Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 10 of 27
Embedding cyber security into your organisation

Introduction
Cyber security is not just ‘good IT'; it underpins operational resilience and when done well, enables your organisation's digital activity to flourish. Done well, it can and does add value. This requires a positive cyber security culture and having the right processes in place across the organisation to manage it.
Cyber security impacts every aspect of your organisation and it’s important for the board to have a clear and effective cyber strategy as part of their business strategy to help reduce risk, financial impact and reputational damage to the organisation. Implemented well, it covers the entire lifecycle from planning, detecting , responding and recovering from a cyber attack. To manage it properly, it must therefore be integrated into organisational risk management and decision making, and all the business units in your organisation should be clear about their cyber security obligations and responsibilities. For example:
- Technical teams need to understand the importance of securing and protecting data and systems through appropriate controls.
- Human resources must ensure that cyber security is covered throughout the staff lifecycle, with appropriate guidelines, policy and support for the workforce.
- Communications and marketing teams that manage data and marketing services must work with the board to prepare for communications with customers and press so they’re prepared for a range of incidents (such as the loss of operational abilities, or data breach).
- Legal teams should be aware of the importance of handling and protecting contracts and legal documents to ensure they don’t fall into competitors' hands, and need to assure liability risks arising out of potential cyber incidents during operations.
- Cyber security teams must design and implement policies that protect employee and customer data from unauthorised access.
- Procurement teams need to consider cyber risk when negotiating with potential suppliers of services, from software and hardware to hiring a contractor, and include cyber risk governance within contract management of the supply chain.
Across all business units, the workforce needs to be resourced and empowered to implement good cyber security measures. The board should recognise the need not only to protect company knowledge from third parties, but also to co-ordinate and prepare for future incidents.
Essential activities
Governance
It's important that cyber security is integrated into your organisation-wide governance frameworks’ including your strategy, risk management processes and compliance and audit procedures. This integration will ensure that cyber security implications are considered in strategic decision making.
The board must understand the cyber risks your organisation needs to manage. Use an independent company to carry out a cyber risk assessment to provide an informed overview of your organisation’s cyber security posture and data for effective decision making.
Cyber governance also includes policies, procedures, roles, responsibilities, organisational structure and controls to protect your organisation from cyber threats. You’ll need to determine how effective your current cyber risk governance is and identify gaps and areas to build upon. The following non-exhaustive list of frameworks can help with this process:
- Cyber Essentials is an effective, government backed scheme that will help you to protect your organisation, whatever its size, against a whole range of the most common cyber attacks.
- For larger organisations, ISO/IEC 27001 is an internationally recognised standard for the establishment and certification of an Information Security Management System (ISMS). It is important that the scope of the system certified is broad enough and reflects an organisations operations. For CNI and other regulated sectors, additional frameworks may also be appropriate, particularly those that have OT (operational technology) in addition to IT.
- The NCSC Cyber Assessment Framework (CAF) helps organisations that play a vital role in the day-to-day life of the UK (such as those designated as forming part of the critical national infrastructure, or subject to certain types of cyber regulation) to achieve and demonstrate an appropriate level of cyber resilience.
The Introduction to security governance pages provide helpful guidance for evaluating whether the framework you are using is appropriate to your context. In addition, Exercise in a Box is a free online resource from the NCSC which helps organisations find out how resilient they are to cyber-attacks, and to practise their response in a safe environment.
Effective communications
Improving the communication between business units and the board requires effort from both sides, as well as a readiness to acknowledge each other's priorities. Boards need a ‘good enough’ understanding of cyber security to appreciate how it supports their overall organisational objectives. Business units (with their understanding of what is happening at an operational level) must have the opportunity to flag the issues and recommend actions to the board, while understanding the board’s concerns for operational and reputational risk.
WaterAid’s Cyber security and Vendor Manager, Mark, explained how the NCSC’s board toolkit has been useful for their organisation and stated, ‘Our board of directors is made up of CEO’s from other organisations and the board toolkit has been key in driving the cyber strategy and engaging other parts of the organisation. Following the board toolkit proved to be a real enabler for us in receiving support from key stakeholders and has really strengthened our thinking.’
Natasha, their senior internal auditor, added, ‘Yes, as very much a non-IT person I found it an incredibly helpful framework for designing a high-level internal audit review of our cyber security arrangements. I used the toolkit’s questions for board members and management as the basis of the audit working paper. Going through these questions with a member of our board and colleagues from IT and other teams helped me develop a better understanding of where our cyber security is strong and where there might be risks which we had not previously considered. The audit delivered a number of recommendations which management is now actioning to make improvements.’
Indicators of success
This is key to understanding the cyber risks your organisation needs to manage, and the organisation's security posture. The result of the assessment will provide the board with an independent view of the organisation's cyber resilience, enabling effective decision-making which will inform the cyber strategy.
Boards play a critical role in ensuring that the cyber strategy is embedded within the broader organisational strategy. This informs decisions around risk mitigation, technology, people-focused initiatives, and resource allocation. A strong cyber strategy is key to building resilience and driving long-term success.
Key strategic elements to guide Executive-level planning include:
- setting the strategic approach for assessing and identifying potential threats and vulnerabilities
- defining priorities and principles for mitigating risks
- outlining objectives for incident response and recovery
- establishing governance frameworks that provide oversight and accountability for cyber security efforts
- embedding a commitment to security awareness as a strategic priority across the organisation
The Board should receive management information on how the cyber strategy and plan are being delivered, and this should be reviewed at least annually or in line with current threat level.
A good indicator that cyber security is embedded into your organisation is if all business functions (such as HR, legal, and public relations) are working collaboratively on cyber security initiatives. If cyber security is being left entirely to technical teams, this is a sign further alignment and investment is required.
Accountability and responsibility for cyber security should be clearly defined. If senior leadership and/or members of the board struggle to clearly and consistently identify where responsibility and accountability sits, this is a sign that work needs to be done on reporting structures or on the communication and visibility of reporting structures.
Cyber security is the responsibility of the entire board. A cyber security incident will affect the whole organisation - not just the IT department. For example, it may impact online sales, contractual relationships, your reputation, or result in legal or regulatory action. There should be sufficient expertise within the Board in order to provide direction on cyber security strategy and hold decisions to account.
Key Performance Indicator (KPI) dashboards simplify the reporting process and provide the board with clear and up to date information to support good decision making. You should expect to see KPIs with an agreed target range for each measurement on what’s acceptable These might include the time taken to implement security patches and mitigate high risk vulnerabilities, and the number of days between detection and remediation.


