UK Cyber Governance Code

UK Cyber Governance Code: What It Asks of Your Board

The UK Cyber Governance Code of Practice sets out what boards are expected to do about cyber risk: 22 actions across five principles, covering risk management, strategy, people, incident response, and assurance and oversight. It is currently voluntary, and it is the standard regulators, insurers and sector bodies increasingly expect boards to meet. This page covers what each principle requires and the evidence a board needs to demonstrate it.

Book a Board Cyber Governance Review

22 actions. 5 principles. No technical knowledge required.

Score your board against the Code

The assessment is free, covers all 22 actions, and returns a board-level report in under five minutes. It sits alongside the rest of the free assessment tools.


The State of UK Board Cyber Governance: What the Data Shows

Cyber governance has moved from a technology concern to a boardroom accountability. The DSIT Cyber Security Breaches Survey 2025 makes that case in numbers that are difficult to dismiss.

Forty-three per cent of UK businesses experienced a cyber security breach or attack in the past 12 months. For medium-sized businesses that figure rises to 67 per cent. For large businesses it reaches 74 per cent. These are not edge cases or statistical outliers. The majority of large UK organisations were breached or attacked in a single year.

What makes those numbers material for boards is the governance context surrounding them. Only 27 per cent of UK businesses have a board member with specific responsibility for cyber security, down from 38 per cent in 2021. The businesses being attacked most frequently are the same businesses least likely to have named board-level ownership of the risk.

The 2025 ransomware incidents affecting Marks and Spencer and the Co-op changed the regulatory conversation in a way that years of guidance had not. Those incidents demonstrated that large, well-resourced UK organisations with established IT functions could be rendered operationally inert by a cyber attack. They also demonstrated that the question regulators and professional indemnity insurers now ask is not whether an organisation was attacked, but whether the board could demonstrate active, documented oversight of cyber risk before the incident occurred. That is the bar. This assessment exists to help you understand whether your board clears it.


Who This Is For

Chairs and NEDs

You carry the governance accountability for cyber whether or not anyone has named it explicitly. This assessment shows you where the board falls short of the UK Cyber Governance Code, in language that does not require a technical background. If you cannot answer the questions with confidence, that is itself a finding.

What you need to be able to demonstrate: that cyber risk has a named board-level owner, that the board has reviewed and approved a cyber risk appetite statement, and that you receive regular briefings that would allow you to discharge your duty of care. The specific question you may face at your next board meeting or at an AGM is: “Who at board level is accountable for cyber, and what evidence does the board review to satisfy itself on this risk?” A gap here looks like a unanimous “we leave that to IT” around the table.

CEOs Without a CISO

Most mid-market businesses run cyber as an unowned, part-time concern, typically allocated to a Head of IT or an outsourced provider who has no mandate to engage the board. The Code exists because that is exactly the governance model that fails under pressure.

What you need to be able to demonstrate: that cyber risk is formally owned, that your organisation has a cyber strategy aligned to its risk appetite, and that you have an incident response plan you have actually tested. The specific question you may face from your insurer or a prospective acquirer is: “Show me your incident response plan and the last time you tested it.” A gap looks like a plan that exists on paper but has never been exercised, or no plan at all.

PE-Backed Boards

Acquirers and insurers now read governance against the Code. A profile generated here is the briefing you want before diligence opens, not after. Cyber governance weakness identified during diligence becomes a valuation lever. Cyber governance weakness identified after acquisition becomes an integration liability.

What you need to be able to demonstrate: that your portfolio company’s board has formal cyber oversight, that supply-chain cyber risk has been assessed, and that the company can produce evidence of each. The specific question you may face in an investor meeting is: “Walk me through your board-level cyber governance structure and the assurance cycle.” A gap looks like a company that cannot produce a cyber risk register, a named board sponsor, or a tested incident response plan.

Audit and Risk Chairs

The Code maps onto the Govern function of NIST CSF 2.0 and the governance clauses of ISO 27001, so the profile it generates translates directly to the frameworks your auditors already use. Cyber should appear on your risk register, your assurance plan, and your internal audit schedule.

