Effective Communication Strategies for Cybersecurity Leaders: Understanding the Preferences of Boards

Paul Connelly, former CISO turned board advisor, independent director and mentor, finds many CISOs focus too heavily on metrics while the board is looking for more strategic insights. The board doesn’t need to know the results of your phishing test, says Connelly. Boards are focused on risks the organization faces, strategies to address these risks, progress updates, obstacles to success, and whether they’re tackling the right things.

“I coach CISOs to study their board — read their bios, understand their background, and understand the fiduciary responsibility of a board,” he says. The goal is to understand the make-up of the board and their priorities and channel their metrics into risk and threat analysis for the business.

Using this information, CISOs can develop a story about their program aligned with the business. “That high-level story — supported by measurements — is what boards want to hear, not a bunch of metrics on malicious emails and critical patches or scary Chicken Little-type of threats,” Connelly tells CSO.

Paul Connelly, a former Chief Information Security Officer (CISO) who now serves as a board advisor, independent director, and mentor, believes that many CISOs place too much emphasis on metrics rather than providing strategic insights to the board. According to Connelly, the board is more interested in understanding the risks facing the organization, the strategies in place to address these risks, progress updates, obstacles to success, and whether the organization is focusing on the right priorities.

Connelly advises CISOs to familiarize themselves with the board members by reading their bios, understanding their backgrounds, and recognizing the fiduciary responsibilities of a board. By doing so, CISOs can tailor their metrics to provide valuable risk and threat analysis for the business.

Instead of bombarding the board with technical metrics such as phishing test results or patch updates, Connelly suggests that CISOs should focus on developing a high-level narrative about their security program that aligns with the overall business objectives. This narrative should be supported by relevant measurements that demonstrate the effectiveness of the security program.

In summary, CISOs should aim to communicate a compelling story about their security program to the board, emphasizing how it aligns with the organization's strategic goals and priorities. By providing strategic insights rather than just metrics, CISOs can better engage with the board and demonstrate the value of their security efforts.

Survey Reveals Decrease in Cyber Incidents Throughout the UK, According to TechRound

The Department for Science, Innovation & Technology and the Home Office released the Cyber Security Breaches Survey 2025. They gathered responses between August and December 2024 from businesses and charities of different sizes. Their questionnaire covered phishing events, malicious software, and other unwanted digital activities.

Results show that 43% of private enterprises and 30% of charitable bodies had one or more breaches or attacks over the past 12 months. This finding is lower than the 50% mark for private enterprises the previous year. Officials traced the drop to fewer small and micro operations flagging phishing attempts, while medium and large ones showed limited change.

Organisations taking part in the interviews cited multiple factors for changes in reporting, and this includes stronger guidance on scam awareness and greater caution when opening emails. Staff training is said to have been introduced to block potential intrusions at an earlier stage, which might have helped to keep unwanted incidents away.

The report also calculates the average financial losses for the worst breach. That cost, based on surveys, is around £1,600 for each business and £3,240 for charities. Analysts at DSIT and the Home Office note that overall expense can climb higher once extra staffing and outside technical help are taken into account.

How Are Different Groups Affected?

DSIT organises charities according to annual income. Low-income ones are around 24%, mid-level hit 42%, and high-income reach 64%. A similar pattern can be seen for businesses, with higher revenues matching higher incident rates.

In interviews, staff from smaller companies mention budget limits hamper training and software updates. Meanwhile, large corporations often fund dedicated security teams who run penetration tests and invest in detection tools. That divide in resources can shape outcomes.

More from News

Medium operations confirm frequent phishing messages, as well as sporadic ransomware attempts. A fraction admit paying ransoms, though law enforcement advises against that. Health and social care organisations record heightened vigilance because patient data must stay protected.

Micro businesses report less sophisticated strikes, but staff sometimes lack technical knowledge to apply consistent safety measures. Numerous depend on outside IT firms for basic support. According to the survey, these external contracts help block plenty of threats early.

Could Phishing And New Laws Change The Story?

Phishing stays the top culprit in reported breaches, hitting 85% of affected firms and 86% of charities. Attackers send fraudulent emails or direct users to cloned login pages. This tactic leads to credential theft or malware installs.

Training is reported as a strong preventive measure, and staff spots odd phrasing, suspicious links, or from-address mismatches. However, artificial voice systems and deepfake images can trick recipients, creating confusion and draining time.

DSIT data shows a smaller breach might run under £1,000, but extensive intrusions climb far higher. Extra staffing or outside consultants add to the bill. Meanwhile, charities with tight budgets mention painful trade-offs.

Another theme of the survey involves the planned Cyber Security and Resilience Bill, which intends to tighten obligations. Campaigners state the Computer Misuse Act from 1990 needs an overhaul, since it predates cloud tech. They propose clearing a path for ethical testing.

