Why Cyber Risk Ownership Is So Often Misunderstood
Ask five people in your organisation who owns cyber risk, and you’ll likely get five different answers. The CISO will say it’s theirs. The CIO will say it sits with IT. The operations director will say it’s a technology problem. The CFO will say they fund it but don’t own it. And the CEO will say the board takes it seriously, without quite being able to explain what that means in practice.
That ambiguity becomes particularly dangerous when operational technology cyber incident response is required and decisions need to be made quickly across IT, security, operations and leadership teams.
This isn’t a minor governance issue. It’s one of the most common reasons organisations struggle to respond effectively when a cyber incident hits. Not because they lack tools or budgets, but because nobody was entirely clear who was responsible for what until it was too late to figure it out calmly.
For organisations operating critical or industrial environments, having a defined cyber incident response process is particularly important because technical containment decisions can have immediate operational consequences.
Why operational technology cyber incident response needs clear ownership
The data paints a stark picture. According to the UK Government’s Cyber Security Breaches Survey 2025/2026, 72% of UK businesses say cyber security is a high priority for senior management. Yet only 31% have a board member who takes explicit responsibility for it. That gap, between saying it matters and someone actually owning it, is where risk quietly accumulates.
And while that 31% figure is an improvement on the previous year’s 27%, it’s worth remembering that in 2021, the figure was 38%. The trend over the last five years has been one of declining board-level ownership, even as cyber threats have intensified.
The Corporate Governance Institute found that 30% of boards in the UK and Ireland rank cyber security as a top business risk, a figure that has remained flat for five consecutive years. Cyber risk has been recognised at senior level without being governed any more tightly.
The incident response gap
Meanwhile, 43% of UK businesses reported a cyber breach or attack in the past year, rising to 67% of medium-sized and 74% of large businesses. And only 25% have a formal incident response plan. That means the majority of organisations that experienced a breach were forced to improvise their response on the day.
Why the confusion exists
Cyber risk doesn’t sit neatly within a single function. It spans IT infrastructure, operational technology, supply chains, people, processes, and third-party relationships. In most organisations, no single person or team has line of sight across all of these domains. The result is a patchwork of partial ownership.
IT teams typically own the tools, the firewalls, the SIEM platform, the endpoint protection. Security teams own the policies and frameworks. Operations teams own the processes and production environments. Finance owns the budget. And the board owns the strategic risk register, in theory.
The problem is what happens between these functions.
-
Who owns the risk created by a third-party vendor with weak security practices?
-
Who is accountable when a legacy OT system can’t be patched but remains connected to the corporate IT environment?
-
Who has the authority to stop production if a compromise is suspected?
-
Who makes that decision at 2am on a Sunday?
These are exactly the questions that become urgent during a real incident.
The IT and OT divide makes it worse
In manufacturing and industrial environments, the ownership question is even more complex. Operational technology, the systems that run production lines, manage utilities, and control physical processes, was historically managed entirely separately from IT. Different teams, different priorities, different risk tolerances.
But those boundaries have blurred. IT and OT networks are increasingly connected, often in ways that neither team fully understands or controls. A vulnerability in the corporate IT environment can become a pathway into OT systems, and vice versa. When something goes wrong, the question of who is responsible for the gap between these two worlds often goes unanswered.
“The question isn’t whether your organisation has cyber risk. It’s whether anyone can tell you, right now, exactly who is responsible for managing it.”
Why visibility across IT and OT is critical
This is a challenge Celerity's exposure management tools frequently uncover, risks that sit in the no-man’s-land between IT and OT, visible to attackers from the outside but invisible internally because nobody considers it their domain. If this resonates, it’s worth knowing that we’ve built a specific assessment for exactly this situation. Our Industrial Threat Insight Report is a free, OT-focused cyber risk assessment designed for manufacturing and industrial organisations.
It combines an external threat intelligence view, showing how your organisation appears to attackers, with a NIST CSF 2.0 aligned review of key IT and OT security controls. The result is a clear, joined-up picture of where exposure exists across both environments and who needs to act on it.
What good ownership actually looks like
Effective cyber risk ownership doesn’t mean one person carries the burden alone. It means the organisation has clear, documented accountability at every level, from the board down to individual teams, and that those lines of accountability are tested, not just written down.
Board-level accountability
The board needs to understand cyber risk as a business and operational risk, not simply a technical problem.
The UK Government’s Cyber Governance Code of Practice, launched in 2025, sets out a practical framework for exactly this. It calls for boards to treat cyber risk as a strategic governance issue, not a technical one and establishes five core principles: risk management, strategy, people, incident planning, and assurance and oversight.
At its heart is the principle that the board must be able to demonstrate that it understands, monitors, and actively governs cyber risk.
