Security Operations

Premier League introduces new cybersecurity rules for football clubs

Soccer or football tactics scribble with the trainers whistle and pointer stick on blackboard. Great soccer event this year

As reported by Tech Radar, the Premier League is implementing new cybersecurity regulations for its clubs, aiming to bolster data protection and mitigate cyber threats.

The Premier League has established new mandatory cybersecurity standards for its 20 clubs, moving from a non-prescriptive baseline to enforceable rules with deadlines. These regulations address critical areas such as backups, incident response, risk management, and security assurance. Clubs failing to meet these requirements by set deadlines, starting April 30, 2027, face potential fines of up to £100,000 or referral to an independent commission. This initiative comes as football clubs handle vast amounts of sensitive personal and financial data, making them prime targets for cyberattacks.

Recent incidents, including a ransomware attack on Bologna FC and data exposure through a vendor breach affecting Ajax, highlight the need for these measures. Experts emphasize that while the fines are modest compared to club revenues, the true value lies in compelling clubs to build robust resilience and recovery capabilities before an incident occurs.

Source: Tech Radar

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds