News & Insight

Guest writer November 21, 2025
From guidelines to boardroom action: embracing the UK Cyber Governance Code of Practice

From guidelines to boardroom action: embracing the UK Cyber Governance Code of Practice

Teruyoshi Adachi is the founder and CEO of cyber security company, Aprio Technologies Limited.

In April 2025, the UK government introduced a Cyber Governance Code of Practice (“Code”) to elevate cybersecurity as a boardroom priority. This comes amid an ever-growing threat landscape – almost one in three UK firms suffered a cyber-attack in the past year, leading to serious operational disruptions and financial losses. Cyber risk is now recognised as a material business risk that demands the same attention from company directors as traditional financial or legal risks.

Yet many boards struggle with overseeing cybersecurity. A government survey found that while senior managers acknowledge its importance, a lack of knowledge and time is preventing boards from engaging effectively. The new Code was created to bridge this governance gap. Co-developed by the Department for Science, Innovation and Technology and the National Cyber Security Centre, the Code lays out five principles (A–E) – practical actions for directors to strengthen cyber oversight.

Below I draw on my insight as CEO of Aprio Technologies Limited and a cybersecurity expert, with experience in UK and global technology firms, to explore each principle and suggest how boardrooms can turn these guidelines into concrete action.

Principle A: Risk Management – embedding cyber into enterprise risk

Principle A (Risk Management) urges boards to embed cyber threats into their overall risk management. Directors should start by identifying and prioritising the organisation’s most critical systems, data and technology (Action A1) – the “crown jewels” whose loss or failure would severely impact business. Knowing what these assets are helps focus protective efforts. Boards must also ensure clear ownership of cyber risk at senior management level and integration of cyber risks into enterprise risk registers (Action A2). In practice, cyber should be a standing item in risk discussions, with regular reports to the board just like other major risks. As part of this, the board should define the company’s cyber risk appetite – how much cyber risk the organisation is willing to tolerate – and verify that management has a plan to keep risks within that threshold.

Another critical aspect is managing the supply chain and third-party cyber risk. Action A4 calls on boards to gain assurance that cyber risks posed by suppliers and partners are being addressed. A weakness in a key vendor’s security can quickly become your problem, so directors should insist on due diligence and regular security assessments of important suppliers. In practice, the board could request periodic briefings on the cyber health of key suppliers and how any risks are being addressed.

Finally, boards should require regular cyber risk assessments and updates (Action A5). As the business and threat landscape evolves, the board needs to ensure that risk analyses are refreshed and that new or heightened risks (from emerging technologies, new regulations, etc.) are mitigated.

Principle B: Strategy – aligning cybersecurity with business strategy

Principle B (Strategy) focuses on having a cybersecurity strategy that is fully aligned with the company’s business objectives. The board should be assured that a cyber strategy exists and is embedded in the wider organisational strategy. In other words, when the business charts its goals (expanding digital services, entering new markets, etc.), there should be a corresponding plan for cybersecurity initiatives. The overall cyber strategy should reflect the organisation’s risk appetite and comply with relevant regulations. Boards need to review this strategy periodically and update it as threats or business plans change.

Crucially, the board must verify that adequate resources are allocated to execute the cyber strategy (Action B3). Grand plans are futile without proper funding, skilled personnel, and tools. Directors should scrutinise budgets and staffing for cybersecurity and compare them against the company’s risk exposure.

Finally, boards should track progress on key cybersecurity initiatives and outcomes (Action B4). This might involve receiving regular updates on major security projects or metrics such as the reduction in security incidents over time.

Principle B’s overall message is that cyber priorities must march in step with business priorities, and it is the board’s role to ensure that happens, by planning, resourcing and monitoring the cyber strategy as diligently as the business strategy.

Principle C: People and Culture – fostering a security-conscious organisation

Even the best technology can be undermined by human error, which is why Principle C (People) is about building a company culture that prioritises cybersecurity. Boards are expected to promote a culture of positive behaviours and accountability relating to cybersecurity at all levels. “Tone from the top” is crucial here – if the board and C-suite visibly care about security, employees will take it seriously too. The board should also ensure there are clear policies that encourage good security practices (Action C2). For example, a policy that rewards employees for promptly reporting security incidents (rather than hiding mistakes) will foster transparency and quicker response to threats. Directors should review such policies to be sure they align with the desired culture and are being followed.

