Arcanum’s Festive Stories – Missing from the Table: Bah Humbug in the Boardroom

Arcanum’s Festive Stories – Missing from the Table: Bah Humbug in the Boardroom

In the sixth of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.

It was the best of times for hackers, the worst of times for Boards.  In this year of our Lord, 2025, the grand boardrooms of the United Kingdom, some presiding over the very sinews of the nation’s infrastructure, remain curiously insensible to the perils of the age: cyber risk.  The matter, once the province of the IT under-clerks, has grown into a veritable spectre haunting the corridors of power, yet too many a Board, with a shrug and a sigh, consigns it to the realm of “someone else’s problem.” The result? A parade of calamities, each more preventable and mortifying than the last.

 

Let us, dear reader, consider the numbers, for numbers, like ghosts, do not lie.  In the year just past, the United Kingdom suffered no fewer than 204 cyberattacks of national significance, a ghastly increase of 48% over the previous annum.  Yet, only 29 in every hundred firms possess a cyber risk programme that aligns with the business’s true priorities.  And a mere one in five Boards dare declare their cyber practices “very mature.” The remainder? They cast their lots with Fate, rolling a weighted dice and hoping for the best.

 

Permit me to recount a tale most recent and grievous.  At Jaguar Land Rover, a villainous ransomware halted the great engines of industry for five weeks, laying waste to £1.9 billion of the nation’s wealth.  The irony? The company had secured an £800 million contract for cybersecurity, yet Board-level vigilance was nowhere to be found, Missing In Action, as the military men say.  Vendor governance and incident response? Alas, not fit for purpose.

 

Nor was this the only misadventure.  The notorious Scattered Spider gang sashayed into Marks & Spencer by way of a third-party helpdesk, absconding with £300 million and erasing £750 million from the market’s ledger.  The Board, never having rehearsed a cyber crisis, was caught as flat-footed as Mr.  Pickwick at a masquerade.

 

The litany continues: In 2023, Capita’s languid response to ransomware exposed the pension and NHS data of countless souls, earning a £14 million rebuke from the Information Commissioner.  The British Library, too, fell victim, its services silenced for months, the cost of recovery exceeding £600,000 and Board-level planning found sorely wanting.  Even the Electoral Commission, guardian of democracy, was not spared; in 2021, attackers filched sensitive voter data, exposing a lamentable want of cyber awareness at the very heart of the nation’s governance.

 

Why, then, do Boards persist in their slumber? They see cyber as a technical nuisance, not a strategic imperative; they fear the exposure of their own governance gaps; they cling to outmoded playbooks and insurance policies and, worst of all, regard cybersecurity as a discretionary expense, to be trimmed when times are lean.  And lean they are, dear reader, which may explain the rising tide of attacks.

 

As one independent director, wise in the ways of the world, observed:

If cybersecurity isn’t on the board calendar, it won’t get the attention it deserves.” Or, as the sage Mr.  Malone of KPMG warns: “Rapport isn’t built in a crisis.  CISOs must engage the Board before calamity strikes.”

 

But lo! The law is stirring.  The government’s Cyber Security and Resilience Bill threatens to arm regulators with sharper teeth and to designate more critical suppliers.  Ministerial missives now land upon the desks of the FTSE 350, urging adoption of the Cyber Governance Code of Practice.  The NCSC, that vigilant sentinel, calls for Boards to enrol in its Early Warning Service and to conduct regular tabletop exercises.

 

What, then, must be done? Cybersecurity must be woven into the very fabric of Board governance, no more box-ticking.  Tabletop exercises must become as regular as the Board’s own repasts.  Cyber risk must be translated into the language of pounds and pence, not mere technical jargon.  True collaboration must flourish between CISOs, operations and the Board itself.

 

For in the end, the bottom line is no longer a matter of theory.  The cost of Boardroom indifference is measured in millions.  Boards must awaken, casting off the mantle of passive observer to become active stewards of cyber resilience.  Upon their vigilance rests the future of many a business.

 

For further reading: the NCSC Annual Review 2025, Cyber Governance Code of Practice.

Read more as part of the Arcanum Festive Stories series:

Arcanum’s Festive Stories – A Dickensian Tale of Cyber Peril in the Age of Legacy

Arcanum’s Festive Stories – Don’t Wait for the Ghost of Breaches Past – Incident Response Readiness

Arcanum’s Festive Stories – Fagin’s Digital Pickpockets – The Art of Phishing & Social Engineering

Arcanum’s Festive Stories – Ghosts in the machine: Shadow IT

Arcanum’s Festive Stories – Great Expectations, Grim Realities: Outsourcing to your MSP