❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Premier League Introduces Mandatory Cybersecurity Standards, Backed by Fines of Up to Β£100,000

19 August 2026 at 06:55

The Premier League has introduced mandatory cybersecurity requirements for its clubs for the first time, with non-compliant clubs facing fines of up to Β£100,000. The rules, which apply from the start of the 2026-27 season, mark a shift away from the league’s previous non-prescriptive security guidance towards a formal framework with fixed deadlines and evidence-based assessment.

Enforcement will sit within the Premier League’s existing disciplinary framework rather than a standalone sanctions regime. The board can issue a reprimand, impose a fine through its summary jurisdiction, or refer a suspected breach to an independent commission. Sources briefed on the matter say points deductions are not on the table for cybersecurity non-compliance.

A Phased Rollout to 2029

The framework covers four core areas: backups, incident response, risk management and security assurance, with later phases adding tested requirements around clubs’ ability to recover from a cyber incident.

Implementation is staged across three phases, with the first set of measures due by April 30, 2027, and further requirements following in April 2028 and April 2029. Clubs must file an interim compliance assessment by January 10 each season and a final assessment with supporting evidence by April 30. Any club found non-compliant at the interim stage has 28 days to submit a remediation plan to the league. The Premier League can also request further evidence at any point and may grant dispensations from specific requirements in exceptional circumstances.

The standards were signed off by clubs at the league’s Annual General Meeting in June, following a two-season consultation period, and are explicitly framed as a preventative measure rather than a response to any specific incident.

Industry Reaction: Right Direction, But Is the Timeline Too Slow?

Security vendors have broadly welcomed the move but raised concerns that both the financial penalty and the multi-year rollout may not match the pace at which clubs are being targeted.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the size of the fine needs to be seen in context: β€œΒ£100,000 sounds significant until you remember that top Premier League clubs generate revenues north of Β£600 million annually.” He also questioned the pace of the rollout, describing the phased timeline of April 2027, 2028 and 2029 as β€œpragmatic but slow given the threat environment,” adding that β€œwaiting until 2029 for full compliance gives attackers three more seasons to find the weakest link.”

Patel was more positive about the substance of the framework itself, calling the shift from a non-prescriptive roadmap to formal requirements with deadlines and evidence submissions β€œa meaningful structural shift,” and praising the choice of foundations: β€œbackups, incident response, risk management, and recovery testing are exactly the right foundations.” He singled out the league’s proactive stance for particular credit: β€œmost governing bodies wait for the headline incident. This one didn’t.” His central caveat was around enforcement: β€œthe real test is enforcement appetite. Rules without credible consequences change nothing.”

Cian Heasley, Principal Consultant at Acumen Cyber, also welcomed the move, arguing that formal standards are overdue given the combination of sensitive data, financial transactions and operational systems held by football clubs.

β€œMoving from advisory guidance to enforceable standards creates much-needed accountability, and the financial incentive will inevitably help drive action,” he said.

For Heasley, however, the Β£100,000 penalty is less important than requiring clubs to demonstrate that they can withstand and recover from an attack. β€œThe Β£100,000 ceiling is modest against the true cost of a serious incident and the amounts of money tied up in football clubs, so the value lies less in the sanction and more in compelling clubs to build tested backups, incident response and recovery capability before they are needed.”

He also welcomed the introduction of defined standards and deadlines, but cautioned that the requirements need to be clear enough to avoid ambiguity. β€œThe key will be making sure those standards provide clear structure rather than leaving too much open to interpretation.”

Jamie Akhtar, CEO and co-founder of CyberSmart, framed the rules as part of a broader trend of cybersecurity becoming a governance issue rather than a purely technical one: β€œcybersecurity is moving from being viewed primarily as an IT responsibility to becoming an enforceable element of club governance.” He pointed to the scale of data and operational systems clubs now manage, β€œfootball clubs hold significant volumes of sensitive supporter, employee and player data, while also relying on systems for ticketing, payments, stadium access and match-day operations,” and argued the new mandatory areas reflect how quickly a cyber incident can escalate: β€œa serious cyber incident can quickly become an operational, financial and reputational crisis.”

