How well are you governing cyber risk?
In recent weeks, we’ve seen how quickly the world can change. In times like these, the risk of a cyber breach becomes more visible, not just within our own organisations, but across the partners and suppliers we rely on.
The numbers speak for themselves. According to the Cyber Security Breaches Survey 2024, half of UK businesses and two-thirds of high-income charities experienced a cyber attack or breach in the last year. Among medium and large businesses, that rises to more than 70%.
The consequences are wide-ranging. Cyber incidents don’t just cause disruption; they affect business continuity, damage competitiveness, and can seriously erode customer trust. That’s why cyber resilience has become essential to long-term viability, and something boards and leadership teams need to govern well.
A helpful benchmark
To support better governance, the Department for Science, Innovation and Technology (DSIT) has published a new Cyber Governance Code of Practice. It sets out clear expectations for how boards and directors should oversee cyber risk.
While the code isn’t mandatory, it provides a useful benchmark. Together with the Cyber Essentials certification scheme, it outlines a sensible minimum standard for organisations to manage cyber risks effectively.
The code is built around five core areas. If you’re reviewing your own approach, these questions might help.
- Risk management
- Do you understand which systems, processes and information are critical to delivering your organisation’s objectives?
- Is your cyber risk appetite clearly defined, and are cyber risks integrated into your enterprise risk management?
- Have you assessed cyber risks in your supply chain and partner relationships?
- Strategy
- Is there a clear cyber strategy in place, with the right resources to deliver it?
- How do you track progress and know whether the outcomes are making a difference?
- People
- What’s the culture around cyber security in your organisation?
- How is it reinforced through policy, training, awareness and day-to-day behaviours?
- Incident planning, response and recovery
- Are response and recovery plans in place and well understood?
- Do you test them, including with external partners?
- Is there a clear process for learning lessons and making improvements?
- Assurance and oversight
- Is the governance structure around cyber risk clear and effective?
- What metrics do you use to monitor cyber risk, and how are thresholds and tolerances defined?
- What assurance do you receive, and how do you make sure improvement actions are followed through?
How we can help
At BRAVE, we work with organisations to assess how their approach compares to the Code and where improvements can be made. Whether you’re looking for assurance, a fresh perspective, or practical support to strengthen your governance, we’re here to help.
It’s a good time to take stock.
If you’d like to talk through where you are – and where you might need to be – get in touch.
Contact: contact@brave-governance.com



