---
title: "Cyber Security for Boards: The Director's Guide… | Firevault"
description: "What a board actually owns on cyber risk, the decisions directors cannot delegate, the questions to ask management, and the evidence to expect before a…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/cyber-security-for-boards#webpage",
      "url": "https://fire-vault.com/learn/guides/cyber-security-for-boards",
      "name": "Cyber Security for Boards: The Director's Guide…",
      "description": "What a board actually owns on cyber risk, the decisions directors cannot delegate, the questions to ask management, and the evidence to expect before a…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcyber-security-for-boards.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/cyber-security-for-boards#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/cyber-security-for-boards#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Cyber Security for Boards: The Director's Guide to Cyber Resilience, Risk and Control",
          "item": "https://fire-vault.com/learn/guides/cyber-security-for-boards"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Cyber Security for Boards: The Director's Guide to Cyber Resilience, Risk and Control",
      "description": "What a board actually owns on cyber risk, the decisions directors cannot delegate, the questions to ask management, and the evidence to expect before a serious incident tests the answers.",
      "url": "https://fire-vault.com/learn/guides/cyber-security-for-boards",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcyber-security-for-boards.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-28T06:40:38.871015+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/cyber-security-for-boards"
      },
      "inLanguage": "en-GB",
      "articleSection": "Guides",
      "wordCount": 1149,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

Who this guide is forWhat the board is actually respo…The decisions you own, and what …The risks a director should unde…The questions to ask managementThe evidence to expectWhat good looks like from the bo…What happens when preventative c…Deciding what you actually needThe Control Blueprints most rele…Where to go nextSources and further readingAbout this guideMore

[Guides](/learn/knowledge?filter=guides)

Guides · 28 August 2026 

# Cyber Security for Boards: The Director's Guide to Cyber Resilience, Risk and Control

What a board actually owns on cyber risk, the decisions directors cannot delegate, the questions to ask management, and the evidence to expect before a serious incident tests the answers.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

7 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcyber-security-for-boards)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcyber-security-for-boards&text=Cyber%20Security%20for%20Boards%3A%20The%20Director's%20Guide%20to%20Cyber%20Resilience%2C%20Risk%20and%20Control%0A%0AWhat%20a%20board%20actually%20owns%20on%20cyber%20risk%2C%20the%20decisions%20directors%20cannot%20delegate%2C%20the%20questions%20to%20ask%20management%2C%20and%20the%20evidence%20to%20expect%20before%20a%20serious%20incident%20tests%20the%20answers.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcyber-security-for-boards)[](mailto:?subject=Cyber%20Security%20for%20Boards%3A%20The%20Director's%20Guide%20to%20Cyber%20Resilience%2C%20Risk%20and%20Control&body=What%20a%20board%20actually%20owns%20on%20cyber%20risk%2C%20the%20decisions%20directors%20cannot%20delegate%2C%20the%20questions%20to%20ask%20management%2C%20and%20the%20evidence%20to%20expect%20before%20a%20serious%20incident%20tests%20the%20answers.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcyber-security-for-boards)

![Cyber Security for Boards: The Director's Guide to Cyber Resilience, Risk and Control](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcyber-security-for-boards.jpg)

Guides 

Why it matters

## What this means for organisations holding critical data

What a board actually owns on cyber risk, the decisions directors cannot delegate, the questions to ask management, and the evidence to expect before a serious incident tests the answers.

**On this page**[Who this guide is for](#section-0)[What the board is actually respo…](#section-1)[The decisions you own, and what …](#section-2)[The risks a director should unde…](#section-3)[The questions to ask management](#section-4)[The evidence to expect](#section-5)[What good looks like from the bo…](#section-6)[What happens when preventative c…](#section-7)[Deciding what you actually need](#section-8)[The Control Blueprints most rele…](#section-9)[Where to go next](#section-10)[Sources and further reading](#section-11)[About this guide](#section-12)

On this page

1.  [Who this guide is for](#section-0)
2.  [What the board is actually responsible for](#section-1)
3.  [The decisions you own, and what you can delegate](#section-2)
4.  [The risks a director should understand](#section-3)
5.  [The questions to ask management](#section-4)
6.  [The evidence to expect](#section-5)
7.  [What good looks like from the board seat](#section-6)
8.  [What happens when preventative controls fail](#section-7)
9.  [Deciding what you actually need](#section-8)
10.  [The Control Blueprints most relevant to this role](#section-9)
11.  [Where to go next](#section-10)
12.  [Sources and further reading](#section-11)
13.  [About this guide](#section-12)

## Who this guide is for

This guide is written for chairs, non-executive directors, managing directors and board committee members who are accountable for how an organisation handles cyber risk, without necessarily holding a technical background. It sets out what the board owns, what it should delegate, and what good evidence looks like.

## What the board is actually responsible for

A board is not responsible for running security. It is responsible for whether cyber risk is being managed in a way that is proportionate to the business, and for being able to demonstrate that judgement was applied. In UK listed and large private companies, this sits inside the wider duty to maintain a sound system of internal control and risk management, as set out in the UK Corporate Governance Code.

