In Conversation with Janette Hodges
15 June 2026
Janette Hodges is an experienced Independent Non-Executive Director with an executive background in Digital, Cybersecurity and Transformation. This is a much sought after skill-set on any Board given the heightened risks and new opportunities for the public sector today.
Janette, welcome to the blog. To start, please tell us about your professional executive background.
I’ve spent much of my career in senior business and technology roles, mostly running large transformation programmes in big multinational companies. These have been business change roles with a lot of digital and cyber elements.
I started out at British Airways where I was Head of IT and Change Programmes. That job was as much corporate as technical which led to a role launching and selling subsidiary airlines for BA. So I learned early not to treat technology and business strategy as separate things.
After BA I moved across a variety of sectors as CIO and Transformation Director, the one often leading to the other, with digital and technology strategies leading to business change and turnaround strategies.
How has your executive career equipped you to serve as a NED on a public sector board?
Being a non-executive is a very different job from being an executive, and people can sometimes underestimate that. As an executive you’re paid to make things happen. As a non-exec you’re there to oversee, challenge and give assurance. You have to influence without any executive authority behind you, and know when to push and when to leave it alone. A few parts of my background help with that.
The obvious one is challenge on technology, digital and cyber. A lot of boards are short of expertise here, and that’s a growing problem. Because I’ve built cyber capability myself, run technology across multiple countries and delivered some big programmes, I can usually tell whether a management team is on top of digital risk or just presenting a confident slide. I know where to dig and where to challenge an optimistic presentation.
I also know what transformation really looks like, including when it goes wrong – I’ve seen large programmes succeed and even more often I’ve seen them fail. That makes me hard to convince with optimistic timelines and under-costed plans, which is where a lot of value gets lost in both sectors.
The governance and risk side translates really well, experience of good corporate governance and risk as an Exec helps as does experience of creating or running projects and programmes.
I also did a NED Diploma when I was thinking of transitioning away from Exec roles and that was invaluable in helping to think through how to adapt to such a new way of thinking and operating.
Which public sector boards have you served on?
The current one is Sellafield Ltd, where I’ve been a non-executive director since September 2023. On the board I have specific responsibility for Cybersecurity, Digital Transformation and Sustainability, and I sit on three committees: Environment, Health, Safety and Security; Audit and Risk; and People and Remuneration. Sitting across all three means I see the organisation through aspects of safety, security, finance and workforce, not only through technology.
Before that I held two linked public-sector roles in the NHS. I chaired the board of North West Shared Infrastructure Services, a public/private partnership of more than £50m providing shared infrastructure across the region, and I was at the same time CIO and a board member of a large NHS Foundation Trust. Between them they taught me a lot about NHS governance, the politics of running shared services across multiple organisations, and what it takes to deliver change under public-sector funding and accountability.
What are the most common challenges and biggest issues you’ve encountered, and how do these differ from the private sector?
In the private sector the accountability line is fairly clear, you answer to shareholders, through the board. In the public sector it’s much wider, and not everyone wants the same thing. You answer to the government department that sponsors you, to ministers, to Parliament, to your regulators, and to the public and taxpayers who pay for you.
Funding works very differently too. Public bodies live within government spending settlements and annual budgets, which makes it harder to commit to steady, multi-year investment than it is in a company that can sign off multi-year capital against a business case. That’s a real issue for digital and operational resilience, which needs consistent investment and the ability to ramp up when things change.
I also found the Seven Principles of Public Life interesting: selflessness, integrity, objectivity, accountability, openness, honesty and leadership. In addition to the other expectations of a director, they sit inside the codes of conduct that public body board members work to, and it isn’t just a rulebook.
What do you enjoy most, or find most rewarding as a NED?
I love the scope of it. At Sellafield I sit across the Environment, Health, Safety and Security committee, Audit and Risk, and People and Remuneration, so I see the whole organisation rather than one function. After a career spent mostly in technology and transformation, I like having to get to grips with operations, safety, environment, finance and workforce all as part of the same picture. It draws on everything I’ve done and I’m still learning.
I also like the way you work through influence rather than authority, although it has taken me a while. As an executive you make change happen directly. As a non-exec your contribution is a question asked at the right moment, or naming a risk nobody else has, or recognising a pattern from experience, an over-optimistic plan or a thin bit of cyber assurance, before it turns into a problem.
