UK Cyber Governance Code

The five principles

The Cyber Governance Code is structured around five principles, each with specific actions for boards to implement:

1. Risk management

Boards must ensure that cybersecurity risks are identified, assessed, and managed as part of the organisation’s overall risk management framework. This means cyber risk appears on the corporate risk register with the same rigour as financial, operational, and legal risks. Boards should understand the organisation’s critical assets, the threats they face, and the potential impact of a cyber incident on business operations, reputation, and regulatory standing.

2. Strategy

Organisations must have a cybersecurity strategy that is aligned with business objectives and reviewed regularly at board level. The strategy should set out the organisation’s current security posture, target maturity level, and a roadmap for closing gaps. It must be resourced,  both in terms of budget and people, and updated in response to changes in the threat landscape, business operations, or technology environment.

3. People

The code requires boards to ensure that the organisation has the right skills, training, and culture to manage cybersecurity effectively. This includes appointing a named individual with responsibility for cybersecurity at senior leadership level, providing regular cybersecurity awareness training for all staff, and building a security culture where reporting incidents and near-misses is encouraged rather than punished.

4. Incident planning

Boards must ensure that the organisation has a tested incident response plan. This goes beyond having a document on a shelf — the code expects organisations to conduct regular exercises, such as tabletop exercises and cyber crisis simulations, to validate that their response procedures work under pressure. The plan should cover escalation routes, communication protocols (internal and external), regulatory notification obligations, and business continuity measures.

5. Assurance and compliance

Organisations must establish mechanisms to assure themselves that their cybersecurity controls are effective. This includes regular security assessments, penetration testing, compliance audits, and independent review. Boards should receive periodic reporting on security posture, incident trends, and the status of remediation activities. Where the organisation operates in a regulated sector, compliance with sector-specific requirements (NIS Regulations, FCA guidance, PRA expectations) should be tracked and reported to the board.

Who the code applies to

The Cyber Governance Code is written for directors and board members, not technical security teams. It deliberately avoids prescribing specific technologies or technical controls, those are covered by frameworks such as [NCSC CAF](/glossary/ncsc-caf/), Cyber Essentials, and ISO 27001. Instead, the code focuses on governance: how boards should oversee, resource, and hold themselves accountable for cybersecurity.

While voluntary, the code carries implicit weight. Government procurement frameworks increasingly reference board-level cybersecurity governance as an evaluation criterion. Regulators in financial services, energy, and telecommunications already expect governance practices aligned with these principles. Organisations that adopt the code proactively position themselves ahead of what may eventually become regulatory expectation.

The code complements rather than replaces existing frameworks. An organisation certified to Cyber Essentials Plus demonstrates baseline technical controls. An organisation following the NCSC CAF demonstrates operational security management. The Cyber Governance Code adds the governance layer, ensuring that the board is actively overseeing and accountable for the security programme, not just delegating it.

Relationship to existing frameworks

The Cyber Governance Code does not exist in isolation. It sits alongside and references several established frameworks:

  • NCSC CAF — the Cyber Assessment Framework provides a detailed set of indicators for managing security. The Governance Code’s five principles align with CAF objectives but operate at a higher governance level
  • Cyber Essentials / Cyber Essentials Plus — baseline technical controls. The Governance Code expects boards to ensure these (or equivalent) are in place and maintained
  • ISO 27001 — an international standard for information security management systems. Organisations with ISO 27001 certification will find significant overlap with the Code’s assurance principle
  • NIS2 Directive — while NIS2 is an EU regulation, its governance requirements for essential and important entities closely parallel the Code’s principles. UK organisations subject to the NIS Regulations face similar expectations

Cyberfort and the Cyber Governance Code

Our cyber resilience audit and review service assesses your organisation against the Cyber Governance Code’s five principles, identifying gaps in board-level governance, incident planning, and assurance. For boards that need ongoing senior security leadership without a full-time hire, our virtual CISO service provides the expertise to implement and maintain compliance with the Code’s requirements.

Related glossary terms

  • Virtual CISO — fractional security leadership that helps boards meet the Code’s governance requirements
  • NCSC CAF — the UK’s Cyber Assessment Framework, which provides operational detail beneath the Code’s governance principles
  • Tabletop Exercises — scenario-based exercises that satisfy the Code’s incident planning principle
  • Cyber Crisis Simulation — advanced incident simulations for testing board-level and organisational response

External references

Frequently asked questions

Is the Cyber Governance Code mandatory?

No. The Cyber Governance Code is a voluntary code of practice, not a legal requirement. However, it reflects the government’s expectations for board-level cybersecurity governance, and its principles align with requirements that regulators in sectors such as financial services and critical national infrastructure already enforce. Organisations that adopt it proactively are better positioned for future regulatory developments.

Who is responsible for implementing the Cyber Governance Code?

The board of directors or equivalent governing body holds ultimate responsibility. The code expects boards to appoint a named senior leader with accountability for cybersecurity, receive regular reporting on security posture, and actively engage with cybersecurity as a business risk — not delegate it entirely to the IT department.

How does the Cyber Governance Code differ from Cyber Essentials?

Cyber Essentials is a technical controls framework — it specifies security measures such as firewalls, access controls, patching, and malware protection. The Cyber Governance Code operates at the governance level — it defines how boards should oversee, resource, and assure their cybersecurity programme. They are complementary: Cyber Essentials ensures baseline technical security, while the Governance Code ensures that security is governed and resourced at the highest level of the organisation.

Awards and Accreditations

blue light commercial logo

Contact Us

Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX

+44 (0)1304 814800

[email protected]


Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.