Cybersecurity is becoming a much bigger issue for football clubs, and the Premier League is now putting greater pressure on clubs to prove they are prepared.
Acumen’s Principal Consultant, Cian Heasley, was recently included in a TechRadar Pro article about the Premier League’s new cybersecurity requirements and why moving from guidance to enforceable standards is a positive step for the industry.
Football clubs make attractive targets. They hold significant amounts of personal information on players, employees and supporters, process high-value financial transactions and depend on technology for everything from ticketing to stadium access. A successful attack can therefore quickly become more than a data security problem.
As Cian explained, “Football clubs are attractive targets because they hold large volumes of sensitive data, process significant financial transactions and rely on operational systems where disruption can have very real consequences. Moving from advisory guidance to enforceable standards creates much-needed accountability.”
There are already plenty of examples demonstrating the risks. In 2024, Italian football club Bologna FC confirmed it had been hit by ransomware group RansomHub. After the club refused to pay the ransom, stolen information was reportedly published online, including player and sponsor data.
More recently, Ajax was among the organisations affected by a breach involving CEVA Logistics. Rather than originating within the club itself, customer data was exposed via a third-party supplier, highlighting the importance of understanding supply chain risk too.
For Cian, however, one of the most important aspects of the Premier League’s approach is its focus on what happens after an attack.
“Preventing every incident simply isn’t realistic, so clubs need to prove they can recover quickly when something does happen.”
That means having tested backups, clear incident response plans and recovery processes that teams know will work when they are needed, rather than discovering weaknesses in the middle of an incident.
The potential £100,000 penalty may be relatively small compared with the financial impact a major cyber attack could have on a Premier League club. The bigger value is the accountability the rules introduce.
Having clubs work towards common standards could also create opportunities to share lessons and improve security collectively. As cyber attacks become an operational and business risk for football, being able to demonstrate that defences and recovery plans actually work will matter far more than simply having them written down.
Read Cian’s comments and the full article here: TechRadar Pro.