The Premier League Just Made Cyber Security a Rule. Your Club Should Take Note
Something quietly significant happened in professional sport this summer. As first reported by The Athletic and since covered by Computer Weekly and others, the Premier League’s 20 clubs have approved mandatory cyber security rules, phased in over three stages from April 2027, with an assessment every January and fines of up to £100,000 for clubs that fall short. No points deductions, no drama. Just an annual check that the basics are in place, and an improvement plan required where they are not.
If you help run a golf club, a sports venue or any organisation whose season lives in a booking system, it is worth pausing on what the League actually asked for. Because it was not gadgets.
What the top flight decided the basics are
The rules, as reported, cover capabilities in three areas: backup measures, incident response and recovery, and cyber risk and assurance.
Read that list again. There is nothing exotic in it. It is not a shopping list of security products, and it does not require a club to become a technology company. It asks whether copies of your data exist and can be restored, whether anyone knows what to do in the first hours of an incident, and whether someone actually owns the risk and can show the work. Those are operational disciplines, the same category of thing as food hygiene in the clubhouse kitchen or the annual accounts.
That is what makes this interesting for everyone below the top flight. When the top of English football writes something into its rulebook, it is not predicting the future. It is naming table stakes.
Sport has been a target for years
None of this came from nowhere. Back in 2020, the National Cyber Security Centre published a report on the cyber threat to sports organisations, and its findings were blunt: at least 70% of the UK sports organisations surveyed had suffered a security incident in the previous year, and around 30% of those incidents caused direct financial damage, at an average of £10,000 a time. The report’s best-known case involved criminals who compromised a club’s email during a £1 million transfer negotiation. The attempt was foiled before the money moved.
The years since have added examples, with TechRadar Pro’s coverage of the new rules pointing to a 2024 ransomware attack on Bologna FC and club data exposed through a supplier breach at Ajax. The reason sport keeps appearing in these stories is structural rather than sinister. Sports organisations hold exactly what ordinary criminals want: member and customer records, card payments, direct debits and a calendar of events that makes downtime expensive. And most of them run lean, with nobody whose actual job is to think about any of this.
A 40-person golf club holds the same categories of data as a Premier League club. It just holds them without a compliance department.
The lesson is the process, not the fear
Here is the part I think matters most, and it is the reason this story earns a blog post rather than a shrug. The Premier League did not respond to years of incidents by telling clubs to buy a product. It built a process: a defined set of capabilities, an annual assessment, and a plan for closing gaps. That is how large organisations make risk boring, and boring is the goal.
The root cause of most incidents at smaller organisations is not a missing gadget. It is that security is treated as an event, something considered after a scare or a renewal quote, rather than as a process that runs on a schedule whether anyone is worried or not.
Scaled honestly to a club or venue of 25 to 60 staff, the League’s three capability areas become three questions:
Backups. Not “do we have them” but “when did we last restore something from them”. A backup that has never been tested is a hope, not a backup. The tee sheet, the membership database, the accounts: if the answer for any of them is “we think so”, that is the gap.
Incident response and recovery. Not a 40-page plan. One page, known to more than one person: who we call, what we switch off, how we run Saturday’s competition if the tills and the booking system are down, and how members are told. The first hour of an incident is a terrible time to start deciding these things.
Risk and assurance. Someone owns it. It is reviewed on a schedule, and there is evidence the review happened. For a smaller organisation, the government-backed Cyber Essentials scheme is a sensible, proportionate baseline to measure against, and it exists precisely so that this does not have to be invented from scratch.
Fix the cause, not the symptom. The cause here is the absence of a process, and no product fixes that.
Getting ahead of it calmly
Clubs in the Premier League have until April 2027 before the first phase bites. Clubs everywhere else have no deadline at all, which is exactly why this tends not to get done. My suggestion is to borrow the League’s homework: take the three areas above, spend an hour with whoever looks after your IT answering them honestly, and write down what came up. That hour costs nothing and usually surfaces one or two things worth fixing properly.
I spent years running technology inside professional sport, including LIV Golf and the European Tour, where the assumption behind the Premier League’s new rules was simply how things worked: the season depends on the systems, so the systems get looked after by process, not by luck. Net Tech IT brings that same discipline to clubs, venues and businesses of 25+ staff across Sussex, Surrey and London as part of managed IT support, with specialist security work delivered through vetted partners when it is genuinely needed. If you would like a second pair of eyes on those three questions, get in touch or book a call whenever it suits.
Pat | Net Tech IT, Horsham
Sources
- Computer Weekly, Premier League to phase in cyber compliance regime (19 August 2026)
- Techerati, Premier League cyber standards backed by fines of up to £100,000 (20 August 2026)
- TechRadar Pro, Why is the Premier League now subject to new cybersecurity rules? (23 August 2026)
- National Cyber Security Centre, The cyber threat to sports organisations (23 July 2020)
- Computer Weekly, NCSC reveals scale of cyber attacks on UK sports industry (23 July 2020)
- National Cyber Security Centre, Cyber Essentials