DSIT continues to advise routine staff training, data backups, password rules, and malware protection. Officials confirm around 612,000 UK businesses and 61,000 charities faced a cyber intrusion in the last year.

The Cyber Security Breaches Survey 2025, released by the Department for Science, Innovation & Technology and the Home Office, collected responses from businesses and charities of various sizes between August and December 2024. The survey focused on phishing events, malicious software, and other unwanted digital activities.

Results indicated that 43% of private enterprises and 30% of charitable bodies experienced one or more breaches or attacks in the past year. This was a decrease from the previous year's 50% mark for private enterprises. The drop was attributed to fewer small and micro businesses reporting phishing attempts, while medium and large organizations showed limited change.

Factors contributing to changes in reporting included stronger guidance on scam awareness, increased caution when opening emails, and staff training to prevent intrusions at an early stage. The average financial losses for the worst breach were estimated to be around £1,600 for businesses and £3,240 for charities.

Different groups were affected differently, with higher incident rates correlating with higher revenues for both charities and businesses. Smaller companies mentioned budget constraints affecting training and software updates, while larger corporations invested in dedicated security teams and detection tools.

Phishing remained the top culprit in reported breaches, affecting 85% of affected firms and 86% of charities. Training was identified as a key preventive measure, but attackers using artificial voice systems and deepfake images could still trick recipients.

The survey also highlighted the planned Cyber Security and Resilience Bill, aimed at tightening obligations and updating laws to address modern cybersecurity challenges. DSIT recommended routine staff training, data backups, password rules, and malware protection to mitigate cyber threats.

Survey Reveals Decrease in Cyber Incidents Throughout the UK, According to TechRound

The Department for Science, Innovation & Technology and the Home Office released the Cyber Security Breaches Survey 2025. They gathered responses between August and December 2024 from businesses and charities of different sizes. Their questionnaire covered phishing events, malicious software, and other unwanted digital activities.

Results show that 43% of private enterprises and 30% of charitable bodies had one or more breaches or attacks over the past 12 months. This finding is lower than the 50% mark for private enterprises the previous year. Officials traced the drop to fewer small and micro operations flagging phishing attempts, while medium and large ones showed limited change.

Organisations taking part in the interviews cited multiple factors for changes in reporting, and this includes stronger guidance on scam awareness and greater caution when opening emails. Staff training is said to have been introduced to block potential intrusions at an earlier stage, which might have helped to keep unwanted incidents away.

The report also calculates the average financial losses for the worst breach. That cost, based on surveys, is around £1,600 for each business and £3,240 for charities. Analysts at DSIT and the Home Office note that overall expense can climb higher once extra staffing and outside technical help are taken into account.

How Are Different Groups Affected?

DSIT organises charities according to annual income. Low-income ones are around 24%, mid-level hit 42%, and high-income reach 64%. A similar pattern can be seen for businesses, with higher revenues matching higher incident rates.

In interviews, staff from smaller companies mention budget limits hamper training and software updates. Meanwhile, large corporations often fund dedicated security teams who run penetration tests and invest in detection tools. That divide in resources can shape outcomes.

More from News

Medium operations confirm frequent phishing messages, as well as sporadic ransomware attempts. A fraction admit paying ransoms, though law enforcement advises against that. Health and social care organisations record heightened vigilance because patient data must stay protected.

Micro businesses report less sophisticated strikes, but staff sometimes lack technical knowledge to apply consistent safety measures. Numerous depend on outside IT firms for basic support. According to the survey, these external contracts help block plenty of threats early.

Could Phishing And New Laws Change The Story?

Phishing stays the top culprit in reported breaches, hitting 85% of affected firms and 86% of charities. Attackers send fraudulent emails or direct users to cloned login pages. This tactic leads to credential theft or malware installs.

Training is reported as a strong preventive measure, and staff spots odd phrasing, suspicious links, or from-address mismatches. However, artificial voice systems and deepfake images can trick recipients, creating confusion and draining time.

DSIT data shows a smaller breach might run under £1,000, but extensive intrusions climb far higher. Extra staffing or outside consultants add to the bill. Meanwhile, charities with tight budgets mention painful trade-offs.

Another theme of the survey involves the planned Cyber Security and Resilience Bill, which intends to tighten obligations. Campaigners state the Computer Misuse Act from 1990 needs an overhaul, since it predates cloud tech. They propose clearing a path for ethical testing.

DSIT continues to advise routine staff training, data backups, password rules, and malware protection. Officials confirm around 612,000 UK businesses and 61,000 charities faced a cyber intrusion in the last year.

