Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 13 of 27
Growing cyber security expertise

As the demand for cyber security professionals grows, your organisation should plan ahead to draw upon expertise.
Introduction
Cyber security covers a broad range of disciplines. Senior Leaders should ensure that recruitment and training meet their cyber security needs. This can be challenging as technologies, threats, and organisations constantly change. You’ll need a dynamic approach that aligns business objectives with the cyber security needs of the wider organisation. The benefits of growing your cyber security expertise include:
- organisations that retain cyber expertise within their workforce have a competitive advantage
- an established and experienced workforce can more effectively manage cyber resilience and empower employees
- recruiting a diverse workforce will ensure your organisation has the diversity of thought necessary to tackle demanding cyber security challenges
- training helps organisations remain compliant with laws and regulations
Essential activities
The most effective approach will depend on your context, but may include a combination of investing in your people, bringing in external experts or companies, and developing a pipeline of talent. The assessment of cyber skills might be an activity within the overall people/talent-planning part of the business, and the board should have sight of this.
Workforce training
Implementing expertise and workforce training will need input from people across the organisation, including your HR, IT and finance teams. Your training provision should be reviewed regularly to account for changes in the cyber landscape and business needs. Note that putting someone through a training course does not make them a cyber security expert; they must also have the opportunity to develop hands-on, practical skills. The NCSC Certified Training scheme is designed to assure high quality cyber security training courses.
Baseline your expertise
Your organisation’s needs for cyber expertise should inform recruitment, derived from a baseline of your organisation's current cyber expertise. It should identify key gaps and areas of weakness, and set out the approach and urgency to address these issues. Buying in expertise where required can provide a quick solution where there's a lack of specialised cyber security knowledge. You might want to consider:
- recruiting a non-executive director with cyber knowledge can enhance board insight, but all board members should complete Cyber Governance training and implement the Code of Practice actions. Boards don’t need technical skills, but they must be equipped to govern cyber risk effectively.
- employing a consultant to provide specific cyber security advice (a good place to look for external expertise is the UK Cyber Security Council (UKCSC))
- identifying specific cyber security services which can be fulfilled by a third party
- making use of established, commodity technologies, which frees your own experts to spend time exploiting the unique insight they have into your organisation (for example, you might choose to allow cloud vendors to build and secure your infrastructure)
Cyber awareness
Your organisation must have an overarching cyber awareness programme which includes a basic level of cyber security awareness for all employees to be carried out at least annually. If you don’t have any existing programmes, the NCSC’S online training package, ‘Top Tips for Staff’ can be used as a starting point, and is provided in a format so that it can be built into your training resources.
You should also consider using outside speakers, awareness posters and company wide messaging for disseminating new insights and guidance to appropriate parts of the business. These may come from the NCSC, or from participation in sector-wide forums, and events like CYBERUK. These initiatives should be co-designed with employees, including comms and training teams, and should be run at all levels from the board down. Leadership play a key role in the success of the programme through effective communication and securing organisation buy-in.
Talent pipeline
Develop future staff through sponsorship, apprenticeships and work experience. Supporting young people to pursue an education in cyber security can be a brilliant way of ensuring a future pipeline of employees with the right skills. NCSC runs apprenticeships and is looking for company sponsors and placements. Ensure that your cyber strategy includes components on cyber expertise, cyber development plans and staff training. It will need input from people across the organisation, including HR, IT , and finance teams.
Indicators of success
Whoever reports to the board on HR matters should be able to report on the specific skills gaps that the organisation is facing at that time with a plan in place to develop cyber expertise where required. The board should be supporting this both in terms of investment and broader resources.
These might include levels of user engagement in phishing emails (exercise and real), levels of incident reporting by staff and scores in awareness training.
Problems with retention of staff may serve as a signal of broader systemic issues that need to be examined.
If it does not, then your organisation might not be drawing and nurturing talent from the largest possible pool, which will put your organisation at a competitive disadvantage. Equality, diversity and inclusion should be integrated throughout (a good set of starting points are recommended in the Decrypting Diversity report).
What counts as ‘regular enough’ will depend on your context, but if the document is not reviewed at least annually, this indicates that your approach to skills and expertise may no longer be aligned with the organisation’s current conditions.
Cyber criminals are quick to exploit new and emerging technologies. As the threat landscape evolves, it is important to regularly assess whether the board would benefit from additional specialist support to ensure you are equipped with the knowledge to provide rigorous oversight of the organisation’s cyber resilience.


