Cyber security toolkit for boards: audio transcripts
Transcripts of the discussions between the NCSC and people who use the Cyber Security Toolkit for Boards about its applicability.

Jacqueline de Rojas, CBE - President of Tech UK and President of Digital Leaders
(NCSC) Hello. Today we're talking about the NCSC's Cyber Security Toolkit for Boards, and the best way of getting cyber security on the board's agenda. I'm lucky to be joined by Jacqueline de Rojas, President of Tech UK and the President of Digital Leaders, and I started by asking her why it's so important that cyber security is a board-level issue?
(J de R) Well, a huge challenge for cyber professionals is that cyber security is perceived as a necessary evil, or a compliance function. And a board can be useful in driving the company's agenda so that cyber security is seen as an enabler of everything the organisation does, and not just a reaction to a breach.
If it is true that all companies are now tech companies, then it's also true that they're also in the cyber game. And it's probably wise to view every technology decision through a cyber security lens. You know, in a similar vein, don't just ask the CISO - you know - about cyber. Every person at C-level (or leadership level) has responsibility for security. So move away from reporting on cyber, and instead perhaps to understand how it affects every business function positively, as well as - you know - the threat vector.
The whole organisation, I think, has to be cyber ready, cyber aware, and clearly that starts in the boardroom. So it's probably important that there isn't a ‘one-size-fits-all' approach, and that board level engagement is tailored to the culture of the organisation in question. So that we are all involved, and we haven't just delegated it to a single person, and therefore [it’s only] their problem to solve.
(NCSC) Definitely, and we often talk about cyber risk being a business risk, like lots of other things. And so with that in mind, do you have any thoughts on what makes the best board discussions on cyber security?
(J de R) Yes I do. You know, I think the best discussions I've ever had are the ones where they're not conducted in 'geek speak' - you'll know what I mean by that. But - you know - we do live in a tech world where we wrap ourselves up in three letter acronyms that are meaningless to the outside world. So I think board-level discussions have to be conducted in a language that everybody understands.
In the past, the challenge for most boards around cyber has been understanding, and insight and interest. And surely - you know - even before the COVID-19 pandemic, cyber threats have come to the fore of public consciousness. But the challenge now, is how we frame and discuss cyber security in the context of our entire workforce now working remotely, and therefore the adoption of technology has been incredibly high.
So I suppose we have to think about that as the next problem. Most companies actually have got a good handle on that, but still too often, I think we discuss risk potential damage and financial loss. And I worry about that - you know - I think the narrative needs to be more positive. And probably never more so than during the pandemic because - you know - cyber security consistently enables organisations to function in an increasingly virtual world.
And in the face of huge moves to homeworking (and therefore underpinning new solutions for communications and data sharing) cyber security has enabled organisations to carry on. And I think that's hugely important, especially - you know - as the threat landscape and changing landscape has increased, and boards should perhaps focus on this impact and this success, and look to unlock further potential and support for those teams that keep the virtual lights on shall we say.
(NCSC) That makes total sense. And looking to the future as well, it's thinking about those 'Right, what are the right questions to ask?', and that was one of the drivers for us in developing the toolkit in the first place, because board members had told us they weren't quite sure what to ask about cyber security. And they were also asking us how much they needed to know. What are your thoughts about how much a board member needs to know about cyber?
(J de R) Gosh, how long is a piece of string? Boards are used to discussing issues which aren't necessarily their speciality or background. And clearly, cyber security professionals are in the minority when it comes to board populations. And - you know - a security officer would find themselves very lucky if there was a non-exec or a board member with comparable or deeper knowledge than they do. So this is always going to be a hurdle for boards to overcome, because by the very nature of cyber, it changes quickly and fast and - you know - we're always behind the curve.
