Raymond Cheung
Chartered Actuary · CRO · Board Adviser · Singapore
A breach happening to your organisation is not, by itself, a director's problem. What is a director's problem is not being able to show the board asked the right questions before it happened. Singapore's stepping-stone liability doctrine and MAS's individual accountability regime both turn on that distinction — and most boards have never tested which side of it they're on.
I have sat with a board in the week after a breach became public, watching individual directors quietly do the math on their own personal exposure for the first time. Up to that point, cyber risk had been a line on the enterprise risk register with a green or amber status next to it. Afterwards, it was a question every director was asking privately: could this come back on me personally, not just on the company? The honest answer in Singapore is yes — but not for the reason most directors assume. A breach happening to your organisation is not, by itself, a breach of your duties. What exposes a director personally is not being able to show, after the fact, that the board asked the right questions before the incident, not after it.
Stepping-stone liability: how a company's failure becomes yours
Singapore law does not treat a cybersecurity incident as an automatic breach of directors' duties. What it recognises is 'stepping-stone' liability — a director becomes personally liable not for the breach itself, but for failing to prevent the company's contravention of its legal obligations, with that contravention acting as the stepping stone to the director's own exposure. Section 157 of the Companies Act requires a director to use reasonable diligence in the discharge of their duties. Directors and officers can be held personally liable where a failure is attributable to their neglect, consent or connivance. Under the Cybersecurity Act, officers of a company — particularly a designated critical infrastructure operator — who consented to or negligently failed to prevent an offence under the Act can be personally prosecuted, not just the company. The distinction that matters is subtle but decisive: the law is not asking whether your organisation was attacked. Every organisation eventually is. It is asking whether you, as a director, kept yourself informed about cyber threats, implemented appropriate risk management strategies, and ensured compliance with legal obligations before the incident happened.
“The breach is not the director's exposure. The absence of a documented, board-level answer to 'what did we do before this happened' is.”
The MAS layer most directors haven't clocked
Stepping-stone liability sits alongside a separate, regulator-driven accountability regime that applies more broadly than most directors realise. MAS's Guidelines on Individual Accountability and Conduct, issued in 2021, make clear that senior managers in key roles — technology risk among them — will be held individually responsible for misconduct or failures on their watch, independent of whatever the company itself faces. For a financial institution's board, that means the question is no longer just 'is the company compliant' but 'can each accountable individual demonstrate they exercised oversight over the specific risk area they were responsible for.' I have seen boards assume this framework only touches the CISO or the head of technology. It doesn't stop there — it reaches any senior individual whose role gives them oversight of technology risk, and increasingly that includes non-executive directors sitting on a board risk or audit committee with cyber explicitly in scope.
What actually protects a director
The practical implication is that a director's defence is built before an incident, not during the crisis response. Minutes that show the board actually engaged with a cyber briefing — asked what the recovery time objective was, challenged an assumption in the risk register, requested a follow-up — are worth more than any post-incident statement of regret. A board that can produce a paper trail of genuine, substantive engagement with cyber risk over time is in a fundamentally different legal position than one that can only produce a stack of status updates nobody questioned. I ask boards I advise a version of the same three questions after every serious incident I have been close to, and I would rather a board ask them before one:
- If a regulator or a court asked to see evidence that this board exercised genuine diligence over cyber risk in the twelve months before an incident, could you produce board minutes that show real engagement, not just noted updates?
- Does every director understand that MAS's individual accountability regime can reach them personally if they hold oversight responsibility for technology risk, not only the named CISO or CTO?
- Has the board tested, in a tabletop exercise, whether its post-incident response would actually demonstrate the 'skill, care and diligence' standard the law expects, or would it look improvised under scrutiny?
None of this is about directors becoming technologists. It is about directors understanding that the legal test was never whether the organisation gets breached — it is whether the board can prove, in writing, that it took the risk seriously before that day arrived. That proof either exists in your board papers already, or it doesn't, and by the time you need it, it is too late to go back and create it.
Common Questions
Can a director in Singapore be personally liable for a cybersecurity incident?
Yes, through 'stepping-stone' liability. A director is not automatically liable because the company suffered a breach, but can become personally liable for failing to prevent the company's contravention of its legal obligations — for example under section 157 of the Companies Act's reasonable diligence duty, or under the Cybersecurity Act where an officer consented to or negligently failed to prevent an offence.
What does MAS's Guidelines on Individual Accountability and Conduct mean for board directors?
Issued in 2021, the guidelines hold senior individuals in key roles — including technology risk — personally accountable for failures on their watch, separate from the company's own liability. This can extend to non-executive directors with oversight responsibility for cyber risk through a board risk or audit committee, not just the CISO.
How can a Singapore board protect its directors from personal cyber liability?
The strongest protection is a documented record of genuine board engagement with cyber risk before an incident — minutes showing substantive questions asked and followed up on, not just status updates noted. Regular tabletop exercises testing the board's actual response also help demonstrate the skill, care and diligence standard the law expects.
About the author
Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.