Skip to main content
Image coming soon

Board-Level Cyber Governance Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
Board-Level Cyber Governance for UK Directors · name the accountable body, determine your own perimeter, build a pack that reads without you, own it individually, record the reasoning, know the first hours · Evidence & Implementation Kit
Hold a cyber governance position you can evidence, without terms of reference that never mention cyber, a perimeter slide inherited from a group function, a pack of maturity scores nobody can challenge, or a minute that says only that the board noted the report.
Every control handed to you adopt-ready, from terms of reference that state which body holds cyber accountability, which matters are reserved to the board, and that delegating a task moves the work rather than the directors' own duty of oversight, through a board skills position that identifies who can interrogate technical and third-party assurance without relying on the executive who produced it and records the questions the board could not answer, written escalation thresholds expressed as observable conditions with an alternative route where the primary route runs through the person the matter concerns, an applicability determination for this legal entity naming why each regime applies and why the others do not, with the supervising authority, the registered contact and legal advice recorded where applicability turns on a question the board is not competent to settle, an obligation map decomposed to duties a single person can own with the artefact named, located and dated and unowned or stale duties reported as exceptions, a dependency register that states what this board remains accountable for where a group function or a critical third party does the work and records the information, audit, notification and exit rights it does not hold, an annual oversight cycle covering appetite, assurance, third parties and an incident exercise the directors take part in, reconciled at year end against what the board actually reached, a pack standard requiring the position against tolerance with the trend, the basis of every number, who produced it and who checked it, an explicit ask, the limitations of the assurance and any unresolved disagreement, minutes carrying the questions asked, the answers given, the points the board declined to accept and what it required next with owners and dates closed on evidence, one named individual against each element of the obligation with shared ownership split rather than shared and the allocation reconciled to whatever the entity has told its regulator, assurance reporting that reaches the board without passing through the executive accountable for delivery and scope restrictions escalated rather than negotiated, named deputies exercised in a real test and handovers that carry open acceptances and live regulatory matters across a change of role holder, decision records carrying the options, the sources, the advice, the recorded dissent and the constraints in force so a later reader can judge whether the decision still holds, risk acceptances with an authorised acceptor, a stated business consequence, tested compensating measures, an expiry that lapses and an observable condition that reopens it early, a controlled board record repository that can reconstruct what the board held on any past date and survives the incident it may be needed to explain, convening criteria and an out-of-hours route tested rather than documented with the notification and joining times recorded, a schedule of the few decisions the board owns in the first hours and the many it deliberately does not, and a single point of coordination for regulatory correspondence with factual statements checked against the entity's own records and the board's own post-incident review minuted.
Ready in a weekend, not a quarter.

