Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 11 of 27
Cyber security regulations and directors duties in the UK

Boards should familiarise themselves with the legal and regulatory requirements related to cyber incidents, including data protection laws and industry- specific standards. They should also gain assurance that Executives have considered these regulations and how compliance might be affected.
UK General Data Protection Regulation (UK GDPR)
UK GDPR requires that personal data must be processed securely using appropriate technical and organisational measures. The Regulation does not mandate a specific set of cyber security measures, but rather expects you to take ‘appropriate’ action. In other words you need to manage risk. What is appropriate for your organisation will depend upon your circumstances, as well as the data you are processing and therefore the risks posed.
GDPR focuses on explicit accountability for data protection, placing a direct responsibility on companies to prove they comply with the principles of the regulation, rather than the hands-off approach of the Data Protection Act. This means firms will need to commit to mandatory activities such as staff training, internal data audits and keeping detailed documentation if they wish to avoid falling foul of the GDPR rules. Breaches must be reported to the relevant authorities within 72 hours of the incident.
The NCSC have worked with the ICO to develop a set of GDPR Security Outcomes. This guidance provides an overview of what the GDPR says about security, and describes a set of security related outcomes that all organisations processing personal data should seek to achieve.
Data Protection Act 2018
The Data Protection Act 2018 provides guidance and best practice for data handling.
Everyone responsible for using personal data has to follow strict rules called ‘data protection principles’. They must make sure the information is:
- used fairly, lawfully and transparently
- used for specified, explicit purposes
- used in a way that is adequate, relevant and limited to only what is necessary
- accurate and, where necessary, kept up to date
- kept for no longer than is necessary
- handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage
Networks and Information Systems (NIS) Directive
The NIS Directive aims to raise levels of the overall security and resilience of network and information systems across the EU. It applies to companies and organisations identified as Operators of Essential Services (OES), outsourced IT and managed service providers (MSPs) essential service providers, such as energy, transport, healthcare and water companies and providers of important digital services, such as cloud computing and online search engines. The regulatory responsibilities are carried out by Competent Authorities (CAs). The criteria for identifying OES and the list of CAs in the UK can be found within the NIS Regulations.
The NCSC has developed some resources that organisations affected by the NIS regulations are likely to find useful. These are:
- a set of cyber security and resilience principles for securing essential services
- a collection of supporting guidance
- a Cyber Assessment Framework (CAF) incorporating indicators of good practice
Collectively, these resources are known as the NCSC CAF collection and can be found on the website. Please note that the use of the CAF collection extends beyond organisations designated as OES by the NIS regulations. For that reason, the terminology of the CAF collection is intended to generalise and extend the terminology used in the NIS regulations.
Directors Duties
Directors have defined responsibilities under Section 172 of the Companies Act and must act in the company’s best interests to promote its success.
You must consider the:
- consequences of decisions, including the long term
- interests of its employees
- need to support business relationships with suppliers, customers and others
- impact of its operations on the community and environment
- company’s reputation for high standards of business conduct
- need to act fairly to all members of the company
The board toolkit will help to embed cyber resilience into all areas of the organisation.
What is the NCSC's role in regulation?
The NCSC is not a regulator. However, as the UK technical authority for cyber security, the NCSC provides support and advice to companies and regulators to help minimise the risk of incidents and respond to them effectively if/when they do occur. The NCSC looks to ensure that any requirements are in line with best practice, and that frameworks are consistent across different pieces of regulation.
The NCSC also has a role to provide support during significant incidents, and these incidents may fall under specific regulation. We will encourage victims to consider their regulatory obligations, but recognise that any regulatory reporting or co-operation must be led by the victim.


