Board Briefing
Board Guide to Cyber and AI Risk in 2026
Published 22 July 2026
The five board questions for cyber risk
- Is our Cyber Essentials certificate current and does its scope cover the whole business?
- What is our worst credible cyber incident and what would it cost in cash, customers and reputation?
- How would we know we were breached, and how fast would we report under the CSR Bill 24/72-hour rule?
- Which suppliers carry our most sensitive data and what assurance do we hold over them?
- What is the management trend on patching, MFA coverage, phishing failure rate over the last 12 months?
The five board questions for AI risk
- What AI tools are staff actually using, and what data are they feeding in?
- Do we have an approved tools list and a written acceptable-use policy?
- Where AI makes decisions affecting customers or staff, is there documented human review?
- How would we explain a model decision if a regulator or customer challenged it?
- How do we keep IP and client confidential information out of public model training?
Board-level KPIs
- MFA coverage – percentage of accounts enforcing MFA (target 100%)
- Patching SLA – percentage of high/critical CVEs patched within 14 days
- Phishing failure rate – simulated phishing click + credential rate
- Backup restore success – proven restore in the last 90 days?
- Supplier assurance freshness – percentage of tier-1 suppliers with current CE+/ISO/SOC 2
- AI tool inventory accuracy – approved tools vs detected shadow-sm AI
- Incident drill recency – days since last tabletop exercise
Investment priorities for 2026
- Close the MFA gaps uncovered by Danzell – every account, every cloud
- Detection and response – managed XDR/MDR for SMEs without 24/7 ops
- AI governance lite – policy, approved tools list, basic logging
- Supplier tiering – stop sending 200-question forms to everyone
- Tabletop exercises twice a year, run by an outsider
Risk appetite – set it explicitly
Most boards do not articulate cyber and AI risk appetite. Pick a one-sentence statement, e.g. "We accept no cyber outage longer than 24 hours and no use of unapproved AI tools on client data." Then test every investment decision against it. Vague risk appetite is the single biggest reason CISOs and CFOs disagree on budget.
The assurance roadmap
- Now: CE / CE Plus, free £25k cyber insurance, AI policy v1
- 6 months: Cyber Assurance, supplier tiering, AI tool register
- 12 months: ISO 27001 if commercially required, AI risk assessments embedded in change control
- 24 months: External assurance over AI controls as ISO 42001 / equivalent matures
How to make this stick
Put cyber + AI risk on every board pack as a standing item, with the same KPIs each quarter. Trends matter more than absolute numbers. A two-page format keeps the conversation strategic, not technical.
