A ransomware attack shut down a mid-sized UK recruitment firm for eleven days last year: no systems, no client data, no payroll access. The board had approved the IT budget six months earlier without a single question about resilience. That gap between spending and scrutiny is exactly where IT infrastructure security stops being a technical line item and becomes a business risk.
Why Should Cyber Security Be a Board-Level Issue?
Cyber security belongs at board level because a serious infrastructure failure threatens revenue, regulatory standing, and client trust simultaneously, not just uptime. Boards routinely govern financial risk, legal risk, and reputational risk. Infrastructure security touches all three at once, yet it is still frequently delegated entirely to IT staff with no board-level reporting line.
This is not a criticism of IT teams. Technical staff can identify vulnerabilities and implement controls, but they rarely have the authority or the budget mandate to make organisation-wide risk decisions. That authority sits with the board. When a board treats security as a technical afterthought, it is effectively delegating a governance responsibility to people who cannot discharge it.
In finance, legal, and recruitment firms specifically, the exposure is sharper. These sectors hold client financial data, privileged case material, and candidate personal information respectively, all of which carry regulatory obligations under UK GDPR and, where relevant, FCA or SRA oversight.
What Is the Average Cost of a Ransomware Attack for a UK SME?
UK SMEs typically face costs of £10,000 to £50,000 in direct recovery expenses following a ransomware incident, before accounting for lost billable hours, client churn, or regulatory penalties. For a 20- to 50-person professional services firm, an eleven-day outage can represent six figures in lost fee income alone.
The direct costs are the visible part. Forensic investigation, system rebuilding, and, in some cases, ransom negotiation through specialist firms all carry a bill. What rarely appears on that invoice is the slower damage: clients who quietly move their instructions elsewhere, or a professional indemnity insurer who raises premiums at renewal once an incident is disclosed.
A common pattern I see with SMEs recovering from an incident is underestimating the reputational tail. A law firm can rebuild its servers in a fortnight. Rebuilding client confidence after a data breach disclosure to the ICO takes longer, and some of that trust never fully returns.
What Boards Get Wrong About IT Infrastructure Security
The most frequent board-level mistake is treating IT infrastructure security as a cost to be minimised rather than a risk to be managed, which leaves the organisation under-protected relative to its actual exposure. Boards that ask what security costs instead of what an incident costs consistently under-invest.
Firms that build proactive IT infrastructure security into their governance structure tend to detect and contain incidents faster than those relying on reactive, break-fix arrangements. The difference is not usually technology sophistication. It is whether someone with budget authority is asking the right questions before an incident, not after one.
A practical fix is simple: add a standing security item to quarterly board meetings, with a named owner reporting on patching status, backup testing, and access control reviews. If nobody on the board can currently answer those three questions, that itself is the finding.
What Is the Zero Trust Security Model?
Under the Zero Trust security model, no user or device is trusted by default, regardless of whether it is inside or outside the corporate network. Each access request is verified based on identity, device health, and other contextual signals. It replaces the older assumption that anything inside the network perimeter is inherently safe.
For professional services firms with hybrid working arrangements, this matters enormously. Staff accessing client files from home laptops or personal devices represent exactly the scenario zero trust is designed to control, through conditional access policies, multi-factor authentication, and continuous verification rather than a one-time login check.
Microsoft's official guidance on the zero trust framework sets out the underlying principles in detail, including how identity, device, and network signals combine to inform access decisions. Boards do not need to understand the technical implementation. They do need to know whether their organisation has adopted the principle at all.
Who Is Legally Responsible for Data Breaches in a UK Company?
Under UK GDPR, the data controller, typically the company itself rather than any individual employee, bears legal responsibility for data breaches, and the ICO can issue fines of up to 4 per cent of annual global turnover for serious violations. Directors carry additional personal exposure where negligence in oversight can be demonstrated.
This is precisely why the issue cannot sit solely with an IT manager or an outsourced provider. The legal liability sits with the organisation and, in some circumstances, with individual directors who failed to exercise reasonable oversight. A board that has never reviewed its security posture has a weaker defence if a regulator asks what governance was in place.
Solicitors regulated by the SRA face a further layer: professional conduct rules that treat client confidentiality failures as a disciplinary matter, separate from any ICO enforcement action.
How Often Should Boards Review IT Security Risk?
Boards should review IT infrastructure security risk at least quarterly, with an annual deeper audit covering penetration testing results, backup recovery testing, and third-party vendor risk. Quarterly is the minimum cadence given how quickly new vulnerabilities and threat actors emerge, and it keeps security visible as a standing governance item rather than an annual afterthought.
An annual review alone leaves too large a gap. New vulnerabilities, staff changes, and shifting supplier relationships all introduce risk between annual cycles. A quarterly touchpoint, even a brief fifteen-minute agenda item, keeps the topic visible and ensures budget requests for security improvements get proper board consideration rather than being deferred indefinitely.
Cyber Essentials certification, reviewed annually, gives many UK boards a useful external benchmark to anchor this discipline around, since it forces a periodic, structured assessment rather than an ad hoc one.
The Governance Gap Is the Real Vulnerability
Exotic technical exploits do not cause most infrastructure security failures at SMEs. They are caused by unpatched systems, weak access controls, and untested backups, all of which are governance failures as much as technical ones. A board that treats security oversight as someone else's job has already accepted a level of risk it has not actually evaluated.
Moving security onto the board agenda does not require directors to become technical experts. It requires them to ask consistent questions, demand regular reporting, and treat infrastructure resilience as a standing item alongside financial and operational risk. That shift alone closes most of the gap that ransomware, compliance penalties, and reputational damage currently exploit.

Comments