Skip to content

11 July, 2025

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board Expertise
      • finance
      • Technology
    • EU sustainability

      Omnibus package must not undermine EU sustainability

      Now is the time for Europe to speed up green transition, rather than slow it...

    • high pay

      Pay gap transparency needs to be better

      It’s not unknown for a CEO to earn 500 times as much the median employee,...

    • executive pay

      Executive pay trends in 2025

      Opposition to remuneration reports has grown sharply, according to Georgeson’s analysis of voting outcomes in...

  • Comment
      • View all
    • EU sustainability

      Omnibus package must not undermine EU sustainability

      Now is the time for Europe to speed up green transition, rather than slow it...

    • high pay Pay gap transparency needs to be better

      It’s not unknown for a CEO to earn 500 times as much the median employee,...

    • future-proof governance levers How to future-proof your business

      For boards to bolster resilience and create value in a polycrisis, a combination of hard...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • UK Corporate Governance Code Board meetings ‘are not up to scratch’

      Nearly three-quarters of board members believe the board’s performance in meetings needs improvement, an expert...

    • financial sanctions Tariffs chaos drives boardroom focus on resilience

      Business leaders will prioritise the resilience of their organisations in the face of economic upheaval...

    • supply chain oversight Act now on supply chain oversight, boards warned

      Board directors need to critically engage with the business’s supply chain activity, a panel of...

  • Board Careers
  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • C-suite barometer: outlook 2025 – UK insights

      Forvis Mazars draws UK insights from its global study and looks at UK executives’ strategic...

    • Talent Management 2025 Mind Gym

      Talent Management in 2025

      From rethinking leadership to wrestling with AI, MindGym's report reveals the trends shaping talent strategies...

    • Korn Ferry CHRO 2025 (Copy)

      On The Highwire: Being a CHRO in 2025

      Korn Ferry surveyed 750 senior HR leaders (including 450 CHROs) to understand their key priorities...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

Boards face cybersecurity regulation hurdles

by Gavin Hinks on May 22, 2024

Complying with the slew of new regulation that is coming means companies must act fast to up their game, a webinar panel heard.

cybersecurity regulation

Image: PeopleImages.com-YuriA/Shutterstock.com

Boards grappling with a wave of new rules regulating cybersecurity should remember that it applies to “material” processes, not all systems.

The warning comes in a new webinar from Board Agenda in association with Diligent, in which experts dissect the preparations needed to cope with cybersecurity measures issued by rule makers and regulators across the world.

Martin Tyley, a partner at KPMG and the firm’s global lead on cyber risk insights, was speaking on the difficulties faced by boards and their organisations attempting to comply with new rules.

He says regulators are mostly focused on how organisations defend the critical parts of their IT infrastructure.

“What that means,” said Tyley, “is you don’t have to have everything at the same level; you’re not trying to fix everything at the same time.”

Critical importance

Critical systems may differ from company to company. One organisation may be reliant on intellectual property, while another needs to keep a factory running. The controls and protections for such diverse aspects of business may be very different.

Companies are facing a slew of recently launched demands on cybersecurity. European Union member states have until October this year to implement NIS2, the Network and Information Security Directive, which expands mandatory reporting of cybersecurity breaches to more companies and sectors, clarifies risk management obligations and asks large companies to assess the cybersecurity risk in their supply chains.

Both the first and second iterations of NIS are under consideration by the UK.

Last year, regulators at the Securities and Exchange Commission introduced similar reporting responsibilities for US companies, which included asking for disclosure on whether cybersecurity would be a board committee responsibility, or handed to a lead individual.

Supply chain vulnerability

Supply chain issues figured heavily in the webinar panel discussion.

“The bad actors have realised that large entities are beefing things up…So, the targets now have become the supply chain,” said Dale Waterman, a compliance and governance expert with Diligent.

However, panellists agreed that the key element in cybersecurity is human behaviour. And that requires smart management. Christiane Wuillamie, chief executive and co-founder of the advisory firm Pyxis Culture Technologies, says organisations require the right “culture” to beat cyber breaches.

“You have to create a culture of individual accountability. And to do that, you need to have positive reinforcement and not ‘compliance and punishment’.

“You also need to have a no-blame culture, which is pretty hard as human beings.”

Fellow panellist Kamal Bechkoum, visiting professor at Abertay University and a veteran researcher in the field of cybersecurity, warned boardroom leaders would need to get involved.

“The cyber landscape can be overwhelming; the legal framework can be really confusing sometimes.

“You don’t have to be an expert in either, but you need to have structures in place that enable you to be informed and enable you to take an active part in the resilience of your organisation.”

Watch the full Board Agenda webinar in association with Diligent here 

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Why risk perception is vital
    June 9, 2022

    It is easy to see the tragic situation unfolding in Ukraine in terms of a failure of risk perception by both Russia and the West.

  • FRC publishes 2022 review of stewardship reporting
    September 8, 2022
    risk resilience

    The review reveals that signatories have doubled since 2021 and the quality of reporting has improved in many areas, including engagement.

  • SEC unveils plan for mandatory climate reporting
    March 23, 2022
    US flag behind polluting factories

    SEC chair Gary Gensler says the measures will provide investors with “reliable information about climate risks to make informed decisions”.

  • Government confirms commitment to sustainability disclosure requirements
    May 13, 2022
    Houses of Parliament

    The UK will proceed with legislative plans for SDRs, including transition reports, after the proposals were missing from the Queen's Speech.

Search


Follow Us

Register Free

Stay in the know! Register to access the latest governance news; plus receive updates about our events and podcasts – Sign up here

 

Most Popular

Featured Resources

wef global risks 2025

The Global Risks Report 2025

The 20th edition of the Global Risks Report reveals an increasingly fractured global...
Supply chain management cover

Strategic Oversight in Supply Chain Management: A Guide for Corporate Boards 2025

Supply chains have become complex, interdependent and opaque and—according to research...
OB-Cyber-Security

Cyber Security: What Boards Need to Know

Maintaining firewalls, protecting servers and filtering malicious emails rarely make...

The IA’S Principles Of Remuneration 2024 2025

This guidance from the Investment Association is aimed at assisting remuneration...
Diligent 2024 leadership tech cover

Leadership, decision-making & the role of technology: Business survey 2024

This research report by Board Agenda and Diligent sheds light on how board directors...

Director Reference Guide: Navigating Conflict in the Boardroom

The 'Director Reference Guide' on navigating conflict in the boardroom provides practical...
Nasdaq 2024 governance report cover

Nasdaq 2024 Global Governance Pulse

This Nasdaq survey gathered data from more than 870 board members, executives, and...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...
art & science brainloop new cover

The Art & Science of Creating an Effective Board

Boards are coming under more scrutiny and pressure than ever before from regulators,...
SAA First time NED guide

First Time Guide for Non-Executive Directors

The role of the non-executive director has never been more vital: to advise, support,...

Register Free

Stay in the know! Register to access the latest governance news; plus receive updates about our events and podcasts. Register


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies
|

Copyright © 2025 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy
  • Sitemap