About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

Corporate Boards Vulnerable to Hacking and Information Theft, Says Thomson Reuters Survey

Subscribe to our newsletter

Most major corporations surveyed have significant security gaps that leave sensitive board-level information open to information theft and hacking. Those are among the findings of a new survey of board members of UK and global corporations conducted by Thomson Reuters Governance, Risk & Compliance.

The findings are particularly noteworthy in light of recent news stories about the handling of board communications involving executive succession decisions at companies including Yahoo and Apple.

The survey found that information provided to members of corporate boards of directors is often in unencrypted email accounts and computers, or otherwise provided in forms that are easily lost, misplaced or stolen. The Thomson Reuters Governance, Risk & Compliance survey polled general counsel and board members at leading global corporations across a wide variety of industries.

Most corporations surveyed have one or more of the following potential security issues involving information provided to board members:

85% Unencrypted board communications

79% Board documents stored on personal computers at home or work

75% Board documents stored on personal mobile devices (e.g., iPad, laptop, smartphone, etc.)

73% Documents sent to board members via personal, non-commercial email addresses

71% Board documents accessible via wi-fi or unsecured networks

10% Have reported computer, mobile devices, or sensitive company documents lost, stolen or left in public places

Another vulnerability is in the area of legal discovery, as most corporations are not accounting for all of the computing devices that board members are using to access and store board documents. The discovery process would then require a canvassing of computers, files and other data storage maintained by board members at their homes or businesses.

“Communications and information handling with board members represents a weak link in the chain of corporate information security,” said David Craig, president, Thomson Reuters Governance, Risk & Compliance. “Boards of directors handle some of their companies’ most critical and sensitive information, including business strategies, discussion of executive hiring and compensation, legal issues, internal investigations and more.

“While most corporations take extraordinary measures to protect information shared with executives and employees, board members – often being outside directors – operate largely outside of a corporation’s secure computer networks and many of their strict internal security policies. The survey found that information given to the board is treated with inadequate levels of care and security with alarming frequency, placing information at risk of loss, theft and exposure.

“In addition, because of the increasingly global nature of boards,” continued Craig, “members often have to travel considerable distances to attend board meetings and functions, providing numerous opportunities for papers, briefcases, laptops and mobile devices to be physically lost, stolen or exposed to hazards such as hackers and unsecured networks.”

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: Managing Non-Financial Misconduct Under SMCR

Non-financial misconduct – encompassing behaviours such as bullying, sexual harassment, and discrimination is a key focus of the Senior Managers and Certification Regime (SMCR). The Financial Conduct Authority (FCA) has underscored that such misconduct is not only unethical but also poses significant risks to a firm’s culture and operational integrity. Recognizing the profound impact on...

BLOG

REP008, FIT, and Beyond: Navigating the FCA’s Reporting Duties on Misconduct

The Financial Conduct Authority (FCA) has long insisted that “non-financial misconduct is misconduct.” That phrase, repeated across speeches and policy statements, reflects the regulator’s conviction that culture, integrity, and behaviour are inseparable from financial soundness. In 2025, the FCA translated that principle into formal rulemaking, finalising changes to the Senior Managers & Certification Regime (SMCR)...

EVENT

Buy AND Build: The Future of Capital Markets Technology

Buy AND Build: The Future of Capital Markets Technology London examines the latest changes and innovations in trading technology and explores how technology is being deployed to create an edge in sell side and buy side capital markets financial institutions.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...