Cyber pros say the buck stops with the board when it comes to security failings
Fines, sanctions, and even prosecution are all on the table when it comes to cyber failings, practitioners believe


A majority of cyber professionals believe responsibility for security and regulatory compliance lies with the board, according to new research.
CIISec’s recent State of the Security Profession report shows 91% of practitioners believe the burden for security lies with the board, and not security managers or CISOs.
Notably, more than half (56%) said they believe senior management figures should “face consequences”, including fines, prosecution, and sanctions, for serious cybersecurity failings.
Just 34% believe the employee who breached policy - if that’s the case - should be held responsible.
Amanda Finch, CEO of CIISec, said the study highlights the need for a more aligned approach to cybersecurity between the board and frontline practitioners.
“If the buck stops with senior management – as the survey makes clear – our profession must take a more collaborative approach to security, ensuring the board is aware of the risks and included in major decisions,” she said.
“This means more learning for cybersecurity professionals, improved understanding of regulations and developing better communication of risk to stakeholders outside of the security function.”
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Regulatory concerns drive demand for change
A key factor behind changing sentiment on board-level responsibility comes amidst a period of growing regulatory scrutiny on both sides of the Atlantic, Finch noted.
The introduction of the EU AI Act, DORA, NIS2, and the UK’s Data (Use and Access) Bill, mean practitioners are more conscious of regulatory compliance than ever before.
“It’s important to remember that regulations aren’t imposed to make the security profession more challenging, although sometimes it may feel that way,” she said.
“They have been developed to help address failures from the past, close gaps that have previously been overlooked and establish a minimum standard across the industry.”
Finch noted that while these regulations have created fresh challenges for enterprises and security professionals alike, they serve a vital purpose and therefore require close attention.
“These laws have been introduced to protect citizens, improve their quality of life and ensure that businesses can be held accountable for irresponsible actions,” she added.
“As cybersecurity matures as a profession, we should view increased regulation not as a burden but as a sign of progress.”
Compliance is easier said than done, however. Research earlier this year showed a significant number of companies were struggling to achieve compliance with NIS2 regulations.
Separate research on DORA showed four-in-ten UK financial services firms were struggling to achieve compliance with the legislation ahead of its introduction.
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- Why does cybersecurity still struggle with professionalization?
- Cyber professionals call for a 'strategic pause' on AI adoption
- Work-related stress “keeps cyber security professionals awake at night”

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Researchers sound alarm over AI hardware vulnerabilities that expose training data
News Hackers can abuse flaws in AI accelerators to break AI privacy – and a reliable fix could be years away
-
Are AI PCs becoming the norm?
ITPro Podcast As manufacturers increasingly embed NPUs in devices, what are the benefits to businesses?
-
A malicious MCP server is silently stealing user emails
News Koi Security says it's discovered the first malicious MCP server in the wild, exposing a risk to the entire ecosystem
-
NCA confirms arrest after airport cyber disruption
News Disruption is easing across Europe following the ransomware incident
-
Cyber skills shortages are pushing firms into dangerous shortcuts – and it’s putting them at huge risk of security breaches
News Chronic cyber skills shortages mean many businesses are implementing quick fixes
-
Pentesters are now a CISOs best friend as critical vulnerabilities skyrocket
News Attack surfaces are expanding rapidly, but pentesters are here to save the day
-
Hackers are disguising malware as ChatGPT, Microsoft Office, and Google Drive to dupe workers
News Beware of downloading applications like ChatGPT, Microsoft Office applications, and Google Drive through search engines
-
Generative AI attacks are accelerating at an alarming rate
News Two new reports from Gartner highlight the new AI-related pressures companies face, and the tools they are using to counter them
-
A terrifying Microsoft flaw could’ve allowed hackers to compromise ‘every Entra ID tenant in the world’
News The Entra ID vulnerability could have allowed full access to virtually all Azure customer accounts
-
‘Channel their curiosity into something meaningful’: Cyber expert warns an uptick of youth hackers should be a ‘wake-up call’ after teens charged over TfL attack
News Encouraging youths to engage in positive tech initiatives will guide them down the right path and away from nefarious activities