

The UK government is urging business leaders to adopt a new cyber-Code of Practice to reinforce their cyber defences and support long-term economic growth.
The new code was published on Tuesday 8 April by the Department for Science, Innovation and Technology (DSIT) alongside the National Cyber Security Centre (NCSC), the code outlines clear guidance for directors and board members to take greater ownership of cyber risks. It is designed to be the first point of reference for senior leaders and forms part of the government’s broader support for cyber governance.
In a press release, Cyber Security Minister Feryal Clark emphasised the stakes involved, stating, “A successful cyber-attack doesn’t just have the potential to grind operations to a halt – it could drain millions from the bottom line.”
She adds that this new Code of Practice is part of how the government intends to stand by businesses and believes it will drive the type of economic growth fundamental to achieving the government’s Plan for Change.
The new guideline is primarily for boards and directors in medium and large organisations across the public and private sectors and outlines five key areas where they should act.
One of its tenets is to embed cyber risks into enterprise-wide risk management, including assessing supply chain exposures. Directors are expected to set a clear cyber strategy, grounded in the organisation’s threat landscape and aligned with business goals.
It places a strong emphasis on creating a cyber-aware culture through regular training and clear staff responsibilities. Boards should ensure that incident response and recovery plans are in place, tested, and continuously improved. The Code also highlights the need for robust oversight — defining roles, assigning accountability at the board level, and monitoring cyber performance to strengthen overall resilience.
Also included in the announcement are practical tools such as online training modules and a detailed Board Toolkit. These resources aim to equip directors with the knowledge needed to govern cyber risks effectively. Meanwhile, the government urges smaller businesses to utilise complementary resources like the NCSC’s Small Business Guide.
While the Code of Practice is voluntary, the government has signalled more formal action ahead. Last week, Secretary of State for Science, Innovation and Technology Peter Kyle said that the forthcoming Cyber Security and Resilience Bill will help monitor uptake and consider a firmer stance, including £100,000 daily fines for non-compliance with cyber security directives from the government.
Want to know more? Computing 's Cybersecurity Festival returns to London in May, where senior IT decision makers can learn about modern challenges, compare strategies with peers, and source solutions. Click here to register for free.
The UK government is encouraging medium and large businesses to adopt a new cyber-Code of Practice to enhance their cyber defenses and support long-term economic growth. Published by the Department for Science, Innovation and Technology (DSIT) alongside the National Cyber Security Centre (NCSC), the code provides clear guidance for directors and board members to take greater ownership of cyber risks.
In a press release, Cyber Security Minister Feryal Clark emphasized the importance of the new code, stating that a successful cyber-attack could have significant financial implications for businesses. The government believes that this Code of Practice will drive economic growth essential for achieving the government’s Plan for Change.
The new cyber governance Code of Practice is designed for boards and directors in medium and large organizations across the public and private sectors. It outlines five key areas where they should take action, including embedding cyber risks into enterprise-wide risk management, setting a clear cyber strategy, creating a cyber-aware culture, ensuring incident response and recovery plans are in place, and providing robust oversight.
Practical tools such as online training modules and a detailed Board Toolkit are included in the announcement to help directors govern cyber risks effectively. While the Code of Practice is voluntary, the government has hinted at more formal action in the future, including potential fines for non-compliance with cyber security directives.
For those interested in learning more about cybersecurity challenges and solutions, Computing's Cybersecurity Festival in London in May provides an opportunity for senior IT decision-makers to network, share strategies, and access resources. Registration for the event is free.