top of page

Webinar summary: A board briefing from UK government

Earlier this week we were pleased to welcome back John Maguire from the Department for Science, Innovation and Technology to update the CxB community on government cyber resilience policy and initiatives that boards should be aware of.


UK cybersecurity challenges

John presented on cybersecurity challenges and the UK's approach to addressing them. He shared findings from the government’s annual Cyber Breaches Survey, noting that 43% of businesses and 28% of charities reported cyber breaches in the past year, with larger organizations both more likely to experience attacks and have board-level responsibility for cybersecurity.


New regulations

John described the Cyber Security and Resilience Bill which has been introduced to the House of Lords. This aims to expand current cyber security regulations to cover managed service providers and data centres, and enhance incident reporting requirements. It includes reforms to empower regulators through simplified enforcement structures, and gives government powers to set strategic priorities and update regulations.


John explained that while further regulation remains a possibility if voluntary measures don't succeed, the government's preference is to work with industry through voluntary commitments.


Cyber Resilience Pledge initiative

John then outlined the Cyber Resilience Pledge initiative, which builds on a previous ministerial letter sent to 400 UK businesses to which over 180 organizations have already responded positively.


The Pledge is a voluntary public commitment which requires signatories to:

  • make cyber resilience a board priority

  • sign up to the NCSC's Early Warning Service, and

  • require Cyber Essentials across their supply chains.


John reported that the Cyber Resilience Pledge launched with over 60 signatories, including major UK businesses like Marks & Spencer, Microsoft and Vodafone. Its launch event at Number 10 was hosted by Minister Liz Lloyd, with speeches from the CEOs of Nationwide and Microsoft UK. Since then the number of signatories had grown to around 90, with about 20 new additions in the past week alone. Signatories have come from many different sectors, and include small and micro businesses.


The pledge remains open indefinitely, with John encouraging organizations to consider it and reach out with any questions.


Cyber governance tools and framework

John discussed the need to focus on driving awareness and uptake of existing cyber governance tools rather than creating new ones, highlighting the Cyber Governance Code of Practice and Cyber Essentials as key baseline resources.


The Cyber Governance Code of Practice currently has limited awareness at 16% of organizations, though awareness is higher among larger organizations.


John outlined additional cybersecurity initiatives including the Product Security and Telecommunications Act, the Software Security Code of Practice, and the upcoming National Cyber Action Plan expected later this year.


He also reported that the Department for Business and Trade will consult later this year on modernizing corporate reporting, presenting an opportunity to incorporate cyber security requirements while noting the government's goal to reduce reporting burden.


Discussion and feedback

Encouragingly, a meeting poll showed that nearly 90% of webinar participants were already aware of the Cyber Governance Code of Practice. Points they raised included:


  • the importance of going beyond awareness to provide organizations with the confidence and means to address cyber risks, particularly charities and smaller organisations working with vulnerable communities

  • the need for better official guidance to help boards mature their practices, similar to guidance that exists in more established areas such as health and safety

  • the possibility of incorporating cyber governance requirements into existing corporate governance codes

  • the potential to consolidate cyber governance requirements under a single overarching cyber regulator.


Launch event for the Cyber Resilience Pledge (image: Department for Science, Innovation & Technology)
Launch event for the Cyber Resilience Pledge (image: Department for Science, Innovation & Technology)

 
 
bottom of page