Skip to main content
ISO 27001

Board-Ready Cyber Governance: The DSIT Cyber Governance Code in Practice (2026)

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

10 min read

Contents

    The cyber question UK boards can no longer defer

    The Marks and Spencer ransomware attack. The Co-op breach. The British Library outage. Every UK board of a medium or large organisation has been asked the same question by an auditor, an investor, or a regulator in the past 12 months: what is the board's cyber governance posture, and what evidence can you produce?

    In April 2025 the UK Department for Science, Innovation and Technology (DSIT) published the Cyber Governance Code of Practice. The Code is aimed at the boards of medium and large UK organisations. It is voluntary today. It is increasingly being treated by regulators, courts, and investors as the benchmark against which directors' compliance with Section 172 and Section 174 of the Companies Act 2006 will be assessed.

    This is the practitioner read on what the Code requires, why mid-market organisations are now treating it as mandatory, and what board-ready cyber governance actually looks like in practice.

    What the Cyber Governance Code of Practice requires

    The Code is structured around five principles. Each principle has expectations the board is responsible for ensuring are in place.

    Principle 1: Risk management

    The board must understand the organisation's cyber risk exposure and ensure cyber risk is integrated into enterprise risk management. This requires a documented cyber risk appetite, a current cyber risk register reviewed at board level, and clear escalation thresholds for material cyber risks.

    Principle 2: Strategy

    The board must ensure cyber resilience is embedded in business strategy and that resourcing is aligned with the risk profile. This includes oversight of how cyber spend tracks against the threat landscape and how cyber capability supports business objectives.

    Principle 3: People

    The board must take responsibility for the cyber culture of the organisation. This covers awareness training, security behaviour reinforcement, board members themselves completing the NCSC Cyber Governance Training, and clear accountability assignment at senior level.

    Principle 4: Incident planning, response, and recovery

    The board must ensure incident response and recovery capability is in place, tested, and adequate. This includes documented incident response plans, tabletop exercises run at least annually with board participation, and post-incident review processes that feed back into the risk register.

    Principle 5: Assurance and oversight

    The board must obtain regular, meaningful assurance on the effectiveness of cyber controls. This requires an internal audit programme covering cyber, independent assurance through certification or third-party assessment, and regular board reporting that provides actual insight rather than dashboards of green lights.

    Why mid-market boards are treating the voluntary Code as mandatory

    The Code is voluntary today. Four forces are pushing mid-market boards to treat it as effectively mandatory.

    Regulatory direction of travel. The UK Cyber Security and Resilience Bill, expected to receive Royal Assent in 2026, will impose stricter cyber requirements on essential service operators, managed service providers, and parts of the digital supply chain. The Code is the governance scaffolding that supports CSR Bill compliance.

    Director duties under the Companies Act. Section 172 (duty to promote success of the company) and Section 174 (duty of reasonable care, skill, and diligence) are increasingly being read by courts, regulators, and investors against the Code. A board that cannot evidence Code-aligned governance is harder to defend in the aftermath of a serious cyber incident.

    Insurance market hardening. UK cyber insurance underwriters are now asking for evidence of Code-aligned governance as part of renewal pricing. Boards without documented governance posture are seeing premiums rise materially or coverage exclusions widening.

    Procurement signal. Public sector procurement frameworks, NHS-adjacent supply chain, and an increasing number of enterprise buyers are asking suppliers to evidence board-level cyber governance. The questionnaire question "Does your board receive regular cyber risk reporting" is no longer a tick-box, it is being audited.

    What "board-ready" cyber governance actually looks like

    The gap between most mid-market organisations and the Code is not a documentation gap. It is an operational gap. Most boards have something that resembles cyber governance on paper. Few have what regulators and investors are now expecting in practice.

    Board-ready governance for a UK mid-market organisation of 150 to 500 employees has five operational hallmarks.

    1. A current cyber risk register reviewed at board level. Not a CISO spreadsheet. A documented register with named risk owners, current ratings, treatment plans, and escalation thresholds. Reviewed at minimum quarterly by the board or audit committee with minuted decisions.

    2. NCSC Cyber Governance Training completed by all board members. Five modules, around 20 minutes each, free of charge. Completion evidenced in board records. This is the single most defensible piece of evidence that the board has taken its cyber responsibilities seriously.