The Cyber Security Breaches Survey 2025, released by the Department for Science, Innovation & Technology and the Home Office, collected responses from businesses and charities of various sizes between August and December 2024. The survey focused on phishing events, malicious software, and other unwanted digital activities.

Results indicated that 43% of private enterprises and 30% of charitable bodies experienced one or more breaches or attacks in the past year, a decrease from the previous year's 50% mark for private enterprises. Factors contributing to this decline included improved scam awareness, cautious email practices, and staff training to prevent intrusions.

The average financial losses for the worst breach were estimated at around £1,600 for businesses and £3,240 for charities. Additional expenses such as staffing and technical support can further increase the overall cost.

Different groups were affected differently, with higher incident rates correlating with higher revenues for both charities and businesses. Smaller companies often face budget constraints that limit training and software updates, while larger corporations invest in dedicated security teams and detection tools.

Phishing remained the top cause of breaches, affecting 85% of affected firms and 86% of charities. Training was identified as a key preventive measure, but attackers continue to use sophisticated tactics such as artificial voice systems and deepfake images to deceive recipients.

The survey also highlighted the proposed Cyber Security and Resilience Bill, aimed at strengthening obligations and updating outdated laws like the Computer Misuse Act of 1990. Routine staff training, data backups, password rules, and malware protection were recommended by officials to mitigate cyber threats.

Survey Results: Decrease in Cyber Incidents Reported Across the UK, According to TechRound

The Department for Science, Innovation & Technology and the Home Office released the Cyber Security Breaches Survey 2025. They gathered responses between August and December 2024 from businesses and charities of different sizes. Their questionnaire covered phishing events, malicious software, and other unwanted digital activities.

Results show that 43% of private enterprises and 30% of charitable bodies had one or more breaches or attacks over the past 12 months. This finding is lower than the 50% mark for private enterprises the previous year. Officials traced the drop to fewer small and micro operations flagging phishing attempts, while medium and large ones showed limited change.

Organisations taking part in the interviews cited multiple factors for changes in reporting, and this includes stronger guidance on scam awareness and greater caution when opening emails. Staff training is said to have been introduced to block potential intrusions at an earlier stage, which might have helped to keep unwanted incidents away.

The report also calculates the average financial losses for the worst breach. That cost, based on surveys, is around £1,600 for each business and £3,240 for charities. Analysts at DSIT and the Home Office note that overall expense can climb higher once extra staffing and outside technical help are taken into account.

How Are Different Groups Affected?

DSIT organises charities according to annual income. Low-income ones are around 24%, mid-level hit 42%, and high-income reach 64%. A similar pattern can be seen for businesses, with higher revenues matching higher incident rates.

In interviews, staff from smaller companies mention budget limits hamper training and software updates. Meanwhile, large corporations often fund dedicated security teams who run penetration tests and invest in detection tools. That divide in resources can shape outcomes.

More from News

Medium operations confirm frequent phishing messages, as well as sporadic ransomware attempts. A fraction admit paying ransoms, though law enforcement advises against that. Health and social care organisations record heightened vigilance because patient data must stay protected.

Micro businesses report less sophisticated strikes, but staff sometimes lack technical knowledge to apply consistent safety measures. Numerous depend on outside IT firms for basic support. According to the survey, these external contracts help block plenty of threats early.

Could Phishing And New Laws Change The Story?

Phishing stays the top culprit in reported breaches, hitting 85% of affected firms and 86% of charities. Attackers send fraudulent emails or direct users to cloned login pages. This tactic leads to credential theft or malware installs.

Training is reported as a strong preventive measure, and staff spots odd phrasing, suspicious links, or from-address mismatches. However, artificial voice systems and deepfake images can trick recipients, creating confusion and draining time.

DSIT data shows a smaller breach might run under £1,000, but extensive intrusions climb far higher. Extra staffing or outside consultants add to the bill. Meanwhile, charities with tight budgets mention painful trade-offs.

Another theme of the survey involves the planned Cyber Security and Resilience Bill, which intends to tighten obligations. Campaigners state the Computer Misuse Act from 1990 needs an overhaul, since it predates cloud tech. They propose clearing a path for ethical testing.

DSIT continues to advise routine staff training, data backups, password rules, and malware protection. Officials confirm around 612,000 UK businesses and 61,000 charities faced a cyber intrusion in the last year.

The Cyber Security Breaches Survey 2025, released by the Department for Science, Innovation & Technology and the Home Office, gathered responses from businesses and charities between August and December 2024. The survey focused on phishing events, malicious software, and other digital activities.

Results showed that 43% of private enterprises and 30% of charitable bodies experienced breaches or attacks in the past year, a decrease from the previous year. Factors contributing to this decline included stronger scam awareness guidance, staff training, and caution when opening emails.