The part I value most, though, is the public benefit. My private-sector roles were rewarding, but the public work carries a weight that means more to me at this point. Sellafield’s job is safe, secure decommissioning and cleaning up the environment over a timescale of decades, work that protects people and the country long after any of us have left the board. Bringing my cyber and digital experience to something of that national importance, is the most rewarding thing about it and where I believe I can add real value.
Running through all of it is mentoring and developing senior people. That’s been part of my whole career and it’s still one of the things I enjoy most.
What IT and cyber-related questions would you ask the Board at your first meeting?
This is where a CIO or technology leader earns their place on a board, because it’s usually the missing perspective and deep understanding. I try to ask governance questions of the exec members of the board, and how they answer tells me whether cyber is being treated as a serious business risk or has been left sitting inside the IT function. Most of these can come from the NCSC’s Cyber Security Toolkit for Boards, which I’d expect any UK board to be working from.
I’d want to know who actually owns cyber risk at executive level, and whether it’s on the corporate risk register as a strategic risk or buried somewhere in an IT report. How often does it come to the board, and through which committee?
I’d ask what our most critical systems, services and data are, and whether we know where they sit, who can get at them, and what would happen to the business if we lost them or they were compromised. Ultimately, what is the operational resilience. What are we most exposed to? And is that picture kept current, or reviewed once a year and filed away?
On assurance, ideally you need to push past reassurance, and that is where you may have to challenge some of the detail. What’s our stated risk appetite for cyber, and how does the board get independent confirmation that the controls actually work, rather than just that the policies exist? Do we measure ourselves against a recognised framework, and who tests us?
The one I press hardest is the operational resilience, not just incident response. We can all say we have a plan but when did the board last see it tested in the real world? An exercise is worth far more than a document nobody has opened, and the board should expect to hear what the exercise turned up and what changed as a result e.g.have we proved we can restore from backups rather than just assuming we can?
Suppliers matter as much as our own systems. How do we understand and manage cyber risk across our supply chain and key third parties? An attack on a supplier can hurt us just as badly as an attack on us, so it has to feature in decisions about new suppliers and partnerships.
Then there’s where the rules are heading, which boards need to be aware of. The Cyber Security and Resilience Bill going through Parliament is expected to bring more organisations into scope, tighten the rules on reporting incidents, and give regulators more teeth, with a lot of the detail still to come in secondary legislation and codes of practice. Put that next to the NCSC toolkit and its Cyber Governance Code of Practice and the message is consistent: cyber resilience is turning into something the board owns, not something it can hand down to IT. The board has to understand and own cyber risk itself. Assurance has to be earned by testing and exercising, not just claimed on paper. And reporting has to stand up to a regulator, and ultimately to the public. So, I’d ask whether we’re clear on how the changing rules apply to us, and whether we’re already running cyber the way we’ll be expected to. For somewhere like Sellafield, in critical national infrastructure, there’s the added question of how any new duties sit alongside the regulation we already answer to.
I’d want to see the metrics the board gets, and ask whether they really tell us if we’re getting more or less secure, or whether they’re just activity counts that make everyone feel better.
The final thing I’d say to anyone going into their first board meeting is that at least initially, the answers probably matter less than how the executives (not just the CIO) handle the questions. If they can talk about all this confidently and without getting defensive, the governance is probably in good shape. If they can’t, you’ve just found the first thing to work on.
What advice would you give to a business leader considering applying for a public sector board role?
First, be honest with yourself about whether you actually want to govern rather than run things, and it doesn’t matter if it is a private or public sector role, it can be very difficult to let go of the executive habit. If you start trying to manage the organisation instead of holding it to account, you’ll be frustrated and you’ll get in the executives’ way. Your influence needs to come from your judgement and the quality of your questions, based on your experience and knowledge of what good looks like.
It is always worth doing your homework on the organisation before you apply, as with any company you were joining. If you can, find out which department sponsors it, what state its funding is in, what its regulators are like and what challenges it may be facing. You can usually get the latest annual report and accounts and any recent National Audit Office or Public Accounts Committee reports, because those will tell you honestly whether the body is under pressure.The recruitment itself tends to be more formal than private recruitment, it may well be regulated and run through a structured process with a panel, and the timelines are longer, sometimes much longer.
If you’re a CIO or a technology leader, my main piece of advice is to go with that. Boards know they’re short of real cyber, digital and data expertise, and that’s the gap where you can add real value and know you are making a difference in something that is some of the most worthwhile work there is.
Thank you, Janette.