Why Boards Now Demand NEDs with Cyber Risk Expertise
By Adrian Lawrence FCA, founder of NED Capital · Part of the Board Governance Hub
In short: Boards now actively seek cyber capability in their non-executives for three connected reasons. First, cyber has become a board-level risk rather than an IT problem: a serious incident can threaten a company’s finances, reputation, operations and customer trust all at once, which makes it a principal risk the board must oversee. Second, accountability has moved to the board itself — regulators, investors and the law increasingly expect directors to be genuinely across cyber, and treat weak oversight as a governance failure rather than a technical mishap, so it is no longer something a board can delegate and forget. Third, the threat and the stakes keep rising, as attacks grow more frequent and sophisticated and the cost of getting it wrong climbs. Together these mean a board can no longer treat cyber as a niche matter for the technology team; it needs the capability to oversee cyber properly — which is why cyber expertise has become a recruitment priority. Crucially, the demand is for oversight capability, not for a director to run security themselves.
A decade ago, cyber risk was rarely a boardroom preoccupation; today it is one of the risks non-executive searches most often name. Understanding why that shift has happened matters, because it explains what boards are really looking for — and it is not what many assume. This article sets out the drivers behind the demand. It concerns why boards now want cyber capability; the practical question of how to recruit and assess for it is taken up in the companion piece, cybersecurity skills: the new priority in NED recruitment.
Cyber Became a Board-Level Risk, Not an IT Problem
The first and most fundamental driver is that cyber risk has migrated from the server room to the boardroom, because its consequences are no longer contained within the technology function. A serious cyber incident today is rarely just a technical inconvenience; it can halt operations, expose sensitive data, trigger regulatory scrutiny, drain finances through remediation and lost business, and inflict lasting damage on a company’s reputation and the trust of its customers. When a single event can threaten the whole enterprise in that way, it stops being an operational IT matter and becomes a principal risk to the business — and principal risks are the board’s responsibility to oversee. This is why cyber now sits squarely within the board’s remit for risk and internal control: just as a board must satisfy itself that financial or operational risks are being properly managed, it must now do the same for cyber, forming its own view of whether the organisation’s exposure is understood and its defences adequate. That oversight duty is precisely what a board cannot discharge if not one of its members can engage credibly with the subject. The board does not need to become a team of security engineers, but it does need to be able to ask the right questions, judge the answers, and avoid being wholly dependent on the very executives it is meant to be overseeing. How cyber fits within the board’s wider risk role is set out in the role of non-executive directors in corporate risk management, and the ongoing oversight task in the growing responsibilities of NEDs in cybersecurity oversight.
Accountability Has Moved to the Board
The second driver is a shift in where accountability for cyber now rests. It is no longer acceptable — to regulators, to investors, or increasingly in law — for a board to treat cyber as something delegated entirely to management and beyond directors’ concern. Regulatory expectations around cyber oversight and disclosure have tightened across many sectors, and where a serious incident occurs, scrutiny now reaches the board: the question asked is not only what the technology team did, but what the directors knew, what they had asked, and whether they had exercised proper oversight. Investors, too, increasingly probe how seriously a board takes cyber, viewing weak oversight as a governance red flag that bears on the quality of the board itself. The effect is to raise the personal stakes for directors: cyber oversight has become part of what it means to discharge their duties competently, and being demonstrably out of their depth on a risk of this significance is no longer a comfortable position to occupy. This accountability shift is a powerful spur to recruitment, because a board that knows it will be judged on its cyber oversight has every reason to ensure it has the capability to exercise that oversight well — and to be seen to have taken the risk seriously in how it composed itself. The danger of leaning too heavily on management’s own reassurances, rather than exercising genuine independent oversight, is explored in the risks of relying too heavily on executive assurances.
The Threat and the Stakes Keep Rising
The third driver is simply that the problem keeps getting harder. The cyber threat facing organisations has grown more frequent, more sophisticated and broader in its reach: attackers are better resourced and more inventive, the tools available to them have advanced, and the attack surface has widened as businesses have become more digital, more connected and more dependent on complex chains of third-party technology. At the same time the potential cost of a serious incident has climbed, whether measured in operational disruption, regulatory consequences, or the erosion of hard-won trust. A board might once have judged, not unreasonably, that cyber was a specialist concern it could safely leave to others; that judgment is far harder to defend when the threat is this material and this dynamic. The moving nature of the risk matters as much as its scale, because it means cyber cannot be understood once and set aside — it requires a board that can keep engaging with a changing picture, which in turn means having capability at the table rather than relying on occasional briefings. Taken together with the other two drivers, this is what has turned cyber capability from a nice-to-have into something boards actively recruit for. It is worth restating what that capability is and is not: boards are not seeking a director to run security, configure defences or lead the technical response to an incident — all of which remain management’s job — but one who can oversee that work with genuine understanding and independent challenge. That distinction, and how to recruit for it well, is the subject of the companion piece on cybersecurity skills as a recruitment priority. At NED Capital we help boards build exactly this capability, including through our technology non-executive recruitment practice. Every search is led personally by Adrian Lawrence FCA, a Fellow of the ICAEW and former listed-company finance director.
Why a Non-Executive, Specifically
One question sits underneath all three drivers and is worth drawing out: if cyber capability matters this much, why seek it in a non-executive director rather than simply hiring a stronger chief information security officer or expanding the security team? The answer goes to the heart of what a non-executive is for. Management — however capable — is the party being overseen; it builds the defences, reports on their effectiveness, and has an understandable interest in presenting the position favourably. The board’s role is to hold that account up to independent scrutiny, and it cannot do so credibly on cyber if it has no capability of its own and must take management’s word for everything. A non-executive with genuine cyber understanding gives the board something a strong security function cannot: an independent mind, owing no loyalty to the technology team’s past decisions, able to ask whether the reassurance the board is being given actually holds up. That is why the demand is specifically for board-level capability and not merely for better management. It is also why the capability boards seek is one of judgment and independence rather than hands-on technical delivery — the value lies precisely in being the overseer, not another member of the team being overseen. Recruiting for that is a distinct skill in itself, which is where the practical work of definition and assessment begins.
About the author
Adrian Lawrence FCA is the founder of NED Capital and a Fellow of the Institute of Chartered Accountants in England and Wales (ICAEW), holding an ICAEW practising certificate in his own name. A former listed-company Finance Director, he holds a BSc from Queen Mary College, University of London and has over 25 years of experience working with boards, investors and business owners across the UK. He founded NED Capital to help boards secure the capabilities they genuinely need — on cyber and across the board’s work — and personally leads every search.
Related Reading & Services
NED Capital helps boards build the capability to oversee cyber and other principal risks. Every search is led personally by Adrian Lawrence FCA.
Recruiting for Cyber
Building Cyber Capability Into Your Board?
Whether you need a cyber-literate generalist, a specialist with real depth, or help defining what your board actually requires, we can help. Every conversation is confidential and led personally by Adrian Lawrence FCA.
NED Capital | Sister practice of FD Capital | ICAEW practising certificate held by Adrian Lawrence FCA.
Adrian Lawrence FCA is the founder of NED Capital and a Fellow of the Institute of Chartered Accountants in England and Wales (ICAEW) and holds an ICAEW practising certificate in his own name. He holds a BSc from Queen Mary College, University of London, and has over 25 years of experience working with boards, investors and business owners across the UK. He founded NED Capital to connect businesses with the independent Non-Executive Directors they need to provide challenge, governance and strategic oversight — and personally leads candidate assessments for board-level appointments.