The UK’s Cyber Governance Code of Practice puts cyber risk squarely on the desks of directors. Here’s a plain-English guide to what it says, why it matters, and how to meet it.
Key takeaways
- What it is: UK government guidance (DSIT and NCSC, April 2025) setting out the cyber security governance actions boards and directors are responsible for.
- Who it’s for: Boards and directors of medium and large organisations — though the principles suit any size.
- The five principles: risk management, strategy, people, incident planning & response, and assurance & oversight.
- Is it mandatory? No — it’s voluntary, but it’s fast becoming the benchmark for good cyber governance.
- Why it matters: 50% of UK businesses reported a cyber breach or attack in the last year (Cyber Security Breaches Survey 2024).
What is the Cyber Governance Code of Practice?
The Cyber Governance Code of Practice is UK government guidance, published by the Department for Science, Innovation & Technology (DSIT) and the National Cyber Security Centre (NCSC) in April 2025. It sets out the most critical cyber security governance actions that boards and directors are responsible for, grouped into five principles: risk management, strategy, people, incident planning, and assurance and oversight.
In other words, it makes cyber security a leadership job — not something quietly parked with the IT team. It’s the foundational code in DSIT’s wider family of cyber security codes of practice, and it works hand in hand with Cyber Essentials certification. If you sit on a board, or you’re the person who briefs one, this is essential reading. And we reckon it’s some of the clearest guidance the government has published in years.
Why does cyber governance matter now?
Cyber governance matters because attacks are now routine, not rare — and the bigger your organisation, the bigger the target. Half of UK businesses reported a breach or attack in the past 12 months, so cyber risk has become a material business risk that boards are expected to govern directly.
Cyber incidents can halt operations, dent your competitiveness and chip away at hard-won customer trust. The government’s own research shows just how exposed organisations have become:
50%
of UK businesses reported a breach or attack in the last 12 months
70%
of medium businesses were hit, rising to 74% of large businesses
66%
of high-income charities also reported a breach or attack
Source: Cyber Security Breaches Survey 2024.
When half of all businesses are getting hit, cyber risk stops being an “IT problem” and becomes a boardroom one. That’s exactly why the Code hands responsibility to the people steering the ship.
What are the five principles of the Cyber Governance Code of Practice?
The Code is built around five principles: risk management, strategy, people, incident planning, response and recovery, and assurance and oversight. Think of them less as a compliance checklist and more as the questions a good board should be asking itself.

Risk management
Know what’s critical to your business, agree who owns cyber risk at a senior level, and set a clear risk appetite. Crucially, keep an eye on your suppliers too — your supply chain is now one of the most common ways attackers get in.

Strategy
Have a cyber strategy that’s genuinely joined up with your wider business plan — not a document in a drawer. It should match your risk appetite, meet your regulatory duties, and be properly resourced to actually deliver.

People
Build a positive security culture where good habits are the norm and people feel safe to speak up. That includes you: directors are expected to improve their own cyber literacy, not just sign off on everyone else’s training.

Planning, response & recovery
Have a plan for when — not if — something goes wrong. Test it at least once a year, learn from the exercise, and know your reporting obligations in advance. A calm, rehearsed response beats a panicked scramble every time.

Assurance & oversight
Put a proper governance structure in place with clear ownership, get formal reporting at least quarterly, and keep a genuine two-way conversation going with your security leaders. In short: make sure someone’s actually checking that the plan is working.
How can your organisation comply with the Code?
To align with the Code, organisations should identify their critical assets, assign senior ownership of cyber risk, build a resourced cyber strategy, foster a positive security culture, test an incident response plan at least annually, and put in place formal quarterly reporting and oversight.
The good news is that meeting the Code isn’t about spending a fortune or turning your board into security experts overnight. It’s about asking the right questions, knowing where your risks sit, and having the right people and plans in place. That’s where a good partner makes all the difference.
How Kascade can help you meet the Code
We don’t just solve IT problems, we solve business problems. Here’s how we help boards and IT teams turn the Code from a document into everyday practice.
Governance & risk consulting
We help you map your critical assets, run regular risk assessments, and build a cyber strategy that lines up with your business goals and the Code’s principles. We’ll even help you brief the board in language everyone in the room understands
Managed security & monitoring
Our proactive monitoring keeps watch around the clock, spotting threats early and helping you respond fast when it counts. From detection to recovery planning, we give you the visibility and resilience the Code expects — without adding to your team’s workload.
Training & awareness
People are your first line of defence, so we build the security culture the Code calls for. From board-level cyber literacy to practical staff training, we help good habits stick and keep everyone confident and up to speed.
Ready to get your cyber governance in shape?
Whether you’re starting from scratch or fine-tuning what you’ve already got, we’ll help you meet the Code with confidence. Let’s have a friendly, no-jargon chat about where you stand.
Frequently asked questions
Quick answers to the questions boards ask us most about the Cyber Governance Code of Practice.
It’s UK government guidance, published by DSIT and the NCSC in April 2025, that sets out the most critical cyber security governance actions boards and directors are responsible for. It covers five areas: risk management, strategy, people, incident planning, and assurance and oversight.
No. It’s voluntary guidance rather than law, and there’s no fine for not following it. However, it’s becoming the benchmark for good cyber governance and, alongside Cyber Essentials, sets out the minimum standard organisations should have in place.
It’s aimed at boards and directors of medium and large organisations, in both the public and private sectors. It’s not intended for those managing cyber security day to day, but small organisations are encouraged to apply its principles too.
The Code sets out how boards should govern cyber risk, while Cyber Essentials is a certification scheme covering fundamental technical controls. Together they set out the minimum standard organisations should have in place to manage their cyber risk.