Nobody's in Charge of Your Cyber Security, and You Won't Find Out Until It's Too Late

Podcast

Nobody's in Charge of Your Cyber Security, and You Won't Find Out Until It's Too Late

There’s a certificate on Dave Kessler’s office wall right now. Gas Safe registered. Every engineer’s ticket current. Insurance sorted. Ask him who’s in charge of keeping a boiler safe and he’ll answer before you finish the question.

Ask him who’s in charge of his company’s cyber security and he laughs. “We’re a heating firm, mate. We’re too small for all that.”

That answer is the trap. Not because Dave is careless. Because he’s exactly the opposite, and he still doesn’t see it applies to his laptop.

Governance Is One Question, Not a Department

The cybersecurity industry has turned “governance” into a word that sounds like it belongs to a corporation with a legal team and a coat of arms. It doesn’t. Strip away the jargon and governance answers one question: who decides?

When something goes wrong, who makes the call? When there’s money to spend on security, who signs it off? When someone on the front desk gets a strange email asking them to move money, who do they check with?

In most small businesses, the honest answer is the owner. One person decides the passwords, who gets a laptop, whether to pay for proper antivirus or make do with whatever came free with the machine. That feels efficient. One brain, no meetings, no committee.

It’s also not a system. It’s a person. People go on holiday. People get flu. People break a leg on a nursery slope in the French Alps during their first ever ski trip, and end up in hospital for a week while the business back home hits the last Friday of the month with no accounts software workaround, no supplier number, and nobody who knows where the passwords live.

That is not a technology failure. The computers work fine. It is a governance failure: nobody ever decided what happens when the person who decides everything isn’t there.

The Law Does Not Care That You’re a Heating Firm

Here’s the part that should make every UK company director sit up straight. Company directors carry legal duties under the Companies Act 2006, which requires a director to exercise reasonable care, skill and diligence. That’s section 174. It isn’t a suggestion.

Most people assume this is about filing accounts on time and not trading while insolvent. It is. But it increasingly covers cyber and data too. A breach of this duty creates civil liability to the company, and in cases of gross negligence or sustained incompetence, a director can face disqualification proceedings lasting between two and fifteen years.

Sitting right alongside that: data protection. If your business holds information about people (and it does: customer names, addresses, card details, staff National Insurance numbers) UK data protection law applies to you, at your own scale, the same as it applies to a bank. The regulator is the Information Commissioner’s Office (ICO), and they have the power to investigate and fine.

None of this is here to frighten you. This show exists specifically because the industry does too much of that already. It’s here because it changes the maths. When security is “a cost,” it’s easy to keep pushing it to next month, forever. When you understand that you personally, as a director, carry the can if it goes wrong, it stops being optional. It becomes part of the actual job, same as your VAT return.

And here’s the reassuring part: regulators are consistently far kinder to a business that can show it took sensible steps and had a bad day, than to one that never gave the subject a moment’s thought.

What Governance Actually Looks Like for a 14-Person Firm

Enough theory. Governance for a small business comes down to four things: ownership, decisions, writing it down, and reviewing it.

Ownership. Somebody needs to own security. One named human, not “the team,” not “oh, IT sorts that.” If you outsource your IT support, understand the distinction that catches people out constantly: your IT provider can run the kit, but you still own the risk. When the ICO comes asking questions, they don’t ring your IT company. They ring you.

Decisions. A handful of basic calls, made once, calmly, instead of invented fresh under pressure. Who’s allowed to install software on work laptops? Who can approve spending on a new tool? And the one everybody forgets: what happens when someone leaves the business? Who cuts off their access, and when?

Writing it down. Not a hundred-page policy binder nobody will ever read. That’s not governance, that’s compliance theatre, and we’ll take a flamethrower to that particular topic in a couple of weeks. What you actually need is one side of A4: who owns security, who decides what, who you ring in a crisis, and where the critical passwords live. That’s the whole document.