The average financial losses for the worst breach were estimated to be around £1,600 for businesses and £3,240 for charities. DSIT categorized charities based on annual income, with higher-income organizations experiencing higher incident rates.

Smaller companies mentioned budget constraints affecting training and software updates, while larger corporations invested in dedicated security teams and detection tools. Medium operations reported frequent phishing messages and ransomware attempts, while health and social care organizations emphasized the importance of protecting patient data.

Phishing remained the top cause of breaches, affecting a high percentage of firms and charities. Training was identified as a key preventive measure, although attackers continue to use sophisticated tactics like artificial voice systems and deepfake images.

The survey also highlighted the upcoming Cyber Security and Resilience Bill, aimed at strengthening obligations and updating outdated laws. DSIT recommended routine staff training, data backups, password rules, and malware protection to mitigate cyber risks.

In 2024, a significant number of UK businesses experienced cybersecurity breaches, affecting over 40% of companies.

A total of 43% of UK businesses and 30% of charities experienced a cyber breach or attack in the past year, according to the newly published Cyber Security Breaches Survey 2025.

The report, published today, was commissioned by the UK Department for Science, Innovation and Technology (DSIT) and the Home Office.

While breach statistics mark a slight decline from 2024, they continue to reflect the significant cybersecurity challenges facing UK organizations.

Phishing remains the top threat, with 85% of affected businesses and 86% of charities identifying it as the cause of attacks. Email remains the primary entry point for these scams, often involving social engineering tactics to steal personal and financial data.

“Phishing continues to plague UK businesses, so it comes as no surprise that this remains the number one threat in this year’s report,” said Matt Cooke, cybersecurity strategist at Proofpoint.

“Cybercriminals target people with social engineering attempts via phishing emails, tricking people into doing what they want, mainly for financial gain.”

Read more on how phishing continues to dominate cyber threat trends: 752,000 Browser Phishing Attacks Mark 140% Increase YoY

Experts also warned that cybercriminals are leveraging artificial intelligence to increase the scale and believability of attacks.

AI tools can help craft realistic phishing emails and fake images and even simulate phone calls, which make it more challenging for individuals to detect.

This technological edge allows attackers to operate more efficiently and on a larger scale.

Decline in Executive Oversight Raises Concern

Another key concern highlighted in the report is the decline in board-level responsibility for cyber-resilience.

Fewer senior executives are taking ownership of cybersecurity strategy, leaving gaps in organizational response to increasingly sophisticated attacks.

The financial impact is also notable:

Calls for Legal Reform Grow Louder

Simon Whittaker, a representative of the CyberUp Campaign, emphasized the urgent need for legal reform.

“Today’s results paint a stark picture,” he said. “The Computer Misuse Act 1990, drafted in a different era, is no longer fit for purpose. It risks criminalizing the very professionals we rely on to detect, defend against and prevent these attacks.”

Although the survey shows a stable level of organizations seeking external cybersecurity guidance – 42% of businesses and 37% of charities – large businesses reported a noticeable drop to 51%, down from 67% in 2024.

The survey follows the recent update to the Cyber Security and Resilience Bill and the government’s closure of its consultation on ransomware, signaling an increased focus on strengthening national cyber-defense strategies.

However, without modern legal support and increased executive accountability, experts have warned the UK’s digital infrastructure remains under pressure.

The Cyber Security Breaches Survey 2025, commissioned by the UK Department for Science, Innovation and Technology (DSIT) and the Home Office, reveals that 43% of UK businesses and 30% of charities experienced a cyber breach or attack in the past year. While these statistics show a slight decline from the previous year, they still highlight the significant cybersecurity challenges facing organizations in the UK.

Phishing remains the top threat, with 85% of affected businesses and 86% of charities attributing attacks to this method. Cybercriminals use social engineering tactics through phishing emails to steal personal and financial data. Experts warn that attackers are increasingly leveraging artificial intelligence to enhance the scale and believability of their attacks.

The report also raises concerns about the decline in board-level responsibility for cyber-resilience, with fewer senior executives taking ownership of cybersecurity strategy. This lack of oversight leaves organizations vulnerable to sophisticated attacks, resulting in financial losses. The average cost of a cyber breach per business is £1600, while for charities it is £3240. The most disruptive breaches can cost up to £3550 for businesses and £8690 for charities.

Calls for legal reform are growing louder, with experts emphasizing the need to update the Computer Misuse Act 1990 to address modern cyber threats. Despite stable levels of organizations seeking external cybersecurity guidance, there has been a noticeable drop in large businesses seeking such support.

