Skip to content

Strategic Business Leader · IT systems security and control

Cyber Security Governance and Risk Management for SBL

Updated 11 October 2026 · Fact-checked

Cyber security governance is how the board sets direction, appetite and accountability for cyber risk. Risk management then identifies and assesses threats, applies controls, monitors them and plans incident response. In SBL, link each point to the case scenario, weigh likelihood and impact, and give practical, justified recommendations.

Understand Cyber Security Governance and Risk Management

Cyber risk is the risk of loss from attacks on, or failures of, an organisation's information systems and data. Losses can be financial, operational, legal and reputational. It is a business risk, not just an IT problem.

Governance is about who decides and who is accountable. The board sets the risk appetite, approves the cyber strategy and policies, and holds management to account. Management designs and runs the controls. Internal audit and the audit committee give independent assurance. In SBL, expect the case to show weak governance: no named owner, a board that lacks technical understanding, or cyber left entirely to the IT department.

Risk management follows a cycle. Identify assets and threats, assess likelihood and impact, choose a response, implement controls, then monitor and report. Typical responses are to avoid, reduce, transfer (for example cyber insurance) or accept the risk. This links to the TARA approach. Controls include technical (firewalls, encryption, access controls), organisational (policies, segregation of duties, training) and physical measures.

Incident response covers what happens when prevention fails. A good plan has a named response team, clear roles, steps to detect, contain, eradicate and recover, and rules for communication. It must cover regulators, customers, staff and the media. Data protection law may require timely notification of a breach. After the incident, the organisation should review what happened and improve its controls.

Monitoring closes the loop. The board needs regular, understandable reports: incidents, test results, audit findings and key risk indicators. Without monitoring, controls decay and the board cannot show it has exercised proper oversight.

Key rules to remember

Risk exposure
Risk exposure = likelihood × impact
A qualitative guide. Rate each as high, medium or low, or use estimated values. It helps rank risks, not prove an exact loss.
Risk response (TARA)
Transfer, Avoid, Reduce, Accept
Match the response to risk level and appetite. High impact and high likelihood usually means avoid or reduce.
Incident response stages
Prepare → Detect → Contain → Eradicate → Recover → Review
Use as a checklist for any incident response question.
Cyber governance chain
Board (sets appetite, oversees) → Management (implements) → Assurance (audit committee, internal audit)
Use to structure who is responsible for what.

How to solve Cyber Security Governance and Risk Management questions

Use this method for any SBL task on cyber governance or cyber risk. Always tie it to the case.

  1. 1Read the requirement. Note the verb: assess, advise, evaluate, recommend, or explain.
  2. 2Identify the key assets and data at stake in the scenario, and the threats they face.
  3. 3Assess the risks by likelihood and impact, and rank the main ones.
  4. 4Review governance: who owns cyber risk, what the board knows, and what is missing.
  5. 5Recommend responses and controls (TARA), linked to risk appetite and cost.
  6. 6Cover incident response and monitoring: team, steps, communication, reporting to the board.
  7. 7Justify each recommendation with a case fact, and note limits or costs.
  8. 8Conclude with a clear priority, written in the format requested (report, memo or briefing).

Quickest way: Four-box cyber answer: Risk, Owner, Control, Response

When to use it: Use when time is short or the requirement is broad, such as advising a board on its cyber duties.

  1. Risk: name two or three case-specific threats and rate likelihood and impact.
  2. Owner: say who is accountable (board, named executive, committee) and what is missing.
  3. Control: give preventive, detective and corrective measures, one line each.
  4. Response: outline incident response and the monitoring reports the board should receive.
  5. Tie every point to a case fact in the same sentence.

Common mistakes in Cyber Security Governance and Risk Management

  • Treating cyber security as only an IT issue.

    Students list technical controls and forget governance.

    Fix: Always cover board accountability, risk appetite, policies and assurance as well as technology.

  • Giving a generic list of threats and controls.

    Students rely on memorised lists.

    Fix: Pick the threats that fit the scenario and justify each recommendation with a case fact.

  • Ignoring what happens after a breach.