    3. An incident response plan that has been tested with board participation. A tabletop exercise within the last 12 months, involving the board or at least the audit committee, with documented learnings fed back into the response plan and the risk register.

    4. Independent assurance evidence. This is typically ISO 27001 certification (the most common UK route), SOC 2 attestation (for organisations with US enterprise customers), or a current internal audit programme with named auditors and findings management.

    5. Board cyber reporting with substance. A quarterly board pack section that goes beyond dashboards. Material risk changes, control failures, incident learnings, regulatory updates, third-party risk events, and strategic decisions required. Not green lights and feel-good metrics.

    The Code, ISO 27001, and integrated assurance

    For most UK mid-market organisations, ISO 27001 is the most efficient route to evidencing Code-aligned governance. The ISO 27001 management system maps almost directly to the five principles of the Code.

    Code principleISO 27001 evidence
    Risk managementClause 6.1 (risk assessment) plus risk register, Statement of Applicability
    StrategyClause 4.4, 5.1, 5.2 (context, leadership, policy)
    PeopleClause 7 (resources, awareness, competence) plus Annex A People controls
    Incident responseAnnex A 5.24-5.27 (incident management lifecycle)
    AssuranceClause 9 (performance evaluation), Clause 9.2 (internal audit), Clause 9.3 (management review)

    An organisation with a mature ISO 27001 management system already has most of the evidence the Code expects. The Code adds explicit board-level responsibility expectations and clarifies what "good" looks like at the governance layer.

    For organisations also running AI systems with material business risk, ISO 42001 provides the equivalent management system architecture for AI governance. The combination of ISO 27001 plus ISO 42001 plus board-level Code alignment is what board-ready governance looks like for UK mid-market organisations supplying regulated buyers.

    The board reporting layer most organisations get wrong

    The single largest gap I see in mid-market cyber governance is the board reporting layer. Most boards receive a quarterly cyber update that is either a green-light dashboard with no narrative insight, an overly technical update that the board cannot meaningfully oversee, or a CISO commentary without supporting evidence.

    What good board reporting looks like in a Code-aligned organisation:

    • Material risk changes since last report (with rationale)
    • Control failures or near-misses with severity assessment
    • Incidents (resolved and ongoing) with learnings
    • Regulatory horizon updates relevant to the organisation
    • Third-party risk events from the supply chain
    • Strategic decisions where the board's input is required
    • Assurance summary (audit findings, certifications, attestations)
    • Forward look for the next quarter

    This is 4 to 6 pages of substance, not a 30-slide deck of charts. The board needs enough material to discharge its duty and to evidence that it has done so.

    Where mid-market boards typically fall short, and what fixes it

    Three recurring gaps in mid-market organisations:

    Gap 1: No senior practitioner in the room. Cyber governance presented to the board by a head of IT who has not run a programme through external audit. The board gets implementation detail without governance insight. Fix: ensure a senior practitioner (internal or fractional) is responsible for board reporting and risk register ownership.

    Gap 2: Documentation that exists but is not living. A risk register that has not been reviewed in 9 months. An incident response plan that has not been tested. Policies dated 2022. Fix: a governance operating rhythm with quarterly board reviews, annual policy refresh, and annual tabletop exercises.

    Gap 3: No independent assurance. No external audit, no certification, no third-party review. The board is taking the CISO's word for it. This is the single hardest gap to defend in the aftermath of an incident. Fix: external certification (ISO 27001 minimum) plus an internal audit programme with named auditors.

    The structural answer

    UK mid-market organisations of 150 to 500 employees need board-level cyber and AI governance programmes delivered by senior practitioners, with multiple stakeholders managed across audit committee, risk committee, and executive layers, against defined deliverables and a fixed timeline.

    This is not a platform onboarding job. It is a programme delivered by people who have run cyber and AI governance against external audit, board scrutiny, and regulatory exposure, and who can defend the work in any of those forums.

    Goldline Consultancy delivers Board Ready programmes for UK mid-market organisations. 150 to 500 FTE. Multiple stakeholders managed throughout. Senior practitioner delivery from first conversation to certification audit. No junior handoff.

    Book the Free Diagnostic to scope your board-ready governance programme.

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.