Cyber risk belongs in the boardroom, not IT
- Published
- Letters to the Editor

If directors were legally accountable for cyber failures, they would stop treating resilience as a technical afterthought
Sir,
I read your recent piece on calls to make company boards legally liable for cyber failures (‘Make boards liable for cyber attacks, security chief warns’) with a mix of recognition and frustration. Recognition, because anyone who has worked inside a large organisation knows cyber risk is already existential. Frustration, because it has taken this long for many boards to treat it as anything other than a technical nuisance to be delegated downwards.
Boards are legally accountable for financial controls, audit failures and regulatory breaches, yet cyber resilience — which as we have seen can easily shut a business down overnight — is still too often handled several layers below director level. When an attack hits, responsibility suddenly rises to the top. Until then, it frequently disappears into PowerPoint updates and risk registers few directors truly interrogate.
I am sympathetic to concerns about over-regulation, but voluntary responsibility has clearly failed. If directors faced real legal consequences for ignoring cyber risk, conversations in boardrooms would change quickly. Cyber would stop being a quarterly update and start being treated like liquidity, solvency and compliance.
The question now is not whether boards should be accountable, but how quickly the law will catch up with reality. As with so many areas of governance, the risk is that regulation arrives only after the damage is already done.
Yours faithfully,
Andrew Collins
Reading, UK
Sign up to The European Newsletter
TOP STORIES
-
Europe’s healthcare sector lags on AI uptake – but leads once it starts using it -
Stranded drivers could soon call for help even with no mobile signal -
NASA backs space ‘air brake’ that could cut years off missions to Uranus and Neptune -
MPs and peers call for UK ban on AI that could evade human control -
France orders €1.3bn in extra cuts as growth falls behind European neighbours -
Bioweapons research, Russian-linked spies, guided rockets and cyber-attacks on Europe used Claude AI, Anthropic reveals -
Cadbury Takes a Break as KitKat tops Britain’s social media sweet rankings -
European network alliance doubles in size as digital sovereignty drive accelerates -
European insurance giants join New York summit on future of AI -
Oxford leads £10m international study as resistance threatens new TB treatments -
Inside the world’s wildest new mini golf course with caves, 13ft waterfalls… and sharks -
Apple’s new boss bets £1,999 on first folding iPhone -
‘Double delight’ as rare red pandas born at Whipsnade Zoo -
This Japanese ski resort has just been named the world’s best place for seasonal work -
Nearly 4m Londoners experienced mental health challenges last year, study finds -
Card fraud accounts for more than one-in-three UK identity fraud cases -
Breast cancer campaigners target Burnham at PMQs over £20m research fund -
Europe leads world in quantum research despite deep industry scepticism -
Australia plans social media algorithm ‘off switch’ in move Europe could follow -
European central banks move gold out of U.S as 'geopolitical risks' mount -
Volkswagen plans another 50,000 job cuts in sweeping overhaul -
Uber launches UK’s first autonomous ride-hailing service in London -
Hackers could plunge Britain into darkness in less than two minutes, report warns -
BP appoints Ian Tyler chairman after Albert Manifold ousting -
Del Boy’s bent cop nemesis inspired David Jason to become a TV detective




























