White Paper: Cybersecurity Is Becoming a Leadership Responsibility 

Edited September 2026


Lané Venter Resourcer
12 min read Reading Time
18 September 2026 Date Created

Cybersecurity has traditionally been treated as a technology issue. IT teams manage systems, security specialists monitor threats, and technical teams respond when something goes wrong. 

That model is becoming harder to sustain. 

Technology now sits across almost every part of a business. Customer information, financial systems, operations, communications and supply chains all depend on digital infrastructure. As a result, a serious cyber incident can quickly become a business continuity, financial and reputational issue rather than an isolated IT problem. 

The UK’s approach to cyber resilience is reflecting this shift. The Government’s 2026 Cyber Resilience Pledge makes “cyber a Board responsibility”. Its first commitment: requiring participating organisations to implement the actions in the Cyber Governance Code of Practice and ensure board members undertake NCSC cyber-governance training. 

For businesses, particularly those going through digital transformation, the question is not whether cybersecurity matters. It’s who is accountable for it. 

Cyber Risk Is A Business Risk 

The scale of the problem makes this difficult to treat as purely technical. 

The UK’s 2025/2026 Cyber Security Breaches Survey found that 43% of businesses had experienced a cyber breach or attack during the previous 12 months. That included 65% of medium-sized businesses and 69% of large businesses. 

The same survey found that only 36% of businesses had a formal cyber security policy and just 25% had a formal incident response plan. It also found that the proportion of medium-sized businesses receiving cyber security updates at least annually at board level had fallen from 78% to 70%. 

These figures do not suggest that businesses are ignoring cybersecurity. They do, however, highlight a potential gap between having technical protections and having cyber risk properly embedded into organisational decision-making. 

A security team can identify vulnerabilities. It cannot, on its own, decide how much operational disruption the business can tolerate, which services are most critical or what level of investment is appropriate. 

Those are leadership decisions. 

The Board Does Not Need to Become a Security Team 

Making cybersecurity a leadership responsibility does not mean asking directors to become cybersecurity specialists. 

The NCSC’s Cyber Governance Code of Practice is specifically designed for boards and directors rather than the people responsible for day-to-day cyber security management. It focuses on governance, accountability, risk management, assurance and oversight. 

Senior leaders need enough understanding to ask the right questions and make informed decisions. They do not necessarily need to understand every technical control behind the answers. 

A board might reasonably ask: 

  • What are our most important systems and data? 
  • What would happen if one of them became unavailable? 
  • Which risks are we actively managing, and which are we accepting? 
  • How quickly could we recover from a serious incident? 
  • Are our suppliers creating additional exposure? 
  • Who has authority to make decisions during an incident? 
  • Are we investing in the areas of greatest risk? 

The answers should come from the people with the relevant technical expertise. But leadership needs to understand what those answers mean for the organisation. 

Cybersecurity Extends Beyond the IT Department 

Modern businesses rarely operate entirely within their own technology environment. 

They depend on cloud platforms, software providers, managed services, payment systems, data suppliers and other third parties. Employees may also access business systems from different locations and devices. 

That makes the boundaries around cybersecurity less clear. 

The Government’s 2026 Cyber Security Longitudinal Survey found that 67% of medium and large businesses had at least one board member whose role included oversight of cyber security risks, while 71% had a designated cyber security staff member reporting directly to the board. 

External support can be valuable, but outsourcing a technical function does not necessarily outsource accountability. 

If a critical supplier suffers an incident, the consequences may still fall on the business and its customers. 

Leadership therefore needs visibility of the wider technology environment, not just the systems directly controlled by the internal IT team. 

The Role of Technology Leaders Is Changing Too 

This shift has implications for CIOs, CTOs, IT Directors and other technology leaders. 

They increasingly need to translate technical risk into business terms. 

That might mean explaining why a particular investment is necessary, helping the board understand a supplier risk, deciding where resilience needs strengthening or working with operational leaders to establish what should happen during an incident. 

The technology leader does not necessarily own every business risk. 

But they may be responsible for making sure the organisation understands the technology risks that contribute to those wider business risks. 

That requires a combination of technical knowledge, communication, commercial awareness and the ability to work across organisational boundaries. 

Cybersecurity should be considered when roles are designed 

This also raises a question for organisations reviewing their technology structures. 

As cyber risk becomes more closely connected to business operations, organisations need to consider whether their current leadership structure provides enough ownership and expertise. 

That does not automatically mean creating a new senior security position. 

For some businesses, responsibility may sit with an existing technology leader. Others may need dedicated security expertise, stronger governance or clearer responsibilities between technology and business functions. 

The important point is to define the requirement around the organisation’s actual risk and operating model. 

This is particularly relevant for growing businesses. A structure that was appropriate when an organisation had a small internal IT function may become less suitable as it introduces more cloud services, handles more data, expands its supplier network or becomes increasingly dependent on digital systems. 

Regulation Is Adding to the Pressure 

The UK’s Cyber Security and Resilience Bill is another indication that cyber resilience is becoming a broader organisational responsibility. 

As of September 2026, the Bill has completed its committee stage in the House of Lords. Parliamentary scrutiny has included proposed changes concerning incident reporting, data centres, service providers and the liability of senior executives. The Bill is intended to strengthen cyber security requirements for organisations providing essential services, update incident-reporting duties and bring additional sectors into the regulatory framework.  

The Bill is still progressing through Parliament, so organisations should not treat its proposed provisions as final requirements. Report Stage is currently scheduled for 26 October 2026.  

The broader direction is towards treating cyber security as an organisational resilience issue, with responsibilities extending beyond technical teams and into wider business oversight and accountability. 

The Right Question Is Ownership 

For technology leaders, the challenge is not to make everyone responsible for cybersecurity. 

It’s to make sure the right people are responsible for the right decisions. 

Technical teams need the expertise to identify and manage security risks. Business leaders need to understand how those risks could affect operations and make decisions about priorities and investment. Boards need sufficient oversight to challenge, support and hold the organisation accountable. 

That requires clear ownership rather than simply adding more processes. 

As technology becomes more deeply embedded in how businesses operate, cybersecurity becomes part of the wider conversation about resilience, risk and leadership. 

The organisations that manage this effectively will not necessarily be those with the largest security teams. They will be those that understand where responsibility sits, have the right expertise available and ensure cyber risk is considered alongside other important business decisions. 

Building The Right Technology Leadership Structure 

For businesses reviewing their technology organisation, cybersecurity is now part of a wider question: does the current leadership structure reflect the organisation’s reliance on technology and the risks that come with it? 

At Bristow Holland, we work with organisations across the technology and change landscape, helping them consider how their technology leadership needs to evolve as the business changes. 

That might mean strengthening an existing team, redefining responsibilities or introducing a new capability. The starting point is understanding what the organisation needs its technology leadership to achieve – including how it manages risk, resilience and security. 

If you’re considering your technology leadership structure, responsibilities or approach to cyber risk, I’d be happy to discuss what that could look like in practice.  

Contact me,  
Andy Bristow