Akhtar was clear that compliance alone should not be the end goal. Clubs, he said, need β€œclear board-level ownership of cyber risk, an accurate inventory of critical systems and data, tested and segregated backups, rehearsed incident-response and recovery plans, strong identity and access controls, and effective oversight of third-party suppliers,” alongside continuous evidence-gathering that controls are actually working. His conclusion: β€œthe organisations that treat the new requirements as a minimum baseline for resilience, rather than simply a regulatory hurdle, will be in the strongest position when an attack inevitably tests those controls.”

Football Has Already Seen the Consequences

The risks are not theoretical. In November 2024, Italian club Bologna FC confirmed a ransomware attack claimed by the RansomHub group. After the club refused to pay the ransom, the attackers published stolen data on the dark web, reportedly including information relating to players and sponsors.

More recently, Ajax was named among the organisations affected by the CEVA Logistics breach, where customer information was exposed through a third-party shipping provider rather than through a direct compromise of the club.

Heasley said, β€œThe incidents demonstrate both the direct and supply-chain risks facing football clubs. The Bologna attack, in particular, shows why resilience and data minimisation matter when stolen information can be used as leverage and subsequently published if negotiations fail.”

Why It Matters

The rules make the Premier League one of the first major sports bodies globally to formally mandate cybersecurity controls across its member organisations, rather than relying on voluntary guidance. With the first compliance deadline less than a year away, clubs will need to move quickly on board-level accountability, backup and recovery testing, and third-party risk oversight; areas that, as both commentators note, are straightforward to name but considerably harder to operationalise and evidence under a compliance deadline.

The post Premier League Introduces Mandatory Cybersecurity Standards, Backed by Fines of Up to Β£100,000 appeared first on IT Security Guru.

Jeff Bezos reportedly joining bid to buy stake in English soccer giant Liverpool FC

By: John Cook
27 July 2026 at 12:17
Jeff Bezos after spaceflight
Jeff Bezos uncorks the bubbly after a suborbital spaceflight in Blue Origin’s New Shepard capsule. (Blue Origin Photo)

Jeff Bezos may never again β€œwalk alone.”

The Amazon founder is reportedly part of a group interested in buying a 30% stake in Liverpool Football Club, the storied English Premier League soccer team whose legendary fans belt out the show tune β€œYou’ll Never Walk Alone” before each home match.

Bezos would join a group that includes the former co-owner of soccer club Queens Park Rangers, Amit Bhatia, who is looking to pay Β£1.35 billion (about $1.8 billion) for the stake, reports The Guardian. The stake is being sold by current owner Fenway Sports Group, the firm that also owns The Boston Red Sox.

Bezos, who founded Amazon in Seattle in 1994, is considered the fourth richest person on the planet with a net worth estimated by Forbes at $224 billion.

The billionaire has long been rumored as a possible sports team owner, and his name was often tossed out as a possible buyer of the Seattle Seahawks and the Washington Commanders. Earlier this month, venture capitalist Vinod Khosla and his family emerged as the lead bidder for the Super Bowl champion Seahawks at a reported purchase price of $9.6 billion.

In addition to his recent marriage to former journalist Lauren Sanchez, Bezos also is highly engaged with his space venture Blue Origin and a new AI company by the name of Prometheus, which just raised $12 billion and where he serves as co-CEO.

Owning a piece of a UK soccer club has become a status symbol of sorts for wealthy Americans, perhaps driven by the popularity of shows like Ted Lasso and Welcome to Wrexham. The latter is a documentary that tracks Hollywood stars Ryan Reynolds and Rob McElhenney and their exploits of owning the Welsh team Wrexham FC.

American owners currently own outright or a piece of some of the top clubs in the English Premier League, including Chelsea led by Todd Boehly; Arsenal owned by Stanley Kroenke; and Manchester United owned by the Glazer family. Liverpool also is considered one of the top soccer clubs on the planet, winning the Premier League trophy in the 2024-2025 season.

On a smaller scale, Remitly co-founder Shivaas Gulati joined an ownership consortium two years ago that purchasedΒ Southend United, a football club founded in 1906 and located in Southend-on-Sea, about an hour from London. They play in the National League, which is the fifth tier of English soccer.

The English Premier League season starts on Friday, Aug. 21 when defending Premier League champs Arsenal take on newly-promoted side Coventry City.

❌
❌