Here is the honest situation. Here is the honest situation. Boards rarely fail at cyber because the directors were careless. They fail because the governance was never written down, so when somebody eventually asks who was accountable, what the board knew and when it knew it, the answer has to be assembled from memory, mailboxes and a shared drive. The first failure is allocation. Cyber usually sits wherever it first arrived, most often the audit committee because it came in with the auditors, and nobody has recorded that decision. Directors' duties under the Companies Act 2006 are personal to the directors, so delegating a task moves the work and not the duty, and a set of terms of reference that never mentions cyber tells a reader exactly how the topic has been treated. The second failure is the perimeter. The regulatory position is specific to a legal entity, turning on what it does, what data it processes, whether it carries out regulated activities, whether it sits in a designated sector, whether it has securities admitted to trading, and what its customers and funders have imposed by contract. Most boards are working from a summary written for another entity in the group, or from an industry-level list that names regimes without saying why they apply here, and almost nobody records the regimes they concluded did not apply, which is the half that protects them when the facts move. The third failure is the reporting. Cyber packs are written to reassure: activity, a maturity score, a heat map, no stated tolerance, no basis for any number, and an ask that amounts to noting the update. A paper that needs its author in the room to make sense is a prompt rather than a record, and a paper handed out at the table cannot support a claim that the board considered it. The fourth failure is individual accountability. Responsibility is described at team level, security and data protection are assumed to be the same allocation, and the element that matters most in the first hour, regulatory notification, belongs to nobody because it looks like a legal task in peacetime and a technical one during an incident. Where the same executive both runs the controls and reports on their effectiveness, the board's only view of the control environment is produced by the person it is grading, and assurance work that was quietly narrowed almost never reaches the board because the restriction gets settled between executives. The fifth failure is the record. Minutes say the report was received and noted, so a year of real challenge leaves no trace. Decisions are recorded without the constraints in force, so a later reader cannot tell whether the decision still holds or rested on a budget position that has since changed, and the rejected options, the most valuable content the record could carry, are missing entirely. Risk acceptances are granted informally, by whoever is under the most delivery pressure, with no expiry and no test of the compensating control they rest on, until the register becomes a list of things nobody intends to fix. The sixth failure is the incident. The plan says the board is informed of major incidents and nobody has defined major, the contact list is a year old, and the out-of-hours route runs through the corporate mail system that is the reason for the call. Once convened, the board interferes rather than decides, asking for hourly updates that consume the responders while the handful of decisions only the board can take sit outstanding. Then the inquiry arrives weeks later, the response team has dispersed, and what gets examined is consistency between what was told to one authority, what was told to another, and what the entity's own records show. The board's own review of its own performance is the item most often skipped, because by then everyone is exhausted and the remediation plan feels like the review, except that the remediation plan does not answer whether the board was told in time. Where boards fall short is predictable: terms of reference silent on cyber, an inherited perimeter slide, an escalation route that has never been used, a pack of scores with no sources, an obligation with no owner, an acceptance with no expiry, a deputy who has never taken a decision, a minute that records only that a report was noted, and a contact list nobody has rung.

This Kit removes the guesswork. It is board-level cyber governance written as adopt-ready controls you personalize in a weekend, with the evidence a chair, a committee, an internal auditor or a supervisor actually examines.

What you get, the moment you buy

18
Controls, adopt-ready. Every control, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what a reviewer examines, plus where teams fall short, so you close the gap first.
1
Control Matrix, pre-built. Every control in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each control and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in UK board and committee practice as it is actually run, across regulated firms, listed issuers, public bodies, charities and private companies. Editable Word and Excel files. These controls describe governance practice rather than legal advice, and where a duty turns on your entity type, your sector or your facts, the control tells you to take your own advice and record that you did.

A governance position you can evidence, or a set of assumptions reconstructed under deadline
Boards are rarely criticised for the decision they took. They are criticised because nothing in the record shows who was accountable, what they were told, what they asked, or why they decided as they did. This Kit builds the accountability, perimeter, reporting, allocation, record and incident controls that make that evidence exist before anybody asks for it.

What one control looks like

This is the opening control, where cyber accountability either becomes a written allocation or stays an assumption reconstructed after the fact. All 18 are built to this depth.

ACC-1 State in the terms of reference which body holds cyber accountability and what it may not delegate BOARD ACCOUNTABILITY AND TERMS OF REFERENCE
Put this control in place

Require [your organization name] to record in its board and committee terms of reference which body holds accountability for cyber risk, which body performs the detailed scrutiny, and how a matter moves between them. Require the terms of reference to name the matters reserved to the board itself, including approval of cyber risk appetite, acceptance of a risk outside that appetite, approval of material technology or security outsourcing, and any decision that changes the entity's regulatory position. Require the document to state that responsibility for performing a task has been delegated while the directors' own duty of oversight under the Companies Act 2006 remains with them, and require legal advice obtained and recorded where the allocation of duty across a group or an outsourced arrangement is genuinely unclear. Require the terms of reference to state how often the accountable body considers cyber, its quorum, who attends by right, and which assurance functions are entitled to attend without invitation. Require the terms of reference reviewed annually and on any material change to the entity's structure, regulated activities or supervisory relationships, with the review recorded whether or not the document changed. Require every director to confirm on the record that they have read the current version, so a later reviewer can see the allocation was known rather than assumed.

Control note.

