MUFG Pension & Market Services
A member of MUFG, a global financial group

::::::::

Globe Icon AU

  • Region

Back to top chevron

Board Management of Cyber Security Risk in the Age of AI – The Critical Role of the Company Secretary

What separates boards that manage a cyber crisis well from those that don’t? Governance – and the professionals who support it. 

Cyber security has become one of the defining governance challenges facing boards. While cyber threats continue to evolve, so do the technologies organisations rely upon – including artificial intelligence, cloud computing, digital platforms and increasingly complex data ecosystems. 

For boards, the challenge is no longer simply preventing cyber incidents. Instead, it is ensuring technology is governed in a way that supports strategy, manages risk and enables confident responses in a complex operating environment. This shift has implications for the role of the company secretary. At MUFG Corporate Markets our company secretaries advise on good governance, and we have lived experience advising boards on, and navigating responses to, cyber breaches. 

The evolving landscape 

The cyber incidents affecting several large Australian companies over the past few years has demonstrated that consequences extend far beyond technology – triggering regulatory investigations, class actions, remediation costs and lasting reputational damage. The lesson was clear: cybersecurity is about demonstrating effective governance before, during and after an incident. 

For some years, technology discussions in the boardroom focused on operational assurance. Directors sought comfort that systems were secure, information assets were protected and disaster recovery plans were in place. These conversations were often highly technical, with boards relying on management and external specialists to explain cyber risks and recommend appropriate controls. 

Cybersecurity now intersects with almost every aspect of organisational governance. A cyber incident can expose weaknesses in risk management, business continuity, regulatory compliance, privacy, supply chain oversight and culture. Emerging technologies such as AI introduce additional considerations around accountability, transparency and responsible use. 

Regulatory expectations have also evolved significantly in Australia. Following several high-profile incidents, regulators have increased their focus on board oversight, governance processes and organisational accountability. Privacy, cyber resilience and operational risk are no longer viewed as matters for technology teams alone – they are board responsibilities that require active oversight and documented decision-making. 

Good governance is measured by more than compliance. It is reflected in the quality of board discussions, the robustness of decision-making and the organisation’s preparedness to respond when challenges arise. 

Best Practice Cyber Security Governance 

The Australian Institute of Company Directors has invested in producing sound advice for directors, management, and governance professionals. It is essential reading and includes five Cyber Security Governance Principles for effective board oversight of cyber risk.  

To find out more search for: AICD Cyber Security Governance Principles (November 2024) and AICD Governing Through a Cyber Crisis  

The critical role of the company secretary 

The company secretary sits at the intersection of the board, executive management and organisational governance – with visibility across committees, risk reporting, compliance obligations and strategic priorities. An effective company secretary helps ensure boards receive focused, timely and meaningful information, identifying if significant risks are reaching the board and if reporting supports strategic oversight rather than operational detail. 

Board papers should address the questions directors actually need answered:  

  • What are the organisation’s most significant cyber risks?  
  • Are those risks aligned with the board’s risk appetite?  
  • What decisions require board oversight?  
  • What are the legal, financial and reputational consequences if controls fail? 

Company secretaries play an important role in keeping cyber security as a standing governance consideration – incorporating it into the board’s annual work plan, coordinating director education, scheduling regular cyber resilience reviews and ensuring lessons from incidents across the market are brought before the board. 

The more things change the more they stay the same 

Ultimately, governance has always been about stewardship. While technology will continue to evolve, the board’s responsibility for oversight remains unchanged. 

Organisations with strong governance are not necessarily those with the most sophisticated technology – they are those whose boards understand the risks, exercise effective oversight and who keep technology, strategy and accountability aligned.  

Experience matters 

While operational responsibility for cyber security rests with management and oversight with the board, a competent company secretary plays a critical governance role by supporting cyber security governance through effective board processes, ensuring cyber risk is appropriately reflected in board agendas and papers, facilitating timely reporting and director education, maintaining governance records, and supporting the board’s overall oversight of cyber resilience and incident response.  

At MUFG Corporate Markets our company secretaries bring lived experience in advising boards on best practice governance and navigating responses to cyber breaches – they have provided practical governance support during the moments that matter most. 

Key Takeaways

  1. Cybersecurity is a governance issue. Strong governance builds organisational resilience. 
  1. Governance quality is judged before, during and after an incident.  
    Recent cyber incidents have reinforced that stakeholders expect boards to demonstrate preparedness, transparency and accountability throughout the lifecycle of a cyber incident.  

To read more insight from Nicole Graham go here MPMS MUFG | Harnessing AI in the Boardroom - The Augmented Company Secretary

Nicole Graham

Nicole Graham
General Manager, Corporate Governance
Linked In Icon Email Icon Telephone Icon

Share this insight

Share on LinkedIn Share on LinkedIn