Importantly, the Code challenges board members to lead by example when it comes to education. Directors should improve their own cyber literacy and take responsibility for the security of the data and systems they use. By undergoing basic cybersecurity training and staying informed on risks, board members can better oversee cyber efforts and signal that security is everyone’s job – including theirs.

Lastly, boards need to ensure that the organisation has effective security awareness and training programs for all staff, with metrics to gauge their success (Action C4). Regular reports to the board might include statistics on training completion or results of internal phishing tests. If these indicators are poor, the board should push for stronger efforts; if they improve over time, it shows a cultural shift is taking hold.

Principle C reminds boards that people are often the weakest link – but with the right culture and training, they can become the strongest defence.

Principle D: Incident Response and Recovery – readiness for cyber crises

Principle D (Incident Planning and Response) ensures that boards drive preparedness for cyber incidents so that the organisation can respond effectively when (not if) a cyber incident occurs. First, the board should confirm that an up-to-date incident response plan exists for major cyber attacks (Action D1). This plan should outline how the company will contain and investigate an incident, keep critical functions running, and communicate with stakeholders and regulators. The board should know the basics of this plan: who leads the response; whether it covers scenarios like ransomware or a serious data breach; and if roles are clear to everyone involved.

A plan on paper is not enough – it must be tested. Boards should mandate regular incident response exercises (at least annually) to simulate cyber emergencies (Action D2). These drills, which might involve both executives and technical teams, reveal gaps in the response and help everyone understand their roles under pressure. The board should ask for a summary of exercise results and ensure that any weaknesses identified (for example, confusion over decision-making authority or a slow customer notification process) are corrected.

When a real incident hits, the board plays a prominent role in crisis leadership. Action D3 reminds directors to be ready to fulfil key obligations such as regulatory breach reporting and to support critical decision-making and communications. For example, ensuring required breach notifications are made to regulators on time and being ready to make high-level decisions about issues like ransom demands or public disclosures. Boards should discuss these high-stakes scenarios in advance so they are not scrambling during the crisis. After the incident, the board must insist on a post-incident review to learn from what happened (Action D4). Directors should review management’s report on the incident’s root causes and remediation steps taken. They then need to follow up to make sure those improvements (stronger controls, new policies, additional training, etc.) are implemented.

Principle D prepares boards to lead during one of the most challenging times for any organisation – a cyber crisis – and to emerge from it smarter and stronger.

Principle E: Assurance and Oversight – sustaining cyber governance

The final principle, Principle E (Assurance and Oversight), is about embedding cybersecurity into the board’s regular oversight and ensuring continuous improvement. To start, the board should integrate cyber governance into its structures and processes. This might mean assigning cyber risk oversight to a specific board committee or scheduling cybersecurity as a regular agenda item at board meetings. It also involves designating an executive (such as a CISO or CIO) who is accountable for cybersecurity and regularly interfaces with the board. Formalising “who is responsible for what” prevents cyber matters from falling through the cracks.

Boards should also establish routine reporting and metrics for cybersecurity. The Code suggests receiving reports at least quarterly with agreed-upon metrics and risk indicators (Action E2). For example, management can report on the number of incidents detected, the status of critical vulnerabilities, or compliance with security standards – and how these trends align with the company’s cyber risk appetite and strategy. The board should set thresholds that trigger concern; if metrics show an uptick in risk (say, more frequent attacks or a backlog in patching systems), the board can press for urgent action. Regular, data-driven oversight enables directors to spot issues early and hold management accountable.

Open dialogue is another facet of strong oversight. Boards are encouraged to maintain two-way communication with senior security leaders like the CISO (Action E3). This could involve periodic deep-dives where the CISO briefs the board on emerging threats and challenges, and board members ask questions or offer guidance. Such exchanges ensure the board isn’t relying solely on high-level summaries – directors get firsthand insights, and security executives understand the board’s expectations.

Finally, the board should seek independent assurance that the company’s cyber controls are effective (Action E4). This might include commissioning internal or external audits of cybersecurity, or benchmarking against industry best practices and standards. If regulators have cybersecurity expectations in the company’s sector, the board should verify that those are being met as well (Action E5). By embedding cyber into audit and compliance processes, directors gain confidence that the rosy picture in reports is accurate and that any deficiencies will be identified and addressed.

