Cyber Risk in Regulated Firms: What Boards Must Oversee

Cyber Risk in Regulated Firms: What Boards and Senior Managers Must Oversee

A serious cyber incident can stop a regulated firm serving its customers, expose their data, trigger notifications to several authorities and do lasting damage to trust. Regulators treat cyber resilience as part of operational resilience, and they expect boards and Senior Managers to own it, not leave it to the IT department.

This article explains where cyber accountability sits, what regulators expect and the questions boards should be asking.

Why Cyber Is a Senior Management Responsibility

Cyber attacks on financial services firms are frequent and increasingly sophisticated, from ransomware and data theft to attacks on third-party suppliers. The consequences go well beyond technology: customers unable to access money, confidential data exposed, regulatory breaches and financial losses. For regulated firms, those consequences fall squarely within the regulators’ interest in customer harm, market integrity and firm resilience.

Under the Senior Managers and Certification Regime, accountability for the systems and controls that manage these risks sits with named Senior Managers. At firms with a Chief Operations function, responsibility for technology and operational resilience often sits there. At smaller firms, it may sit with an executive director or the chief executive. Either way, the board is responsible for overseeing it.

How Cyber Fits Into Operational Resilience

The UK’s operational resilience rules require firms to identify their important business services, set impact tolerances for how much disruption they could tolerate, and test whether they can stay within those tolerances in severe but plausible scenarios. Cyber attacks are among the most important scenarios to test. SMF Capital’s analysis of where operational resilience expectations stand explains the regulators’ current focus.

The approach changes the question the board asks. Instead of “how secure are we?”, the question becomes “if we’re attacked successfully, can we keep serving customers within tolerance, and how quickly can we recover?”

What Regulators Expect

Clear Ownership

A named Senior Manager should be accountable for cyber and technology risk, with a clear line to the board.

Risk-Based Controls

Firms should understand their critical systems and data, the threats they face and the controls in place, and prioritise investment accordingly. The National Cyber Security Centre publishes guidance that many firms use as a baseline.

Third-Party Security

Many incidents begin with a supplier. Firms should assess the security of third parties that access their systems or data, and plan for their failure.

Incident Response

Firms need a tested plan for responding to an incident, including who decides what, how customers are protected and how the firm communicates.

Notification

Significant incidents may need to be reported to the FCA and PRA, and personal data breaches to the Information Commissioner’s Office, often within tight timescales. Firms should know in advance who makes those decisions.

Testing

Controls and response plans should be tested regularly, including through scenario exercises involving senior management and, for larger firms, more advanced testing.

The question for the board isn’t whether the firm will be attacked. It’s whether it can keep serving customers when an attack succeeds.

What Good Board Oversight Looks Like

  • Regular reporting on cyber risk in business terms: which important services could be affected, how the firm would respond and how quickly it could recover.
  • Clear risk appetite for cyber and technology risk.
  • Scenario exercises in which the board and executive rehearse their response to a serious incident.
  • Independent assurance on whether controls work, not just whether they exist.
  • Investment decisions informed by risk, not just by budget cycles.
  • Board expertise sufficient to challenge the executive on technical issues.

The Board Expertise Gap

Many boards in regulated firms lack members with deep technology or cyber experience. That makes it hard to challenge the executive effectively or to judge whether reassurances are justified. Common responses include board training, access to independent advisers, and appointing a non-executive with technology or cyber expertise. NED Capital, a sister practice of SMF Capital, specialises in non-executive appointments, including directors with technology and cyber backgrounds for regulated boards.

Common Failings

  • Treating cyber as an IT issue. Leaving it to technology teams without board-level ownership.
  • Technical reporting. Board reports full of metrics the board can’t interpret, without a view of business impact.
  • Untested plans. Incident response plans that have never been rehearsed with the people who would use them.
  • Ignoring suppliers. Strong internal controls undermined by weak third parties.
  • Unclear notification decisions. No agreed process for deciding what to tell regulators and when.

