Description

Department for Science, Innovation and Technology issued Cyber Governance Code of Practice

On 8 April 2025, the UK Department for Science, Innovation and Technology published the Cyber Governance Code of Practice to support boards and directors in managing cyber security risks. The code outlines critical governance actions for directors, emphasising the integration of cyber risk management into broader enterprise risk management. The code includes identifying and prioritising critical technology processes, defining cyber risk appetite, ensuring supplier cyber resilience, and developing a cyber strategy aligned with organisational goals. The code also stresses the importance of promoting a positive cyber security culture, conducting regular risk assessments, and having plans for incident response and recovery.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2024-01-23
in consultation

On 23 January 2024, the British Department for Science, Innovation and Technology (DSIT) opened a c…

2024-03-19
processing consultation

On 19 March 2024, the British Department for Science, Innovation and Technology (DSIT) closed a con…

2025-04-08
adopted

On 8 April 2025, the UK Department for Science, Innovation and Technology published the Cyber Gover…