Why FDs can no longer delegate cyber compliance

SMEs unprepared for overhaul of cyber security rules with new requirement for multifactor authentication (MFA) by default, potentially raising software licence costs, as well as shift in accountability to actual directors, explains David McLeod, co-founder of Backbone

The UK’s most comprehensive cyber security standard - Cyber Essentials, backed by the government - undergoes its most significant transformation yet when new rules come into effect from 27 April 2026.

This update to Cyber Essentials has a direct impact on business owners, CFOs and finance directors, as it shifts responsibility for cyber compliance directly to them, and holds them accountable. Not just on audit day, but every single day.

Your free features:

  • Breaking news and expert analysis
  • Customisable daily newsletters
  • Six free CPD learning modules each year
  • Personalised CPD tracker
  • Top 75 Firms league tables
  • Regulatory changes
  • Hardman’s Tax Data

Sign up to Business & Accountancy Daily

Related Articles
Subscribe