Cyber risk belongs in the boardroom, not IT
- Published
- Letters to the Editor

If directors were legally accountable for cyber failures, they would stop treating resilience as a technical afterthought
Sir,
I read your recent piece on calls to make company boards legally liable for cyber failures (‘Make boards liable for cyber attacks, security chief warns’) with a mix of recognition and frustration. Recognition, because anyone who has worked inside a large organisation knows cyber risk is already existential. Frustration, because it has taken this long for many boards to treat it as anything other than a technical nuisance to be delegated downwards.
Boards are legally accountable for financial controls, audit failures and regulatory breaches, yet cyber resilience — which as we have seen can easily shut a business down overnight — is still too often handled several layers below director level. When an attack hits, responsibility suddenly rises to the top. Until then, it frequently disappears into PowerPoint updates and risk registers few directors truly interrogate.
I am sympathetic to concerns about over-regulation, but voluntary responsibility has clearly failed. If directors faced real legal consequences for ignoring cyber risk, conversations in boardrooms would change quickly. Cyber would stop being a quarterly update and start being treated like liquidity, solvency and compliance.
The question now is not whether boards should be accountable, but how quickly the law will catch up with reality. As with so many areas of governance, the risk is that regulation arrives only after the damage is already done.
Yours faithfully,
Andrew Collins
Reading, UK
RECENT ARTICLES
-
Lasers finally unlock mystery of Charles Darwin’s specimen jars -
Strong ESG records help firms take R&D global, study finds -
European Commission issues new cancer prevention guidance as EU records 2.7m cases in a year -
Artemis II set to carry astronauts around the Moon for first time in 50 years -
Meet the AI-powered robot that can sort, load and run your laundry on its own -
Wingsuit skydivers blast through world’s tallest hotel at 124mph in Dubai stunt -
Centrum Air to launch first European route with Tashkent–Frankfurt flights -
UK organisations still falling short on GDPR compliance, benchmark report finds -
Stanley Johnson appears on Ugandan national television during visit highlighting wildlife and conservation ties -
Anniversary marks first civilian voyage to Antarctica 60 years ago -
Etihad ranked world’s safest airline for 2026 -
Read it here: Asset Management Matters — new supplement out now -
Breakthroughs that change how we understand health, biology and risk: the new Science Matters supplement is out now -
The new Residence & Citizenship Planning supplement: out now -
Prague named Europe’s top student city in new comparative study -
BGG expands production footprint and backs microalgae as social media drives unprecedented boom in natural wellness -
The European Winter 2026 edition - out now -
Parliament invites cyber experts to give evidence on new UK cyber security bill -
EU sustainability rules drive digital compliance push in Uzbekistan ahead of export change -
AI boom triggers new wave of data-centre investment across Europe -
Lammy travels to Washington as UK joins America’s 250th anniversary programme -
China’s BYD overtakes Tesla as world’s largest electric car seller -
FTSE 100 posts strongest annual gain since 2009 as London market faces IPO test -
Five of the biggest New Year’s Eve fireworks happening tonight — and where to watch them -
UK education group signs agreement to operate UN training centre network hub

