The survey comes in the wake of updates to the Cyber Security and Resilience Bill and the government's consultation on ransomware, indicating a renewed focus on strengthening national cyber-defense strategies. However, without modern legal support and increased executive accountability, experts warn that the UK's digital infrastructure remains under pressure.

New Cyber Governance Code Released by UK Government for Business Leaders

Advice aimed at medium and large businesses

The UK government is urging business leaders to adopt a new cyber-Code of Practice to reinforce their cyber defences and support long-term economic growth.

The new code was published on Tuesday 8 April by the Department for Science, Innovation and Technology (DSIT) alongside the National Cyber Security Centre (NCSC), the code outlines clear guidance for directors and board members to take greater ownership of cyber risks. It is designed to be the first point of reference for senior leaders and forms part of the government’s broader support for cyber governance.

In a press release, Cyber Security Minister Feryal Clark emphasised the stakes involved, stating, “A successful cyber-attack doesn’t just have the potential to grind operations to a halt – it could drain millions from the bottom line.”

She adds that this new Code of Practice is part of how the government intends to stand by businesses and believes it will drive the type of economic growth fundamental to achieving the government’s Plan for Change.

What’s in the new cyber governance Code of Practice?

The new guideline is primarily for boards and directors in medium and large organisations across the public and private sectors and outlines five key areas where they should act.

One of its tenets is to embed cyber risks into enterprise-wide risk management, including assessing supply chain exposures. Directors are expected to set a clear cyber strategy, grounded in the organisation’s threat landscape and aligned with business goals.

It places a strong emphasis on creating a cyber-aware culture through regular training and clear staff responsibilities. Boards should ensure that incident response and recovery plans are in place, tested, and continuously improved. The Code also highlights the need for robust oversight — defining roles, assigning accountability at the board level, and monitoring cyber performance to strengthen overall resilience.

Also included in the announcement are practical tools such as online training modules and a detailed Board Toolkit. These resources aim to equip directors with the knowledge needed to govern cyber risks effectively. Meanwhile, the government urges smaller businesses to utilise complementary resources like the NCSC’s Small Business Guide.

While the Code of Practice is voluntary, the government has signalled more formal action ahead. Last week, Secretary of State for Science, Innovation and Technology Peter Kyle said that the forthcoming Cyber Security and Resilience Bill will help monitor uptake and consider a firmer stance, including £100,000 daily fines for non-compliance with cyber security directives from the government.

Want to know more? Computing 's Cybersecurity Festival returns to London in May, where senior IT decision makers can learn about modern challenges, compare strategies with peers, and source solutions. Click here to register for free.

The UK government is encouraging medium and large businesses to adopt a new cyber-Code of Practice to enhance their cyber defenses and support long-term economic growth. Published by the Department for Science, Innovation and Technology (DSIT) alongside the National Cyber Security Centre (NCSC), the code provides clear guidance for directors and board members to take greater ownership of cyber risks. It is designed to be a key reference point for senior leaders and is part of the government's broader support for cyber governance.

In a press release, Cyber Security Minister Feryal Clark emphasized the importance of the new code, stating that a successful cyber-attack could have significant financial implications for businesses. The government believes that this Code of Practice will drive economic growth essential for achieving the government's Plan for Change.

The new cyber governance Code of Practice is aimed at boards and directors in medium and large organizations across the public and private sectors. It outlines five key areas where action should be taken, including embedding cyber risks into enterprise-wide risk management, setting a clear cyber strategy aligned with business goals, creating a cyber-aware culture through training, ensuring incident response and recovery plans are in place, and providing robust oversight at the board level.

Practical tools such as online training modules and a detailed Board Toolkit are included in the announcement to help directors govern cyber risks effectively. The government also encourages smaller businesses to utilize resources like the NCSC's Small Business Guide.

While the Code of Practice is voluntary, the government has indicated that more formal action may be taken in the future. The forthcoming Cyber Security and Resilience Bill could include fines for non-compliance with cyber security directives from the government.

For more information, Computing's Cybersecurity Festival in London in May provides an opportunity for senior IT decision makers to learn about modern challenges, share strategies with peers, and find solutions. Registration for the event is free.

New Cyber Governance Code Released by UK Government for Business Leaders

Advice aimed at medium and large businesses

The UK government is urging business leaders to adopt a new cyber-Code of Practice to reinforce their cyber defences and support long-term economic growth.

The new code was published on Tuesday 8 April by the Department for Science, Innovation and Technology (DSIT) alongside the National Cyber Security Centre (NCSC), the code outlines clear guidance for directors and board members to take greater ownership of cyber risks. It is designed to be the first point of reference for senior leaders and forms part of the government’s broader support for cyber governance.

In a press release, Cyber Security Minister Feryal Clark emphasised the stakes involved, stating, “A successful cyber-attack doesn’t just have the potential to grind operations to a halt – it could drain millions from the bottom line.”

