CEO's pay should be linked to security performance, says government committee
New report recommends that CEOs be held directly accountable for data breaches


CEOs' compensation - including salary, bonuses and stock options - should be linked to their companies' cyber security performance, according to a new report from the Culture, Media and Sport committee.
The report comes after an inquiry into cyber security and data breaches, which was initiated following last year's massive TalkTalk hack.
As part of the committee's recommendations, it suggested a laundry list of requirements for companies to minimise and respond to data breaches.
This included general company-wide policies, such as reporting cyber security and data protection strategies to the Information Comissioner's Office (ICO), as well as including cyber security in their annual bottom-line reporting alongside social and environmental reporting.
However, the recommendations also included measures designed to make CEOs and IT decision makers more accountable in the wake of data breaches, as well as recommending that those who trade in stolen personal data should be sentenced to up to two years in jail.
The report advised that while CEOs should lead crisis response in the wake of a breach, full responsibility a breach should reside with whoever handles it day-to-day, who can be "fully sanctioned" if the company has not adequately protected itself.
It also recommended that CEOs' financial earnings be directly linked to their companies' security, "to ensure this issue receives sufficient CEO attention".
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Today's report by the Culture, Media and Sport Committee highlights the importance of good cyber-security practices for businesses of all sizes that have an online presence or service," said Talal Rajab, techUK's head of cyber and national security.
"To maintain user confidence in digital services, and the growth of the UK's digital economy, companies must have appropriate cyber-security policies and processes in place."
In addition to penalties for not preventing breaches, the report also advocated that the ICO should institute a series of escalating fines for companies that fail to disclose data breaches.
It was also noted that the ICO's current maximum fine of 500,000 "may not be a significant deterrent" for larger organisations. However, this is set to change anyway once the European General Data Protection Regulation comes into force in 2018.
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
Huawei MatePad Pro 13.2 PaperMatte (2025) review
Reviews No Google, an awkward keyboard, and an AI-heavy camera are the only issues with Huawei's beautiful MatePad Pro
-
Does computer vision have strong business potential?
Computer vision is a technology that allows machines to ‘see’ – and it’s already transforming the way industries such as manufacturing and healthcare work.
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
-
ICO slams Electoral Commission over security failures
News The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies
-
Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms
News Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement
-
ICO reprimands Coventry school over repeated data protection failures
News The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach
-
ICO dishes out fine to HelloFresh for marketing spam campaign
News HelloFresh failed to offer proper opt-outs, the ICO said, and customers weren’t warned their data would be used for months after they cancelled