Ransomware and Difficult Decisions

Ransomware attacks force boards to make difficult decisions quickly, often with incomplete information: whether to shut down systems, how to communicate with customers, when to notify regulators and law enforcement, and how to respond to demands. UK authorities strongly discourage paying ransoms, and payment doesn’t guarantee recovery of data or systems. Boards that have discussed these questions in advance, and agreed who will make which decisions, respond far better than those facing them for the first time during an attack.

Data Protection

Many cyber incidents involve personal data, bringing data protection obligations alongside regulatory ones. Firms may need to notify the Information Commissioner’s Office of certain personal data breaches within a short period, and in some cases to tell affected individuals. Senior Managers responsible for technology and customer-facing areas should understand how data protection and regulatory notifications interact, and who in the firm leads each. Aligning the two processes in advance avoids confusion during an incident.

Recruiting Technology Leadership

Regulated firms increasingly need technology leaders who can operate at Senior Manager level: people who understand cyber and resilience, can explain technical risk in business terms, and are comfortable being accountable to the board and the regulator. Chief operating officers and chief information officers with that combination are in short supply. When recruiting, firms should test how candidates have handled real incidents, how they’ve reported technology risk to boards, and how they’ve managed critical suppliers.

Smaller Firms

Smaller regulated firms often rely heavily on third parties for technology and may have little in-house expertise. That doesn’t reduce their accountability. Practical steps include adopting a recognised baseline framework, making sure key suppliers meet appropriate standards, having a simple, tested incident plan and making sure a named Senior Manager owns the risk. Where the firm lacks expertise, bringing in fractional or advisory support can be a proportionate answer.

Cyber and Customer Outcomes

Cyber incidents affect customers directly: lost access to accounts, delayed payments, exposed data and increased exposure to fraud. Under the Consumer Duty, firms need to think about how they’d support customers during and after an incident, including vulnerable customers who may be particularly affected. Communications plans, alternative service channels and processes for handling complaints and redress should all form part of the response.

Questions for Boards

  • Which Senior Manager is accountable for cyber and technology risk?
  • Do we understand which important business services depend on which systems and suppliers?
  • Have we rehearsed a serious cyber incident as a board and executive team?
  • Do we know how quickly we could recover, and whether that’s within tolerance?
  • Do we have enough expertise on the board to challenge effectively?
  • Who decides what to tell regulators and customers, and how quickly?

The Bottom Line

Cyber risk is a board and Senior Manager responsibility in every regulated firm. Firms that frame it in terms of important business services, test their response, oversee their suppliers and make sure the board has the expertise to challenge are far better prepared for the incident that will eventually come. For more on the Senior Manager Functions involved, see SMF Capital’s guide to SMF24 Chief Operations.

Related Guides

Guides to operational accountability from SMF Capital. Every SMF search is led personally by Adrian Lawrence FCA

Practice Area

Operations


The Senior Managers closest to cyber risk.

→ SMF24 Chief Operations
→ SMF4 Chief Risk


All SMF designations →

Practice Area

Board


Oversight and challenge.

→ SMF9 Chair
→ SMF1 Chief Executive


SMFs by firm tier →

Practice Area

Structure


Clear ownership of technology risk.

→ Governance structure review
→ The Responsibilities Map


SMF Capital home →


Every SMF search is led personally by Adrian Lawrence FCA

About the Author

Adrian Lawrence FCA is the founder of SMF Capital. He is a Chartered Accountant and Fellow of the ICAEW, holds a practising certificate in his own name, and is a former listed-company Finance Director with a BSc from Queen Mary College, University of London. He founded FD Capital in 2018 and has since built a network of five specialist recruitment practices. He leads SMF Capital’s Senior Manager searches, including chief operations and technology-focused board appointments. View Adrian’s ICAEW profile.

Strengthening Technology Oversight?

SMF Capital recruits chief operating officers, risk leaders and board members with technology expertise for regulated firms. Get in touch for a confidential conversation.

Leave a Reply