Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 7 of 27
Risk management for cyber security

Good risk management will help you to make better, more informed decisions about your cyber security.
Introduction
Every organisation has to make difficult decisions around how much time and money to spend protecting their technology and services. One of the main goals of cyber risk management is to inform and improve these decisions.
Cyber security risk management therefore has a huge impact on an organisation’s ability to achieve their goals. It helps organisations identify their ‘security posture’ (that is, their overall status of cyber security readiness), mitigate risks, and ensure that resources and investment are spent in the right areas. It should also support and enable the business, and it should do this by managing its risks without slowing things down, or making the cost of doing business disproportionately expensive.
Note: Many of your operational and organisational risks will have a cyber component to them. Cyber security risk should therefore be integrated within your overall approach to risk management, and not be dealt with as a standalone topic (or considered simply in terms of 'IT risk').
Avoiding tick-box compliance
Encouragingly, many organisations are already taking steps to assess and manage their cyber security risk1. However, it’s worth checking what’s driving this activity. Carrying out cyber risk management solely for 'compliance' purposes can lead to risk being managed in a 'tick-box' fashion and can prevent organisations questioning whether they have ticked the right boxes, leading to overconfidence in how well risks have been managed.
While it’s important that controls are in place to demonstrate compliance with laws and regulations relevant to your sector, compliance and security are not the same thing. They may overlap, but compliance with common security standards can coexist with (and mask) very weak security practices. Good risk management should go beyond just compliance; it should give insight into the health of your organisation and identify not just issues, but potential opportunities.
Essential activities
Perform risk assessments, and review regularly
You should have assurance that your organisation has chosen a method or framework for managing risk that fits with the organisation's business and technology needs, and changes to risk are assessed at least bi-annually2. Some commonly used compliance frameworks that can help with this (including ISO/IEC 27001, NCSC Cyber Assessment Framework and Cyber Essentials) are discussed in the section on Embedding cyber security into your organisation. Setting a risk appetite for cyber will help define the ‘level’ of risk an organisation will manage when pursuing its objectives, thereby aiding effective decision making.
Integrate cyber security risks with operational and organisational risks
A way to check if this is working is to look at a decision taken in your organisation and review whether cyber security risk has been balanced with other business risks. For example, an organisation may assess that introducing a ‘bring your own device’ (BYOD) policy brings substantial benefit to the organisation in terms of flexible working. There are many different things you would expect to be considered in this decision (the most significant being the security implications of ‘unmanaged’ devices connecting to the organisation's networks). But there are also cost and liability implications. Were these considered ‘in the round’ when making the decision? Or was security only discussed once the decision was already made?
Reporting from audit/risk committee meetings
The board has a responsibility to ensure that risks to delivering the strategy are identified, evaluated, and mitigated in line with the business risk appetite. Cyber presents a critical risk to most businesses, so it is vital that the committee chair communicates the organisational risks clearly to the board so they understand the risk that cyber incidents present to delivery of the business strategy.
Use risk metrics with caution
Don't make reducing risk levels the measure of success. While risk metrics generated (such as risk numbers, risk levels and impact levels) are useful, they can easily be misinterpreted if used in isolation. It is important that parties collaborate to understand and agree the meaning and context of the risk management information provided.
Stay informed regarding managing risk for newer technologies
You may need to review cyber security risks more regularly than other risks. Cyber security is still a relatively new field, so your organisation won't have as intuitive an understanding of cyber security risks, as it might for say, financial risks. As new technologies emerge, such as Artificial Intelligence, there might not be a huge evidence base to draw on to form a risk assessment. NCSC guidance will help to identify and assess cyber security risks (as we have done for Cloud Security).
Indicators of success
This is difficult to capture when every industry sector will have different priorities based on their size, sector, and risk appetite. It might be easier to consider reputational impact, financial loss, operational impact, personal impact, and where these are felt within the organisation. If you are aware how many risks are within the agreed threshold (and the cost of the high priority risks that are outside it), that would be a good indication that the board has a good understanding of cyber risk.
In assessing all key risks, a key question for the board to ask is ‘Have we considered cyber security risk in the decisions we make'? For example, a company that is bidding for a contract will have lots of risks associated with pricing, quality and competitors, but there is also a cyber risk (namely, it’s possible that commercially sensitive bid information is stolen by a competitor or an insider, and the information is then published on the internet).
The board need assurance that a cyber risk register is in place (as part of the overall organisation risk register), that covers risk ownership and an escalation mechanism for the whole extended enterprise (e.g. front line business units, subsidiaries, suppliers and partners, and in some cases customers.) This should involve all of the key stakeholders in the organisation and reflect the agreed priorities and tolerances endorsed by the board. It should take account of change (for example business priorities, technology changes and geopolitical or economic context). The NCSC’s detailed Risk Management guidance includes advice on choosing suitable frameworks for your organisation.
Be specific when defining what is and isn’t accepted. Whilst you might be unwilling to tolerate any significant risk to personal data, you might be willing to accept email being unavailable for a day. Also consider the cumulative risk you are accepting; it's possible that all your cyber risk could be realised at the same time and and at a crucial time of the year i.e. end of year financial reporting, important retail periods, annual events. In a single incident, you might lose email for a day, the public website might be unavailable and financial data you hold might be stolen. Whilst you may have accepted some risk of all those things happening you may not have considered whether the organisation could tolerate them all happening at once.
- 63% of medium businesses and 72% of large businesses have undertaken cyber security risk assessments in the last year [Source, DCMS Cyber Security Breaches Survey 2024]
- For organisations operating in high risk or regulated sector who are going through business change, exposed to more sophisticated threats, geo political changes or similar will need to review on a more regular cadence. It will be for senior leadership to discuss and agree this cadence.


