business.

If the organisation falls victim to a ransomware threat it is vital to act quickly. Wherever possible, ensure that the incident is contained while the business continues to operate. Then, prepare to notify all relevant stakeholders, including insurers, regulators, lawyers, the police and clients as is necessary and practicable.

Training should prepare board members for “what if?” scenarios along with clear roles and responsibilities in case of a cyber-attack. How will an organisation respond to its networks being compromised or customers being unable to access online services?

These issues should be a standing agenda item at board meetings, if only to confirm that no changes are needed since the previous review.

The threat landscape is constantly moving and, while it may be unrealistic to ask executives to follow the details of every twist and turn that happens, they can encourage IT managers or the COO to join external organisations and forums where information and good practice is shared. This can be used to provide regular updates that are specifically prepared for the executive.

The organisation should develop a corporate ransomware policy and turn the strategic principles agreed by the board into a working tactical plan.

Worryingly, research shows that a third of companies believe that it has become more cost-effective for them to simply pay a ransom than invest in proper security systems and training.

Unfortunately this creates a catch-22 where businesses continue to pay and ransomware grows as a popular money-making tactic for criminals—only encouraging the problem further. It is up to boards to decide where the line will be drawn.

Professor Kamal Bechkoum is head of business and technology at the University of Gloucestershire.

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Business concern over cyber attacks rises in wake of Ukraine conflict
    February 28, 2022
    Ukraine flag with coding

    Geopolitical uncertainty is leading firms to boost their defences against cyber attacks. But true digital resilience is a continuous process.

  • How boards can build an effective ransomware response plan
    March 11, 2022
    Red lock on safe, ransomware response plan concept

    The impacts of a ransomware attack are immediate, significant and hugely damaging to company reputation. Boards should be prepared.

  • Identity crisis: the threat of malicious credential abuse
    September 1, 2021
    Employee credentials login screen

    The security risks posed by malicious credential abuse is fast becoming every chief information security officer’s worst nightmare.

  • AI decision-making presents new ethical risks
    May 18, 2022
    AI thinker

    Businesses are allowing artificial intelligence to make decisions that need a human touch. Boards must balance the risks and benefits.

Search


Follow Us

Most Popular

Featured Resources

wef global risks 2025

The Global Risks Report 2025

The 20th edition of the Global Risks Report reveals an increasingly fractured global...
Supply chain management cover

Strategic Oversight in Supply Chain Management: A Guide for Corporate Boards 2025

Supply chains have become complex, interdependent and opaque and—according to research...
OB-Cyber-Security

Cyber Security: What Boards Need to Know

Maintaining firewalls, protecting servers and filtering malicious emails rarely make...

The IA’S Principles Of Remuneration 2024 2025

This guidance from the Investment Association is aimed at assisting remuneration...
Diligent 2024 leadership tech cover

Leadership, decision-making & the role of technology: Business survey 2024

This research report by Board Agenda and Diligent sheds light on how board directors...

Director Reference Guide: Navigating Conflict in the Boardroom

The 'Director Reference Guide' on navigating conflict in the boardroom provides practical...
Nasdaq 2024 governance report cover

Nasdaq 2024 Global Governance Pulse

This Nasdaq survey gathered data from more than 870 board members, executives, and...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...
art & science brainloop new cover

The Art & Science of Creating an Effective Board

Boards are coming under more scrutiny and pressure than ever before from regulators,...
SAA First time NED guide

First Time Guide for Non-Executive Directors

The role of the non-executive director has never been more vital: to advise, support,...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies
|

Copyright © 2025 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy
  • Sitemap