Premier League cyber standards backed by fines of up to £100,000
Written by Rebecca Uffindell Thu 20 Aug 2026

The Premier League is set to introduce mandatory cybersecurity standards across its 20 member clubs, replacing its previous voluntary guidance-based approach with a phased compliance regime running through to 2029. Non-compliance could lead to fines of up to £100,000 ($136,439), although points deductions will not form part of the enforcement regime.
The plans were first reported by The Athletic, part of The New York Times, which obtained exclusive details of the arrangements, with Computer Weekly subsequently reporting on how the regime would be introduced.
Clubs will be required to meet standards covering areas including cyber risk management, backups, incident response, and recovery, with evidence expected to form part of the assessment process.
Clubs Will Move Into a Formal Compliance Regime
According to Computer Weekly, the Premier League has previously taken a non-prescriptive approach to cybersecurity, providing clubs with guidance rather than imposing mandatory requirements.
The new framework will change that. Clubs will be expected to meet formal standards and show evidence that those requirements are in place.
Rather than prescribing particular security products, the regime is expected to focus on whether clubs have the processes and capabilities needed to manage cyber risk and respond effectively when incidents occur.
The framework will be introduced in phases, beginning in 2027 and continuing through 2028 and 2029.
According to The Athletic, clubs will face an annual assessment each January during that period. Where security arrangements fall short of the required standard, clubs will be expected to produce a detailed improvement plan setting out how deficiencies will be addressed.
Football’s Cyber Exposure is Already Well Established
The move follows a series of incidents showing the range of cyber threats faced by professional football organisations.
Leeds United disclosed that a February 2025 cyberattack against its retail website compromised the card details of a small number of customers. The club brought in forensic specialists, contacted affected customers, and worked with the Information Commissioner’s Office.
Manchester United experienced a cyberattack on its systems in November 2020. The club said it had taken action to contain the incident and was not aware of any breach of personal data associated with supporters. Its website and app were also unaffected.
An English Football League club also suffered a ransomware attack that affected systems including CCTV and turnstiles, creating the possibility that a fixture would have to be postponed.
The National Cyber Security Centre has previously highlighted a case in which the email account of a Premier League managing director was compromised while the club was negotiating a player transfer. Criminals monitored the discussion and attempted to redirect a payment worth around £1 million ($1.3 million) to an account they controlled. The payment was stopped after the receiving account triggered a fraud marker at the bank.
The NCSC Had Already Identified Sport as a Target
Cybersecurity concerns within professional sport predate the Premier League’s proposed regime.
In its 2021 Annual Review, the NCSC said the sports industry was seen as a high-value target by cyber criminals, with at least 70% of clubs and sporting bodies surveyed suffering a breach every 12 months at the time — twice the average for UK businesses.
In January of that year, the NCSC held its first security summit with professional sports clubs and organisations. More than 180 representatives took part, including representatives from 11 Premier League and 35 English Football League teams, alongside rugby and cricket clubs and national governing bodies.
The sessions were designed to help organisations understand the threat and the measures they could take to reduce their likelihood of falling victim to cyber criminals.
The figures are historical rather than an assessment of the current threat level, but they show that cyber resilience has been an established concern across professional sport for several years.
Premier League Sets a Common Cyber Standard
The proposed regime takes that response a stage further.
Previous efforts have focused on guidance and awareness. The Premier League’s new framework will place all 20 clubs within a common process of requirements, annual assessment and remediation.
By 2029, clubs will be expected to demonstrate that they can manage cyber risk, respond to incidents and recover from disruption against a shared set of standards.
For a sector that has already experienced payment diversion, ransomware, and customer data compromise, the proposed regime marks a move towards formalised operational resilience.
Written by Rebecca Uffindell Thu 20 Aug 2026
Tags:
cyber standards Incident response Operational Resilience Premier League sportMost Viewed News
Tue 25 Aug 2026
Lambda’s £2.1bn pre-IPO talks put neoclouds back into focusTue 25 Aug 2026
OpenAI says Jalapeño delivers up to 1.9x more AI work per watt
