Date Posted: Friday, 7th August 2026
Ask most leadership teams whether information security matters and the answer will be yes. The more useful question is what happens next.
The UK Government's Cyber Security Breaches Survey 2025/2026 found that 72% of businesses considered cyber security a high priority for senior management. Yet only 31% had a board member with explicit responsibility for it. Just 30% had carried out a cyber security risk assessment in the previous 12 months, and only 25% had a formal incident response plan.
That gap matters. There is a real difference between believing information security is important and building an organisation that is genuinely prepared to manage the risk.
An organisation takes information security seriously when cyber risk is treated as a business risk rather than an IT responsibility.
That does not mean eliminating every possible vulnerability. No organisation can remove cyber risk entirely, and trying to would quickly become impractical. As security professionals often point out, security ultimately has to serve the business. Leadership needs to decide what level of risk it is willing to accept, provided that decision is informed rather than accidental.
The National Cyber Security Centre (NCSC) takes a similar governance-led approach. Its Cyber Governance Code of Practice is built around five areas: risk management, strategy, people, incident planning and recovery, and assurance and oversight. Crucially, the guidance is aimed at boards and directors, not just security teams.
In practice, an organisation taking security seriously should be able to demonstrate:
The key word is demonstrate. A policy document or a security product is evidence that something has been purchased or written. It is not evidence that the organisation would respond effectively under pressure.
One of the clearest indicators is accountability.
Who can ultimately make decisions about cyber security risk? Who can accept that risk, authorise investment, or challenge the organisation when known vulnerabilities remain unresolved? If the answer is simply "IT", responsibility probably isn't clear enough.
The Government's latest survey found that only 31% of UK businesses had a board member responsible for cyber security, a figure that rises considerably with business size, from 29% of micro businesses to 68% of large ones.
Board ownership doesn't mean directors need to become security engineers. It means they need enough understanding to challenge assumptions, evaluate risk and make informed decisions. The NCSC describes cyber risk as a principal business risk and says boards have a critical responsibility for governing it effectively.
A serious information security conversation shouldn't begin with the number of attacks blocked last month. It should start with the things the organisation cannot afford to lose, which might include:
Grant Thornton made a useful distinction in its original discussion of this issue: organisations cannot keep pace with every possible threat, so they need to identify what represents the greatest danger to the business and prioritise protection accordingly. That remains the better way to think about information security.
A cyber risk register listing dozens of technical vulnerabilities is useful to specialists. A board needs to understand what those vulnerabilities could actually mean for revenue, operations, customers, regulatory obligations and reputation.
There is a difference between fixing vulnerabilities and managing risk. A mature organisation understands its exposure before an incident forces the issue.
Yet only 30% of UK businesses reported conducting a cyber security risk assessment during the previous year, and penetration testing was even less common, at 13%. The appropriate level of testing naturally varies by organisation; a small professional-services firm doesn't need the same security programme as a multinational bank. What matters is whether the level of scrutiny matches the risk.
A serious organisation should know:
Security stops being serious the moment unresolved risks quietly disappear into a backlog.
People are routinely described as the "weakest link" in cyber security, but that description can be too simplistic. If employees haven't been trained properly, systems are difficult to use securely, or business processes push people to work around controls, the problem is organisational rather than individual.
This is another area where stated priority and actual practice diverge. Only 19% of UK businesses reported providing cyber security training or awareness activities in the previous 12 months, though the figure rises to 84% among large businesses.
A stronger security culture goes beyond an annual phishing test. Developers, finance teams, administrators, executives, customer-service staff and new starters don't necessarily need the same training, and the stronger organisations make secure behaviour part of normal operations rather than an annual compliance exercise.
A security incident is a bad time to establish who has decision-making authority. Who shuts a critical system down? Who contacts customers, insurers or regulators? Which services need restoring first, and how does the business operate while systems are unavailable? Those questions need answers before the incident, not during it.
Only a quarter of UK businesses currently report having a formal cyber incident response plan. Among large organisations the figure is much stronger, at 76%, but that still doesn't tell us whether those plans have actually been rehearsed.
