Board-Level Governance (Cyber Governance Code)
Does your organisation have…
✅ A recent risk register that identifies critical technology and processes, the cyber risks they face and realistic plans to address them.
✅ An effective cyber strategy that supports the business strategy and meets regulatory obligations while aligning with an agreed risk appetite.
✅ A cyber security culture, with awareness, policies and training across the organisation supported by a nominated board member.
✅ An incident response plan tested within the last 12 months.
✅ Supplier risk management policies with clear oversight.
✅ Effective cybersecurity governance, the clear roles, regular dialogue and at the exec level, supported by relevant audits and reporting to the board.
Software Security Practices (Software Security Code)
Can you confidently say yes to the following?
✅ Development follows an established secure development framework, led by a senior staff member.
✅ Security testing is built into every software release.
✅ All third-party components are tracked and updated.
✅ Developers receive regular security training.
✅ The build environment is secured and monitored for unauthorised activity.
✅ Vulnerabilities are managed, detected and resolved with timely notifications published to customers and relevant suppliers.
✅ The supported lifetime of the software is clearly published and at least 1 years notice is provided before end of support.
✅ Software is distributed securely.
Cross-Team Ownership (Software Security Code)
Are your teams working together on compliance?
✅ Tech, legal and operations collaborate on cyber governance
✅ Cyber responsibilities are embedded in role descriptions
✅ You’ve assessed your readiness against the new Codes
✅ You’re prepared to show evidence of alignment in audits or tenders
Want help with implementation?
FoxTech offers a range of workshops, secure SDLC audits, and governance support.
Book a 15-minute consultation today
Check your Cyber Readiness with our free Cyber Risk assessment