Guidance: Cyber Governance Code of Practice
Cybersecurity Classified by Officially
This Code of Practice and wider governance package shows boards and directors how to manage digital risks and protect their businesses and organisations from cyber attacks.
Effective management of cyber risks is critical to the operation of modern businesses.
This Cyber Governance Code of Practice shows how company boards and directors can build resilience to a wide range of cyber risks across their organisation. The Code, which has been co-designed with technical experts from the National Cyber Security Centre (NCSC) and a range of governance experts across industry, focuses on the actions senior leaders should take to govern cyber risks effectively within their organisation.
The Code forms part of the government’s free package of support on cyber governance and should be the first point of reference for board members. It is underpinned by Cyber Governance Training, which helps boards and directors to strengthen their understanding of how to govern cyber security risks, and the Cyber Security Toolkit for Boards, which supports boards and directors in implementing the actions set out in the Code.
There are also documents showing how the Code maps to cyber standards, such as the NCSC’s Cyber Assessment Framework (CAF).
A one-page summary of the Cyber Governance Code of Practice has also been provided to offer a concise view of the Code.
The Code of Practice was launched on 8 April 2025.
The government is monitoring uptake of this Code of Practice and seeking feedback. If you are using the Code of Practice, please fill out the monitoring and evaluation survey.
Why do we need the Cyber Governance Code of Practice?
This is an extract. The publication continues at the source.
Read the original at the source: https://www.gov.uk/government/publications/cyber-governance-code-of-practice
Officially imported this from National Cyber Security Centre’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- National Cyber Security Centre — imported from official source
- Official source
- https://www.gov.uk/government/organisations/national-cyber-security-centre.atom ATOM
- Imported
- September 15, 2026 20:43
- Versions
- 1 recorded
- Identity
https://www.gov.uk/government/publications/cyber-governance-code-of-practice#2025-04-07...