International Edition
Latest News
World

FRC Guidance: Cyber Security Reporting under Provision 29

UK listed companies facing annual reporting deadlines under the 2024 UK Corporate Governance Code received new compliance clarity on 23 September 2026. The Financial Reporting Council published specific guidance regarding cyber security reporting under Provision 29, addressing corporate…

FRC Guidance: Cyber Security Reporting under Provision 29

UK listed companies facing annual reporting deadlines under the 2024 UK Corporate Governance Code received new compliance clarity on 23 September 2026. The Financial Reporting Council published specific guidance regarding cyber security reporting under Provision 29, addressing corporate anxieties over commercially sensitive disclosures and legal liabilities following potential data breaches.

Provision 29 Requirements and Cyber Security Scope

The Financial Reporting Council revised Provision 29 as part of the UK Corporate Governance Code 2024, applying to financial years starting on or after 1 January 2026. Under this provision, corporate boards must describe how they monitor and review their risk management and internal control framework. Directors must also issue a formal declaration regarding the effectiveness of the company’s material controls throughout the financial year. Given rising digital threats, many corporate entities identify digital defenses and resilience measures as material controls requiring formal board oversight.

Commercial Sensitivity and Technical Disclosure Limits

The regulatory body confirmed that companies are not required to disclose commercially sensitive data or detailed technical specifications regarding their security infrastructure. According to the published guidance, the required board declaration must center on the assurance process and its outcomes rather than specific defensive mechanisms. Companies must satisfy themselves that material controls operate effectively and explain their monitoring processes without exposing vulnerabilities to malicious actors.

The Financial Reporting Council emphasized that a Provision 29 declaration does not constitute an absolute guarantee against future cyber incidents. Because digital threats evolve continuously, boards cannot eliminate all operational risks. The regulatory assurance speaks strictly to the control environment’s status at the balance sheet date. Consequently, a board can legitimately declare its material controls effective on that specific date without implying permanent immunity from subsequent attacks.

Breach Reporting and Remediation Obligations

The new guidance clarifies that Provision 29 does not establish a standalone mandate to report every minor cyber breach or incident independently. Instead, boards must evaluate any security failure within their broader risk management framework to determine if it invalidates the effectiveness declaration for the financial year-end. If an incident demonstrates that a material control failed at the balance sheet date, the annual report must feature a high-level description of the failure alongside implemented remediation measures.

FRC Guidance: Cyber Security Reporting under Provision 29

Regulatory Alignment with Government Cyber Frameworks

The Financial Reporting Council directed boards toward established government resources to support digital risk oversight. These tools include the UK Government’s Cyber Governance Code of Practice, associated training modules, and the Cyber Security Toolkit for Boards. The Information Commissioner’s Office also stated that organizations handling personal data under the UK General Data Protection Regulation should implement the core actions outlined within the Cyber Governance Code of Practice.

About the author: Ibrahim Khalil - World Editor

PhD in International Relations, former UN press officer. Ibrahim has reported from 40+ countries, translating complex geopolitical shifts into clear, human‑focused narratives. “Ibrahim Khalil provides authoritative world news, from diplomacy to conflict zones, with on‑the‑ground insight.”