But on the boards I sit on, I've always sought to achieve a grounding in cyber security, for example, by bringing them into the National Cyber Security Centre to actually develop the Toolkit has forced them to ask the questions that are relevant to [them]; what should I now have on my risk register, now that I've seen what the threat landscape looks like? And as well as having regular updates and contributions from the CISO on company matters, broaden the conversation perhaps, and there might be a number of things that you can do to focus board members' minds around cyber from a discussion, perhaps on the latest high-profile breach. Or having some external briefing on emerging threats.
But sometimes it is also useful to have other people talk about the opportunities that they've created by leveraging cyber security, especially as we operate in this more virtual world. I think it's probably most important that the board has a clear idea of the roles and responsibilities of their senior leadership team - you know - what we do when we need to escalate something, and who's in the chair when we need to go to the next step? So I think it's those kinds of questions. I would say 'What happens if?' but also 'What opportunities are there by using cyber security in our business opportunities and virtual world?'
(NCSC) Thank you, and we really like the positive side of this. Because we we feel cyber security should enable organisations as much as, as other things. And you've touched on this already, but getting the language right between technical experts in-house, and cyber security specialists and the board is really important. And I didn't know if you had any advice for boards on ensuring they get the information they need on what the organisation already has in place for their cyber security?
(J de R) Yeah, I think the first thing I would say is 'Give the CISO enough time to formally brief the board regularly.' This isn't an annual thing, because the pace of change is too fast. Equally, it doesn't have to be at every board meeting, but - you know - by giving cyber security the same prominence as finance or legal in board discussions, it will certainly reinforce the message that it is a critical business issue and opportunity, and ensure that the right information is presented to the board. So I think it's firstly ‘give it space give it time’, but also the CISO must have a clear strategy to improve cyber resilience across the organisation. And that might be through investment or attention, and that can only be enabled by the board and the leadership team.
It requires deeper debate than just risk management. You know, we do need clear reporting lines, we do need investment in the function. We do need to raise cyber awareness across the workforce because we all know that human error is perhaps one of our - you know - easiest lines penetration. And on a practical note, we all live in a virtual world so there are challenges associated with that, and communication at board level is now a little bit different.
So virtual platforms are great at keeping us connected, but it's not the same as meeting in person, and that's something we'll need to monitor as we go forward, and how we can still get the board's attention when it comes to cyber security.
Regularly communicate outside of the board as well. It's not just at the board; it should be all the way down. I think we also know that companies give cyber security most attention when a breach has happened. And I would much, much rather that we did it proactively than reactively, if we're going to support the digital economy and enable it to thrive.
(NCSC) Definitely we would totally agree. We would like people getting started a lot earlier about thinking about cyber security, rather than at the point of a breach. And one of the things people really told us was 'How can we find a good place to start, and where should we get started with cyber security?' That was part of the driver for the Toolkit, but I don't know if you have any recommendations for how to get started with the Toolkit based on your experience and the input that you helped and gave us on this developing this product?
(J de R) Yeah, I mean we really enjoyed helping to shape the Toolkit, and I think it's because - you know - what we found most useful coming out of it, was it's almost like having a cheat sheet of questions that the board can ask. You know, and they are world-class questions inside the Toolkit. I'd recommend everyone to have a look at it, because there are sections that - you know - start to explore how to identify baseline cyber capabilities, and developing a positive cyber security culture. You know, all of these things are really important and I would say have a look at the Toolkit, think about - you know - the cheat sheet questions, and start from there.
And I think it will, as sophisticated as it becomes, when all is said and done, we will still come back to the basic questions of education, attention and investment. So I think that's where we should start.
(NCSC) Thank you so much, and so moving on to our last question to consider today, and that's 'If you were to recommend one thing board members could ask of their organisations right now, to help discussions on cyber security, what would it be?'
(J de R) I think the first thing I would do - I've got more than one, I'm sorry I'm just going to blow the question to one side here - if there was one thing to ask though it would be ‘Are you clear about what your critical assets are? What are you protecting? And is it the right thing?’ So I think that would be my number one.