    Focus stays on prevention.

    Fix: Include incident response steps, communication, legal notification duties and post-incident review.

  • Recommending that all risk be eliminated.

    Students overlook cost and risk appetite.

    Fix: Explain that controls must be proportionate. Some risk is reduced, transferred or accepted.

  • Failing to say who is responsible.

    Roles of board, management and audit blur together.

    Fix: State the board's oversight role, management's operating role and the assurance role separately.

  • Weak professional skills in the answer.

    Students write notes instead of advice.

    Fix: Use the requested format, prioritise, show scepticism about reassurances and give clear, commercial advice.

Worked examples

Example 1

A global online retailer holds millions of customer payment records. The board has delegated all cyber matters to the IT manager and receives no cyber reports. Advise the board on how its governance of cyber risk should improve. (10 marks, illustrative)

Show the solution
  1. Point out the weakness: cyber risk is a business risk and the board remains accountable. Delegating everything to IT leaves no oversight, which is serious for a business holding payment data.
  2. Recommend the board sets a cyber risk appetite and approves a cyber strategy and policies.
  3. Assign clear ownership: a named senior executive accountable, with the risk or audit committee overseeing. Consider adding board members with technology understanding or using expert advice.
  4. Require regular reporting: incidents, vulnerability and penetration test results, key risk indicators and audit findings, in language non-experts can follow.
  5. Seek independent assurance through internal audit or external specialists to test controls, rather than relying on the IT manager's own view.
  6. Ensure there is an incident response plan the board has approved and tested, covering customers, regulators and media, given the volume of customer data.

Answer: The board should own cyber risk: set appetite and strategy, name an accountable executive, receive regular reports, obtain independent assurance and approve a tested incident response plan.

Example 2

A manufacturer discovers ransomware has locked its production scheduling system. Outline the incident response the company should follow and the lessons the board should seek afterwards. (10 marks, illustrative)

Show the solution
  1. Detect and assess: confirm the attack, find which systems are affected and activate the incident response team with defined roles.
  2. Contain: isolate infected systems from the network to stop the spread, and preserve evidence for investigation.
  3. Eradicate: remove the malware and close the weakness used, with specialist help if needed.
  4. Recover: restore from clean, tested backups, checking integrity before reconnecting. Use business continuity arrangements, such as manual scheduling, to keep production going.
  5. Communicate: inform staff, customers and suppliers as needed. Notify regulators or law enforcement where required, including data breach duties if personal data is affected. The board should decide its approach to any ransom demand with legal advice, noting payment does not guarantee recovery.
  6. Review: after recovery, analyse root cause, update controls, backups, training and the plan, and report findings to the board and audit committee.

Answer: Follow detect, contain, eradicate, recover, communicate and review. Use backups and continuity plans to protect production, and report lessons to the board so controls and the plan improve.

Exam tips

  • Link every recommendation to a specific fact in the case. Generic answers score poorly on application.
  • Always address governance (who is accountable) as well as technical controls.
  • Show balance: controls cost money and must fit risk appetite. Mention proportionality.
  • Use the format requested, and prioritise your points so the board knows what to do first.
  • Cover both prevention and response. Examiners often reward the incident response and monitoring points that others skip.

Practice questions from IT systems security and control

Cyber Security Governance and Risk Management in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Security Governance and Risk Management: frequently asked questions

What is the board's role in cyber security?

The board sets risk appetite, approves strategy and policies, assigns accountability and oversees reports. It does not run technical controls, but it stays accountable for cyber risk. It should also seek independent assurance.

How do you assess cyber risk in an SBL case?

Identify the key assets and threats in the scenario. Rate each risk by likelihood and impact, rank them, then choose a response such as reduce, transfer, avoid or accept. Justify using case facts.

What should a cyber incident response plan include?

It should name a response team and roles, and set out steps to detect, contain, eradicate and recover. It should also cover communication with staff, customers and regulators, plus a post-incident review.

Is cyber risk examined as a standalone question?

It can appear as part of a wider SBL task on risk, governance, technology or ethics. Treat it as a business risk and link it to the case.