Resilience is built before the breach, not during it.
The UK Government’s Ministerial Letter on Cyber Security delivers a stark message: hostile cyber activity is becoming more intense, frequent, and sophisticated, and boards must act now.
Addressed to CEOs and Chairs of UK companies, the letter urges immediate action in three areas:
- Make cyber risk a board priority, using the Cyber Governance Code of Practice to embed resilience into governance and decision-making.
- Join the NCSC’s Early Warning Service, to detect and contain incidents before they escalate.
- Require Cyber Essentials across supply chains, raising baseline defences across the wider ecosystem.
The NCSC Annual Review 2025 reinforces this message, highlighting a 50% increase in nationally significant incidents, and a clear warning that “cyber security is now critical to business longevity and success.”
The Review advocates a shift from reactive defence to proactive resilience – a change that every board should now be embedding across governance, operations and supply chains.
To translate that into practice, organisations should focus on:
- Board-Level Cyber Governance – equipping leadership teams to see cyber not just as a technical risk but also as a strategic one, ensuring board decisions are informed by real-world threats and potential operational impact.
- Incident Response & Exercising – building and testing crisis documents that prepare leadership to act decisively under pressure – connecting board decisions, operational response, and external communications in real time.
- Supply-Chain Resilience – mapping and securing the extended digital ecosystem, recognising that a single weak vendor can halt operations, disrupt trade, and trigger reputational and regulatory consequences.
- Operational Continuity & Recovery – validating how quickly your organisation can detect, contain and recover from disruption – improving confidence in your ability to maintain critical services when the unexpected happens.
As the foreword of the Review states: “Nobody wants to believe their business could grind to a halt following a cyber attack. But any leader who fails to prepare for that scenario is jeopardising their business’s future.”
From Awareness to Action
The message from Government and the NCSC is clear. Good intentions don’t stop cyber attacks, preparation does.
For UK boardrooms, the challenge is no longer awareness but accountability. Resilience is built before the breach, not during it.
If you would like support improving or testing your organisation’s cyber resilience through training, incident response planning or exercising contact Craig Kennedy, Partner and Head of Cyber Consulting.
Related Insights
The Wrong Cyber Story Is Making Headlines
A recent striking headline reported that AI belonging to a major technology company had hacked into another company's systems during...
Ten Things Every Board Needs to Know About Cyber Risk
Recent developments in artificial intelligence have underlined how quickly the cyber risk landscape is evolving. The recent controlled release of...
Wiping the Slate Clean… As An Act of Cyber Warfare
A recent cyberattack on US medical technology company Stryker with bases in Ireland, highlights a dangerous trend in modern cyber...
How the Escalating Iran Crisis Is Impacting Marine, Aviation and Cyber Risk for Clients
The Middle East has entered a period of severe instability, with the Strait of Hormuz experiencing a rapid escalation in...