But you know, at Tech UK we're working on a report where one of our recommendations is that the CISO should have visibility of the wider business, and be empowered to drive change where cyber security is an opportunity to impact the whole organisation, rather than a very narrow view of - you know - 'Fix it when it's broken' or proactively, you know, manage the cyber security threat landscape. And I think that's super important; that the wider the lens, the bigger the opportunity for cyber security to be a force for good and something to help us work and live and thrive in our new virtual reality.
(NCSC) Thank you so much that's been really helpful. And thanks again for all the help you gave us as we developed the toolkit. It really did shape what we came up with, and how we hopefully are helping board members think about getting started with discussions on cyber security.
(J de R) Thanks, let's hope we all stay safe.
(NCSC) Thanks so much for listening, and we hope you find the resources on our website useful for starting your own conversations about cyber security.
Listen to our chat with Jacqueline de Rojas
Download the podcast (9.21MB) using the panel above.
Peter Yapp, former Deputy Director of the NCSC
(NCSC) Hello, and welcome to the latest podcast in the NCSC's Cyber Security Toolkit for Boards. In this episode I talk about supply chain security with Peter Yapp, who was the NCSC lead for Cyber Security Supply Chain Risk while we were developing the toolkit. The first question I asked him was 'Why is it so important we think about cyber security while working with suppliers and partners?'
(PY) So cyber security is really important, right the way through the supply chain. Because the supply chain is so integral to what we do now. So, we are outsourcing far more, and that's only going to increase. That just gives a larger attack surface so you really need to make sure that your suppliers are as good at cyber security as you are.
(NCSC) OK, so what do you see as being the top challenges for organisations trying to manage their supply chain risks?
(PY) So, I think the biggest challenge is the very first thing that businesses should do - organisations should do - and that is to bring together a list of who all their suppliers are. That sounds like a really simple thing to do, but organisations are finding it very difficult and typically they haven't even taken this step.
So perhaps for GDPR, somewhere in the organisation, someone has a list of all those organisations that either hold or process data. But who has the list of who has access to your network? You know, people that you give direct access into a server, or an air conditioning system, or an accountancy system. And that list - if it exists - is probably held elsewhere. And there are probably other suppliers who you let on to your network as subcontractors or whatever. You need all of that in one place, because without that list of all your suppliers, your direct suppliers, how can you risk assess who is most critical to your business? Who do you think needs to be involved in the managing of this risk? Because clearly this is a topic that goes beyond just the security function of an organisation. Absolutely so this is a business risk it cannot just sit in the CISO security department.
This covers HR, this covers the purchasing department, the contract department (if you have one). It really is a fundamental business risk that needs to be looked at not in isolation. Not as something 'just for IT'.
(NCSC) What do you see as the role of the board? What should board members be doing themselves? And what do you think they need to seek assurance on from the rest of their organisation?
(PY) So, I think for the board, particularly at this stage, if they're not very far down the path of securing their supply chain, they need to think about the first level of risk. So their tier one suppliers - their direct suppliers.
The board should be making sure that their organisations know who their suppliers are. Know that they've been ranked into some kind of risk order, so that you have a small number of critical suppliers that you concentrate on that you put all your efforts into (or most of your efforts into). And the board needs to test that out. Those are two fundamental first tests. And beyond that, I think the board would want to know that cyber security terms are in the contracts that they let to their suppliers. That if one of their suppliers has an incident, that they have to notify you. So is that built into the contract as well?
These are easy things for a board to test, and absolutely these are the kind of probing questions that the board should be asking of their organisation as a whole. Not just the CISO.
(NCSC) So is there an example of an incident you could talk about where supply chain has been a critical element?
(PY) So I think the biggest incident was the attack by the Chine e state (so APT 10). And that really was an eye-opener for all of us, I think. And it wasn't terribly sophisticated in terms of its technical ability. Perhaps organisationally and process-wise it was very clever, and it was done on a very large scale. But this was the attack on managed service providers worldwide, so the Chinese were using fairly simple techniques to get into the networks of these very large companies. So perhaps phishing and malware that anyone would recognise, that would - that should - have been picked up by antivirus.