Turning guidance into leadership

The UK Cyber Governance Code of Practice provides a clear blueprint for boards to enhance their cybersecurity governance. But its impact depends entirely on execution. It’s up to directors and executives to move from guidelines to boardroom action, integrating these principles into how they govern day-to-day. This means treating cyber risk as seriously as other business risks, asking probing questions about preparedness, investing in people and processes to build resilience, and leading by example in fostering a security-first mindset.

A proactive board can be the difference between a company that merely checks the compliance box and one that truly protects its business and stakeholders from cyber harm. By embracing the Code’s recommendations – not as a tick-box exercise but as part of the organisation’s culture – boards send a powerful signal that cybersecurity is a strategic priority under constant attention. In an era of sophisticated cyber threats, such leadership is essential for long-term success.

Effective cyber resilience starts in the boardroom – it’s time for leaders to take the helm.

This Insight piece was written by Teruyoshi Adachi, CEO and founder of various cybersecurity businesses and cybersecurity advisor to governments, banks, insurance companies and businesses in both the UK and Japan. Teru has led businesses in the cybersecurity sector for over two decades, including a company in Japan that went on to secure a 70% share of its domestic market before achieving a successful exit. He is now based in the UK, but continues to contribute to the establishment of Japan’s cyber insurance market. In 2023 he founded APRIO TECHNOLOGIES, which provides the Cyber Insight Portal, a cyber risk management platform applied across M&A and investment due diligence, supply chain risk oversight, and cyber insurance. He is also a Visiting Scholar at UCL, specialising in AI and cyber risk, and has authored multiple books, all of which have reached No.1 on Amazon rankings.

If you’d like to discuss how the Cyber Governance Code of Practice may affect your organisation or need guidance on strengthening board-level cyber governance generally, contact HLaw at enquiries@humphreys.law.

All the thoughts and commentary that HLaw publishes on this website, including those of Teruyoshi Adachi set out above, are subject to the terms and conditions of use of this website. None of the above constitutes legal advice and is not to be relied upon. Much of the above will no doubt fall out of date and conflict with future law and practice one day. None of the above should be relied upon. Always seek your own independent professional advice.

JAPANESE:

イントロダクション

2025年4月、英国政府はサイバーセキュリティを取締役会の優先課題に位置付けるため、サイバーガバナンス実践規範(Cyber Governance Code of Practice)を導入しました。サイバー脅威が高まり続ける中、過去1年間に英国企業の3社に1社がサイバー攻撃を受け、深刻な事業中断と財務的損失を招いたためです。サイバーリスクは今や、従来の財務リスクや法的リスクと同様に、取締役会が注意を払うべき重要な事業リスクとして認識されています。

しかし、多くの取締役会ではサイバーセキュリティの監督に苦慮しており、政府の調査によると経営層はその重要性を認識しているものの、知識と時間の不足が取締役会の効果的な関与を妨げていることが明らかになっています。新しい実践規範は、このガバナンスのギャップを埋めるために策定されました。科学・イノベーション・テクノロジー省(DSIT)と国家サイバーセキュリティセンター(NCSC)が共同開発したこの規範は、サイバー監督を強化するための取締役会の実践的な行動として5つの原則(A-E)を定めています。

以下では、英国内外のテック企業で経営者を務め、サイバーセキュリティの専門家である当社CEOの足立照嘉の知見を交えながら、各原則を考察し、取締役会がこれらのガイドラインを具体的な行動に変える方法を提案していきます。

原則A:リスク管理 – サイバーリスクを事業リスクに組み込む

原則A (リスク管理) は、取締役会がサイバー脅威を総合的なリスク管理に組み込むことを求めています。取締役会はまず、組織にとって最も重要なシステム・データ・技術、つまりその喪失や故障がビジネスに深刻な影響を与える「最重要資産」を特定し、優先順位を付けることから始める必要があります(アクションA1)。これらの資産を把握することで、保護努力を集中させることができます。

