Cyber Security Toolkit for Boards: updated briefing pack released
New presentation includes voiceover and insights on ransomware attack on the British Library.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

The NCSC’s ‘Cyber security briefing packs’, which are part of the NCSC’s Cyber Security Toolkit for Boards, are an excellent way to introduce the domain of ‘cyber security’ to non experts.
This latest version of the briefing pack includes a case study featuring Sir Roly Keating, CEO of the British Library, who shares insights on the high-profile ransomware attack that targeted his organisation. Reflecting on the incident, he noted, "It felt like it was an act of vandalism as well as theft.”
The British Library case study highlights the importance of:
While the British Library had implemented a range of cyber security measures prior to the attack, some of their critical systems were still vulnerable. This emphasises the need for ongoing vigilance, and the need to apply regular updates to software and devices.
Board members play a crucial role in addressing these challenges. The British Library’s report into the attack emphasises that “cyber-risk awareness and expertise at senior level” are essential for making informed strategic decisions that impact investment outcomes. The report also recommends that regular discussions on current risks and mitigations take place at the senior level, and strongly suggests the “recruitment of a Board member or adviser with cyber expertise” to strengthen decision-making and improve governance.
The cyber attack on the British Library could have been much worse. However, the library’s well-prepared incident response plan enabled a swift, effective response, helping to maintain trust with stakeholders and staff. Commendably, they refused to pay the attackers and acted decisively, communicating openly with users and staff and notifying the Information Commissioner’s Office (ICO) and the NCSC.
Using the attack as a learning opportunity, they implemented changes to policies, processes, and technology. The British Library’s detailed report will help other organisations prepare for such attacks, emphasising the need for senior leaders and board members to have a clear understanding of cyber risk for informed strategic decisions.
By learning from organisations like the British Library, Boards can take action to ensure effective oversight of cyber security risks. While Board members don't need to be technical experts, but they do need to have a holistic understanding of cyber security to have constructive discussions with key staff, so they can be confident that cyber risk is being appropriately managed.
If you have any comments or questions, or have ideas about what else you’d like to see in the Cyber Security Toolkit for Boards, please get in touch using [email protected]


