No ignorance defence on cyber-risk
Over the last 20 years of my advisory practice, the standards for cybersecurity corporate governance have generally evolved incrementally every few months — that is, until now.
On July 17, the Bermuda Government tabled its much anticipated report from the joint select committee on the September 2023 cyberattack that completely disabled the government’s IT infrastructure.
As an integral part of its findings, the report makes the looming nature of cyber-risk, and the urgency for preparedness, abundantly clear.
Unfortunately, the report omits some essential information. For example, it does not disclose exactly what personal data might have been compromised in 2023, nor does it disclose what the overall cost will be to reconstruct critical data or to securely rebuild the Government's IT infrastructure.
Instead, the committee recommends that its report be referred to the Public Accounts Committee to determine those issues, as well as how much the perpetrator was paid and to uncover all related data and systems remediation activities.
More poignantly, even though the majority of the report is stated to be “deliberately forward-looking”, the report fails to mention Bermuda’s Cybersecurity Act 2024, which has, for over two years, been the primary source for all future cybersecurity protection standards for the Government.
Although we still await that Act’s required cybersecurity regulations, the omission of that most essential basis for governmental cybersecurity responsibility and compliance seems rather glaring.
Bermuda, which appears to still be scrambling towards cyber preparedness, is not alone in experiencing the heat of a fast-changing cybersecurity landscape across both our public and private sectors.
Britain’s 2025 Cyber Security and Resilience Bill will be, when it becomes law as expected later this year, a game-changer for UK corporate directors. Many believe the CSRB will quickly influence cybersecurity and resiliency regulation across many other Commonwealth jurisdictions.
In essence, the CSRB will enhance current cybersecurity oversight duties to include: all managed service providers who are often a gateway into company systems; more robust incident reporting; data centres; and, service suppliers that regulators designate as operationally critical.
Like Canada, the regulation of “outsourcing” and related cyber-risk will now be superseded in Britain by the more pragmatic concept of third-party, service-risk management.
Proponents of the CSRB have long argued that many corporate directors and managers have been far too deferential to so-called cybersecurity experts to whom boards have ostensibly delegated their cyber-risk governance.
The motivation for such functional delegation is understandable given the often overwhelming complexities of quickly advancing technology risk, such as those associated with cybersecurity and AI deployment.
Although there may not be an “ignorance defence” for corporate directors when it comes to informed cybersecurity governance, the UK cyber governance organisation OxCyber recently proclaimed that the CSRB will constitute, “The end of the ignorance defence” and that, “The era when senior management could delegate cyber-risk and plead ignorance is over. Under the CSRB, cybersecurity is now unequivocally (a matter of) board-level accountability.”
The Bermuda Companies Act makes it clear that corporate directors are required to exercise the care, diligence and skill that a reasonably prudent person would exercise in comparable circumstances. The Bermuda Monetary Authority’s operational cyber-risk management codes of conduct specifically stipulates that the board of directors and the senior management teams of financial service providers have a non-delegable duty of cyber-risk oversight.
As a corporate director, I know well that those governance duties require reasonable enquiry into, and the consideration of, even the most complex of matters that pertain to the company’s operational risk management, regulatory compliance and best commercial interests — whether those complexities are financial, technological or otherwise.
Certainly, cyber-risk is now a ubiquitous media reality, and no corporate director can reasonably say that they are not well informed of, and do not appreciate, the pervasive and malevolent risks to all business sectors posed by cyberattacks.
For example, Aon’s 2025 Global Risk Management Survey reported, based on responses from nearly 3,000 executives in 63 countries, that cyberattack and data breach is now regarded as the leading risk to business globally.
Similarly, the 2026 Global Threat Report from the acclaimed Austin based cyber advisory firm, CrowdStrike, cited that in 2025 AI-enabled bad actors increased their cyberattacks by 89 per cent year-over-year and that “cloud-conscious intrusions” rose 37 per cent in 2025.
Especially relevant to Bermuda, a section of CrowdStrike’s cyber report is devoted to the pronounced cyber-risks of “Cloud Platforms and Services”.
In addition, corporate directors and regulators also have access to many other widely-published cyber-risk reports, including: the Coalition’s 2026 Cyber Claims Report; the World Economic Forum’s Global Cybersecurity Outlook 2026; Checkpoint’s Cyber Security Report 2026; and, Cybercube's Cyber Predictions 2026 report, among many others.
Also impossible to escape is the constant flow of publicly issued cyber-risk alerts. For example, the Ministry of National Security issued a “Cybersecurity Alert on Fortinet Device Credential Compromise” on June 28, citing “Fortibleed” as an active cyberthreat that must be treated “as a priority” without delay.
Together, the Cybersecurity Act 2024 (which addresses the Government and all critical infrastructure), the BMA’s evolving cyber-risk management and resiliency regulations, the “appropriate safeguard” requirements of Bermuda's Personal Information Protection Act 2016, all now pervasively inform most boards of the cyber-risks they face.
There is also the constant barrage of government warnings and committee reports, advisory publications and media coverage that is fuelling the rapid development of cybersecurity governance at a never before seen pace.
In aggregate, it is exceedingly difficult for any governance leader to reasonably say they are not well informed about the potentially devastating risks of a cyberattack and are not aware of all their related statutory, regulatory and common law duties of governance concerning those risks.
Any claim of lingering ignorance concerning this subject’s intimidating complexity likely provides very little shelter for directors.
Enterprise governance leaders in both the public and private sectors must take note of the now leading refrain, “ … our cyber-risk future is already here”, and none can say they haven’t been warned.
• Duncan Card is the chief executive of The Advisory Group in Bermuda, www.advisory.bm, and is a sought-after adviser and frequent author on topics related to cybersecurity governance best practices, cyber and privacy compliance, and outsourcing transactions. This article is not intended as advice.
