The governance frameworks that regulate how directors oversee cyber risk within their organisations have advanced significantly in recent years.

What has advanced far more slowly is the conversation about the cyber risk that sits with directors personally.

These are not the same conversation.

Every major financial jurisdiction has moved decisively to make cyber risk a board-level governance matter.

The UK's Cyber Security and Resilience Bill progresses through Parliament with Royal Assent expected before year end.

CIMA's Corporate Governance Rule has placed cyber firmly within the personal accountability of Cayman directors since October 2023.

DORA has been in full application across Luxembourg and EU structures since January 2025.

Across the jurisdictions where directors govern regulated fund and corporate structures, Guernsey, Jersey, Cayman, Luxembourg, Singapore, Ireland, DIFC and ADGM to name a few, regulators have made the direction of travel clear.

Cyber risk is a board matter. Directors are accountable. But accountable for what, exactly?

For overseeing the cyber risk within the organisations they govern - yes.

For managing the cyber risk that sits with them personally - that is a different and largely unaddressed question.

A non-executive director or an executive holding external board appointments usually has no corporate device for that role.

No IT support, and no corporate security policy that extends to their personal setup.

Directors usually have personal devices, personal networks and personal email accounts through which some of the most sensitive information routinely passes.

Ponemon Institute's 2025 research found that 51% of organisations had experienced attacks specifically targeting executives or board members, up from 42% in 2023.

Directors are high-value targets. Not because they are technically vulnerable. But because of what they know and what information they store.

On Wednesday we look at what the director's personal cyber risk actually looks like, the data footprint, the AI dimension, the regulatory expectations and the infrastructure standards that governance-sensitive information demands.

www.mydirector-os.com