The NCSC recommends defined incident responsibilities, clear escalation processes and preparation for recovery as part of effective cyber governance. A plan stored somewhere on SharePoint is not resilience. The organisation needs to know whether it can actually use it.
Organisations increasingly rely on cloud platforms, software providers, consultancies and outsourced partners, which means somebody else's weakness can quickly become your problem.
Despite this, only 15% of UK businesses said they formally reviewed cyber risks from their immediate suppliers, and just 6% reviewed risks further into their supply chain. Even among large businesses, only 48% reviewed immediate suppliers and 24% considered the wider supply chain.
Taking information security seriously means understanding which third parties could materially affect your organisation. Useful questions include:
Supplier security can't stop at a questionnaire completed during procurement.
Security strategies don't implement themselves, which is where the people question becomes important.
The Government's UK cyber security labour-market research estimates that 49% of businesses have a basic technical cyber security skills gap, around 30% have an advanced technical skills gap, and 32% lack the confidence to deal with a cyber security incident without outsourcing that capability.
That distinction matters. The issue isn't simply whether the UK has enough people working in cyber security, a workforce the same research estimates at around 143,000. The harder question is whether each organisation has the right combination of skills, experience and authority for its particular risk profile. A business might need stronger:
Hiring more people without understanding the capability gap won't necessarily improve security.
There is a final difference between organisations that take security seriously and those that simply employ somebody with "security" in their title: authority.
A Head of Information Security or CISO can identify risks, recommend controls and build a strategy, but they cannot create organisational commitment on their own. Strong security leaders need access to senior decision-makers, clarity over their mandate, and the ability to challenge business decisions when the risk justifies it.
A CISO becomes particularly relevant where an organisation is facing:
The best CISO isn't simply the most technical candidate available. The role increasingly requires someone who can translate complex security problems into decisions that executives can understand and act on. That's one reason senior information security hiring can be difficult: businesses sometimes search for technical breadth, regulatory knowledge, leadership, incident experience, commercial judgement and board communication in one person, without first deciding which problem they actually need that person to solve.
Need to strengthen your cyber security team? Explore TRIA's technology recruitment solutions.
Individual weaknesses don't automatically indicate a poor security culture; priorities vary according to risk, size and resources. Patterns are more revealing. Warning signs include:
The frustration behind these problems is visible in security communities too. Practitioners regularly describe raising the same vulnerability repeatedly, only to see it deferred because another upgrade or migration is supposedly around the corner. That's anecdotal rather than a measure of the wider market, but it illustrates exactly the organisational behaviour that stronger governance is designed to prevent.
If you want to understand how seriously your organisation treats information security, start with ten questions:
If the organisation can't answer most of those questions confidently, buying another security product is unlikely to be the first problem worth solving. Governance probably is.
There will always be vulnerabilities. There will always be new technology, new attackers, and decisions where stronger security conflicts with cost, speed or convenience. Taking information security seriously isn't about refusing those trade-offs; it's about making them consciously.
The strongest organisations know what matters, understand where they're exposed, assign accountability, build the right capability and test whether their plans actually work. They also give security leaders enough authority to influence the business, rather than leaving them to document problems that nobody intends to resolve.
That's when information security stops being something an organisation says is important, and becomes something visible in the way it actually operates.
What is information security? Information security is the practice of protecting an organisation's information from unauthorised access, alteration, loss or disruption. It includes technology, but also covers people, processes, governance, physical security and how information is handled throughout the organisation.
What is the difference between information security and cyber security? The terms overlap but aren't identical. Cyber security focuses primarily on protecting digital systems, networks and data against cyber threats. Information security is broader and covers information regardless of whether it's digital, physical or communicated in another form.
Who should be responsible for cyber security? Operational responsibility may sit with a CISO, Head of Information Security, CIO, CTO or another technology leader, depending on the organisation. Ultimate governance of material cyber risk should involve senior leadership and the board; the NCSC specifically identifies cyber security governance as a responsibility requiring board-level ownership.
As a founder of TRIA, Harriet is proud of the company's impact in transforming recruitment through strategic insight and deep market understanding. Her leadership style is characterised by a focus on sustainable growth and the development of long-term client relationships.
Connect on LinkedIn