Premier League clubs risk an own goal with cyber security failures

For a Premier League club, a £100,000 fine may barely register alongside transfer fees and player salaries. Its appearance in the Premier League rulebook is still significant. For the first time, all 20 clubs face mandatory cyber security requirements, annual compliance assessments and potential disciplinary action if they fail to meet them.

The new rules form part of the Premier League Handbook for the 2026/27 season, and must be implemented by 30 April 2027, followed by further requirements in 2028 and 2029. Clubs must submit an interim assessment by 10 January each season and a final assessment, supported by evidence, by 30 April. 

The Premier League has powers to demand further information and evidence, issue a reprimand or fine of up to £100,000, or refer a breach to an independent commission. 

What do Premier League clubs actually have to do?

The new Information Security Baselines are considerably more detailed than simply telling clubs to “have good cyber security”. The first phase includes requirements around risk management and security governance, annual cyber security training for personnel, access controls, multi-factor authentication wherever feasible, asset registers, network segmentation, firewalls and endpoint detection and response.

Across the three phases, the baseline develops into a substantial security management framework. Clubs are expected to address a range of cyber vulnerabilities from email security, to backups, incident response, third-party suppliers, monitoring, and aligning with recognised security frameworks like ISO 27001.

Some requirements give an indication of how far cyber security has moved into the operational life of a football club. Internet of Things devices must eventually be inventoried, hardened and segregated from other networks. Clubs are expected to have contingency arrangements where their failure could affect operations, with the rules specifically contemplating manual fallback mechanisms for systems such as stadium access control.

Football has already had some expensive warnings

There is good reason for the Premier League to be concerned.

In research published by the National Cyber Security Centre (NCSC), at least 70% of sports clubs and organisations were reported to have suffered a cyber breach or incident during the previous 12 months, around twice the average recorded for UK businesses. The NCSC subsequently brought together more than 180 representatives from professional sport, including 11 Premier League and 35 English Football League clubs, to improve the sector’s cyber resilience given some remarkable incidents.

One Premier League managing director had their email account compromised while negotiating a player transfer. Criminals monitored the discussion and attempted to divert a payment worth around £1 million to an account they controlled. The payment was stopped after the receiving account triggered a fraud marker at the bank.

An EFL club suffered a ransomware attack that affected systems including CCTV and turnstiles, creating a real possibility that a fixture would have to be postponed. The incident demonstrated how a cyber attack on a football club can quickly move beyond data and into physical operations.

Manchester United experienced a significant cyber attack in November 2020. The club said it had contained the attack and that systems required for matches at Old Trafford remained secure, allowing games to continue. Its corporate filings have subsequently acknowledged that non-consumer data was compromised during the attack and recognise cyber incidents as a material business risk.

More recently, Leeds United disclosed that a cyber attack against its retail website in February 2025 compromised the card details of a small number of customers. The club brought in forensic specialists, contacted affected customers and worked with the Information Commissioner’s Office.

Football is moving in the same direction as UK cyber regulation

The timing is particularly interesting because the UK is simultaneously undertaking its biggest overhaul of cross-sector cyber regulation since the Network and Information Systems Regulations 2018.

The Cyber Security and Resilience (Network and Information Systems) Bill is expected to be in force next year. The existing NIS regime focuses primarily on essential services such as energy, transport, health, drinking water and digital infrastructure, together with certain digital services. The Bill will expand the regime to areas including data centres, larger managed service providers and large load controllers. It will also strengthen enforcement, incident reporting and supply-chain security.

In parallel, the Premier League is also strengthening its cyber defences. Both regimes are concerned with organisations understanding their critical systems, managing dependencies on suppliers, preparing for incidents and being able to recover when preventive controls fail. Both reflect an increasingly important regulatory assumption that a cyber security programme must be demonstrable rather than theoretical.

The Bill’s approach to supply chains is particularly relevant to football. It will allow certain suppliers to essential and digital services to be designated as critical suppliers, placing direct statutory cyber security obligations on them where their failure could seriously disrupt an essential service. Regulated organisations will also face clearer expectations around managing cyber risks within their supply chains.

A football club may have hundreds of technology dependencies, from payment processors and ticketing platforms to cloud services, security systems and outsourced IT providers. A club’s cyber resilience can therefore be only as strong as some of those suppliers.

Could Premier League clubs become critical infrastructure?

For now, Premier League clubs are not within the sectors regulated under the NIS regime, and the Cyber Security and Resilience Bill does not propose bringing professional football directly into scope.

There is, however, an interesting provision in the Bill that makes the question less fanciful than it initially sounds. The government wants powers to add new services and activities to the NIS regime through secondary legislation where they have become essential to the UK economy or to the day-to-day functioning of society. Any such expansion would require consultation and parliamentary approval. The government says the power is intended to allow the regime to respond more quickly as technology, economic dependencies and cyber threats change.

Professional football nonetheless sits in an interesting grey area. Modern stadiums hold tens of thousands of people and rely on interconnected systems for access, ticketing, communications, surveillance and other operations. Clubs handle substantial financial flows and highly sensitive data. Matchdays can involve policing, public transport, emergency services, broadcasters and extensive local infrastructure. The Premier League itself is a major part of the UK’s international sporting and commercial presence.

A prolonged and coordinated cyber incident capable of disrupting several major stadiums, league-wide infrastructure or critical technology suppliers would raise quite different questions. Such an assault could see massive national disruption. Just imagine on derby day, hundreds of thousands of fans completely stuck as critical infrastructure breaks down. 

The Bill’s future-proofing provisions mean government will have a mechanism to reconsider where the boundaries of essential services should lie if the evidence changes. Football demonstrates how digital dependencies are making the distinction between an ordinary commercial organisation and nationally significant infrastructure increasingly complicated.

Cyber resilience is becoming a compliance issue

The Premier League’s decision has relevance far beyond football. Organisations have traditionally encountered cyber security through data protection requirements, contractual questionnaires, insurance conditions or voluntary frameworks such as Cyber Essentials and ISO 27001. Increasingly, regulators and industry bodies are turning resilience expectations into auditable obligations with named controls, deadlines, reporting requirements and consequences for failing to comply.

For Premier League clubs, the first deadline is 30 April 2027. The annual assessment process means the work cannot safely be left until then. Clubs will need to establish where they already meet the baseline, identify gaps, allocate responsibility and retain evidence showing that the required controls are operating in practice.

That includes the human side of security. The new baseline expressly requires security training for all personnel at least annually, alongside more specialised training for higher-risk roles and later tabletop exercises for key stakeholders.

The lesson for organisations outside football is similar. Cyber security regulation is increasingly concerned with whether an organisation can continue operating during an attack, recover afterwards and prove that it had prepared for the possibility beforehand.

For Premier League clubs, failing that test could now result in a fine from the same rulebook that governs what happens on the pitch. While the financial penalty may be relatively modest, the disruption caused by a serious cyber incident could be anything but.

Looking for more support? Try VinciWorks cyber security training.

Be the first to know about releases and industry news and insights.

By filling in this form you agree to share your information with VinciWorks. We take privacy seriously, click here to read our privacy notice.