-   Setting risk appetite for disruption, data loss and third-party exposure.
-   Confirming that cyber risk is treated as a business risk with named executive ownership.
-   Assuring that continuity and recovery plans exist, are funded and have been tested.
-   Understanding the material scenarios: extended outage, data theft, supplier failure.
-   Ensuring the organisation can meet its notification duties to regulators, customers and insurers.

## The decisions you own, and what you can delegate

Directors get into trouble when they delegate the judgement as well as the work.

-   **Own** risk appetite, investment trade-offs, crisis decision-making authority, and whether the residual risk being carried is acceptable.
-   **Own** the decision on whether the organisation would pay a ransom, taken calmly and in advance.
-   **Delegate** control selection, architecture, tooling and day-to-day operations to the executive.
-   **Delegate** technical assurance, but require the results to reach the board in plain language.

## The risks a director should understand

-   **Operational disruption.** The cost is usually the outage, not the data. Model the loss per day.
-   **Recovery dependency.** Backups that depend on the same identity platform as the live estate can be reached by the same attacker.
-   **Third-party exposure.** Suppliers and maintenance access are a common route in, and their incidents become your incident.
-   **Data exposure.** Personal data losses attract regulatory attention under UK GDPR, and the reputational cost often exceeds the fine.
-   **Concentration.** A single cloud tenancy or a single administrator group can be a single point of failure for the whole business.

## The questions to ask management

1.  Which processes must survive, and how long can each be down before the damage is material?
2.  If our identity platform were compromised tonight, what would we still be able to restore, and from where?
3.  When did we last restore a critical system from scratch, and how long did it take?
4.  Which suppliers hold live access into our systems, and who reviews that access?
5.  What would we do in the first four hours, and who is authorised to disconnect systems?
6.  What are we deliberately choosing not to protect, and does the board accept that?

## The evidence to expect

Ask for artefacts, not assurances.

-   A tested recovery plan with dates, durations and named owners.
-   Results of the most recent restore test, including what failed.
-   A short register of critical suppliers and their access rights.
-   An incident response plan that works when email and the intranet are unavailable.
-   Independent assurance, whether internal audit, an accreditation such as ISO/IEC 27001, or an external review.

## What good looks like from the board seat

-   Cyber risk appears in the same register, and the same language, as every other principal risk.
-   Recovery times are stated as business outcomes, not technical metrics.
-   The organisation has rehearsed a crisis at board level within the last twelve months.
-   Reporting shows trend and exception, not volume of blocked attacks.

## What happens when preventative controls fail

Prevention buys time. It does not remove the need to answer a simple question: if an attacker holds your identity platform and your management console tonight, what still works tomorrow morning? Most organisations discover that their backup catalogue, their recovery credentials and their runbooks all depend on the systems that have just been taken. That is the dependency worth removing first.

No control removes the possibility of a serious incident. The realistic goal is a smaller blast radius, a recovery path that does not depend on the compromised estate, and evidence that both were tested.

## Deciding what you actually need

The board question is not which product to buy. It is whether the organisation can still operate and recover when its normal controls have been defeated, and whether the cost of closing that gap is proportionate. Firevault is the company. It provides three distinct things, and the honest answer is often that you need one of them rather than all of them.

-   **[Offline Secure Storage®](/offline-secure-storage)** holds a defined set of critical records and clean recovery data physically disconnected from the live estate. It is a protected set, not a replacement for your backup infrastructure.
-   **[Control Modules](/control)** are a suite of nine purpose-built tools and techniques that give you physical control over the paths into and across your estate. Introduce only the modules that map to the risk you are treating.
-   **[Control Blueprints](/control-blueprints)** are proven combinations of those modules assembled for a named outcome, such as containing a live breach or governing third-party access.

If your existing controls already deliver a tested recovery path that survives the compromise of your identity and management planes, and you can evidence it, you may not need any of this. Test that assumption before you buy anything. If you are unsure which of the three applies, the [Firevault Concierge](/find-my-oss) walks through the question set without a sales conversation.

## The Control Blueprints most relevant to this role

A board does not need to specify controls, but it helps to know what the executive is choosing between. Control by Firevault is a set of nine Control Modules, grouped into the FIRE layer (Firebreak, Isolate, Relay, Execute) and the VAULT layer (Validate, Archive, Unlink, Lock, Transfer). Seven Control Blueprints combine those modules for a specific outcome. You do not need all nine modules, and most organisations start with one blueprint.

