Skip to main content
Guidance

Cyber Security Toolkit for Boards

Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.

Page 3 of 27

Introducing the Cyber Security Toolkit for Boards

Guides Board members on how to navigate the toolkit and its benefits.

The vast majority of organisations in the UK rely on information, data and digital technology to create value. Cyber security ensures organisations can operate effectively in our increasingly online world.

When it’s done well, cyber security is so much more than a compliance function or the implementation of technical controls. You can use it to exploit the opportunities that technology brings, drive your company’s agenda, and deliver real value throughout your organisation. 

Crucially, good cyber security facilitates better cyber resilience; the ability of an organisation to protect itself from, prepare for, respond to, and recover from a cyber incident, data breach or service outage. The Executive Team, Audit Committee, Risk Committee and Remuneration Committee all have roles to play in making sure that there is the right level of assurance in the business, but ultimate accountability to the shareholders is with the Board. 




Note:

Smaller organisations who may not have the resources to implement the Board Toolkit in full (but still want to improve their cyber security) should, in the first instance, refer to the NCSC's Small Business Guide.


Note:

The indicators of success are designed to encourage productive cyber security discussions between boards and key stakeholders in your organisation (such as your legal, procurement and HR as well as technical teams). They are designed as a ‘starting point’, rather than a checklist that’s simply to be worked through. 

Board members don't need to be technical experts, but you do need to know enough about cyber security to discuss issues with key staff. The Board Toolkit supports the Board by providing the relevant questions to ask to gain a good understanding of the cyber risk profile of the organisation.

Published

Reviewed

Version

3.0