---
title: "Board Cyber Governance Guide: briefing | Firevault"
description: "Directors face increasing personal liability for cyber governance failures. This guide translates technical security concepts into the governance language…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/board-guide-cyber-governance#webpage",
      "url": "https://fire-vault.com/learn/guides/board-guide-cyber-governance",
      "name": "Board Cyber Governance Guide: briefing",
      "description": "Directors face increasing personal liability for cyber governance failures. This guide translates technical security concepts into the governance language…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/board-guide-cyber-governance#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/board-guide-cyber-governance#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Board Guide to Cyber Governance",
          "item": "https://fire-vault.com/learn/guides/board-guide-cyber-governance"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Board Guide to Cyber Governance",
      "description": "Directors face increasing personal liability for cyber governance failures. This guide translates technical security concepts into the governance language that boards understand, and explains why physical controls matter for director-level accountability.",
      "url": "https://fire-vault.com/learn/guides/board-guide-cyber-governance",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/og-cached/649ad906347d6f17.png",
      "author": {
        "@id": "https://fire-vault.com/#organization"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-02-19T09:13:51.962911+00:00",
      "dateModified": "2026-04-21T21:06:02.133858+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/board-guide-cyber-governance"
      },
      "inLanguage": "en-GB",
      "articleSection": "Governance",
      "wordCount": 627,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

Why This Is Now a Board IssueThe Governance GapWhat "Appropriate Measures" Mean…The Five Things Every Board Shou…How OSS Supports Board GovernanceQuestions Directors Should AskConclusionMore

[Guides](/learn/knowledge?filter=guides)/ Governance 

Governance · 19 February 2026 

# Board Guide to Cyber Governance

Directors face increasing personal liability for cyber governance failures. This guide translates technical security concepts into the governance language that boards understand, and explains why physical controls matter for director-level accountability.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fboard-guide-cyber-governance)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fboard-guide-cyber-governance&text=Board%20Guide%20to%20Cyber%20Governance%0A%0ADirectors%20face%20increasing%20personal%20liability%20for%20cyber%20governance%20failures.%20This%20guide%20translates%20technical%20security%20concepts%20into%20the%20governance%20language%20that%20boards%20understand%2C%20and%20explains%20why%20physical%20controls%20matter%20for%20director-level%20accountability.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fboard-guide-cyber-governance)[](mailto:?subject=Board%20Guide%20to%20Cyber%20Governance&body=Directors%20face%20increasing%20personal%20liability%20for%20cyber%20governance%20failures.%20This%20guide%20translates%20technical%20security%20concepts%20into%20the%20governance%20language%20that%20boards%20understand%2C%20and%20explains%20why%20physical%20controls%20matter%20for%20director-level%20accountability.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fboard-guide-cyber-governance)

Governance #OSSOffline Secure Storage® 

Article record

**Governance**Category 

**19 February 2026**Published 

**4 min read**Reading time 

**Mark Fermor**Written by 

**beginner**Level 

Why it matters

## What this means for organisations holding critical data

Directors face increasing personal liability for cyber governance failures. This guide translates technical security concepts into the governance language that boards understand, and explains why physical controls matter for director-level accountability.

In this piece

1.  01 [Why This Is Now a Board Issue](#section-0)
2.  02 [The Governance Gap](#section-1)
3.  03 [What "Appropriate Measures" Mean…](#section-2)
4.  04 [The Five Things Every Board Shou…](#section-3)
5.  05 [How OSS Supports Board Governance](#section-4)
6.  06 [Questions Directors Should Ask](#section-5)

**On this page**[Why This Is Now a Board Issue](#section-0)[The Governance Gap](#section-1)[What "Appropriate Measures" Mean…](#section-2)[The Five Things Every Board Shou…](#section-3)[How OSS Supports Board Governance](#section-4)[Questions Directors Should Ask](#section-5)[Conclusion](#section-6)

On this page

1.  [Why This Is Now a Board Issue](#section-0)
2.  [The Governance Gap](#section-1)
3.  [What "Appropriate Measures" Means for Directors](#section-2)
4.  [The Five Things Every Board Should Govern](#section-3)
5.  [How OSS Supports Board Governance](#section-4)
6.  [Questions Directors Should Ask](#section-5)
7.  [Conclusion](#section-6)

## Why This Is Now a Board Issue

The UK Corporate Governance Code, the Companies Act 2006, and upcoming legislation including the Cyber Security and Resilience Bill are making cyber governance an explicit board responsibility. Directors who cannot demonstrate they understood and governed cyber risk face personal liability.

This is not about understanding firewalls or endpoint detection. It is about three questions every director must be able to answer:

1.  What are our most critical digital assets, and how are they protected?
2.  If we suffered a major cyber incident tomorrow, can we recover?
3.  What evidence exists that we have exercised appropriate governance?

