How to secure board engagement in strategic cyber discussions

Businesses that do not invest in cybersecurity face the risk of huge financial and reputational damage.

The pandemic has raised the threat of cyber attacks for businesses. Many reports show an alarming increase in incidents in the last year, with the attack methods of cybercriminals becoming increasingly sophisticated. Despite this, boards are still not taking the initiative when it comes to cybersecurity.

With this in mind, Ash Patel, Head of Cyber at ECI Partners, the leading growth-focused mid-market private equity firm, who advises the boards of the portfolio on how to identify and understand the scale of the cyber risks they face, shares his thoughts on how businesses can mitigate the cyber risks facing their operations.

Why CEOs should care?

Four in 10 businesses suffered a breach or attack last year; of those, more than a third reported negative impacts, ranging from financial loss to business disruption. However, the consequences of a cyber attack go well beyond that, businesses could face:

  • Loss of crucial intellectual property to a rival, allowing them to secure a competitive advantage
  • Punitive regulatory sanctions with fines of up to 2% of a company’s global revenues, as mandated under the General Data Protection Regulation (GDPR)
  • Reputational damage and loss of customer revenue with more than one in four consumers stating they would stop doing business with a company following an incident compromising their data security or privacy

Ash Patel, Head of Cyber at ECI Partners, comments: “The financial and reputational fallout from a cyber attack can create huge problems for mid-sized businesses. And with cybercrime showing no signs of slowing down, it’s imperative that businesses understand the threat and are proactive in mitigating the dangers.”

“Tackling these risks is not a one-size-fits-all approach. Businesses need to identify the gaps in their own cybersecurity defences, make their own decisions about acceptable risks, and find the right strategies to counter them.”

How CTOs can push cybersecurity up the board agenda

In order to truly protect the business from breaches and attacks, it’s important that the board makes cybersecurity a priority. CTOs have a responsibility to make this happen, and the best way of achieving this is:

  1. Talk to boards in the language of the business
    Technical IT jargon is far less likely to resonate strongly with the board than a discussion about how cyber attacks threaten the business’s value story.
  1. Focus on future proofing as well as today’s operations
    It is important to not overlook the threat that cyber poses to innovation. Boards’ efforts to pursue a digital agenda may be undermined by cyber risk if it is not properly understood and planned for.
  1. Concentrate on areas of weakness
    Conducting cyber gap analysis, which focuses on the areas of risk where controls are often weaker and take steps to mitigate these specific risks. For example, the human link is often one of the weakest, so firms should invest in regular staff training to mitigate these
  2. Learn from experience
    Spend time discussing incident reports with the board, focusing in particular on what the company has learned – and what is required to prevent a reoccurrence of that type in the future
  1. Agree on targets and monitoring
    With a set of key performance indicators included in each board pack, the board will have a clear view of how the company is performing and where they might need to divert more resource to

Ash Patel continues: “Cybersecurity, and the risk management associated with it, is and should be a board-level responsibility. For businesses that don’t have their own cyber team or specialist, it falls to the CTO to work with the board, to educate them on the risks, strategy, performance indicators and reporting.”

“Once CEOs and the board have a full grasp of cyber in context of their business, they will be better equipped to not only protect against and properly handle potential attacks, they will also be able to pursue the business’s digital transformation and growth priorities.”

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Amber Donovan-Stevens

Amber is a Content Editor at Top Business Tech

TPIs are the Future of Energy Solutions

David Sheldrake SVP POWWR • 19th June 2025

The energy industry is undergoing a transformation, and Third-Party Intermediaries (TPIs), those brokers and consultants who help businesses procure energy, are at the centre of it. With growing complexity, increasing regulation, and evolving customer expectations, the role of TPIs is shifting from price-focused brokers to strategic energy advisors. While renewable energy adoption continues to reshape...

Quick Commerce and the Retail Media Revolution

Sue Azari • 11th June 2025

Quick commerce has transformed the way consumers shop, redefining convenience with near-instant delivery of groceries, meals, and household essentials. However, beyond its impact on logistics and e-commerce, quick commerce is now emerging as a major force in digital advertising. As consumer behaviours shift toward on-demand purchases, these platforms are leveraging their vast first-party data and...

Is It Time for a VMware Alternative?

Wind River • 22nd May 2025

Companies have options when it comes to replacing VMware as their cloud platform, to address rising costs, support concerns, and a shrinking partner ecosystem. If you are ready to contemplate a different vendor, here are five reasons why Wind River Cloud Platform should be on your short list of VMware alternatives.

AI Leads as VivaTech Unveils Top 100 Startups

Viva Technology • 14th May 2025

Viva Technology has unveiled the first edition of its “Top 100 Rising European Startups for 2025,” spotlighting the most promising young companies shaping Europe’s tech future. Germany, France, and the UK lead the ranking, which highlights high-growth startups across 13 countries. Artificial intelligence dominates the list, with 15 companies spanning AI agents, models, and infrastructure....

Birmingham Unveils the UK’s Best Emerging HealthTech Advances

Kosta Mavroulakis • 03rd April 2025

The National HealthTech Series hosted its latest event in Birmingham this month, showcasing innovative startups driving advanced health technology, including AI-assisted diagnostics, wearable devices and revolutionary educational tools for healthcare professionals. Health stakeholders drawn from the NHS, universities, industry and front-line patient care met with new and emerging businesses to define the future trajectory of...

Why DEIB is Imperative to Tech’s Future

Hadas Almog from AppsFlyer • 17th March 2025

We’ve been seeing Diversity, Equity, Inclusion, and Belonging (DEIB) initiatives being cut time and time again throughout the tech industry. DEIB dedicated roles have been eliminated, employee resource groups have lost funding, and initiatives once considered crucial have been deprioritised in favour of “more immediate business needs.” The justification for these cuts is often the...