Skip to main content

Cyber Security Toolkit for Boards: updated briefing pack released

New presentation includes voiceover and insights on ransomware attack on the British Library.
Color_life via Getty Images

The NCSC’s ‘Cyber security briefing packs’, which are part of the NCSC’s Cyber Security Toolkit for Boards, are an excellent way to introduce the domain of ‘cyber security’ to non experts.

This latest version of the briefing pack includes a case study featuring Sir Roly Keating, CEO of the British Library, who shares insights on the high-profile ransomware attack that targeted his organisation. Reflecting on the incident, he noted, "It felt like it was an act of vandalism as well as theft.” 

The British Library case study highlights the importance of:

  • the need for proactive cyber security measures in addressing vulnerabilities associated with legacy systems
  • ensuring effective implementation of multi-factor authentication (MFA) for privileged users, the lack of which left the organisation exposed
  • the importance of managing third parties across the wider supply chain, who may have administrative access to critical systems

While the British Library had implemented a range of cyber security measures prior to the attack, some of their critical systems were still vulnerable. This emphasises the need for ongoing vigilance, and the need to apply regular updates to software and devices. 

Board members play a crucial role in addressing these challenges. The British Library’s report into the attack emphasises that “cyber-risk awareness and expertise at senior level” are essential for making informed strategic decisions that impact investment outcomes. The report also recommends that regular discussions on current risks and mitigations take place at the senior level, and strongly suggests the “recruitment of a Board member or adviser with cyber expertise” to strengthen decision-making and improve governance. 

The cyber attack on the British Library could have been much worse. However, the library’s well-prepared incident response plan enabled a swift, effective response, helping to maintain trust with stakeholders and staff. Commendably, they refused to pay the attackers and acted decisively, communicating openly with users and staff and notifying the Information Commissioner’s Office (ICO) and the NCSC. 

Using the attack as a learning opportunity, they implemented changes to policies, processes, and technology. The British Library’s detailed report will help other organisations prepare for such attacks, emphasising the need for senior leaders and board members to have a clear understanding of cyber risk for informed strategic decisions.

Download briefing pack

By learning from organisations like the British Library, Boards can take action to ensure effective oversight of cyber security risks. While Board members don't need to be technical experts, but they do need to have a holistic understanding of cyber security to have constructive discussions with key staff, so they can be confident that cyber risk is being appropriately managed. 

If you have any comments or questions, or have ideas about what else you’d like to see in the Cyber Security Toolkit for Boards, please get in touch using [email protected] 

Clare C, Economy and Society Team

Written by

Clare C NCSC Economy and Society Team