取締役会はまた、経営層によるサイバーリスクの明確な責任体制の確立と、サイバーリスクを企業のリスクレジスターに統合しなくてはなりません(アクションA2)。実務上、サイバーリスクは他の主要リストと同様に、リスクに関する議論の常設議題とし、取締役会への定期的な報告を行うべきです。この一環として、取締役会は企業のサイバーリスク許容度、つまり組織が許容するサイバーリスクの程度を定義し、経営層がその範囲内にリスクを収める計画を有していることを確認すべきです。

そして、もう一つの重要な側面は、サプライチェーンとサードパーティのサイバーリスク管理で、サプライヤーやパートナーがもたらすサイバーリスクに対処していることを確認するよう取締役会に求めています(アクションA4)。主要ベンダーのセキュリティ上の弱点は、すぐに自社の問題となり得るため、取締役会は重要なサプライヤーに対するデューデリジェンスと定期的なセキュリティ評価を要求すべきであるとしています。実際には、取締役会は主要サプライヤーのサイバーセキュリティ健全性とリスクへの対応策について、定期的な報告を求めるべきです。最後に、取締役会は定期的なサイバーリスク評価と、その更新を要求する必要があります(アクションA5)。事業環境やサイバー脅威が変化する中、取締役会はリスク分析を更新し、新しいテクノロジーや新規規制などによる新たなリスクや高まったリスクが軽減されていることを確認する必要があります。

原則B:戦略 – サイバーセキュリティと事業戦略の整合性

原則B (戦略) は、企業の事業目標と完全に整合したサイバーセキュリティ戦略の策定に焦点を当てています。取締役会は、サイバー戦略が存在し、より広範な組織戦略に組み込まれていることを確かめる必要があります。そして、デジタルサービスの拡大や新規市場への参入など新たな事業計画を策定する際にも、サイバーセキュリティへの取り組みに対応した計画がなくてはなりません。包括的なサイバー戦略は、組織のリスク許容度を反映し、関連規制に準拠する必要があります。取締役会はサイバー脅威や事業計画の変更に応じて、この戦略を定期的に見直し、更新していく必要があります。

特に重要なことは、取締役会がサイバー戦略を実行するために十分なリソースが割り当てられていることを確認することです(アクションB3)。適切な資金、熟練した人材、ツールが無ければ、壮大な計画だけでは意味がありません。取締役会はサイバーセキュリティの予算と人員配置を精査し、会社のリスクエクスポージャーと比較する必要があります。

最後に、取締役会は主要なサイバーセキュリティ施策の進捗と成果を追跡していく必要があります(アクションB4)。これには主要なサイバーセキュリティプロジェクトの定期的な進捗報告や、サイバーインシデントの減少といった指標を受け取ることが含まれます。

原則Bが伝えるメッセージは、サイバーセキュリティの優先事項は事業戦略の優先事項と歩調を合わせる必要があり、取締役会の役割は事業戦略と同様に、サイバーセキュリティ戦略の計画立案・リソース配置・モニタリングを徹底的に行うことで、これらを確実に実現することです。

原則C:人材と文化 – セキュリティ意識の高い組織の育成

優れた技術があっても人的ミスによって損なわれる可能性があるため、原則C(人材と文化)ではサイバーセキュリティを優先する企業文化の構築を求めています。あらゆる階層において積極的な行動と説明責任を重視するサイバーセキュリティ文化を、取締役会が促進していくことが期待されています。ここで重要なことは、取締役会や経営層がサイバーセキュリティに率先して取り組む“トップダウンの姿勢”で、取締役会と経営層がサイバーセキュリティを重視する姿勢を明確に示すことで、従業員も真剣に受け止めるようになることが期待されています。取締役会はまた、優れたセキュリティ実践を奨励する明確な方針を整備する必要があります (アクションC2)。例えば、過ちを隠蔽するのではなく、サイバーインシデントを迅速に報告した従業員を報奨する方針は、透明性と脅威への迅速な対応を促進します。取締役は、こうした方針が望ましい文化と整合し、遵守されていることを確認すべきです。

