The governance frameworks that regulate how directors oversee cyber risk within their organisations have advanced significantly in recent years. What has advanced far more slowly is the conversation about the cyber risk that sits with directors personally.
These are not the same conversation. And conflating them has left a meaningful gap.
What the frameworks say
Across every major financial jurisdiction regulators have moved decisively to make cyber risk a board-level governance matter.
In the UK the Cyber Security and Resilience Bill, introduced to Parliament in November 2025 and progressing through the House of Lords with Royal Assent expected before year end, represents the most significant reform of the nation's cyber security framework since 2018. It mandates 24-hour incident reporting and empowers regulators to levy fines of up to £17 million or 4% of global turnover.
The NCSC's Board Toolkit is explicit: cyber security is a matter for the board itself, not something to be delegated entirely to management.
In Cayman, CIMA's Corporate Governance Rule, in force since October 2023, requires regulated entities to have documented frameworks for material operational risks including cyber. Directors are personally accountable for ensuring those frameworks exist and function.
In Luxembourg, DORA entered full application in January 2025, placing specific ICT risk management obligations on financial entities and the boards that govern them.
In Guernsey, the GFSC's Finance Sector Code expects boards to maintain effective oversight of operational resilience. The 2024 MONEYVAL evaluation specifically referenced the need for regulated businesses to demonstrate robust cyber and data governance.
In Singapore, MAS Technology Risk Management Guidelines place clear expectations on boards to provide effective oversight of technology and cyber risk.
The direction is consistent. Cyber risk is a board matter. Directors are accountable.
What the frameworks don't address
Every one of those frameworks addresses how directors govern cyber risk within their organisations. None of them address the cyber risk that sits with the director as an individual.
This distinction matters.
A corporate cyber security programme is built around a defined perimeter, corporate networks, corporate devices, corporate systems. It is staffed, monitored and maintained by people whose job it is to protect it.
A director sits outside that perimeter. By definition.
A director, whether non-executive or an executive holding external board appointments, generally has no corporate device issued for that role and therefore no managed endpoint, no corporate network, no IT support and no company security policy that applies to their personal setup.
They have personal devices, personal networks and personal email accounts through which some of the most sensitive information in the organisations they govern routinely passes.
Ponemon Institute's 2025 research found that 51% of organisations had experienced attacks specifically targeting executives or board members, up from 42% in 2023. GetApp's research from the same period puts the figure at 72% of senior executives targeted in the prior 18 months.
Directors are high-value targets. Not because they are technically vulnerable. But because of what they know. And the information they hold sits largely outside any corporate security perimeter.
The personal digital footprint of a director
Consider what a director's governance-related digital footprint actually looks like.
Board packs, typically distributed by administrators five to seven days before a meeting, are received by email either in PDF or through a link to an external portal, downloaded to personal devices and stored in personal document applications.
Meeting invitations, agendas, minutes and action logs arrive through personal inboxes.
Correspondence with fellow board members, with management and with regulators flows through personal email.
Fee arrangements, engagement letters and invoices are handled through personal systems.
And increasingly, governance-related documents are being processed through general-purpose AI tools for summarisation, drafting and research.
Together these create a governance data footprint that is largely unprotected, largely unmonitored and largely unconsidered.
The AI question
General-purpose AI tools have added a specific dimension to the director's personal cyber risk that most governance frameworks have not yet caught up with.
These tools are genuinely capable and widely used. The question is not whether they are powerful. It is whether they were built with the confidentiality standards that governance-sensitive information demands.
When a director uses a general-purpose AI tool to process a document containing unpublished financial results, a pending transaction or price-sensitive information, that document enters a third-party environment.
The data handling standards, retention policies and training data practices of general-purpose AI tools are designed for general use. They were not designed for the governance context.
The NACD's 2026 Director's Handbook on Cyber-Risk Oversight, the most authoritative annual guidance on this subject, is direct: confidential information input into a third-party AI tool can be retained, logged or reused by the vendor, resulting in potential loss of confidentiality.
This is not a reason to avoid AI. It is a reason to be deliberate about which AI to use.
What good looks like
The NACD's Personal Cybersecurity Protection Guide for Corporate Directors, published alongside the 2026 Handbook, sets out a practical baseline:
Maintain heightened awareness of phishing, vishing and social engineering, attacks that rely on human psychology rather than technical sophistication. Use secure, reputable services for board-related communications. Enable automatic updates on all personal devices. Use strong authentication including biometrics where available. Keep board-related communications and documents separate from personal digital life wherever possible.
These are not aspirational standards. They are the minimum expected of anyone handling the information that directors routinely handle.
Beyond the minimum the question is structural. The information a director holds demands a level of security that personal devices, personal email and general-purpose tools were not designed to provide. The corporate security programme protects the company. Nobody has built the infrastructure to protect the director.
Until recently that was simply the gap that existed. It no longer needs to.
The infrastructure behind MyDirector-OS
MyDirector-OS is built on infrastructure that meets the standards regulators, and institutional investors apply to the organisations directors govern, not the standards of a consumer application.
The platform is ISO 27001:2022 certified, the internationally recognised standard for information security management, applied consistently across the UK, EU, Crown Dependencies, Cayman Islands, Singapore, Luxembourg, Ireland, BVI, DIFC and ADGM. ISO 27001 is not jurisdiction-specific, it is the global benchmark, recognised and respected by regulators in every jurisdiction MyDirector-OS covers.
It is SOC 2 Type II compliant, independently audited and verified, not self-assessed. SOC 2 Type II is the most demanding attestation available for cloud-based platforms, requiring an independent auditor to confirm that security controls have been operating effectively over a sustained period, not just at a point in time.
It is GDPR compliant with a Data Processing Agreement available, relevant to directors with appointments in the UK, EU, Guernsey, Jersey and any jurisdiction that recognises GDPR-equivalent data protection standards.
Data is hosted in certified data centres with physical security, biometric access controls and environmental safeguards. Staff undergo background checks, sign confidentiality agreements and receive annual security training. Sub-processors are vetted and contractually bound to equivalent protections.
Within that infrastructure MyDirector-OS adds a further layer specific to the governance context:
Board packs and documents processed through BoardLens are handled statelessly, reviewed and then gone. No storage. No logs. No training data. No residual exposure. The AI model that reviews a director's documents does not retain, learn from or share what it has seen.
The director's workspace is encrypted end-to-end and accessible only to them. Their @mydirector-os.com email address provides a dedicated, secure channel for board communications entirely separate from their personal digital life. Their documents, meeting records, compliance obligations and governance history are held in a private encrypted vault, not on a personal device, not in a personal email folder, not in a shared drive.
The standards that apply to MyDirector-OS are the same standards directors are expected to oversee in the regulated entities they govern.
That is not a coincidence. It is the point.
The cyber risk that sits with directors personally is real, specific and increasingly in the regulatory spotlight. The tools to manage it, built to the standards the role demands, now exist.