She adds that this new Code of Practice is part of how the government intends to stand by businesses and believes it will drive the type of economic growth fundamental to achieving the government’s Plan for Change.

What’s in the new cyber governance Code of Practice?

The new guideline is primarily for boards and directors in medium and large organisations across the public and private sectors and outlines five key areas where they should act.

One of its tenets is to embed cyber risks into enterprise-wide risk management, including assessing supply chain exposures. Directors are expected to set a clear cyber strategy, grounded in the organisation’s threat landscape and aligned with business goals.

It places a strong emphasis on creating a cyber-aware culture through regular training and clear staff responsibilities. Boards should ensure that incident response and recovery plans are in place, tested, and continuously improved. The Code also highlights the need for robust oversight — defining roles, assigning accountability at the board level, and monitoring cyber performance to strengthen overall resilience.

Also included in the announcement are practical tools such as online training modules and a detailed Board Toolkit. These resources aim to equip directors with the knowledge needed to govern cyber risks effectively. Meanwhile, the government urges smaller businesses to utilise complementary resources like the NCSC’s Small Business Guide.

While the Code of Practice is voluntary, the government has signalled more formal action ahead. Last week, Secretary of State for Science, Innovation and Technology Peter Kyle said that the forthcoming Cyber Security and Resilience Bill will help monitor uptake and consider a firmer stance, including £100,000 daily fines for non-compliance with cyber security directives from the government.

Want to know more? Computing 's Cybersecurity Festival returns to London in May, where senior IT decision makers can learn about modern challenges, compare strategies with peers, and source solutions. Click here to register for free.

The UK government is encouraging medium and large businesses to adopt a new cyber-Code of Practice to enhance their cyber defenses and support long-term economic growth. Published by the Department for Science, Innovation and Technology (DSIT) alongside the National Cyber Security Centre (NCSC), the code provides clear guidance for directors and board members to take greater ownership of cyber risks.

In a press release, Cyber Security Minister Feryal Clark emphasized the importance of the new code, stating that a successful cyber-attack could have significant financial implications for businesses. The government believes that this Code of Practice will drive economic growth essential for achieving the government’s Plan for Change.

The new cyber governance Code of Practice is designed for boards and directors in medium and large organizations across the public and private sectors. It outlines five key areas where they should take action, including embedding cyber risks into enterprise-wide risk management, setting a clear cyber strategy, creating a cyber-aware culture, ensuring incident response and recovery plans are in place, and providing robust oversight.

Practical tools such as online training modules and a detailed Board Toolkit are included in the announcement to help directors govern cyber risks effectively. While the Code of Practice is voluntary, the government has hinted at more formal action in the future, including potential fines for non-compliance with cyber security directives.

For those interested in learning more about cybersecurity challenges and solutions, Computing's Cybersecurity Festival in London in May provides an opportunity for senior IT decision-makers to network, share strategies, and access resources. Registration for the event is free.

New Cyber Governance Code Released by UK Government for Business Leaders

Advice aimed at medium and large businesses

The UK government is urging business leaders to adopt a new cyber-Code of Practice to reinforce their cyber defences and support long-term economic growth.

The new code was published on Tuesday 8 April by the Department for Science, Innovation and Technology (DSIT) alongside the National Cyber Security Centre (NCSC), the code outlines clear guidance for directors and board members to take greater ownership of cyber risks. It is designed to be the first point of reference for senior leaders and forms part of the government’s broader support for cyber governance.

In a press release, Cyber Security Minister Feryal Clark emphasised the stakes involved, stating, “A successful cyber-attack doesn’t just have the potential to grind operations to a halt – it could drain millions from the bottom line.”

She adds that this new Code of Practice is part of how the government intends to stand by businesses and believes it will drive the type of economic growth fundamental to achieving the government’s Plan for Change.

What’s in the new cyber governance Code of Practice?

The new guideline is primarily for boards and directors in medium and large organisations across the public and private sectors and outlines five key areas where they should act.

One of its tenets is to embed cyber risks into enterprise-wide risk management, including assessing supply chain exposures. Directors are expected to set a clear cyber strategy, grounded in the organisation’s threat landscape and aligned with business goals.

It places a strong emphasis on creating a cyber-aware culture through regular training and clear staff responsibilities. Boards should ensure that incident response and recovery plans are in place, tested, and continuously improved. The Code also highlights the need for robust oversight — defining roles, assigning accountability at the board level, and monitoring cyber performance to strengthen overall resilience.

Also included in the announcement are practical tools such as online training modules and a detailed Board Toolkit. These resources aim to equip directors with the knowledge needed to govern cyber risks effectively. Meanwhile, the government urges smaller businesses to utilise complementary resources like the NCSC’s Small Business Guide.