What you need to be able to demonstrate: that the board’s assurance framework covers cyber, that there is a governance structure with clear ownership and reporting cadence, and that findings from cyber audits or health assessments are tracked to closure. The specific question you may face from your external auditors is: “How does the board satisfy itself that cyber risk is being managed within appetite?” A gap looks like cyber appearing on the risk register but never appearing on the audit committee agenda.


What the UK Cyber Governance Code Requires: The Five Pillars in Practice

Published by the Department for Science, Innovation and Technology with the National Cyber Security Centre in April 2025, the Code sets out five principles and 22 actions that directors are expected to own. Below is what each principle actually requires in practice and the evidence a board would need to produce to demonstrate it.

A: Risk Management

The Code requires: critical assets identified, a named board-level owner of cyber risk, a defined risk appetite statement, supply-chain risk assessed, and regular reassessment of all of the above.

In practice, this means the board must be able to produce a documented asset register of the systems and data that would cause material harm if compromised, a risk appetite statement signed off at board level, evidence that supply-chain cyber risk has been assessed (not just acknowledged), and minutes or board papers showing that cyber risk is reviewed at a defined frequency. Believing these things are in order is not the same as having the evidence to demonstrate it. The Code asks for the latter.

B: Strategy

The Code requires: a cyber strategy embedded in the business strategy, aligned to the organisation’s risk appetite and regulatory obligations, resourced against stated priorities, and monitored for measurable outcomes.

In practice, this means that cyber investment decisions are traceable to a strategy, that the strategy has been reviewed at board level, and that someone is reporting against it. The most common gap here is a cyber strategy that exists inside the IT function but has never been presented to or approved by the board.

C: People

The Code requires: a security culture led visibly from the top, clear and current policies, director-level cyber awareness training, and assurance that awareness activity actually changes behaviour.

In practice, this means directors themselves need to have completed cyber awareness training and be able to say what it covered. Culture led from the top requires something more than a policy on an intranet. The board needs to be able to point to specific actions it has taken to model the right behaviours and to evidence that employee awareness is measured rather than assumed.

D: Incident Planning, Response and Recovery

The Code requires: a tested incident response plan covering critical assets, exercising at least annually with the board involved, director crisis roles defined, and lessons from incidents or exercises fed back into the plan.

In practice, this means a tabletop exercise has taken place within the last 12 months and the board was represented in it. The M&S and Co-op incidents of 2025 demonstrated how quickly a cyber incident becomes a board-level crisis. Directors who have never participated in an incident exercise will be running one under live fire conditions when an attack occurs.

E: Assurance and Oversight

The Code requires: a governance structure with clear ownership, quarterly (at minimum) reporting to the board with defined tolerances, two-way dialogue between the board and the security lead, and integration of cyber assurance into the organisation’s wider audit function.

In practice, this means the board receives a cyber risk report at least quarterly, that report includes a tolerance or threshold so the board knows when to escalate, and the security lead has a direct route to the board rather than being filtered through the executive. The most common gap here is a CISO or Head of IT who reports to the CEO with no direct board relationship.


Legal and Governance Implications for Directors

Directors in the UK have a statutory duty of care under the Companies Act 2006. That duty does not exclude cyber risk simply because it is technical in nature. A material cyber incident that results in financial harm to the company, loss of customer data, or operational disruption can, in the right circumstances, give rise to questions about whether the board discharged its duty of care in relation to cyber risk oversight.

The principle of “plausible deniability” worked differently before the Code existed. Before April 2025, a director could credibly argue that cyber risk was a specialist matter properly delegated to the IT function. After the Code, the position is harder to sustain. The Code is explicit that cyber governance is a board responsibility, not a technical one. The NCSC and DSIT have published the standard. Regulators, insurers, and litigants can now point to it.

What this means practically is that the absence of named board-level ownership, documented risk appetite, and a tested incident response plan are no longer just operational weaknesses. They are governance weaknesses that are visible to auditors, underwriters, and, following a material incident, to solicitors. Directors and Officers liability policies are increasingly requiring evidence of cyber governance as a condition of coverage.

This is not legal advice and should not be treated as such. But it is an accurate description of the landscape boards are now operating in, and why the question “could we demonstrate compliance today?” matters beyond regulatory box-ticking.