They were using tools that you could download off Google to traverse across the network. They used Quasar RAT, which you could download with a tutorial and use. And then they were getting into thousands of clients. So this small band of managed service providers were providing an open door to the Chinese to get to thousands of other companies. And I think that really opened our eyes to how effective targeting the supply chain was, and how much data could be at risk. And how some of the simple things just putting in proper monitoring, keeping antivirus up to date, and segmenting networks would have really stopped that kind of attack. So some of the simple principles that you could apply to your business just hadn't been applied in these managed service providers.
(NCSC) Great! So do you think there's also a question, a conversation that the board needs to have-as a board - about their strategy for using suppliers, for example?
(PY) So absolutely. I think cyber security should be a regular conversation at the board and just because some industries and some companies are not regulated, doesn't mean that there shouldn't be a regular topic at the board.
So risk is really important. You need to, risk is a board-level conversation to have. So you need to know what risk you're willing to accept in using suppliers. So, your suppliers will get compromised from time to time. And you need to think about reputational risk, and financial risk. So is it going to stop your business. Or are you just going to be tied into that supplier's business so closely because, perhaps you have a brand name (and they don't). So when it comes out into the press, it will be your brand that gets hit and not the suppliers. So you need to look at that risk and think about what you're prepared to accept, and whether you need to pay more for a supplier who perhaps has spent more on cyber security. But it's a risk-based decision, so you say 'OK, it's going to cost me this much more, and I'm balancing this against any reputational financial risk of losing that that supplier for a period of time. Or losing data and the publicity around it. So you absolutely need to 'bake-in' cyber security into the costing. But it's a risk decision about how much you spend. So it may not be that you would spend the - you know - choose the most expensive because someone has put in so much cyber security that they cost a lot more than the market. You've got to balance out whether reputation and financial risk makes that worthwhile.
(NCSC) Some organisations will also be suppliers themselves. What security responsibilities do they have towards their customers?
(PY) So I think there's a role particularly for the larger organisation to help out the smaller organisation. So accepting that they are part of your supply chain and therefore part of your cyber security. If you have a small supplier who maybe doesn't have the resources or the experience or just the knowledge to do this, then the larger organisation could lean in and help. And it could be a kind of 'value add' to the whole , the whole infrastructure between supplier and purchaser. And I'd especially encourage the larger organisations to look at that and - you know - one example that the NCSC is working on to help in this, is in logging. So we're putting together something that will help smaller organisations do proper logging of networks for free. But the installation of that might be a little bit too complex for the smaller organisation. And i think that's where the larger organisation can help. So not necessarily with money or resources from that larger organisation, but just in terms of help and pointing at some of the tools and guidance that the NCSC offer.
(NCSC) The NCSC supply chain guidance particularly highlights the importance of continuous improvement. Could you say something more about that?
(PY) So I think there's something in supply chain particularly, but in in cyber security in general that this is a continuous process, and this is an improvement process. So what I've talked about today, it's about raising the bar. It's about putting in some of the basics like identifying your suppliers and risk rating your suppliers. Putting in cyber security clauses and notification clauses. Getting the questionnaires right. Perhaps reducing the burden of the questionnaire on your suppliers, and hoping that when you're a supplier to them, that the burden is also reduced for you. But I think there's something about that continuous improvement cycle that you're not just testing a supplier out on one day. You want to know what that supplier is like on an ongoing basis. So you need to know if they've become less secure over the last three months for instance.
So have you got those conversations between your contract teams and the supplier contract teams going? Have you got any kind of monitoring that would tell you whether their cyber security is less good than when they signed up? And overall, you want their cyber security to improve over time, and that can't be measured just once a year when you send out a questionnaire or once a year when you do an on-site audit or a penetration test.
(NCSC) Great! And the last question we always ask is: 'What is the one thing that you would like board members to take away from this podcast?'