-   **[CP-01 Stop Kill-Chain Ransomware](/control-blueprints/cp-01)** uses Firebreak, Isolate, Execute. Read the [stop kill-chain ransomware guide](/learn/guides/stopping-kill-chain-ransomware-control-blueprint).
-   **[CP-02 Contain Active Breaches](/control-blueprints/cp-02)** uses Firebreak, Isolate, Execute. Read the [contain active breaches guide](/learn/guides/containing-active-breaches-control-blueprint).
-   **[CP-03 Control Third-Party Access](/control-blueprints/cp-03)** uses Validate, Relay, Lock. Read the [control third-party access guide](/learn/guides/controlling-third-party-access-control-blueprint).
-   **[CP-05 Protect Critical Infrastructure](/control-blueprints/cp-05)** uses Firebreak, Isolate, Relay, Execute. Read the [protect critical infrastructure guide](/learn/guides/protecting-critical-infrastructure-control-blueprint).
-   **[CP-06 Prove Compliance Through Control](/control-blueprints/cp-06)** uses Validate, Lock, Archive. Read the [prove compliance through control guide](/learn/guides/proving-compliance-through-control-blueprint).

The full set is on the [Control overview](/control) and the [Control Blueprints index](/control-blueprints).

## Where to go next

Finance leaders should read the [CFO guide to cyber risk and financial resilience](/learn/guides/cfo-guide-cyber-risk-financial-resilience). For the assurance and evidence view, see the [cyber risk and compliance guide](/learn/guides/cyber-risk-and-compliance-guide). The [leaders playbook](/playbook/leaders) covers the crisis rehearsal in more depth.

## Sources and further reading

-   [NCSC Cyber Security Board Toolkit](https://www.ncsc.gov.uk/collection/board-toolkit)
-   [FRC UK Corporate Governance Code](https://www.frc.org.uk/library/standards-and-codes/uk-corporate-governance-code/)
-   [ICO guidance for organisations](https://ico.org.uk/for-organisations/)
-   [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework)
-   [NIS2 and the UK equivalent regime explained](/solutions/oss/compliance/nis2)

## About this guide

**Author** Mark Fermor, Firevault. **Reviewed by** Firevault advisory board. **Last reviewed** 28 August 2026.

This guide draws on primary regulatory and technical sources together with Firevault's own field work on physical isolation and offline recovery. It is guidance, not legal advice. Where a legal or regulatory duty is in question, take advice on your own circumstances.

Other guides in this series are listed on the [role guide hub](/learn/guides/by-role).

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Control by Firevault governs the physical paths into your systems.**[Explore Control →](/solutions/control)

Keep a clean copy**Offline Secure Storage® holds a copy no attacker can reach.**[Why #OSS →](/why-oss)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### Security Architecture Guide: Physical Isolation, Segmentation and Cyber Resilience
    
    The deepest guide in the series: trust boundaries, attack paths, failure domains, Layer 1 isolation versus logical segmentation, control and management planes, Zero Trust, the Purdue Model and IEC 62443.
    
    Read guide ](/learn/guides/security-architecture-guide)
-   [
    
    ### Cyber Risk & Compliance Guide: Controls, Evidence and Resilience for GRC Leaders
    
    How risk and compliance leaders can move from control existence to control effectiveness: risk treatment, evidence, third-party assurance, exceptions and remediation that survive audit.
    
    Read guide ](/learn/guides/cyber-risk-and-compliance-guide)
-   [
    
    ### IT Director's Guide to Ransomware Recovery, Backups and Infrastructure Resilience
    
    The practical recovery guide: immutable versus offline, Active Directory rebuild, management plane compromise, clean recovery environments, restore testing and realistic RTO and RPO.
    
    Read guide ](/learn/guides/it-director-guide-ransomware-recovery)
-   [
    
    ### CISO Guide to Cyber Resilience: Risk, Recovery and Physical Control
    
    Threat modelling, attack paths, blast radius and recovery from the CISO seat, and an honest read of where Offline Secure Storage, Control Modules and Control Blueprints do and do not help.
    
    Read guide ](/learn/guides/ciso-guide-cyber-resilience)

Related Reading

## You may also find these useful

[

![Protecting Students, Peers and Partners: A Practical Education Data Briefing](/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg)

Guides 

### Protecting Students, Peers and Partners: A Practical Education Data Briefing

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

29 Jul 2026 13 min 







](/news/guide-safeguarding-education-data)[

![Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye](/__l5e/assets-v1/084c38b8-253b-4cc2-9056-c78a2fbd36c3/urgent-warning-triangle-20260714-2x.jpg)

Guides 

### Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye

Practical steps for serving and former politicians, councillors, campaigners, journalists, executives, broadcasters and anyone in the public eye, covering email security, device hygiene, threat handling and offline secure storage.

14 Jul 2026 22 min 







](/news/urgent-guide-protecting-personal-data-high-profile-public-eye)[

![500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fcontrolled-access-buyers-guide.jpg)

Guides 

### 500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide

In April 2026, approved researchers exfiltrated the health records, genetic data, and medical histories of 500,000 UK Biobank volunteers through authorised access channels, then listed the data for sale on Alibaba. The breach was not caused by a hack. It was caused by a model that assumes licence agreements can prevent data theft. This guide covers why that model fails and what physical controls replace it.

23 Apr 2026 18 min 







](/news/controlled-access-buyers-guide-offline-secure-storage)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Control by Firevault governs the physical paths into your systems.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up