Cyber attacks, data breaches, and AI governance are now central to D&O underwriting across the Asia Pacific region. Regulators, such as the Australian Securities and Investments Commission, continue to warn about financial and reputational damage from system failures. Insurers expect boards to demonstrate ongoing oversight of digital risk, including AI adoption, with tailored D&O policies covering emerging liabilities.
Regional developments highlight the need for targeted risk management strategies tailored to the environments directors and officers operate in.
Ensuring that organizations are well-prepared to handle cyber incidents allows directors and officers to protect themselves and their business from the increasing risks associated with the digital ageLing Yu, Aon’s financial services and professions group leader for Asia
To address increasing cyber threats, regulatory scrutiny, and organizational exposure, directors and officers can take the following steps:
1. Regular Review of Risk Management Frameworks
Directors must ensure that cyber security protocols are consistently reviewed and updated to reflect emerging threats. Tools such as Aon’s Cyber Impact Analysis can help quantify the financial impact of cyber risks. In the event of an incident, these assessments may serve as evidence to regulators, courts, and shareholders that the board identified and addressed material risks with the intent to protect shareholder value, customer trust, and public interests.
2. Board Oversight and Accountability
Active involvement from the board in overseeing cyber security efforts is essential. The experience of Wyndham Worldwide Corporation demonstrates this. After facing a shareholder derivative suit over data breaches between 2008 and 2010, the company successfully defended itself by showing that the board had made cyber security a consistent agenda item, conducted regular risk reviews, and consulted experts, establishing a clear record of oversight and due diligence.
3. Training and Awareness
Boards should allocate resources to ensure both directors and senior management receive ongoing training in privacy and cyber security. Awareness of current threats and best practices helps strengthen organizational readiness and supports regulatory compliance.
4. Incident Response Planning
An effective response plan is critical for minimizing the damage from cyber incidents. Directors must confirm that such plans are in place and tested regularly to ensure rapid action and clear communication during disruptions.







