Executive Summary
Bauer's board carries formal responsibility for cyber risk oversight across a group operating as a federation of largely autonomous media brands. That structure serves the business well commercially, but it creates a specific governance problem: without a deliberate design, the board's view of cyber risk becomes whatever each brand happens to report, in whatever form, at whatever interval, rather than a consistent picture the board can actually challenge.
Bauer engaged Epitechnic to assess how cyber risk was being owned, reported, and challenged across the group as it actually operated, not as policy assumed it operated. Epitechnic reviewed governance structures, reporting lines, and accountability at both group and brand level, identifying where ownership was clear, where it was assumed, and where board reporting was not giving directors what they needed to exercise real oversight.
The result is a governance model and board reporting approach designed around Bauer's real structure rather than a generic template, giving the board a consistent, challengeable view of cyber risk across every brand, and giving each brand clarity on what it owns and what it must report upward.
Business Challenge
Bauer is one of Europe's largest media companies, publishing more than 600 titles and operating over 50 radio and TV stations across multiple European markets, with more than 100 brands in the UK alone reaching over 25 million consumers. A board's ability to govern cyber risk depends entirely on the quality and consistency of what reaches it. In a decentralised group where brands operate with real autonomy, that consistency cannot be assumed. Without a governance model designed for a federated structure, board reporting tends to reflect whichever brands are most engaged or most exposed at a given moment, rather than the group's actual risk position.
Left unaddressed, this creates a specific and serious exposure: a board that believes it is exercising oversight, because it is receiving reports, while in practice it cannot challenge what it receives, because ownership and accountability for the underlying risk are unclear. That gap is difficult to detect until it is tested, whether by an incident, a regulator, or an auditor asking who was accountable for a specific decision.
Success Criteria
- A clear, consistent picture of how cyber risk is owned and managed across every brand
- A board reporting approach the board can genuinely challenge, not simply receive
- Explicit accountability for cyber risk decisions at both group and brand level
- A governance model proportionate to the group's actual structure and risk profile, not a generic template
Epitechnic Approach
Epitechnic began by establishing how cyber risk governance actually operated across Bauer today, engaging with group-level leadership and brand-level teams to map where ownership, reporting, and challenge genuinely existed versus where they were assumed. This governance-first approach reflects a consistent principle across Epitechnic's advisory work: a board reporting line that no one is accountable for feeding accurately is not a control, it is a formality.
Findings were prioritised by their significance to the board's ability to exercise real oversight, rather than treated as a uniform list of governance gaps. Throughout, Epitechnic worked directly with the structures responsible for board reporting, positioning the engagement as advisory design work rather than a compliance audit.
Solution
Mapping ownership and accountability
Ownership of cyber risk decisions varied across Bauer's brands, and it was not always clear who was accountable for what reached group and board level. Epitechnic decided to map ownership and accountability explicitly across the group, rather than assume the group's formal structure reflected where decisions were actually made. Epitechnic reviewed existing governance structures against how brands actually operated in practice.
Accountability that is assumed rather than assigned tends to default to whoever is easiest to ask, not whoever is actually responsible. Making ownership explicit is what allows a governance model to function under pressure, not just on paper. The result was a clear map of where cyber risk ownership genuinely sat across the group.
Reporting lines to the board
Board reporting on cyber risk did not consistently give directors a basis to challenge what they were told. Epitechnic decided to review reporting lines end to end, from brand-level risk information through to what actually reached the board, rather than assess the board papers in isolation.
A board can only challenge what it can see clearly. Reporting that is inconsistent in scope, depth, or frequency across brands leaves directors unable to compare risk across the group or ask informed questions. The result was a clear view of where reporting gave the board a genuine basis for oversight and where it did not.
A proportionate governance model
A single, centralised governance model would not fit a group where brands operate with real autonomy, but no governance model at all left the board without consistent oversight. Epitechnic decided to design a model and board reporting approach proportionate to Bauer's actual structure and risk profile, rather than apply a generic governance template.
A governance model that does not fit how the organisation actually operates will not be sustained once the engagement ends. Designing for the group's real structure was intended to make the model durable rather than a document a review would produce once and no one would maintain. The result was a governance model and board reporting approach proportionate to the group's structure and risk profile.
Outcomes
Governance improvements: Accountability for cyber risk decisions clarified across group and brand level, replacing assumed ownership with explicit ownership.
Executive benefits: The board now has a reporting approach designed to give it a genuine basis for challenge, rather than a summary it can only receive.
Risk reduction: Reporting inconsistencies that previously left gaps in the board's view of cyber risk have been identified and addressed by the new model.
Decision-making improvements: Cyber risk decisions are owned by the people accountable for them, at the level of the organisation where those decisions are actually made.
Compliance improvements: A governance model that reflects actual practice gives the group a stronger position when demonstrating board oversight to auditors, regulators, or insurers.
Why It Worked
The engagement succeeded because it treated board reporting as a design problem rooted in the group's real structure, not a template to be applied uniformly. A federated organisation that receives centralised, uniform governance will either outgrow it or quietly ignore it. By mapping where ownership and accountability genuinely sat before designing the reporting model, Epitechnic ensured the board's new view of cyber risk reflects how Bauer actually operates, which is what makes it durable.
Client Testimonial
[Client testimonial to be added]
Key Takeaways
Challenge: A decentralised, international group needed the board to have a genuine, challengeable view of cyber risk, but accountability and reporting had grown inconsistently across autonomous brands.
Approach: Epitechnic mapped how cyber risk was actually owned and reported across the group, then designed governance and board reporting around that real structure.
Outcomes: Explicit accountability, consistent board reporting, and a governance model proportionate to the group's actual structure.
Lessons: A board can only govern what it can see and challenge; governance design has to start from how the organisation actually operates, not from a standard template.