(PY) So I think the most important is to get that basic first step done properly. So who are all your suppliers. Not just the suppliers who hold data, but the suppliers who have access to your network. That list, held centrally, is the starting point for the proper handling of supply chain risk. And that risk question that you need to ask has to be based on the full picture of all your suppliers.
Listen to our chat with Peter Yapp
Download the podcast (11.8MB) using the panel above.
Paul Maddison (NCSC), Dr Bernard Parsons (Becrypt) and Mark Hughes (DXC Technology)
In this podcast, industry experts discuss how the NCSC's Board Toolkit can help board members get to grips with cyber security. Featuring Paul Maddison (NCSC), Dr Bernard Parsons (Becrypt) and Mark Hughes (DXC Technology).
(NCSC) Welcome to this podcast from the NCSC - the National Cyber Security Centre.
In this episode we'll be discussing the cyber security Board Toolkit, a set of resources specifically designed to help board members get to grips with cyber security, something that Paul Maddison, the NCSC's former Chief Operating Officer, is keen to emphasise.
(PM) The big point we want to make of course is that this is a board level risk issue, and I think most people have got that now. Disruptive cyber operations, whether that's data theft or a really sort of disruptive ransomware attack that takes your computers offline, stops you delivering your services, or doing whatever your business is, is a real business risk. It costs, you know, thousands - millions in some occasions. It has massive reputational damage issues, and it can really take a long time to restore services and get back up and running.
So it's a major business risk, and it's one amongst the other business risks that boards need to consider, to understand, and take appropriate risk decisions. What's the right level of investment? What are the right capabilities? How do you best do this?
But also crucially, this is not something that any organisation can deal with on their own. A lot of the vectors that attackers use now are through the supply chain, through all the sort of services and interdependencies we all have on different organisations. And so working this collectively, and understanding how we can build our collective cyber resilience I think is really important.
(NCSC) One organisation that's made extensive of the Board Toolkit is Becrypt, who supply governments and private organisations with a range of security solutions and services.
Their Chief Executive Officer, Dr Bernard Parsons, explained how it helped them.
(BP) So we've been on a bit of a journey over the last couple of years to increase our cyber resilience, and very much made use of the board toolkit. So we found that a really important asset to help us on the journey. And I'll just share a few examples of why and how that's been the case.
So we started off with cyber risk very much sitting pretty much in isolation with the IT manager, but also our IT security manager, making a lot of these decisions around risk and cyber controls in isolation. He did report into the CFO, so there was a level of representation at board, but it was very much kind of one direction. It wasn't the meaningful engagement that we have more recently been looking for. And a lot of the change that we've experienced as a business was actually driven outside of IT. So areas like DevOps, looking at transforming how we do a product development and build and test automation. IT operations, so separate parts of the business delivering services out to our customers. So we needed a much broader conversation, and the Board Toolkit highlights the need to start thinking about how you want cyber responsibility to be picked up across the business, owned across the business, and then how that drives engagement with board.
And what we decided to do was actually establish a new committee we call it our 'Information Security Management Board', and that has a representation from main board. So me and two of my colleagues will sit on the ISMS board, but importantly it has representation from all of our departmental leads. So that that creates the forum for us to start to have the conversations we need to have. I chair that board. I've effectively become our Senior Risk Owner, and we explicitly made that shift of taking responsibility; decision-making out of what was pretty much a silo into this forum.
What the toolkit advises you to do is think afresh about what you really care about as a business. So what are your assets? What are your crown jewels? And this forum provided the opportunity for us to do that, and it was valuable in coming up with some perspectives that would be difficult to achieve for by individuals in isolation. So once you understand what you care about - what your assets and your risks are - the Toolkit advises that you think about the right controls to put in place, and also the right mechanism of getting the confidence that those controls are being effective. It talks about the importance of thinking afresh about what your business objectives are. Thinking about how all forms of risk (so legal, financial and cyber) are relevant to those business objectives, and the business processes that you have in place to support those, and what security objectives they should be driving.