Frameworks help turn ownership into action
Frameworks such as NIST CSF 2.0 provide a practical structure for managing cyber security risk and connecting technical security activity to wider organisational governance. But the challenge for many industrial organisations isn’t knowing that frameworks exist.
It’s understanding where the real gaps sit within their own environment, particularly at the intersection of IT and OT. Understanding governance maturity, asset visibility, identity controls, segmentation, detection readiness and recovery capabilities across both environments creates a stronger starting point for assigning meaningful ownership.
Because you can’t own what you can’t see.
The incident is where ownership is truly tested
Governance structures matter most when they’re under pressure. During a cyber incident, clear ownership determines how quickly decisions are made, how effectively resources are mobilised, and how confidently the organisation communicates, internally and externally.
The Breaches Survey found that while 81% of businesses informed directors following a breach, only 40% reported their most disruptive breach externally. And only 25% had a formal incident response plan in place.
Without clear ownership, the response defaults to whoever happens to be available, capable, and willing to step up. That might work once. It won’t work reliably.
For operational technology cyber incident response, this becomes especially important because containment decisions may have consequences beyond IT. Isolating an OT asset might interrupt production, affect physical processes or create safety and service availability considerations.
Technical response therefore needs to be connected to operational decision-making from the start.
A documented incident response process helps define how incidents are identified, escalated, contained and recovered from, while specialist cyber incident response consultancy can help organisations test whether those processes will work under real pressure.
For organisations that need continuous monitoring as well as response capability, Celerity’s MDR and MXDR services can also support earlier threat detection and action across complex environments.
Our guide to what operational resilience really means explores how organisations can move beyond reactive plans towards an operating model designed to continue and recover when disruption occurs.
Three questions every board should be able to answer
1. Who is accountable for cyber risk at board level, and what does that accountability include?
Not just a named individual, but a clear scope: do they oversee strategy, budget allocation, incident response decisions, and regulatory reporting? Or do they receive a quarterly update and nod?
2. Where are the gaps in ownership between functions?
The most dangerous risks live in the spaces between IT, OT, operations, and third parties. Mapping these intersections is where real security gaps get identified and where ownership needs to be explicitly assigned.
3. If a significant incident happened tonight, who would make the critical decisions, and are they prepared?
Incident response isn’t just a technical function. It involves legal, communications, regulatory, commercial, and executive decision-making. If those roles aren’t assigned and rehearsed, the response will be slower, messier, and more damaging than it needs to be.
Clarity now, confidence later
Cyber risk ownership isn’t a question that can be deferred until something goes wrong. The organisations that recover fastest and suffer least are the ones that settled the ownership question long before the incident arrived. They know who decides, who acts, who communicates, and who reports, because they planned it, documented it, and tested it.
At Celerity, we help organisations build this clarity. From cyber security assessments that identify gaps in governance and controls, to managed detection and response services that ensure threats are identified and acted on around the clock, we work across the full spectrum of cyber resilience, so that when the question of ownership is tested, your organisation is ready.
Explore Security Consultancy
Give your board a clearer view of ransomware risk
Cyber incidents quickly become business decisions, which is why leadership needs to understand its role before disruption begins.
Download What Boards of Directors Must Know About Ransomware to explore what senior leaders need to understand about ransomware risk, governance, resilience and response. The guide complements the ownership questions above by helping boards prepare for the decisions they may need to make during a serious cyber incident.
Frequently asked questions
Operational technology cyber incident response is the process of preparing for, detecting, containing, managing and recovering from cyber incidents that affect OT systems and industrial environments.
Unlike a purely IT-focused response, it must also consider operational continuity, physical processes, safety implications and the potential impact of taking critical systems offline.
Ownership should be shared through clearly defined responsibilities rather than left solely with IT or security.
Boards and senior leadership should own strategic cyber risk, while security, IT, OT and operations teams need clearly documented responsibilities for detection, escalation, containment, recovery and operational decision-making.
OT environments often contain specialist systems, legacy technology and operational processes where availability can be as important as confidentiality.
Actions that are routine in IT, such as isolating or rebooting a system, may have significant operational consequences in an industrial environment. Response plans therefore need input from both security specialists and operational teams.
An OT cyber incident response plan should define escalation routes, decision-makers, technical and operational responsibilities, communication processes, containment options, third-party contacts, recovery priorities and criteria for safely returning systems to operation.
It should also be regularly tested through exercises involving both technical and business stakeholders.
Celerity can support organisations with cyber incident response, exposure management, security assessments, managed detection and specialist consultancy designed to improve visibility and clarify responsibilities across IT and OT environments.
A joined-up approach helps organisations strengthen operational technology cyber incident response before a real incident puts those responsibilities to the test.