Reviewing it. Governance isn’t a plaque you frame once. Put a recurring reminder in the calendar, every three months, and spend ten minutes asking “still true?” That habit is the entire difference between a system and a folder of good intentions.

The Story That Makes It Real

Here’s what that one page is worth on an ordinary Tuesday morning. An email lands from a regular supplier: same logo, same friendly tone, an invoice attached, asking for payment to a “new” bank account. Everything about it looks right, because someone has done their homework, copied the branding, and is about to redirect several thousand pounds into their own pocket.

This is invoice fraud, sometimes called mandate fraud, and it is one of the most common ways small firms lose real money. There’s no hooded figure and no dramatic warning. Just a polite email on a busy morning.

But if the one page exists, and it says plainly that “changes to supplier bank details are always checked by phone, on the number we already have, never the number in the email,” the person opening that invoice doesn’t need to be certain it’s a scam. She just has to follow the rule. A phone call to the old, trusted number confirms nothing has changed, and the money stays exactly where it belongs.

What actually saved that money wasn’t clever software. It was a decision made in advance, on a calm day, written on one page. That’s the entire point of governance in a single story.

How to Turn This Into a Competitive Advantage

Clients, insurers, and bigger partners are increasingly asking small suppliers to prove they take security seriously before signing a contract. A business that can produce a clear one-page governance statement on request looks materially more credible than a rival who goes quiet when asked “who’s in charge of this?”

  • Win the tender question first. Procurement questionnaires increasingly ask who owns security at your organisation. A one-line, confident answer beats a paragraph of waffle.
  • Turn staff departures into a strength. A documented leaver process (revoking access on the day someone leaves, not months later) is exactly the kind of detail that reassures a nervous client or insurer.
  • Make your outsourced IT relationship a selling point. Being able to say clearly “we own the risk, our provider manages the controls” shows a level of maturity many similarly sized competitors cannot demonstrate.

How to Sell This to Your Board

If you need to make the case for spending even a modest amount of time on this, three arguments land consistently:

  1. Personal liability is real. Section 174 of the Companies Act 2006 applies to every director, regardless of technical background. This is not a hypothetical risk confined to large corporations.
  2. The ICO treats preparation as a mitigating factor. A business that can demonstrate sensible, documented decisions fares better under regulatory scrutiny than one that cannot.
  3. It costs almost nothing. The one-page governance sheet described here costs a sheet of paper and roughly an hour of a director’s time. Compare that to the cost of a single successful invoice fraud.

What This Means for Your Business

  1. Name an owner, out loud, this week. Say “I own our security” to at least one other person in the business, or formally hand that ownership to someone else and confirm they’ve accepted it. Unacknowledged ownership isn’t ownership.
  2. Start your one page. Four headings: who owns security, who decides what, who you ring in a crisis, where the critical passwords live. Fill in what you can. The gaps you can’t fill are your to-do list.
  3. Put a quarterly reminder in the calendar today. Call it “GRC review.” Ten minutes, four times a year, asking whether the page is still accurate.
  4. If you outsource IT, clarify who owns the risk. Confirm in writing that your provider manages controls, while ultimate accountability sits with a named person inside your business.
  5. Check your leaver process. Confirm access is removed on the employee’s last day, not whenever someone remembers to do it.

Do those five things and you will have more genuine governance in place than a great many companies ten times the size of a 14-person firm. That is not an exaggeration. It costs the price of a sheet of paper.

SourceArticle
legislation.gov.ukCompanies Act 2006, Section 174: Duty to exercise reasonable care, skill and diligence
NCSCCyber Security Board Toolkit
ICOUK GDPR guidance and resources
ICOReport a breach
LegalClaritySection 174 Companies Act: the duty to exercise reasonable care
Action FraudInvoice and mandate fraud

Filed under

  • smb-security
  • uk-business
  • executive-security
  • business-risk
  • social-engineering
  • compliance-failure