So there's more of an integrated approach advocated, and that's certainly our experience. That if you do take an approach where it's very much aligned with your business processes and business objectives, then the whole exercise can become more about genuinely looking to enable cyber and digital to deliver business value, as opposed to just focusing on 'stopping bad things happening'.
(NCSC) That was Dr Bernard Parsons explaining how Becrypt used the Board Toolkit to improve cyber security governance across the board.
Mark Hughes, President of Security at DXC Technology, has also used the toolkit extensively, and he started by outlining the challenges that boards face.
(MH) But let me just start by saying the first thing about cyber risk to most boards, in my experience, is it's not intuitive yet. And what I mean by that is you go into any boardroom setting (in any large company, listed companies, SME company, really any company), and one of those things that is incredibly intuitive to most boards is financial risk, and how that gets managed. Because it's been established for many years. Cyber risk isn't there yet.
So the first thing is that the board toolkit is a really good resource to enable someone who's coming into a board context to understand how they should approach cyber risk when it isn't necessarily intuitive. Now a few things though that I really want to drill into. So there are a number of steps that are talked about in the toolkit that are really well done with some good Q&A in there to enable understanding to be tested at the board.
And one of those things that is really important is "well what actually is the role of the board?" And there is often some confusion because for something that isn't particularly well understood, some board members might want to delve right into the real detail, or may think that actually it's just purely an oversight role. And of course those two extremes aren't right - there's something in the middle. And the toolkit is very good at guiding and really helping a board understand what what their role should be.
But very specifically, I think the first point I want to highlight (and I'm not going to go through them all) but the one that I really do want to highlight is about cyber risk, and how that is managed. Now again, my experience is that in most organisations there is a functioning risk framework of how business risk is is measured and managed. From financial risk, operational risk, other types of risk. And cyber risk at the end of the day is another risk within that spectrum of risk that any organisation operates within. And the toolkit is very good about talking about risk, and again, my experience of how this often gets implemented is that that risk is, is sometimes considered separate. Bernard just talked about this - it needs to be *not* a separate thing it needs to be put into that context of the overall risk framework.
The second thing that the toolkit is really useful for is another area that I think most organisations that I see really do struggle with, and that is one of governance. It is what are the roles and responsibilities, not just of the board, but often the Chief Information Security Officer, and the people who run the operational IT. And it's not just inside the organisation. Often in many cases that operational IT is outsourced to organisations like DXC, and others as well. And so how does all of that ecosystem work, so that the roles and responsibilities are well understood? And that is something that I see quite a few organisations. I was in talking to an organisation the other day that didn't really have that right, and then when it came to something going wrong, the individuals who were responsible for trying to deal with the incident there and then really didn't know uh what they were doing vis-a-vis each other and indeed with the suppliers that were supporting them. And that created a lot of confusion at a time when clarity was really important during an incident.
So if I just go on a couple of other considerations that I think are really important. And one of them is about where and when things go wrong, and how incidents are managed. And that is one thing which again the toolkit talks about in some detail, and it's almost where the board often has a role to play and unless that is well understood, with the right processes, and has been well rehearsed, then things can get very confusing very quickly. And again the toolkit is important, is really useful here. Talks about incidents, talks about how incidents should be managed (I'm sure many of us on this call have been involved in incidents), and really getting that right and understanding what the role of the board is vis-a-vis the operational parts of the organisation is critical.
Now, put all that together it sounds like a lot. Actually, stepping through the different parts of the toolkit, framing the way in which the board should operate at what level they should operate, making sure the government is right and rehearsing the incident process. Three or four things; get those right and it can make a huge difference to an organisation in terms of how they can be resilient to the types of things that we're going on.
(NCSC) Thanks for listening, and we hope the Board Toolkit helps improve your cyber security resilience.
If you'd to leave us any feedback, you can do so by emailing [email protected]


