Here is the honest situation. Here is the honest situation. Boards rarely fail at cyber because the directors were careless. They fail because the governance was never written down, so when somebody eventually asks who was accountable, what the board knew and when it knew it, the answer has to be assembled from memory, mailboxes and a shared drive. The first failure is allocation. Cyber usually sits wherever it first arrived, most often the audit committee because it came in with the auditors, and nobody has recorded that decision. Directors' duties under the Companies Act 2006 are personal to the directors, so delegating a task moves the work and not the duty, and a set of terms of reference that never mentions cyber tells a reader exactly how the topic has been treated. The second failure is the perimeter. The regulatory position is specific to a legal entity, turning on what it does, what data it processes, whether it carries out regulated activities, whether it sits in a designated sector, whether it has securities admitted to trading, and what its customers and funders have imposed by contract. Most boards are working from a summary written for another entity in the group, or from an industry-level list that names regimes without saying why they apply here, and almost nobody records the regimes they concluded did not apply, which is the half that protects them when the facts move. The third failure is the reporting. Cyber packs are written to reassure: activity, a maturity score, a heat map, no stated tolerance, no basis for any number, and an ask that amounts to noting the update. A paper that needs its author in the room to make sense is a prompt rather than a record, and a paper handed out at the table cannot support a claim that the board considered it. The fourth failure is individual accountability. Responsibility is described at team level, security and data protection are assumed to be the same allocation, and the element that matters most in the first hour, regulatory notification, belongs to nobody because it looks like a legal task in peacetime and a technical one during an incident. Where the same executive both runs the controls and reports on their effectiveness, the board's only view of the control environment is produced by the person it is grading, and assurance work that was quietly narrowed almost never reaches the board because the restriction gets settled between executives. The fifth failure is the record. Minutes say the report was received and noted, so a year of real challenge leaves no trace. Decisions are recorded without the constraints in force, so a later reader cannot tell whether the decision still holds or rested on a budget position that has since changed, and the rejected options, the most valuable content the record could carry, are missing entirely. Risk acceptances are granted informally, by whoever is under the most delivery pressure, with no expiry and no test of the compensating control they rest on, until the register becomes a list of things nobody intends to fix. The sixth failure is the incident. The plan says the board is informed of major incidents and nobody has defined major, the contact list is a year old, and the out-of-hours route runs through the corporate mail system that is the reason for the call. Once convened, the board interferes rather than decides, asking for hourly updates that consume the responders while the handful of decisions only the board can take sit outstanding. Then the inquiry arrives weeks later, the response team has dispersed, and what gets examined is consistency between what was told to one authority, what was told to another, and what the entity's own records show. The board's own review of its own performance is the item most often skipped, because by then everyone is exhausted and the remediation plan feels like the review, except that the remediation plan does not answer whether the board was told in time. Where boards fall short is predictable: terms of reference silent on cyber, an inherited perimeter slide, an escalation route that has never been used, a pack of scores with no sources, an obligation with no owner, an acceptance with no expiry, a deputy who has never taken a decision, a minute that records only that a report was noted, and a contact list nobody has rung.
This Kit removes the guesswork. It is board-level cyber governance written as adopt-ready controls you personalize in a weekend, with the evidence a chair, a committee, an internal auditor or a supervisor actually examines.
What you get, the moment you buy
Grounded in UK board and committee practice as it is actually run, across regulated firms, listed issuers, public bodies, charities and private companies. Editable Word and Excel files. These controls describe governance practice rather than legal advice, and where a duty turns on your entity type, your sector or your facts, the control tells you to take your own advice and record that you did.
What one control looks like
This is the opening control, where cyber accountability either becomes a written allocation or stays an assumption reconstructed after the fact. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A policy and a heat map are not evidence. This tells you what a chair, an audit or risk committee, an internal auditor or a supervisor examines and where boards fall short, for every control.
- The hard specifics built in. Terms of reference naming the accountable body and the reserved matters, a skills matrix that identifies who can challenge the assurance independently, escalation thresholds as observable conditions with an alternative route, an applicability determination for your own legal entity recording why each regime applies and why the others do not, an obligation map decomposed to duties one person can own, a dependency register stating what the board remains accountable for and which rights it does not hold, an annual cycle reconciled against what was actually reached, a pack standard requiring position against tolerance and the basis of every number, minutes carrying the questions and the points not accepted, one named individual per element reconciled to what the regulator has been told, assurance that bypasses the delivery executive, deputies exercised in a real test, decision records carrying constraints and rejected options, acceptances with an expiry and a reopening condition, a record repository that reconstructs any past date, tested convening criteria and out-of-hours routes, a schedule of the few decisions the board owns in the first hours, and a single coordination point for regulatory correspondence with the board's own review minuted are written into the controls, not left generic.
- Built on real practice, not one person's opinion, grounded in how UK boards actually oversee cyber risk and where that oversight usually breaks down under examination.
- It compounds. This work shares its shape with operational resilience, data protection accountability, third-party risk and internal control reporting, so it feeds your wider governance framework.
Who buys this
Non-executive directors, board and committee chairs, audit and risk committee members, senior independent directors, company secretaries and general counsel, and the executives who prepare what the board sees, in UK-regulated entities, listed issuers, public bodies, charities and private companies with real obligations. If you have to say which body is accountable for cyber and what it may not delegate, which regimes apply to this legal entity and why, how the board knows the assurance is independent of the people who built the controls, who individually owns regulatory notification, why a risk was accepted and when that acceptance expires, and what the board itself decides in the first hours of an incident, these are your controls. Whether you are joining a board, taking a committee chair, preparing for a supervisory visit or repairing a governance record that has been kept in mailboxes, you save weeks and walk in with your accountability, perimeter, oversight, allocation, record and incident controls structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does it cover the whole practice? Yes. Board accountability and terms of reference, regulatory perimeter and obligation mapping, oversight cadence, reporting and challenge, executive accountability allocation, decision records and risk acceptance, and incident escalation and regulatory response each have their own controls with their own evidence.
Is this tied to one sector or one regulator? No. The controls are written so that where a duty depends on your entity type, your sector or your regulated status, the control says so and tells you to determine and record your own position rather than assuming somebody else's. They apply to a regulated firm, a listed issuer, a public body, a charity and a private company alike, and they point you to your own advisers on the questions that are genuinely legal ones.
Is this legal advice? No. It is governance practice written as controls, and several controls exist precisely to make sure the board obtains and records its own legal advice rather than settling a legal question on its own reading.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com