This Week: Governance Sorted. Next Week: The Stuff That Could Actually Sink You
Week one of the Governance, Risk and Compliance series is done. If you missed it, or you’ve been meaning to sit down with it properly, here’s the quick version.
What We Covered This Week
The starting question was simple: who’s actually in charge of your business’s cyber security? Most small businesses can’t answer instantly, and that hesitation is itself the problem. Under the Companies Act 2006, company directors already carry a legal duty to exercise reasonable care, skill and diligence, and that duty increasingly covers cyber and data, whether or not you feel like a “computer person.”
The fix isn’t complicated. One page, four headings: who owns security, who decides on spending and software, who you ring in a crisis, and where the critical passwords live. Thursday’s how-to guide walked through exactly how to build that page in about 45 minutes, and Tuesday’s data deep-dive showed why regulators consistently treat documented decisions more favourably than businesses that show no evidence of having thought about the risk at all.
Friday’s case study looked at a UK legal firm fined £60,000 after a ransomware breach, where the regulator specifically called out a 43-day delay in reporting as an aggravating factor in its own right, not just the underlying technical failure.
If You Haven’t Started Yet
There’s no penalty for starting late. Pull up Monday’s episode and companion piece this weekend, and give yourself the same 45 minutes Thursday’s guide describes. The one-page governance sheet is the foundation everything else in this series builds on, so it’s worth having in place before next week.
What’s Coming Next Week
Next week we move to risk. You cannot protect against everything, and trying to is how businesses end up spending money on the dramatic, rare threat while leaving the boring, likely one wide open. We’ll walk through five plain questions that surface your business’s genuine top risks, and the four honest responses available for each one: treat it, tolerate it, transfer it, or terminate it.
How to Turn This Into a Competitive Advantage
Following this series in order, one document at a time, gives you a complete, evidence-backed governance and risk process by the end of the month, well ahead of most competitors your size.
How to Sell This to Your Board
The entire series asks for roughly an hour of focused effort per week. Four weeks, four hours, for a documented governance, risk and compliance programme that most businesses ten times your size cannot currently produce.
What This Means for Your Business
- Finish your governance one-pager this weekend if you haven’t already, using Thursday’s step-by-step guide.
- Block out an hour next Monday and Tuesday to work through the risk assessment material as it’s published.
- Keep this week’s page somewhere you’ll actually find it again, since next week builds directly on it.
| Source | Article |
|---|---|
| NCSC | Small Business Guide: Cyber Security |
| legislation.gov.uk | Companies Act 2006, Section 174 |