While the Code of Practice is voluntary, the government has signalled more formal action ahead. Last week, Secretary of State for Science, Innovation and Technology Peter Kyle said that the forthcoming Cyber Security and Resilience Bill will help monitor uptake and consider a firmer stance, including £100,000 daily fines for non-compliance with cyber security directives from the government.

Want to know more? Computing 's Cybersecurity Festival returns to London in May, where senior IT decision makers can learn about modern challenges, compare strategies with peers, and source solutions. Click here to register for free.

The UK government is advising medium and large businesses to adopt a new cyber-Code of Practice to strengthen their cyber defenses and support long-term economic growth. Published by the Department for Science, Innovation and Technology (DSIT) alongside the National Cyber Security Centre (NCSC), the code provides clear guidance for directors and board members to take greater ownership of cyber risks. This initiative is part of the government's broader support for cyber governance.

In a press release, Cyber Security Minister Feryal Clark emphasized the importance of this new code, stating that a successful cyber-attack could have significant financial implications for businesses. The government believes that this Code of Practice will drive economic growth essential for achieving the government's Plan for Change.

The new cyber governance Code of Practice is aimed at boards and directors in medium and large organizations in both the public and private sectors. It outlines five key areas where action should be taken, including embedding cyber risks into enterprise-wide risk management, setting a clear cyber strategy aligned with business goals, creating a cyber-aware culture through training, establishing incident response and recovery plans, and ensuring robust oversight at the board level.

The government has also provided practical tools such as online training modules and a Board Toolkit to help directors govern cyber risks effectively. While the Code of Practice is voluntary, the government has hinted at more formal action in the future, including potential fines for non-compliance with cyber security directives.

For those interested in learning more about cybersecurity, Computing's Cybersecurity Festival in London in May offers an opportunity for senior IT decision makers to address modern challenges, share strategies with peers, and find solutions. Registration for the event is free.

Major Cybersecurity Breach Impacts OCC

occ seal

Andrew Harrer/Bloomberg

The Office of the Comptroller of the Currency experienced a significant email system security breach, according to the agency, which notified Congress of the hack Tuesday. 

According to an agency release, a high-level user account with administrative privileges over the OCC's email system was breached, revealing highly sensitive information about one of the banks regulated by the OCC. The OCC regulates nationally chartered banks, which include some of the largest and most systemically important firms in the country.

"The OCC discovered that the unauthorized access to a number of its executives' and employees' emails included highly sensitive information relating to the financial condition of federally regulated financial institutions used in its examinations and supervisory oversight processes." the agency said in a release. "The OCC has utilized third-party cybersecurity experts to perform a full review of the investigation and forensics efforts [and] is also launching an immediate and thorough evaluation of its current IT security policies and procedures to improve its ability to prevent, detect and remediate potential security incidents going forward."

The agency says the breach was detected after internal and third-party reviews of OCC emails revealed that an as-of-yet unidentified party gained unauthorized access to emails within the agency's internal system. The breach began on February 11, 2025, when unusual activity between a system administrator's account and staff mailboxes was identified. 

The OCC says it promptly initiated incident response protocols following the breach, including a third-party investigation and notification to the Cybersecurity and Infrastructure Security Agency. By February 12, OCC said, compromised administrative accounts were disabled.

In consultation with the Treasury Secretary, the agency says, the breach was classified as a major incident due to the nature of the exposed data, prompting the OCC to enhance its IT security and consult with third-party experts to address vulnerabilities. The agency is also conducting a review of its cybersecurity policies and working with the Treasury Department to assess the breach's impact and improve future defenses.

"The confidentiality and integrity of the OCC's information security systems are paramount to fulfilling its mission," said Acting Comptroller of the Currency Rodney E. Hood. "I have taken immediate steps to determine the full extent of the breach and to remedy the long-held organizational and structural deficiencies that contributed to this incident. There will be full accountability for the vulnerabilities identified and any missed internal findings that led to the unauthorized access."

The breach at the OCC is not the first major cybersecurity incident involving a key U.S. agency under the Trump administration, and is the second known hack at the Treasury department — within which OCC is housed — this year. 

In January, hackers allegedly linked to the Chinese government infiltrated theTreasury department's systems via a third-party vendor's cloud-based remote support service. 

The January breach was significant for the hackers' use of an advanced persistent threat method of attack, allowing them to remain undetected within a system for months, gradually transferring sensitive information from the system. Both incidents highlight the ongoing risk of vulnerabilities in federal cybersecurity systems, particularly in the reliance on third-party services. 