Write the reserved matters as thresholds rather than as topics. Any acceptance of a risk outside appetite survives a change of personnel; significant cyber matters does not.

Evidence a reviewer examines
  • Current board and committee terms of reference showing where cyber accountability sits and how matters route between bodies
  • The schedule of matters reserved to the board, with the cyber matters named explicitly
  • Minutes recording the annual and change-triggered review of the terms of reference
  • Quorum and attendance rules for the accountable body, including assurance functions attending by right
  • Directors' confirmations that the current terms of reference have been read
  • Legal advice obtained and recorded where the allocation of duty across a group or outsourced arrangement was unclear
Common finding they raise: Cyber appears nowhere in the terms of reference, it sits informally with the audit committee because that is where it first landed, and the first attempt to state who was accountable happens after an incident rather than before one.

Why this is not another template pack

  • The evidence is the point. A policy and a heat map are not evidence. This tells you what a chair, an audit or risk committee, an internal auditor or a supervisor examines and where boards fall short, for every control.
  • The hard specifics built in. Terms of reference naming the accountable body and the reserved matters, a skills matrix that identifies who can challenge the assurance independently, escalation thresholds as observable conditions with an alternative route, an applicability determination for your own legal entity recording why each regime applies and why the others do not, an obligation map decomposed to duties one person can own, a dependency register stating what the board remains accountable for and which rights it does not hold, an annual cycle reconciled against what was actually reached, a pack standard requiring position against tolerance and the basis of every number, minutes carrying the questions and the points not accepted, one named individual per element reconciled to what the regulator has been told, assurance that bypasses the delivery executive, deputies exercised in a real test, decision records carrying constraints and rejected options, acceptances with an expiry and a reopening condition, a record repository that reconstructs any past date, tested convening criteria and out-of-hours routes, a schedule of the few decisions the board owns in the first hours, and a single coordination point for regulatory correspondence with the board's own review minuted are written into the controls, not left generic.
  • Built on real practice, not one person's opinion, grounded in how UK boards actually oversee cyber risk and where that oversight usually breaks down under examination.
  • It compounds. This work shares its shape with operational resilience, data protection accountability, third-party risk and internal control reporting, so it feeds your wider governance framework.

Who buys this

Non-executive directors, board and committee chairs, audit and risk committee members, senior independent directors, company secretaries and general counsel, and the executives who prepare what the board sees, in UK-regulated entities, listed issuers, public bodies, charities and private companies with real obligations. If you have to say which body is accountable for cyber and what it may not delegate, which regimes apply to this legal entity and why, how the board knows the assurance is independent of the people who built the controls, who individually owns regulatory notification, why a risk was accepted and when that acceptance expires, and what the board itself decides in the first hours of an incident, these are your controls. Whether you are joining a board, taking a committee chair, preparing for a supervisory visit or repairing a governance record that has been kept in mailboxes, you save weeks and walk in with your accountability, perimeter, oversight, allocation, record and incident controls structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 areas
✓  A completed control matrix
✓  The evidence a reviewer examines
✓  A perimeter determination for your own entity
✓  A readiness percentage and a fix list
✓  The highest-risk gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Does it cover the whole practice? Yes. Board accountability and terms of reference, regulatory perimeter and obligation mapping, oversight cadence, reporting and challenge, executive accountability allocation, decision records and risk acceptance, and incident escalation and regulatory response each have their own controls with their own evidence.

Is this tied to one sector or one regulator? No. The controls are written so that where a duty depends on your entity type, your sector or your regulated status, the control says so and tells you to determine and record your own position rather than assuming somebody else's. They apply to a regulated firm, a listed issuer, a public body, a charity and a private company alike, and they point you to your own advisers on the questions that are genuinely legal ones.

Is this legal advice? No. It is governance practice written as controls, and several controls exist precisely to make sure the board obtains and records its own legal advice rather than settling a legal question on its own reading.

What if it is not for me? A 30-day money-back guarantee.

Do not let your next cyber conversation be terms of reference that never mention it, a perimeter slide written for another entity, a pack of scores with no sources, or a minute recording only that the board noted the report.
Every control is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com