
UK FRC Publishes Cybersecurity “Mythbuster” on Provision 29

On 23 September 2026, the UK Financial Reporting Council (the “FRC”) published a Provision 29 Mythbuster: Focus on Cyber (the “Mythbuster”), offering targeted guidance on companies’ approach to cybersecurity when reporting under Provision 29 of the UK Corporate Governance Code 2024 (the “Code”). The Mythbuster seeks to address practical concerns raised by the industry concerning the scope of the required reporting including, whether Provision 29 could require companies to disclose commercially or operationally sensitive information. In response, the Mythbuster advises that “The declaration should not include commercially sensitive information or specific details of the technical controls implemented to support the company’s cyber resilience. However, the board needs to satisfy itself that the company’s material controls are effective and explain how it has monitored and reviewed their effectiveness. The declaration focuses on that assurance process and its outcome, rather than the detailed design or operation of individual technical controls.”
Background
Provision 29 requires boards to monitor their companies’ risk management and internal control framework and, at least annually, review the framework’s effectiveness. That monitoring and review traditionally covers all material controls — financial, operational, reporting, and compliance — and boards typically include in the annual report a declaration as to the effectiveness of those controls as at the balance sheet date.
Cybersecurity controls are likely to be material for many listed companies, particularly those that depend on digital systems, process significant volumes of customer data, or operate in sectors where cyber threats are well-established. Where that is the case, boards will likely need to address cyber as part of their Provision 29 disclosures.
Five Key Takeaways from the Mythbuster
- Provision 29 does not require a guarantee of cybersecurity.
According to the Mythbuster, a board’s Provision 29 declaration on the effectiveness of cyber controls is not a promise that the company will never suffer a cyber incident. In the Mythbuster, the FRC indicates that boards are expected to assess and explain how they have monitored and reviewed the controls in place to manage cyber risk, but not to certify that those controls will hold indefinitely or that risk has been eliminated. The Mythbuster acknowledges that companies operate in a dynamic threat environment, and that the effectiveness of controls can be affected by developments that post-date the declaration.
- Companies do not need to disclose sensitive technical information.
The Mythbuster confirms that Provision 29 does not require reporting so granular as to reveal the specific technical controls used to prevent or mitigate cyber incidents. Companies can describe how their boards monitor and review cyber controls in their declarations without disclosing configurations, vulnerability assessments, or other operationally sensitive details that could themselves create security risks if published.
- Cyber controls form part of the wider internal control framework.
According to the Mythbuster, the FRC expects companies to address material cyber controls within their Provision 29 disclosures alongside their respective board’s broader description of its monitoring and review process and its effectiveness declaration.
- A cyber incident does not necessarily mean that material controls were ineffective.
According to the Mythbuster, Provision 29 does not create a standalone obligation to report every cyber incident or breach, and the FRC indicates that the occurrence of an incident does not, itself, mean that a prior effectiveness declaration was incorrect. The relevant question for Provision 29 purposes, is whether the board can conclude that material controls were effective as at the balance sheet date.
That said, companies may need to assess the specific circumstances of any incident, including whether the particular incident indicates that a material control was not effective. An incident that exposes a systematic failure may require a more careful analysis than one that represents a novel attack method against an otherwise well-maintained control environment.
- The FRC underscores that boards should keep pace with the evolving cyber risk environment.
Although the Provision 29 declaration is made as at a point in time, in the Mythbuster, the FRC emphasises that companies should take account of reasonably foreseeable changes in cyber risk when designing, monitoring, and reviewing their controls. Cyber threats continue to evolve as threat actors adapt their methods, and boards are expected to ensure their oversight arrangements keep up.
Practical Implications
In short, whilst the Mythbuster is clear that the effectiveness declaration does not (1) amount to a warranty that cyber incidents cannot happen, or (2) require publication of sensitive details about a company’s specific defences, it does not appear to lower the compliance bar. Companies that identify cyber controls as material may want to double-down on efforts to weigh whether their boards have a sufficiently robust basis for their effectiveness assessment. In practice, boards may want to consider, among other things:
- How the company identifies and tracks changes in its cyber risk profile.
- The quality and timeliness of information reaching the board when it reviews the operation of relevant controls.
- Whether cyber incidents or penetration testing results indicate weaknesses that may need to be addressed before the board can make a positive effectiveness declaration.
This post is as of the posting date stated above. Sidley Austin LLP assumes no duty to update this post or post about any subsequent developments having a bearing on this post.