The Office of the Comptroller of the Currency (OCC) recently experienced a significant email system security breach, as reported by the agency. The breach involved a high-level user account with administrative privileges over the OCC's email system, leading to the exposure of highly sensitive information related to one of the banks regulated by the OCC. The OCC oversees nationally chartered banks, including some of the largest and most systemically important institutions in the country.

Upon discovering the breach, the OCC took immediate action by engaging third-party cybersecurity experts to conduct a thorough investigation and forensic analysis. The agency also initiated a comprehensive evaluation of its current IT security policies and procedures to enhance its ability to prevent, detect, and address potential security incidents in the future.

The breach was detected through internal and third-party reviews of OCC emails, which revealed unauthorized access to emails within the agency's internal system. The breach was identified on February 11, 2025, when unusual activity involving a system administrator's account and staff mailboxes was observed.

Following the breach, the OCC promptly activated incident response protocols, including disabling compromised administrative accounts by February 12. The agency classified the breach as a major incident due to the nature of the exposed data, leading to enhanced IT security measures and collaboration with third-party experts to address vulnerabilities.

Acting Comptroller of the Currency Rodney E. Hood emphasized the importance of maintaining the confidentiality and integrity of the OCC's information security systems. Immediate steps were taken to investigate the breach, address organizational and structural deficiencies, and ensure accountability for any vulnerabilities that led to unauthorized access.

This breach at the OCC is not the first cybersecurity incident involving a key U.S. agency under the Trump administration. It is the second known hack at the Treasury department, where the OCC is housed, this year. In January, hackers allegedly linked to the Chinese government infiltrated the Treasury department's systems through a third-party vendor's cloud-based remote support service.

Both incidents underscore the ongoing risk of vulnerabilities in federal cybersecurity systems, particularly in relation to reliance on third-party services. The OCC remains committed to strengthening its cybersecurity defenses and safeguarding sensitive information to fulfill its mission effectively.

OpenAI Makes Strategic Investment in Adaptive Cybersecurity Technology

The company OpenAI has invested 43 million US dollars in the startup company Adaptive Security, which focuses on cybersecurity. Quoted from Antara, Tech Crunch's report on Friday, 4th April 2025, stated that this investment, made through the OpenAI Startup Fund and Andreessen Horowitz, is the first of its kind in the cybersecurity company.

Adaptive Security uses a unique approach by simulating AI-based attacks to train users to recognize threats.

What is Adaptive Security?

Adaptive Security utilizes AI to help mitigate cyber threats. This security system selects AI to detect, analyze, and respond to cyber threats that also use artificial intelligence. The approach to handling these attacks and cyber threats also uses a real-time response system, as cited from Techno Science.

OpenAI aims to enhance cybersecurity by increasing the number of their AI design models. Since December 2023, the company has formed a team dedicated to overseeing and assessing security risks of AI development.

OpenAI has also partnered with the US defense technology company, Anduril Industries. This collaboration will help utilize AI in military systems to combat artificial intelligence attacks.

OpenAI has also invested in the Adaptive Security company to support the use of AI in identifying engineered attacks in phone calls or emails. The approach used by Adaptive Security to simulate AI-based attacks in training all users to recognize threats.

According to Brian Long, the CEO and one of the founders of Adaptive Security, this investment will be used to recruit more workers and develop existing systems. The products from Adaptive Security will be innovated in the future.

Editor's Choice: Elon Musk Takes Over X Through xAI, Valuing It at Rp546 Trillion

Click here to get the latest news updates from Tempo on Google News

OpenAI, a prominent company, has recently invested 43 million US dollars in the cybersecurity startup Adaptive Security. This investment, facilitated through the OpenAI Startup Fund and Andreessen Horowitz, marks the first of its kind in the cybersecurity sector, as reported by Tech Crunch on Friday, 4th April 2025.

Adaptive Security distinguishes itself by employing AI simulations to train users in identifying and responding to cyber threats. By leveraging AI technology, this security system can detect, analyze, and counter cyber threats that also utilize artificial intelligence. The real-time response system employed by Adaptive Security enhances its ability to handle such attacks effectively.

In a bid to bolster cybersecurity measures, OpenAI has been expanding its AI design models. Since December 2023, the company has established a dedicated team to evaluate and address security risks associated with AI development. Furthermore, OpenAI has joined forces with Anduril Industries, a US defense technology company, to integrate AI into military systems for combating AI-driven attacks.

OpenAI's investment in Adaptive Security aims to support the use of AI in identifying engineered attacks in communication channels like phone calls and emails. Brian Long, CEO and co-founder of Adaptive Security, plans to utilize the investment to recruit more personnel and enhance existing systems. The company's products are expected to undergo further innovation in the future.

For more news updates on technology and innovation, visit Tempo on Google News.