Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in

Aug 23, 2026 - 13:14
0 0
Why is the Premier League now subject to new cybersecurity rules, and what punishments could they face? The experts weigh in
A close-up of the official Premier League match ball. (Image credit: Visionhaus/Getty Images)

With the 2026-27 season kicking off this weekend, Premier League football teams are facing a new set of rules. But these ones aren’t enforced on the pitch, they’re being enforced by the Premier League board.

As the Premier League has adapted to a new era of fan engagement and interaction, teams are holding huge amounts of personal data, including names, email addresses, credentials, and even financial information. These place them at greater risk of data leaks and make them a primary target for cyber attacks.

In order to ensure teams take the necessary steps to protect both their data and the data of their fans, the board can impose fines of up to £100,000 for teams that don’t meet the requirements across backups, incident response, risk management, security assurance and much more.

What do the new rules mean for Premier League teams?

The teams previously had to align with a non-prescriptive security baseline issued in 2024, but the new rules place requirements on teams with deadlines for their implementation.

If these deadlines are not met, the teams can be subject to the aforementioned fine, or referred to an independent commission.

The teams will be required to meet the first set of requirements by April 30, 2027, with further requirements to be met in April 2028 and April 2029. The teams will also have to assess their own compliance by January 10 each year, with a final assessment and evidence submitted to the Premier League board by April 30.

The board can also request additional detail and evidence where needed to track a team’s progress in adhering to the new rules. If a team does not meet requirements during the interim stage it must submit a plan on how it aims to become compliant within 28 days.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Expert perspectives on Premier League cybersecurity rules

  • Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA, Huntress:

The Premier League introducing mandatory cybersecurity standards is the right move, but the detail is where the questions start. £100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.

The phased timeline, April 2027, 2028, 2029, is pragmatic but slow given the threat environment. Waiting until 2029 for full compliance gives attackers three more seasons to find the weakest link.

£100,000 sounds significant until you remember that top Premier League clubs generate revenues north of £600 million annually.

That said, the direction is unambiguously right. Moving from a non-prescriptive roadmap to formal requirements with deadlines and evidence submissions is a meaningful structural shift.

Backups, incident response, risk management, and recovery testing are exactly the right foundations. The Premier League doing this proactively rather than reactively before a major breach forces the issue deserves genuine credit.

Most governing bodies wait for the headline incident. This one didn’t. The real test is enforcement appetite. Rules without credible consequences change nothing.


  • Jamie Akhtar, CEO and Co-founder, CyberSmart:

This is an important shift for the Premier League. Cyber security is moving from being viewed primarily as an IT responsibility to becoming an enforceable element of club governance.

Football clubs hold significant volumes of sensitive supporter, employee and player data, while also relying on systems for ticketing, payments, stadium access and match-day operations. Making areas such as backups, incident response, risk management and security assurance mandatory reflects the reality that a serious cyber incident can quickly become an operational, financial and reputational crisis.

For clubs, compliance should not become an annual box-ticking exercise.

For clubs, compliance should not become an annual box-ticking exercise. They need clear board-level ownership of cyber risk, an accurate inventory of critical systems and data, tested and segregated backups, rehearsed incident-response and recovery plans, strong identity and access controls, and effective oversight of third-party suppliers.

Just as importantly, clubs should continuously collect evidence that these controls are operating effectively. The organisations that treat the new requirements as a minimum baseline for resilience, rather than simply a regulatory hurdle, will be in the strongest position when an attack inevitably tests those controls.


  • Anna Collard, SVP of Content Strategy and CISO Advisor, KnowBe4:

Good to see the Premier League treating cybersecurity as a governance issue rather than an IT afterthought. Mandatory rules with real financial consequences (fines of up to £100,000) send the right signal: boards are expected to own this risk, not just delegate it.

As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.

But fines only address one side of the equation. As I've said before, sport is uniquely exposed because it runs on the very emotions social engineers exploit: passion, urgency, loyalty and trust.

A rushed transfer payment, a fan chasing tickets, an official acting on a "verified" WhatsApp message from someone posing as a coach or chairperson, these are moments of heightened emotion and time pressure, exactly when human judgment degrades. That's not a firewall problem.

It's worth remembering that one of the most costly incidents in this sector involved a Premier League club being spear-phished during a £1 million transfer negotiation. That wasn't a technical breach, but a person deceived at a moment of pressure.

Rules with teeth are a welcome start. But real resilience means pairing compliance with genuine behavioural readiness, for example helping people recognise urgency as a red flag, not a reason to skip verification.


  • Cian Heasley, Principal Consultant, Acumen Cyber:

I think it’s a positive step forward. Football clubs are attractive targets because they hold large volumes of sensitive data, process significant financial transactions and rely on operational systems where disruption can have very real consequences. Moving from advisory guidance to enforceable standards creates much-needed accountability, and the financial incentive will inevitably help drive action.

Requiring clubs to have a clear plan, aligned to defined standards and delivered within a set timeframe, also gives them something measurable to work towards. The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.

The key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.

The focus on backups, incident response and recovery is particularly important. Preventing every incident simply isn’t realistic, so clubs need to prove they can recover quickly when something does happen. If clubs are working towards common standards, there is also a real opportunity to share lessons around what works, where implementation falls short and how security can continue to improve across the league.

In November ‘24, Italian club Bologna FC confirmed a ransomware attack claimed by the RansomHub group, which exfiltrated sensitive data. After the club declined to meet the ransom demand, the ransomware gang published the full dataset on the dark web. The leaked material reportedly included player and sponsor information, and the attackers went as far as invoking GDPR exposure to pressure the club into paying, a tactic that turns a club's own regulatory obligations into leverage.

More recently, Dutch club Ajax was named among the organisations affected by the CEVA Logistics breach, where customer data was exposed through a shared shipping vendor rather than a direct compromise, underlining that supply-chain exposure is also as material a risk as any attack on a club's own estate.

Taken together, these incidents show why these rules were needed then, though they are pitched as proactive, they must also be driven by these football-related breaches.

The £100,000 ceiling is modest against the true cost of a serious incident and the amounts of money tied up in football clubs, so the value lies less in the sanction and more in compelling clubs to build tested backups, incident response and recovery capability before they are needed. The Bologna case in particular demonstrates that ransomware leaks can be damaging, which makes resilience and data minimisation far more important than any assumption that a club can negotiate its way out of trouble.


How do I submit my own perspective on emerging news?

If you have an expert perspective you would like to share on an emerging story or particular topic, please get in contact here: [email protected]


Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.

Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.

Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with a robust academic framework for deconstructing complex international conflicts and intelligence operations, and the ability to translate intricate security data into actionable insights.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0

Comments (0)

User