In brief

On 23 September 2026, the Financial Reporting Council (FRC) published a new “mythbuster” on cyber security reporting in the context of Provision 29 of the UK Corporate Governance Code 2024 (“Code”). The mythbuster is intended to address concerns raised by companies regarding the reporting of cyber risks and controls, particularly where disclosure could reveal commercially sensitive information, and whether a subsequent cyber incident could call an earlier effectiveness declaration into question.

Provision 29, which was revised as part of the Code published in 2024 and applies to financial years commencing on or after 1 January 2026, expects boards to include in the annual report a description of how they have monitored and reviewed the effectiveness of the risk management and internal control framework and a declaration of the effectiveness of the company’s material controls. Given the increasing importance of cyber security and cyber resilience, many companies are likely to identify cyber controls as material controls for these purposes.

In more detail

Key guidance from the mythbuster

No requirement to disclose sensitive technical information: the FRC recognises that cyber security information can be commercially sensitive. It confirms that the declaration should not include commercially sensitive information or specific details of the technical controls or implemented to support the company’s cyber resilience. However, the board must still satisfy itself that the company’s material controls are effective and explain how it has monitored and reviewed their effectiveness. The declaration should focus on that assurance process and its outcome.

Provision 29 is not a guarantee against cyber incidents: the FRC makes clear that a declaration under Provision 29 should not be interpreted as a guarantee that a company will not experience a future cyber incident. Cyber threats continue to evolve and boards cannot be expected to eliminate all cyber risk.

Point-in-time assurance: the declaration speaks only to the position as at the balance sheet date. A board can therefore conclude that its material controls were effective at that date without suggesting that the company will remain protected going forward.

Cyber controls should be considered within the wider control framework: where cyber controls are identified as material controls, they should be included in the company’s Provision 29 reporting alongside other material controls, rather than reported separately. Companies may also cross-refer to other areas of their reporting where appropriate.

Reporting cyber breaches: Provision 29 does not create a separate requirement to report every cyber incident or breach. Boards should consider any breach in the context of their wider risk management and internal control framework and assess whether it affects their declaration on the effectiveness of material controls. Where a cyber incident demonstrates that a material control was not operating effectively as at the balance sheet date, companies should provide in the annual report a high-level description of the control failure, the actions taken or proposed to address it, and any remediation measures implemented in response to previously identified issues.

Further guidance for boards: the mythbuster signposts a number of government resources intended to support boards in overseeing cyber risk, including the UK Government’s Cyber Governance Code of Practice, Cyber Governance Training and the Cyber Security Toolkit for Boards. The FRC also notes that the Information Commissioner’s Office has recently stated that it expects organisations that are using or storing personal data, as set out in the UK GDPR, to have implemented the actions set out in the Cyber Governance Code of Practice.

Key takeaways

The FRC’s mythbuster provides welcome reassurance for companies concerned that compliance with Provision 29 may require disclosure of sensitive cyber security information. The FRC has confirmed that reporting should focus on the board’s assurance process and its outcome in relation to the effectiveness of material controls, rather than detailed technical measures or a guarantee of cyber security.

For many listed companies, the challenge will be striking the right balance between providing meaningful disclosure on cyber control effectiveness while avoiding disclosures that could compromise security. The FRC’s mythbuster provides helpful clarification on how that balance can be achieved.

Tatiana Kalaji, Associate, has contributed to this legal update.

Explore More Insight