Cyber Governance Code of Practice
Effective cyber governance, like financial oversight, requires strong leadership and proactive engagement at Board level. To support leaders in this critical role, the government has introduced the Cyber Governance Code of Practice (the Code) opens to GOV.UK.

What is the Cyber Governance Code of Practice?
The Code has been developed to support Boards and Directors in governing cyber security risks and it sets out the most critical governance actions that Boards need to take ownership of.
It outlines the responsibilities and accountability required at Board level, helping leaders fulfil their duty of care to their organisation.
The Code is built around five key governance principles:
-
Risk Management
-
Strategy
-
People
-
Incident Planning, Response & Recovery
-
Assurance & Oversight
Each principle is accompanied by specific actions for Boards to implement. By embedding these principles, you'll ensure you are governing your organisations cyber security risks more effectively.

Who should use the Cyber Governance Code of Practice?
The Cyber Governance Code of Practice is tailor-made for Boards and directors of both public sector and private organisations across the UK. The code is not intended to be used by those who are responsible for the day-to-day management of cyber security but can be used to highlight to boards what their responsibilities are.
The Cyber Governance Code of Practice has been designed for medium and large organisations. However, while the code has not been specifically designed for smaller organisations, many small organisations play a critical role in the cyber security of wider digital supply chains. Depending on their cyber maturity and/or risk profile, they may wish to use Cyber Governance Code of Practice to inform how they govern cyber risk. Small organisations should refer to the NCSC's resources for small & medium sized organisations for further guidance.
Why should Boards and Directors use the Cyber Governance Code of Practice?
Governing cyber risks requires strong engagement and action at a leadership level. Cyber incidents can disrupt business continuity, reduce an organisation’s competitiveness, and damage customer trust. Cyber criminals exploit weaknesses in systems, regardless of the size or sector of the organisation.
Building and maintaining cyber resilience is therefore crucial to protecting your organisation’s financial stability. Doing so will allow organisations to take full advantage of digital technologies, like artificial intelligence, which can drive the business strategy and improve business performance and efficiency, whilst managing the risks.