
Cyber Governance Code of Practice
Sets out the most critical governance actions that directors need to take ownership of.
Resources to enable Boards to govern cyber risks with confidence.
Technology and digital systems are at the heart of modern business, driving innovation, growth, and competitiveness. As organisations adopt emerging technologies, they also introduce new risks - cyber risk being one of the most significant.
Cyber threats can disrupt operations, damage reputation, and weaken competitiveness, making cyber risk a principal business risk. As with any major risk, Boards and directors have a critical responsibility to govern it effectively. However, many organisations are still not addressing this challenge with the urgency it demands.






These Cyber Governance resources have been created to support boards and directors in governing cyber security risks. They also clarify the government’s expectations for Board accountability in overseeing cyber security risk management in medium and large organisations.
Sets out the most critical governance actions that directors need to take ownership of.
Resources to enable Boards to govern cyber risks with confidence.
Resources to enable Boards to govern cyber risks with confidence.
These resources are tailor-made for Boards and directors of both public and private organisations across the UK.
That could be:
Although not specifically designed for smaller organisations, they offer valuable benefits and practical insights that can help strengthen their approach to governance.
Boards should begin with the Cyber Governance Code of Practice, which is the foundation of government’s support for cyber governance. The Code is the essential starting point for board members, outlining the key actions needed to govern cyber security risks effectively.
Next, the Cyber Governance Training helps Boards and directors deepen their understanding of these actions, providing practical insights into why they matter and how to implement them.
Finally, the Cyber Security Toolkit for Boards offers in-depth resources to support the implementation of the actions outlined in the Code, ensuring Boards have the tools they need to manage cyber risks comprehensively.
Cyber security risks demand Board-level attention. While directors don’t need to be technical experts, they must understand cyber governance principles so they can ask the right questions, evaluate preparedness, and ensure cyber security measures align with the business’s goals.




