Recent developments in artificial intelligence have underlined how quickly the cyber risk landscape is evolving. The recent controlled release of Anthropic’s Mythos model, reportedly capable of autonomously identifying and exploiting previously unknown software vulnerabilities, prompted urgent discussions among regulators, banks and government agencies in both the US and UK.
This was not a technology story; it was a governance signal. It demonstrated how AI is accelerating the speed, scale and asymmetry of cyber threats, compressing the window between vulnerability discovery and exploitation to hours rather than weeks or months. For Boards, this reinforces the need to treat cyber resilience as an immediate and strategic risk, not a future concern – and one they need to take ownership of.
The cyber threat landscape is more varied, sophisticated and challenging than ever before, and with regulators, investors, customers and insurers all expecting informed oversight of cyber risk and resilience from directors, it’s a challenge Boards must take very seriously.
Cyber threats are increasing in frequency and impact so Boards need to be confident in their knowledge, preparedness and resilience in order to demonstrate that their organisations are not exposed to legal, regulatory, financial and reputational harm.
Ten key areas represent the minimum standard of oversight for Boards.
1. Clear Board level accountability
Every organisation should have a named executive owner and a Board sponsor accountable for cyber resilience to provide clear ownership and accountability Regulators increasingly expect Boards to demonstrate who is responsible for cyber risk and to show that those individuals are equipped with the right information to govern effectively.
2. Meaningful visibility of cyber and resilience risks
Directors must receive regular, relevant and objective updates on cyber and operational resilience risks, including supply chain and third party exposures.
High level dashboards are no longer sufficient – Boards need information that supports informed decision making.
3. Incident response plans are only credible if tested
An incident response plan that has never been tested is unlikely to work during a live incident.
Boards should ensure that response and escalation procedures have been tested within the last 12 months through cyber exercises involving senior stakeholders.
Cyber exercises reveal gaps, clarify roles and build capability for decision making under pressure.
4. Regulatory notification obligations
Cyber incidents frequently trigger mandatory legal and regulatory notification duties with strict deadlines.
Failure to meet these obligations can result in financial sanctions being imposed regardless of the underlying cause of the incident.
Boards should be confident that notification requirements are clearly understood, rehearsed and embedded within response plans.
5. Recovery objectives must align to business reality
It is not enough to assume systems can be restored “quickly”.
Boards must understand whether Recovery Time Objectives (RTOs) for critical systems and suppliers are defined, tested and realistic.
The thresholds should align with incident response arrangements and reflect the organisation’s tolerance for disruption, revenue loss and customer impact.
6. Third party risk is now a primary attack vector
Many cyber incidents originate within the supply chain.
Boards should ensure that they understand the resilience of the people they do business with.
Ongoing assurance, proportionate monitoring and contingency planning are essential to avoid unmanaged cyber risk or significant disruption through the failure of a third party.
7. Cyber insurance does not remove accountability
Cyber insurance can provide financial support, but it is not a substitute for resilience.
Boards need to understand policy scope, exclusions, conditions and dependencies.
Insurance gaps are often discovered at the point of claim, creating costly and unexpected exposure.
8. Cyber resilience depends on culture, not just controls
Technology alone does not create resilience.
Boards should ensure cyber risk is embedded into organisational culture, staff training and everyday decision making.
Consistent messaging from leadership helps reinforce cyber resilience as a shared responsibility, not simply an IT function.
9. Data protection and recoverability are business critical
Data is the lifeblood of most organisations.
Boards should be confident that controls exist to protect the confidentiality, integrity and availability of critical data and that backup and recovery processes are regularly tested.
The recoverability of data is central to recovering from ransomware and other data loss events.
10. The threat landscape is constantly changing
It’s crucial for Boards to look beyond current risks.
Emerging technologies such as AI, quantum computing, and connected devices introduce both opportunity and new vulnerabilities.
Regular horizon scanning briefings help directors anticipate future threats and ensure resilience strategies remain relevant rather than reactive.
Why it is so important
Failure to manage and maintain oversight of cyber risk at Board level creates significant and unacceptable levels of risk.
Cyber attacks cause lasting damage. irrecoverable costs, client attrition and lost confidence.
Effective cyber governance does not require Boards to become technical experts, but it does require them to ask the right questions, demand evidence based assurance, and treat cyber resilience as a core business issue.
If a Board cannot confidently demonstrate that it is overseeing the key areas set out above, it’s a clear signal that focused action is required now, before a cyber incident tests that preparedness for real.
Related Insights
The Wrong Cyber Story Is Making Headlines
A recent striking headline reported that AI belonging to a major technology company had hacked into another company's systems during...
Wiping the Slate Clean… As An Act of Cyber Warfare
A recent cyberattack on US medical technology company Stryker with bases in Ireland, highlights a dangerous trend in modern cyber...
How the Escalating Iran Crisis Is Impacting Marine, Aviation and Cyber Risk for Clients
The Middle East has entered a period of severe instability, with the Strait of Hormuz experiencing a rapid escalation in...
Free Webinar: Autonomous Vehicles – The Cyber Risk
With autonomous vehicles poised to redefine mobility, the conversation is shifting from infrastructure and insurance to one of the most...




