The Premier League has raised the bar on cyber security – what can other sports learn?
Football’s Premier League has become the first major sports league to introduce mandatory cyber security standards for its clubs, backed by fines of up to £100,000. It is a significant shift: cyber security is no longer simply an IT issue, but a governance and business risk. Other sports should take note.
From the 2026/27 season, Premier League clubs will be required to meet mandatory cyber security standards covering four core areas: backups, incident response, risk management and security assurance. Requirements will be introduced in three phases, with the first set due by the end of April 2027, and additional measures each April until 2029, with interim assessment every January.
For a league generating billions in revenue, this is about more than compliance. It is an acknowledgement that cyber risk has become a business risk, and one that professional sport can no longer afford to ignore.
Why is professional sport such an attractive target?
Premier League clubs hold huge volumes of sensitive personal, financial and commercial data belonging to players, employees, supporters, sponsors and partners.
They also operate complex digital ecosystems involving ticketing, retail, hospitality, broadcasting, payment systems, cloud platforms and third-party suppliers.
Then there is the profile of the league, the 20 clubs and their players. A successful attack on a high-profile club can deliver financial rewards, valuable data and “kudos” for attackers. Celebrity players – who are global brands in their own right – and senior executives can also become targets.
The consequences extend beyond the IT department and into the fabric of each club. A serious breach could disrupt operations, expose sensitive information, damage relationships with sponsors, partners and fans; and undermine a club’s reputation – potentially affecting the wider competition.
The real lesson isn’t the fine
The £100,000 fine may grab the headlines, but the more significant change is that cyber security has been formally embedded into the rules of the competition.
That represents an important shift in mindset. Cyber security can no longer sit solely with the IT or security team. Boards and senior leaders need visibility of their organisation’s cyber risk and must ensure resilience is properly funded, tested and maintained.
That is the real lesson for other sports.
What can other sports learn?
Make cyber security a leadership issue
Whether it is football, rugby, cricket, motorsport or tennis, cyber security should be treated as a business responsibility. Senior leaders need to understand where the organisation is vulnerable and what its most critical systems and data are.
Focus on resilience, not just prevention
No organisation can guarantee it will never be breached. The objective should be to prevent attacks where possible, while ensuring the organisation can respond, recover and continue operating when something goes wrong.
That means robust, tested backups and effective incident response plans.
This is exactly what the Premier League has mandated for its clubs.
Understand the supply chain
Sports organisations depend on ticketing platforms, payment providers, broadcasters, cloud services and other third parties. Every connection creates potential risk, making supply-chain security an essential part of cyber resilience.
Don’t wait for an incident
The Premier League has recognised that waiting for any, or all, of its 20 clubs to suffer a serious breach before taking action would be the wrong approach.
Other sports should learn from that example now. Cyber resilience needs to be built into governance, investment and operational planning before an attack exposes the gaps.
The Premier League may have kicked things off, but there’s no reason why other sports can’t play by the same rules so that sport is the winner (not the cyber criminals).