Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in
The Premier League wants to harden teams against emerging cyber threats
The Premier League has introduced new cybersecurity rules for its teams as they prepare for the 2026-27 season. These rules aim to safeguard the personal information of fans and players, as well as financial data, from cyber attacks. If teams fail to meet the requirements by April 30, 2027, they may face fines of up to £100,000 or be referred to an independent commission.
The rules cover various aspects, including backups, incident response, risk management, and security assurance. Compliance will be assessed annually, with teams required to submit evidence of their progress. Experts have mixed opinions on the implementation. While some, like Muhammad Yahya Patel, believe the rules are long overdue, others, like Jamie Akhtar, are concerned about the slow timeline and the need for genuine enforcement.
Anna Collard emphasizes the importance of treating cybersecurity as a governance issue, while Cian Heasley highlights the need for behavioral readiness alongside compliance measures.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.