ComputerWeekly

Premier League to phase in cyber compliance regime


Top flight football clubs may be fined up to £100,000 for breaching cyber security rules imposed by the English Premier League under a new sanctions regime approved by its 20 member clubs at a meeting earlier in the summer.

According to the New York Times, which obtained exclusive details of the new arrangements, new disciplinary procedures will allow the League to impose summary judgements against clubs found in breach of the rules, although it will not dock points. The newspaper cited sources with knowledge of the developments who requested anonymity to break cover.

It is understood that the new measures are to be introduced in three stages, in April 2027, April 2028, and April 2029, and will cover capabilities in areas such as backup measures, incident response and recovery, and cyber risk and assurance. The newspaper said that during that timeframe clubs will face an annual January assessment and if their security arrangements are not up to code, will have to set out a detailed improvement plan.

Computer Weekly contacted the Premier League’s press office to confirm the nature of its new cyber regime but the organisation had not yet responded to our enquiries at the time of publication.

Although cyber attacks against high-profile English football clubs rarely make the news, the football industry is not immune to the attentions of threat actors. In 2020, two notable exceptions took place, first when an undisclosed club was hit by a spear-phishing incident during a key player transfer negotiation, and second when Manchester United shut down an in-progress attack on its systems that may have avoided a ransomware incident.  

More recently, two years ago Italy’s Bologna FC suffered a RansomHub ransomware attack, while earlier in August 2026, Dutch club Ajax found itself caught up in a supply chain attack after CEVA Logistics, a key supplier used for processing orders at its online store, was breached.

Statistics published prior to the 2026 World Cup by Darktrace revealed that 80% of the sports organisations it works with experienced cyber incidents in the past 12 months, and 57% saw multiple breaches, with the average cost set at about £125,000.

Clubs lack resilience off the pitch

A 2023 report prepared by cyber firm NCC Group revealed that football clubs at every level of the game were critically under-resourced when it came to cyber resilience.

Some of the top digital threats to football clubs identified in the NCC report included industrial espionage from rivals and even nation-states, organised criminal gangs attempting to rig matches, conduct gambling or ticketing fraud, and even real-world crime against high-net-worth players, insider threats, hacktivists, and cyber bullies and trolls targeting players for abuse.

Anna Collard, senior vice president of content strategy and CISO advisor at KnowBe4 said: “[It is] good to see the Premier League treating cyber security as a governance issue rather than an IT afterthought. Mandatory rules with real financial consequences send the right signal: boards are expected to own this risk, not just delegate it.

“But fines only address one side of the equation…. Sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust. A rushed transfer payment, a fan chasing tickets, an official acting on a ‘verified’ WhatsApp message from someone posing as a coach or chairperson, these are moments of heightened emotion and time pressure, exactly when human judgment degrades. That’s not a firewall problem,” she said.

Collard said that rules with sufficient teeth were a welcome start, but real resilience would mean pairing compliance with genuine behavioural readiness. She added: “It’s worth remembering that one of the most costly incidents in this sector involved a Premier League club being spear-phished during a £1 million transfer negotiation. That wasn’t a technical breach, but a person deceived at a moment of pressure.”

Muhammad Yahya Patel, virtual chief information security officer (vCISO) and EMEA cyber security advisor at Huntress, also welcomed the new regime, but said there were more questions raised by the detail of the initiative.

“[A fine of] £100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually. The phased timeline, April 2027, 2028, 2029, is pragmatic but slow given the threat environment. Waiting until 2029 for full compliance gives attackers three more seasons to find the weakest link.

“That said, the direction is unambiguously right. Moving from a non-prescriptive roadmap to formal requirements with deadlines and evidence submissions is a meaningful structural shift. Backups, incident response, risk management, and recovery testing are exactly the right foundations. The Premier League doing this proactively rather than reactively before a major breach forces the issue deserves genuine credit. Most governing bodies wait for the headline incident. This one didn’t.”

The 2026-2027 Premier League season gets underway on Friday 24 August when Arsenal meet newly-promoted Coventry City at home.



Source link