Topics
Newsletter

Get the latest cyber news and updates straight to your inbox.

The Cyber Governance Code of Practice, Broken Down

Cyber governance is no longer a "nice to have". It’s a board-level imperative. The UK’s new Cyber Governance Code of Practice outlines exactly what regulators, clients, and insurers expect from boardrooms in medium and large organisations. This Code shifts cyber from IT’s responsibility to the board’s. If you're a COO, compliance lead, or board member, this applies to you now.

Want to Know Where You Stand?

Benchmark your alignment with our Cyber Code Readiness Checklist.

What is the Cyber Governance Code of Practice?

Published by the Department for Science, Innovation and Technology (DSIT), this Code sets out clear actions that boards should take to ensure effective oversight and resilience against cyber threats. 

It applies to medium and large UK organisations – plus small tech firms – and it complements, but doesn’t replace, standards like Cyber Essentials or ISO 27001. 

Key Weaknesses the Code Addresses

Many boards still: 

  • Treat cyber security as a pure IT issue 
  • Lack visibility into supply chain and SaaS risks 
  • Don’t regularly test incident response plans 
  • Fail to align cyber strategy with business goals 

 

The Code is designed to correct that. 

Want More Detail On How This Plays Out?

We cover it in our recent webinar

5 Actions Every Board Should Take

1. Own the Risk

Ensure your organisation has a cyber risk register, with clear ownership and defined risk appetite. 

2. Align Cyber to Strategy

Cyber resilience should be built into business planning, budgeting, and outcomes. 

3. Build a Security Culture

Mandate cyber training from the board down. Ensure culture, policies, and behaviours support resilience. 

4. Plan for Incidents

Test incident response plans at least annually. Boards must take responsibility for regulatory reporting and post-incident reviews. 

5. Demand Reporting

Set quarterly reporting expectations. Integrate cyber into audit plans. Talk to your CISO regularly. 

Why It Matters to You

Boards are increasingly accountable for cyber posture. That means questions from auditors, regulators, and clients are coming your way. 

FoxTech helps organisations run board workshops, assess governance maturity, and build cyber resilience from the top down. 

Ready to take action?

Book your free cyber risk assessment