Cyber threats are no longer just a technology issue. They are an all-of-business risk that can affect operations, finances, reputation and regulatory compliance. As cyber-attacks become more frequent and sophisticated, boards and senior leaders are expected to play an increasingly active role in cyber governance, organisational resilience and incident response.
Our Cyber Governance: A Practical Framework handbook provides guidance on the legal, regulatory and governance issues organisations should consider before, during and after a cyber incident. Drawing on recent developments in New Zealand and overseas, it outlines the key questions boards should be asking to understand and manage cyber risk.
Key takeaways
Is cyber security a board/senior leadership issue or an IT issue?
Cyber risk is no longer solely an IT issue. It is a whole-of-business risk shaped by increasingly sophisticated criminal activity, AI-enabled threats, supply chain exposure and the potential for serious financial, operational and reputational harm. Boards and senior leaders should treat cyber security as a critical and growing business risk and ensure it receives appropriate governance attention.
Can directors be personally liable for a cyber breach?
Internationally, the trend is towards greater personal accountability for directors and officers in relation to cyber risk management and disclosure. Boards and senior leaders should keep cyber security under active governance, ensure appropriate expertise is available, and align risk management and disclosure practices to reduce both organisational and individual liability exposure.
Could a cyber-attack lead to a class action or shareholder claim?
Cyber incidents are increasingly likely to give rise to litigation risk, including class actions, shareholder claims and urgent applications to restrain the misuse or publication of stolen data. Boards should ensure their organisations are prepared to respond quickly, preserve evidence and make early decisions about legal strategy, disclosure and mitigation.
What cyber security regulations apply in New Zealand?
Cyber security and privacy compliance are becoming increasingly important areas of regulatory focus. Depending on their sector, organisations may be subject to reporting, notification and resilience obligations, alongside wider privacy and governance requirements. Before an incident occurs, boards and senior leaders should understand which obligations apply and how they would operate during a cyber incident.
What does good cyber governance look like?
Effective cyber governance requires more than technical controls. Boards and senior leaders should ensure cyber security is built into governance processes, supported by clear data oversight, tested controls, external assurance, staff training, supply chain management and appropriate insurance arrangements.
What should an incident response plan include?
A well-prepared incident response plan helps organisations make clear, coordinated decisions under pressure. Boards and senior leaders should ensure roles, escalation pathways, communications processes and post-incident review requirements are agreed, tested and understood before a cyber incident occurs.
Should a business pay a cyber ransom?
There is rarely a straightforward answer. Whether to pay a ransom is a business decision that requires careful consideration of legal, operational, regulatory, insurance and reputational factors. Organisations should have a clear governance framework for making these decisions before an incident occurs.
How should businesses manage communications during a cyber incident?
Communications during a cyber incident can become important evidence in regulatory investigations and litigation. Organisations should have clear processes for managing internal and external communications, preserving legal privilege and ensuring decision-making records are appropriately controlled.
How is artificial intelligence changing cyber risk?
AI is increasing the speed, scale and sophistication of cyber threats, while also creating new defensive opportunities. The same capabilities that make attackers faster can also make defenders faster, but only where strong cyber security fundamentals are in place. Boards and senior leaders that keep cyber security under active, well-resourced governance will be best placed to respond as AI continues to reshape the threat landscape.
Key questions every board or senior business leader should be asking
The handbook concludes with practical questions directors can use to assess organisational preparedness, including:
- Is cyber security a standing item on our board agenda?
- How confident are we that the board, collectively, has the cyber literacy required to oversee management effectively?
- What are our most critical systems and data assets, and how are they protected?
- When did we last test our incident response plan?
- Do we have a clear decision-making framework for responding to ransom demands?
- Are we managing cyber risk effectively across our supply chain and third-party relationships?
- Do we have appropriate cyber insurance in place?
- How do we ensure communications during a cyber incident are disciplined and legally protected?