Cybersecurity Skills: The New Priority in NED Recruitment

Cybersecurity Skills: The New Priority in NED Recruitment

By Adrian Lawrence FCA, founder of NED Capital · Part of the Board Governance Hub

In short: As cyber risk has climbed the board agenda, cybersecurity capability has become something boards actively recruit for — but recruiting for it well means understanding what it actually is at board level. It is not technical delivery skill: a non-executive does not run security, configure defences or lead incident response, any more than a finance NED does the bookkeeping. What a board needs is the capability to oversee cyber competently — to ask the right questions, judge whether management’s approach is sound, treat cyber as a business and board risk rather than an IT problem, and gain genuine assurance. For most boards the goal is not to parachute in a deeply technical specialist but to ensure the board collectively is cyber-literate enough to oversee the risk, ideally with at least one member who brings real depth. Getting the recruitment right starts with an honest skills audit, a role defined around oversight rather than delivery, and assessing candidates on judgment and the ability to translate cyber for the board — not on the length of a technical CV.

Cybersecurity has moved from a technical afterthought to a standing board concern, and with it has come a clear shift in what boards look for when they recruit: cyber capability is increasingly named as a priority in non-executive searches. This article is about how to approach that recruitment well — what cyber capability means for a board member, whether you need a specialist, and how to assess it. It concerns board composition and hiring; the separate question of why this demand has risen so sharply is taken up in why boards now demand NEDs with cyber risk expertise, and how a board actually oversees cyber day to day in the growing responsibilities of NEDs in cybersecurity oversight.

A Cyber Specialist, or a Cyber-Literate Board?

The first question a board should ask is the one most often skipped: do we actually need a cybersecurity specialist on the board, or do we need a board that is collectively cyber-literate? The distinction matters, because it points to quite different recruitment decisions. The instinct, when cyber rises up the agenda, is to reach for a deep technical expert — a former chief information security officer or similar. Sometimes that is right, particularly for businesses where cyber is existential: a bank, a critical-infrastructure operator, a large data-holding platform may genuinely benefit from a non-executive with serious technical depth. But for many boards it is the wrong target. A single deeply technical specialist can end up as the person everyone else defers to, which paradoxically weakens oversight: the rest of the board switches off on cyber, treats it as “handled”, and the collective challenge that good governance depends on evaporates. What most boards actually need is broad cyber-literacy — enough shared understanding across the whole board that cyber can be discussed, questioned and overseen by the board as a body — perhaps complemented by one member with real depth, but not substituted by them. Framed this way, the recruitment question becomes richer than “find us a cyber expert”: it is about how to lift the board’s collective capability, of which a specialist appointment is only one possible lever, alongside development for existing directors and better assurance from management and advisers. Answering it well is the foundation of getting the rest of the recruitment right.

What “Cyber Capability” Means for a NED

The second thing to get right — and the one the market most often gets wrong — is what cyber capability actually means in a board member, because it is not what a technical job description would suggest. A non-executive is not there to implement security controls, architect defences, run the security operations centre or lead the technical response to a breach. All of that is management’s job, delivered by the executives and the security function. The non-executive’s capability is one of oversight: the ability to hold that management activity to account. Concretely, that means being able to ask the questions that reveal whether the organisation’s cyber posture is genuinely sound rather than merely reassuring on paper; to judge whether management’s assessment of the risk is realistic; to understand cyber as a business and board-level risk — one that bears on strategy, resilience, reputation and regulatory standing — rather than as a narrow IT matter to be delegated and forgotten; and to seek independent assurance rather than taking comfort from management’s own account alone. This is the same oversight-not-execution principle that governs every part of the non-executive role, and it applies to cyber exactly as it does to finance: a finance NED need not do the accounting, but must be able to read the numbers and challenge them, and a cyber-capable NED need not run security, but must be able to interrogate it. This reframing has a direct bearing on recruitment, because it changes who you are looking for: not necessarily the most technically expert candidate, but the one who can turn whatever technical understanding they have into effective board-level oversight and challenge. How this oversight works in practice sits within the board’s wider risk role, covered in the role of non-executive directors in corporate risk management.

How to Recruit and Assess for It

With those two questions settled, the practical recruitment becomes far more focused. Begin with an honest board skills audit: map what cyber understanding the board already has, where the genuine gaps lie, and what the specific business actually needs given its risk profile, so that any appointment addresses a real deficiency rather than a vague sense that the board ought to have “someone on cyber”. A structured skills audit before hiring, discussed in how to conduct a board skills audit before hiring a NED, turns a fashionable priority into a precise brief. Then define the role around oversight rather than delivery: the appointment should be described in terms of the judgment, challenge and assurance the board needs on cyber, not as a quasi-executive security post, which both attracts the right candidates and deters those who would try to operate rather than oversee. When you assess candidates, weight judgment and communication as heavily as technical background: the most valuable cyber-capable non-executive is often not the deepest technologist but the person who can translate cyber risk into terms the whole board understands, ask the questions that expose weak assurance, and raise the board’s collective literacy rather than becoming its single point of dependence. Test for this directly — ask candidates how they would help a non-technical board oversee cyber, not merely what they know about the latest threats. And be realistic about the market: genuinely board-ready cyber talent, combining real understanding with governance judgment, is in short supply and much in demand, so a well-defined brief and a search that looks beyond the obvious technical CVs will serve a board far better than a scramble for a marquee name. Approached this way, recruiting for cyber capability stops being a box-ticking exercise and becomes what it should be — a deliberate strengthening of the board’s ability to oversee one of its most important risks. At NED Capital we help boards define and fill exactly these briefs, including through our technology non-executive recruitment practice. Every search is led personally by Adrian Lawrence FCA, a Fellow of the ICAEW and former listed-company finance director.

About the author

Adrian Lawrence FCA is the founder of NED Capital and a Fellow of the Institute of Chartered Accountants in England and Wales (ICAEW), holding an ICAEW practising certificate in his own name. A former listed-company Finance Director, he holds a BSc from Queen Mary College, University of London and has over 25 years of experience working with boards, investors and business owners across the UK. He founded NED Capital to help boards define the capabilities they genuinely need — on cyber and across the board’s work — and find the non-executives to match. He personally leads every search.

Related Reading & Services

NED Capital helps boards recruit for the capabilities they genuinely need. Every search is led personally by Adrian Lawrence FCA.

Building Cyber Capability Into Your Board?

Whether you need a cyber-literate generalist, a specialist with real depth, or help defining what your board actually requires, we can help. Every conversation is confidential and led personally by Adrian Lawrence FCA.

Start a confidential conversation

NED Capital | Sister practice of FD Capital | ICAEW practising certificate held by Adrian Lawrence FCA.