A Turning Point for Cyber Governance – Why We Must Get Behind the UK’s New Code of Practice

Today marks a pivotal moment in the evolution of cybersecurity governance in the UK.

The launch of the Cyber Governance Code of Practice by the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC) is not just a new set of guidelines. It is a signal. A wake-up call. A long-awaited shift in how we view and manage cyber risk at the highest levels of business.

As the CEO of a cybersecurity company that has been advocating for change for years, I could not be more thrilled to see the government not just listening – but leading.

Why Now? Because the Stakes Have Never Been Higher

The numbers speak for themselves:

  • 74% of large businesses and 70% of medium-sized firms reported cyber breaches in the past year.
  • Cyber threats cost the UK economy an estimated £22 billion annually.
  • Yet a third of large companies still lack a formal cyber strategy, and almost half do not have an incident response plan.

That is a dangerous gap, and it is time we close it.

Cybersecurity is no longer just a technical issue. It is a business-critical risk, right alongside financial oversight and legal compliance. Every boardroom in the country must treat it that way. The new Code provides the framework to make that happen.

What Makes This Different?

This is not just another white paper that ends up collecting digital dust in someone’s inbox.

The Code is clear, actionable, and backed by industry heavyweights, including the Institute of Directors, EY, and the Chartered Institute of Internal Auditors. It promotes a cultural shift at the leadership level, ensuring that cyber resilience is embedded into business strategy, risk management, and day-to-day operations.

For too long, those of us in the infosec industry have been calling for this. We have said that leadership needs to take cybersecurity seriously. We have asked for better alignment between governance and technical realities. We have urged policymakers to engage with those on the front lines.

And now, they have.

DSIT is Listening – And Making Waves

This is not just a policy shift; it is a mindset shift. DSIT and NCSC have listened to the security community, worked with real practitioners and directors, and delivered something meaningful.

They have created training, toolkits, and guidance that boards can actually use. Not just to tick boxes, but to lead with confidence. To build resilience. To grow safely in a digital world that is getting more dangerous by the day.

At Custodian360, we have always believed that strong cybersecurity starts with strong leadership. And now, that belief is reflected in national policy.

A Rallying Cry for the Industry

To my fellow cybersecurity professionals: this is our moment.

We have the government’s ear. We have the frameworks. Now it is on us to deliver.

Let us help our clients understand the importance of this Code. Let us partner with boards to put it into action. Let us stop speaking in technical jargon and start translating risk into language that directors can act on.

This is the bridge between IT and the C-suite we have all been asking for. Let us cross it together.

What’s Next?

At Custodian360, we will be working closely with our partners and clients to help implement the Code across all sectors – not just to meet guidelines, but to lead by example.

We will also be launching tailored advisory and support services aligned to the Cyber Governance Code, ensuring organisations have the expertise and support they need to succeed.

Let us turn this Code into more than policy. Let us make it a movement.

Because if we want a safer, more resilient digital economy – we all have a role to play in making it happen.

Andy James

CEO, Custodian360

Cybersecurity. Simplified. Secured.