top of page

Directors Are Now Personally Accountable for Cyber Failures. Most Don't Know It.

For years, cyber security sat firmly in the IT department's corner. If something went wrong, it was a technical problem for technical people to fix. That understanding is now out of date, and the gap between what directors think their responsibilities are and what they actually are has quietly widened. Cyber security has become a board-level duty in the UK, and directors who treat it as someone else's job may be exposing themselves personally, not just their company.


Empty dark boardroom with a laptop showing a lock icon on the table under a spotlight, suggesting secrecy and security

What Has Actually Changed?

The direction of travel, more than any single new law. The clearest signal came in April 2025. The government's Department for Science, Innovation and Technology, working with the National Cyber Security Centre, published a Cyber Governance Code of Practice aimed squarely at boards and directors. The Code was launched in April 2025 to guide boards in governing cyber risk, setting out five pillars, risk management, strategy, people, incident planning, and assurance, and it makes clear that boards and directors are expected to own cyber risk rather than delegate it solely to IT.


Crucially, the Code did not invent a new duty out of nowhere. It made an existing one explicit. Directors already have a legal duty under the Companies Act 2006 to exercise reasonable care in how they oversee and manage company risks, including those related to cyber security, and aligning with the Code helps demonstrate that directors are meeting that duty. In other words, the law already said directors must oversee the company's material risks with reasonable care. What has changed is the settled recognition that cyber is one of those material risks, on a par with financial and legal risk, and that overseeing it is a board job.


Are Directors Really Personally Accountable?

Yes, though it is worth being precise about how, because the reality is more nuanced than scare headlines suggest. Directors are not routinely handed personal fines when their company suffers a breach. Regulatory penalties under data protection law, for example, are generally levied on the organisation, not the individual. So the risk is not that the regulator personally bills you for a hack.


The real exposure runs through directors' own legal duties. Under the Companies Act, directors must act in the company's best interests and exercise reasonable care, skill and diligence. If a director neglects cyber oversight entirely and the company suffers serious, foreseeable harm as a result, that can amount to a breach of those duties, which can lead to claims against the director, and in serious cases to disqualification from acting as a director. In regulated sectors such as financial services, named senior managers are already personally accountable for their areas under the regulator's senior managers regime, and cyber resilience increasingly falls within that. The picture, then, is not "you will be fined for a breach", but "if you fail to govern cyber risk with reasonable care, you carry personal legal and professional exposure, and the standard you are now measured against clearly includes cyber". The Code matters here because it sets out what "reasonable care" looks like in practice, which makes it harder to argue you did not know what was expected.


Why Do So Few Directors Know This?

Because board attention has actually been drifting the wrong way while the expectations rose. The figures are striking. While 72% of businesses treat cyber security as a key focus, board-level responsibility for it has steadily declined over four years, and just under 3 in 10 businesses have a board member explicitly responsible for cyber security as part of their role. So in the majority of businesses, no one at the top formally owns it. The old assumption, that cyber is a technical matter safely left to IT, has proven remarkably sticky, even as regulators and government have moved decisively in the opposite direction. That mismatch, rising responsibility meeting falling ownership, is exactly why so many directors are exposed without realising it.


What Does Board-Level Cyber Governance Look Like in a Smaller Business?

This is where directors often panic unnecessarily, imagining they need to become technical experts or build a large governance apparatus. They do not. Board-level governance is about oversight, not hands-on management. The Code itself is clear that it is aimed at what directors should oversee, not how to configure the technology. Translated for a small or mid-sized business, the five principles come down to sensible, non-technical questions the board should be able to answer:


  • Risk: do we know what our most important data and systems are, and what it would cost us if they were lost or breached?

  • Strategy: have we decided how much cyber risk we are willing to accept, and are we putting appropriate resources behind protecting against it?

  • People: is it clear who is responsible for what, and are our staff trained to spot the threats that target them?

  • Incident planning: do we have a plan for when something goes wrong, and have we actually tested it?

  • Assurance: how do we know our protections are working, and have we had an independent check rather than just taking IT's word for it?


None of that requires technical knowledge. It requires the board to ask the questions, understand the answers, and make deliberate decisions, which is exactly what directors do with every other business risk.


A Practical Checklist for Directors

To turn that into action, a straightforward starting checklist:


  • Give cyber a named owner at board level, so it is somebody's explicit responsibility rather than nobody's.

  • Put cyber on the board agenda as a standing item, with a proper discussion at least a few times a year, not just after an incident.

  • Understand your critical assets, knowing what data and systems the business could not function without, and where they are.

  • Confirm there is a tested incident response plan, so a breach is met with a rehearsed plan rather than panic.

  • Get independent assurance, an external review of your security rather than relying solely on internal reassurance.

  • Check your insurance and compliance position, covered below.

  • Document your decisions, keeping a record that shows the board considered cyber risk and acted reasonably. Should your oversight ever be questioned, that evidence matters.


How This Ties to Cyber Insurance and Compliance

These threads increasingly pull together. Cyber insurers now expect to see genuine security controls and governance before they will offer cover or pay out, and directors' and officers' insurance sits alongside that. Being able to show that the board took cyber seriously, made decisions and put controls in place is part of what protects both the company and the individuals on the board. Recognised standards help here too, because achieving something like Cyber Essentials or ISO 27001 gives you documented evidence that you meet a baseline, a point we cover in our article on using virtual desktops as a compliance shortcut. Good governance, sensible insurance and recognised certification are three parts of the same picture, and directors are wise to see them together rather than separately.


What Directors Should Do Now

The practical route is to treat cyber like any other serious business risk you do not personally specialise in: take ownership at the top, get competent help, and oversee it properly. Most smaller businesses do not have in-house security expertise, and do not need to, but they do need a capable partner handling the protection and giving the board clear, honest assurance. That is much of what a managed security service exists to provide, and our own managed security service is built to give business leaders both the protection and the visibility they need to govern it, with the monitoring and controlled environment described in our overview of virtual desktops and Desktop as a Service in 2026.


The Bottom Line

Cyber security has moved from the server room to the boardroom, and the law now expects directors to oversee it with the same care they give to money and legal risk. The exposure is real but manageable: it is not about becoming technical or about being personally fined for every incident, it is about being able to show you took the risk seriously and governed it reasonably. Most directors have not yet caught up with this, which is precisely why acting now, giving cyber an owner, putting it on the agenda, and getting proper assurance, is both the responsible move and the one that protects you personally.


This article is general information, not legal advice. Directors should take proper legal and professional advice on how these duties apply to their own company and circumstances.

Comments


Contact Us

Thanks for submitting!

Have a question you want answered quicker?

Give us a ring or try our online chat!

Tel. 02039064600

Please do not block Caller ID so our team can assist you faster.

  • LinkedIn
  • Facebook
  • Instagram
  • Twitter

© 2026 SystemsCloud Group Ltd.

bottom of page