重要な点として、この実践規範は教育に関しても取締役会が模範を示すように求めていることです。取締役が自らのサイバーリテラシーを向上させ、使用するデータやシステムのサイバーセキュリティに責任を負うべきであるとしています。基本的なサイバーセキュリティトレーニングを受け、サイバーリスクに関する情報を常に把握することで、取締役会はサイバーセキュリティへの取り組みをより適切に監督でき、サイバーセキュリティが自身も含む全員の責務であることを示すことができます。最後に、取締役会は全従業員向けの効果的なサイバーセキュリティ意識向上とトレーニングプログラムを整備し、その成果を測定する指標を設ける必要があります(アクションC4)。取締役会への定期報告には、トレーニングの修了率や内部フィッシングテストの結果などの統計データを含めることが考えられます。これらの指標が低水準であれば、取締役会は対策強化を推進する必要があり、時間の経過とともに改善が見られれば、文化的な変化が定着しつつあることを示しています。原則Cは、人間がサイバーセキュリティ上の「最も脆弱な部分」になりがちだと指摘しつつも、適切な教育と組織文化次第で従業員を「最強の防御壁」に変えられることを示しています。

原則D:インシデント対応と復旧 – サイバー危機への備え

原則D(インシデント対応と復旧)は、取締役会がサイバーインシデントへの備え(発生するかどうかではなく)を推進し、組織が効果的に対応できるようにすることを保証します。まず、取締役会は、大規模なサイバー攻撃に対する最新のインシデント対応計画が存在することを確認する必要があります(アクションD1)。この計画では、企業がインシデントを封じ込めて調査する方法、重要な機能を稼働させ続ける方法、利害関係者や規制当局との連絡方法を明記する必要があります。取締役会は、この計画がランサムウェアや重大なデータ侵害などのシナリオをカバーしているか、関係者の役割が明確かといった基本事項を知っておく必要があります。

そして、紙の上の計画だけでは不十分であり、テストされなければなりません。取締役会は、サイバー緊急事態をシミュレートした定期的なインシデント対応演習を少なくとも年1回は実施することを義務付けるべきであるとしています(アクションD2)。経営陣と技術チームの両方が参加する可能性のあるこれらの訓練は、対応上のギャップを明らかにし、全員がプレッシャー下でも自分の役割を理解するのに役立ちます。取締役会は演習結果の概要を求め、特定された弱点(例えば、意思決定権限に関する混乱や顧客通知プロセスの遅延など)が是正されることを確認する必要があります。

実際のインシデント発生時には、取締役会は危機管理において主導的役割を担い、規制当局への違反報告といった主要な義務の履行準備や、重要な意思決定と情報発信の支援を促します(アクションD3)。具体的には、必要な違反通知が規制当局に期限内に確実に行われることや、身代金要求や情報公開といった問題に関する高レベルの意思決定を行う準備が整えることなどです。取締役会はこうした重大なシナリオを事前に議論し、危機発生時に慌てふためくことがないようにしなくてはなりません。インシデント発生後は、取締役会は事後検証を徹底し、発生原因から学ばなくてはなりません(アクションD4)。また、取締役会はインシデントの根本原因と講じられた是正措置に関する経営層の報告書を精査し、その後の改善策(統制強化、新規ポリシー、追加のトレーニングなど)が確実に実施されるようフォローアップする必要があります。原則Dでは、あらゆる組織にとって最も困難な局面の一つであるサイバー危機において、取締役会が主導的役割を果たし、より賢明かつ強固な組織として聞きを乗り越えるための準備を整えます。

原則E:保証と監督 – サイバーガバナンスの持続

最後の原則である原則E(保証と監督)は、サイバーセキュリティを取締役会の定期的な監督に組み込み、継続的な改善を確保することを目的としています。まず、取締役会はサイバーガバナンスを自らの構造とプロセスに統合する必要があります。具体的には、特定の取締役会委員会にサイバーリスクの監督を割り当てたり、サイバーセキュリティを取締役会の定期的な議題として組み込んだりすることを意味する場合があります。また、サイバーセキュリティの責任を負い、取締役会と定期的に連携する役員(CISOやCIOなど)を指定することも含まれます。「誰が何に責任を負うのか」を正式に定めることで、サイバー関連の事項が見落とされるのを防ぐことができます。