What Good Looks Like: A Board Cyber Governance Checklist

A board with sound cyber governance can demonstrate all of the following. This is not an exhaustive list, but each item is specific enough to be evidenced or not evidenced:

  • A named board-level sponsor of cyber risk, recorded in board minutes
  • A documented cyber risk appetite statement, approved at board level and reviewed within the last 12 months
  • Quarterly (minimum) cyber risk briefings to the board, with a defined reporting format
  • An incident response plan reviewed within the last 12 months and tested (via tabletop exercise or equivalent) with board participation
  • Cyber risk included in the business continuity plan, not treated as a separate and disconnected document
  • An annual cyber health assessment conducted by an independent practitioner, with findings reported to the board
  • Director-level cyber awareness training completed within the last 12 months, with a record of completion

If your board cannot produce evidence for each of these items, the gap between current state and the Code’s bar of Level 4 maturity is material.


Frequently Asked Questions

What Is the UK Cyber Governance Code?

The UK Cyber Governance Code of Practice is a standard published by the Department for Science, Innovation and Technology (DSIT) with the National Cyber Security Centre (NCSC) in April 2025. It sets out five principles and 22 actions that directors and boards are expected to own. It is distinct from Cyber Essentials, which governs technical controls. The Code governs board-level behaviour and governance structure.

Is the Code Mandatory?

The Code is currently voluntary, but that framing can create a false sense of comfort. Regulators, insurers, and sector-specific bodies are increasingly referencing it as the expected standard. In a regulated sector, your regulator may already expect evidence of board-level cyber governance consistent with the Code’s requirements. Following a material incident, the absence of Code-consistent governance will be visible and consequential.

What Is the Board’s Role in Cyber Governance?

The Code is explicit on this point: cyber governance is a board responsibility, not a technical one. The board is expected to own the cyber risk appetite, ensure that a named director has accountability for cyber risk, receive regular assurance on cyber risk management, and participate in incident response exercising. The board does not need to understand the technology. It does need to understand the risk and demonstrate active oversight of how it is managed.

How Does This Differ from Cyber Essentials?

Cyber Essentials is a technical certification. It assesses whether an organisation has five foundational technical controls in place: firewalls, secure configuration, user access control, malware protection, and patch management. The UK Cyber Governance Code operates at a different level. It assesses whether the board is governing cyber risk appropriately: whether there is ownership, strategy, culture, incident readiness, and assurance. A business can hold Cyber Essentials certification and still fail every principle of the Code. Both matter. They address different things.

What Happens if We Have a Breach and Cannot Demonstrate Board-Level Oversight?

The immediate consequences of a breach are operational. The secondary consequences are reputational and financial. The tertiary consequences relate to the questions asked by insurers, regulators, and, in serious cases, legal advisers. If the board cannot demonstrate that it had named ownership of cyber risk, a documented risk appetite, and a tested incident response plan, those absences become part of the post-incident record. D&O insurers, professional indemnity underwriters, and regulators can and do ask for that evidence. The time to build it is before an incident, not after.


Four Steps to a Board-Ready Profile

Step 1: Pick the level. For each of the 22 actions, choose the behaviourally anchored description that matches what your board could evidence today.

Step 2: Declare the evidence. Say whether each answer rests on documents you could produce, knowledge you hold, or belief. The tool grades its own reliability.

Step 3: Get the profile. A principle-by-principle maturity profile, each principle constrained by its weakest action, against the Code’s bar of Level 4.

Step 4: See the gap. The exact gap action by action, weakest first, with the evidence artefact to create for each one.


Book a Board Cyber Governance Readiness Call

If the assessment surfaces gaps you want to close with external support, or if your board needs an independent view on its current cyber governance posture before a regulatory review, an investor conversation, or an audit, the next step is a conversation.

In 45 minutes, we will assess your current board-level cyber posture, identify the specific gaps relative to the UK Cyber Governance Code, and outline the practical steps to close them. No jargon. No sales pitch. A structured view of where you stand.

Book a 45-minute Board Cyber Governance Readiness Call


The UK Cyber Governance Code of Practice was published by the Department for Science, Innovation and Technology and the National Cyber Security Centre in April 2025. Statistics cited from the DSIT Cyber Security Breaches Survey 2025.