Cyber Governance Code of Practice: A Board Checklist for 2026
The Cyber Governance Code of Practice is DSIT and NCSC’s framework making UK boards directly accountable for cyber risk, not just IT. Published jointly by the Department for Science, Innovation and Technology and the National Cyber Security Centre in April 2025, it sets out five governance duties that medium and large organisations are expected to embed at board level.
What is the Cyber Governance Code of Practice?
The Code is the foundation of DSIT’s wider suite of cyber security codes of practice, developed with the NCSC and industry leaders following a government call for views. Unlike Cyber Essentials or ISO 27001, which set technical and operational controls, the Code is written explicitly for boards and directors — it does not tell a CISO how to configure a firewall, it tells a board what questions it must be able to answer about cyber risk. It applies most directly to medium and large organisations, though DSIT encourages smaller firms to adopt its principles given their role in UK supply chain resilience.
The Code sits alongside the forthcoming Cyber Security and Resilience Bill, which INFORMD covered in our briefing on what CISOs must build now. Where the Bill will impose statutory duties on regulated sectors, the Code is a voluntary governance standard — but voluntary is not the same as low-stakes. Regulators, insurers and institutional investors are increasingly using it as the reference point for “reasonable” board oversight of cyber risk.
Executive Action:
- Confirm whether your board has formally reviewed the Cyber Governance Code of Practice — most have not.
- Ask your company secretary to map the Code’s five principles against existing risk committee terms of reference.
- Distinguish, in board papers, between the Code (governance) and Cyber Essentials/ISO 27001 (technical assurance) — boards regularly conflate the two.
Which five principles must boards embed?
The Code sets out five principles, each with supporting actions for directors rather than technical staff:
- Risk Management — integrating cyber risk into the organisation’s overall risk register and risk appetite statement, not a standalone IT risk log.
- Cyber Strategy — setting direction and ensuring cyber resilience has adequate budget and resourcing relative to the risk it poses to the business.
- People — defining clear roles and accountability for cyber risk from board level down, including who owns the decision in a live incident.
- Incident Planning — ensuring the organisation can respond to and recover from an attack, with the board rehearsed in its own role.
- Assurance and Oversight — regularly reviewing controls and commissioning independent assurance rather than relying solely on management self-reporting.
Executive Action:
- Run each of the five principles as a standing agenda item across the next four board or risk committee cycles, not a single one-off session.
- Require the CISO or equivalent to report against Assurance and Oversight using independent, not self-assessed, evidence.
- Use INFORMD’s AI and technology governance self-assessment tools to benchmark current board maturity against the five principles.
Why does board-level cyber accountability still lag?
The gap the Code is designed to close is well documented. According to DSIT’s Cyber Security Breaches Survey 2025, only 27% of UK businesses have a board member or trustee who takes explicit responsibility for cyber security as part of their role — meaning nearly three-quarters of boards have no named owner for the risk. According to the same survey, 43% of UK businesses reported a cyber security breach or attack in the past 12 months, yet cyber security remained a stated high priority for only around seven in ten (72%).
That gap between stated priority and named accountability is precisely what the Code targets. A board that treats cyber as “an IT matter” until an incident forces its hand is, under the Code’s own framing, failing the Risk Management and People principles simultaneously — and increasingly exposed if a breach triggers scrutiny from the FCA, ICO or shareholders over what the board knew and when.
Executive Action:
- Name a specific board member as cyber risk owner in the next board pack — not “the executive team” collectively.
- Ask internal audit to test whether cyber risk reporting reaches the board in a form directors can actually challenge.
- Benchmark your incident response plan against the Code’s Incident Planning principle using INFORMD’s capital approval and technology strategy review templates.
How should boards turn the Code into assurance, not just policy?
Adopting the Code on paper is straightforward; embedding it is not. The most common failure mode INFORMD sees is a board approving a cyber policy document once a year and treating that as compliance. The Code instead expects continuous, evidenced governance: minuted challenge of management’s risk assumptions, independent assurance rather than self-reported metrics, and a board that has actually rehearsed its own role in a live incident — not merely reviewed a slide about one.
Boards that have already built strong technical controls, such as those following our earlier briefing on zero trust architecture, should treat the Code as the governance layer that sits above those controls — the mechanism by which the board demonstrates it understood and directed the strategy, rather than simply approved a budget line.
Executive Action:
- Commission an annual independent review of cyber governance against all five principles, distinct from technical penetration testing.
- Build a board-level cyber incident tabletop exercise into the annual governance calendar, not just the technical team’s.
- Document board challenge and decisions on cyber risk in minutes — regulators and insurers increasingly ask to see it.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
A framework published by DSIT and the NCSC in April 2025 setting five cyber governance principles — Risk Management, Cyber Strategy, People, Incident Planning, and Assurance and Oversight — for boards and directors of medium and large UK organisations.
No, it is voluntary. However, regulators, insurers and investors are increasingly using it as the reference standard for reasonable board oversight of cyber risk, making non-adoption harder to defend after an incident.
Cyber Essentials and ISO 27001 set technical and operational security controls. The Code is written for boards and directors — it defines governance accountability and oversight, not technical configuration.
DSIT designed it primarily for medium and large public and private sector organisations, though it recommends smaller organisations adopt its principles given their role in UK supply chain resilience.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/).