取締役会はまた、サイバーセキュリティに関する定期的な報告と指標を確立する必要があります。この規範では、合意された指標とリスク指標を含む報告書を少なくとも四半期ごとに受け取ることを推奨しています(アクションE2)。例えば、経営層は、検知されたインシデントの数、重大な脆弱性の状況、セキュリティ基準への準拠状況、そしてこれらの傾向が企業のサイバーリスク許容度や戦略とどのように整合しているかを報告するといったことがあげられます。取締役会は懸念を引き起こす閾値を設定する必要があり、指標がリスク上昇(例えば、攻撃頻度の増加や、パッチ適用遅延など)を示した場合、取締役会は緊急対応を要請することができます。データ駆動型の定期的な監視により、取締役は問題を早期に発見し、経営層に説明責任を果たさせることが可能となります。

オープンな対話も強力な監督のもう一つの側面です。取締役会はCISOなどの上級セキュリティ責任者との双方向コミュニケーションを維持することが推奨されています(アクションE3)。これには、CISOが新たな脅威や課題について取締役会に説明し、取締役が質問や助言を行う定期的な詳細の検討が含まれています。このようなやりとりによって、取締役会は高レベルの要約だけに頼るのではなく、取締役 自身が直接的な洞察を得ることができ、セキュリティ責任者は取締役会の期待を理解することができます。

最後に、取締役会は自社のサイバーガバナンスが有効であることの独立した保証を求める必要があります(アクションE4)。これには、サイバーセキュリティに関する内部または外部監査の実施、業界のベストプラクティスや基準とのベンチマークが含まれる場合があります。規制当局が自社のセクターでサイバーセキュリティ要件を定めている場合、取締役会はそれらも満たされていることを確認する必要があります(アクションE5)。監査およびコンプライアンスプロセスにサイバーセキュリティを組み込むことで、取締役は報告書に良好な状態と示されていることが正確であることを確かめ、不足点があれば特定され、対処されるという確信を得られることができます。

ガイダンスをリーダーシップに変える

英国のサイバーガバナンス実践規範は、取締役会がサイバーセキュリティガバナンスを強化するための明確な青写真を提供しています。しかし、その効果は実行次第です。ガイドラインから取締役会の行動へと移行し、これらの原則を日常的なガバナンス手法に統合できるかどうかは、取締役と経営層次第です。これは、サイバーリスクを他の事業リスクと同様に真剣に扱い、備えについて徹底的に質問し、レジリエンス構築のための人材とプロセスに投資し、セキュリティファーストの考え方を育む模範を示すことを意味します。

積極的な取締役会は、コンプライアンスのチェックリストにチェックを入れるだけの企業と、事業と利害関係者をサイバー被害から真に保護する企業との差を生む可能性があります。規範での提言を単なるチェックリストではなく組織文化の一部として受け入れることで、取締役会はサイバーセキュリティが絶えず注意を払うべき戦略的優先事項であるという強力なメッセージを発信できます。高度化するサイバー脅威の時代において、このようなリーダーシップは長期的な成功に不可欠です。

効果的なサイバーレジリエンスは取締役会から始まります。今こそ、リーダーが主導権を握る時です。

本稿は、英国の法律事務所 HUMPHREYS LAW(https://humphreys.law/)に、当社APRIO TECHNOLOGIES LIMITEDのCEOである足立照嘉が寄稿した文章を、本ホワイトペーパー向けに和訳し加筆修正を加えたものです。上記のいずれも法的アドバイスを構成するものではありません。

APRIO TECHNOLOGIES LIMITEDについて

APRIO TECHNOLOGIESは、リスク関連取引の中心地である英国ロンドンに本社を置くサイバーセキュリティ企業です。2023年7月に設立された同社は、サイバーセキュリティの専門家であるCEOの足立照嘉のリーダーシップの下、その深い知識と経験がソリューション開発の基盤となり、サイバーリスク管理の新たなフロンティアを開拓しています。 APRIO TECHNOLOGIESの基本理念は、「リスクを機会に変える」ことです。シンプルでインテリジェント、かつ強力なサイバーリスクに関する洞察をリーダーシップチームに提供し、より高い知識・自信・精度をもって行動できるようにすることを目指しています。主力製品であるCyber Insight Portal(CIP)はSaaSベースのサイバーリスク管理プラットフォームで、経営幹部、投資家、リスク管理者などの戦略的意思決定者が、ビジネス・エコシステム全体のサイバーリスクをプロアクティブに管理できるように設計されています。

ハンフリーズ法律事務所

If you would like to contact a member of our team, please get in touch by filling in the form below.

"*" indicates required fields

Humphreys Law