Contents

Newsletter

Get the latest cyber news and updates straight to your inbox.

The Cyber Governance Code of Practice, Broken Down

Cyber governance is no longer a "nice to have". It’s a board-level imperative. The UK’s new Cyber Governance Code of Practice outlines the minimum standards that regulators, clients, and insurers expect from boardrooms in medium and large organisations. This Code shifts cyber from IT’s responsibility to the board’s. If you're a COO, compliance lead, or board member, this applies to you now.

Want to Know Where You Stand?

Benchmark your alignment with our Cyber Code Readiness Checklist.

What is the Cyber Governance Code of Practice?

Published by the Department for Science, Innovation and Technology (DSIT), this Code sets out clear actions that boards should take to ensure effective oversight and resilience against cyber threats. 

It applies to medium and large UK organisations – plus small tech firms – and it complements, but doesn’t replace, standards like Cyber Essentials or ISO 27001. 

Key Weaknesses the Code Addresses

Many boards still: 

  • Treat cybersecurity as a pure IT issue 
  • Lack visibility into supply chain and SaaS risks 
  • Don’t regularly test incident response plans 
  • Fail to align cyber strategy with business goals 

 

The Code is designed to correct that. 

Want More Detail On How This Plays Out?

We cover it in our recent webinar

5 Actions Every Board Should Take

1. Own the Risk

Ensure your organisation has a cyber risk register, with clear ownership and defined risk appetite. 

2. Align Cyber to Strategy

Cyber resilience should be built into business planning, budgeting, and outcomes. 

3. Build a Security Culture

Mandate cyber training from the board down. Ensure culture, policies, and behaviours support resilience. 

4. Plan for Incidents

Test incident response plans at least annually. Boards must take responsibility for regulatory reporting and post-incident reviews. 

5. Demand Reporting

Set quarterly reporting expectations. Integrate cyber into audit plans. Communicate regularly with senior managers on Cyber Security topics. 

Why It Matters to You

Boards are increasingly accountable for cyber posture. That means you will be asked questions by auditors, regulators, and clients. 

FoxTech helps organisations run board workshops, assess governance maturity, and build cyber resilience from the top down. 

Ready to take action?

Book your free cyber risk assessment

giles.atkinson

Hiding in Plain Sight

Webinar Hiding in Plain Sight: The Cyber Risks Built Into Your Daily Operations The UK’s biggest cybersecurity threat might already be inside your organisation. Are you ready to face it? Cybersecurity breaches aren’t just the

Read More »
anthony.green

Ransomware Red Flags

Ransomware attacks are a growing concern for businesses of all sizes, but especially for mid-sized companies that may not have the extensive resources of larger corporations.

Read More »