Cyber risk belongs in the boardroom, not IT
- Published
- Letters to the Editor

If directors were legally accountable for cyber failures, they would stop treating resilience as a technical afterthought
Sir,
I read your recent piece on calls to make company boards legally liable for cyber failures (‘Make boards liable for cyber attacks, security chief warns’) with a mix of recognition and frustration. Recognition, because anyone who has worked inside a large organisation knows cyber risk is already existential. Frustration, because it has taken this long for many boards to treat it as anything other than a technical nuisance to be delegated downwards.
Boards are legally accountable for financial controls, audit failures and regulatory breaches, yet cyber resilience — which as we have seen can easily shut a business down overnight — is still too often handled several layers below director level. When an attack hits, responsibility suddenly rises to the top. Until then, it frequently disappears into PowerPoint updates and risk registers few directors truly interrogate.
I am sympathetic to concerns about over-regulation, but voluntary responsibility has clearly failed. If directors faced real legal consequences for ignoring cyber risk, conversations in boardrooms would change quickly. Cyber would stop being a quarterly update and start being treated like liquidity, solvency and compliance.
The question now is not whether boards should be accountable, but how quickly the law will catch up with reality. As with so many areas of governance, the risk is that regulation arrives only after the damage is already done.
Yours faithfully,
Andrew Collins
Reading, UK
Sign up to The European Newsletter
TOP STORIES
-
British buyers fuel Greek luxury property boom after non-dom tax change -
New York named world’s most attractive city for tourists -
Saab lands German frigate deal after Poland submarine order -
Students unveil world’s first solar-powered ambulance -
Burnham told to tackle Britain’s cyber weak spots on day one -
Doctors using AI before health systems set the rules -
Humanoid robots could become the next K-pop stars -
Hormuz flashpoint keeps global shipping on high alert -
Scientists to gather in Lisbon to tackle next pandemic threats -
Burnham warned digital exclusion is now a national security risk -
Masts from Kent ‘doomsday wreck’ to be cut to prevent catastrophic explosion -
GigaCloud and Cubbit launch sovereign cloud storage for Ukraine and Poland -
Tributes paid to ‘forthright and fearless’ Ann Widdecombe -
Boeing to debut Ghost Bat drone at Farnborough Airshow -
Reeves opens ‘£2bn lifeline’ for small firms -
Babymoon boom: Rhodes crowned 2026's top pre-baby escape as Salcombe leads UK getaway list -
Xavier Niel to become Vodafone’s largest shareholder in £4.4bn deal -
Two-thirds of lawyers say strong legal claims are dropped because of cost -
UK government must "think again" about small business plan -
Lockheed Martin pushes European missile expansion at NATO summit -
Britain's new homes face 2050s heat test as experts warn of overheating crisis -
Sky agrees £1.6bn deal to buy ITV’s broadcasting and streaming arm -
Scientists crack dinosaur egg mystery by building life-size nest -
Nobel laureate Omar Yaghi launches global science network -
Cardiff drivers safest in Britain as London comes last


























