Skip to main content

Cyber resilience gets a P&L: Treasury reframes the board conversation

HM Treasury has published evidence positioning cyber resilience as a driver of financial performance and growth, not a compliance cost. For boards, it shifts the internal argument from risk avoidance to capital allocation, with implications for how CROs, CFOs and CEOs frame investment cases.

HM Treasury has recast the cyber resilience debate. Its new report, The Value of Resilience: Cyber Resilience in Financial Services, published on 8 July 2026, argues that resilience should be treated as a strategic enabler of growth and stability, rather than solely as a compliance cost (HM Treasury). The document, developed with Accenture, KPMG, FreedomPay, Retail Economics, Resilience and the Association of British Insurers, sets out evidence that stronger resilience reduces the likelihood and impact of disruptions, supports faster recovery, and improves financial performance (HM Treasury). The framing matters more than the findings.

For years, cyber has sat awkwardly on board agendas: too technical for strategy discussions, too consequential to delegate. Treasury's intervention gives CFOs and CEOs a sanctioned vocabulary to move cyber spend out of the compliance column and into the growth column. That is a meaningful shift in stakeholder dynamics. CISOs and operational resilience leads have long struggled to compete for capital against revenue-generating initiatives. A government-backed evidence base, co-authored with two of the big four and the ABI, changes the internal bargaining position. Expect resilience business cases to be rewritten this autumn with explicit references to the report's growth and recovery arguments.

The timing is not accidental. The Financial Policy Committee's July record noted that recent rapid advances in frontier AI capabilities have increased financial stability risks related to cyber and operational resilience (Bank of England). The FPC also flagged that vulnerabilities across risky asset valuations, sovereign debt, and private credit have become more pronounced since December 2025, with a substantial increase in equity market leverage (Bank of England). Sarah Pritchard, FCA deputy chief executive, used her 8 July speech at the Whitehall Industry Group to reinforce that markets shift faster with AI, and that good regulation means being both principled and agile (FCA). Three arms of the official family, Treasury, the Bank and the FCA, are aligning around the same message: operational fragility is now a first-order financial stability question, and firms that treat it as back-office hygiene will be exposed.

The stakeholder implication cuts in two directions. Internally, resilience leaders have new leverage in capital allocation debates, but they also inherit a higher burden of proof. If cyber investment is a growth story, boards will want returns modelled, not just risk registers updated. Externally, insurers, auditors and rating agencies now have a Treasury-endorsed framework for pricing resilience into their assessments. The ABI's involvement in the report signals that cyber insurance underwriting standards will tighten around the evidence base it establishes. Firms that cannot demonstrate the recovery metrics Treasury highlights should expect harder conversations at renewal.

Senior leaders should read the report not as guidance but as a repositioning. The compliance framing that has dominated cyber governance since the operational resilience rules took effect is being retired in favour of a performance framing. That changes who owns the conversation at board level: less the CRO alone, more the CFO and COO jointly. The firms that adjust their governance and disclosure to match will find capital, insurance and regulatory goodwill easier to secure. Those that do not will be defending yesterday's argument.

What this reveals

Treasury's reframing exposes how long cyber and operational resilience have been miscategorised inside firms as compliance overhead rather than strategic capital. That miscategorisation was itself a stakeholder misread: boards assumed regulators, investors and government viewed resilience spend as a cost of doing business, when in fact the official family is converging on resilience as a growth and financial stability lever. Other leadership teams may now wrongly assume their existing cyber investment case is still fit for purpose, when the burden of proof has quietly shifted from 'we spent enough to be compliant' to 'we can evidence the return on resilience'. The wider issue is that when Treasury, the Bank and the FCA align on a reframing, firms that keep using the old vocabulary in board papers will look out of step with supervisory expectations before they realise the language has moved.

Questions accountable leaders should ask

  • 01Does our current cyber and operational resilience investment case articulate a return in growth and recovery terms, or only in risk-avoidance and compliance terms?
  • 02When did we last test whether our board's mental model of what regulators and Treasury expect on resilience matches what those decision-makers are actually saying in 2026?
  • 03If the CRO, CFO and CEO were asked separately to describe the strategic value of our resilience spend, would their answers align, and would they align with the Treasury framing?
  • 04Who inside the firm currently owns the burden of proof that resilience investment generates financial performance, and do they have the evidence base to defend it under board or supervisory challenge?
  • 05Are we treating the FPC's AI-linked resilience warnings as a technical matter for the CISO, or as a first-order financial stability question the board itself should be tracking?

What accountable leaders should do now

  1. 1Commission a rapid review of every live resilience business case and board paper to identify where the framing still leans on compliance language rather than the growth, recovery and financial performance vocabulary Treasury has now sanctioned.
  2. 2Pressure-test the board's assumptions about what regulators, investors and government actually expect on resilience against the current Treasury, Bank and FCA positioning, and record where the gaps sit.
  3. 3Ask the CRO, CFO and CISO to jointly produce a single evidence base linking resilience investment to measurable financial and operational outcomes, so the higher burden of proof is met before the next capital allocation round rather than during it.
  4. 4Add resilience to the standing board agenda as a strategic and financial stability item, not a technology risk update, and require dissent and challenge to be recorded on the decision.
  5. 5Brief investor relations and external stakeholders on how the firm now frames resilience, so the internal shift is visible in the places that shape reputation and cost of capital.

Explore the practical guide

This guide identifies where board-level strategic thinking typically diverges from what supervisors actually care about in financial services, and how to spot and close those gaps before they become enforcement problems. After reading, you will be able to audit your own board papers and strategy documents for the specific blind spots regulators notice.

Read the guide

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity

Stakeholder Signals

Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.