## The Governance Gap

Most boards receive quarterly security reports that focus on prevention: how many threats were blocked, how many vulnerabilities were patched, how many employees completed awareness training. Prevention metrics are important, but they answer the wrong question.

The question boards should be asking is not "how well are we preventing attacks?" but "what happens when prevention fails?" Because prevention will fail. The NCSC, the ICO, and every credible security authority acknowledges this. The measure of an organisation's cyber maturity is not whether it can prevent every attack, but whether it can recover from one.

## What "Appropriate Measures" Means for Directors

UK GDPR Article 32 requires "appropriate technical and organisational measures" for data protection. The standard is proportionality: measures should be appropriate to the risk. For an organisation's most critical assets, physical controls represent the highest standard of appropriateness.

Physical controls are:

-   **Demonstrable.** Unlike software configurations that require technical expertise to verify, physical disconnection is self-evident.
-   **Tamper-evident.** Physical access logs provide audit trails that software logs cannot match for integrity.
-   **Comprehensible.** Directors can understand and explain physical controls to regulators, insurers, and shareholders without technical translation.

## The Five Things Every Board Should Govern

### 1\. The Crown Jewels Register

A documented list of the organisation's most critical digital assets, with clear ownership and protection standards for each. The board should review this annually.

### 2\. Recovery Capability

Evidence that the organisation can recover from a major cyber incident without depending on systems that might themselves be compromised. This includes offline storage of recovery credentials and procedures.

### 3\. Incident Response Readiness

A practised incident response capability, tested at least annually, with documented results reported to the board. Tabletop exercises should include scenarios where primary systems are unavailable.

### 4\. Regulatory Compliance Posture

Demonstrable compliance with applicable regulations, with evidence that goes beyond checkbox compliance to reflect genuine governance commitment.

### 5\. Insurance Alignment

Confirmation that cyber insurance coverage aligns with actual risk exposure, and that policy conditions (including security requirements) are being met.

## How OSS Supports Board Governance

[Offline secure storage](/offline-secure-storage) directly addresses the governance requirements that boards face:

-   **Evidence of appropriate measures:** Physical controls for the organisation's most critical assets demonstrate proportionate protection.
-   **Recovery assurance:** Physically disconnected recovery credentials provide the certainty that recovery is possible regardless of attack sophistication.
-   **Audit trail integrity:** Tamper-evident access logs provide the governance evidence that regulators and insurers expect.
-   **Director accountability:** Documented physical controls demonstrate that directors exercised reasonable care in governing cyber risk.

## Questions Directors Should Ask

1.  Where are our recovery credentials stored? Could they be encrypted by the same attack we are trying to recover from?
2.  Have we identified our crown jewels? Are they protected with measures proportionate to their value?
3.  When did we last test our ability to recover from a major incident? What were the results?
4.  What physical controls exist for our most critical data? Can we demonstrate these to a regulator?
5.  Does our cyber insurance policy specifically require or reward physical security controls?

## Conclusion

Cyber governance is no longer optional for directors. Physical controls through offline secure storage provide the demonstrable, comprehensible, and auditable governance that directors need to fulfil their responsibilities and protect both the organisation and themselves.

About the author

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### Crown Jewels Audit: What Deserves Disconnection
    
    Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only physical disconnection can provide.
    
    Read guide ](/learn/guides/crown-jewels-audit)
-   [
    
    ### The 72-Hour Breach Notification Window
    
    UK GDPR requires breach notification to the ICO within 72 hours. When your email, document systems, and contact databases are encrypted, meeting this deadline becomes a governance challenge that only prior preparation can solve.
    
    Read guide ](/learn/guides/72-hour-breach-notification)
-   [
    
    ### Credential Governance: Managing Your Keys
    
    Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability becomes irrelevant. Credential governance through OSS ensures the keys to your kingdom survive any incident.
    
    Read guide ](/learn/guides/credential-governance)
-   [
    
    ### Cyber Insurance and Physical Controls
    
    Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance. Understanding this shift can reduce premiums and improve coverage terms.
    
    Read guide ](/learn/guides/cyber-insurance-physical-controls)

Related Reading

## You may also find these useful

[

![GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gta6-leaks-rockstar-2026.jpg)

Insight 

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min 







](/news/gta-6-leaks-rockstar-development-footage-2026)[

![Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/nine-pbs-archives-cloud-vendor-shutdown-2026.jpg)

Insight 

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min 







](/news/nine-pbs-archives-cloud-vendor-shutdown-2026)[

![When Access Fails: Continuity Needs Offline Secure Storage](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg)

Industry Insight 

### When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

18 Aug 2026 9 min 







](/news/when-the-grid-fails-offline-secure-storage-business-continuity)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

![David Bailey](/assets/david-bailey-CnLw95Ao.jpg)

![Kenny Phipps](/assets/kenny-phipps-DxIqwaIL.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up