International Cyber Expo International Cyber Expo
  • About Us
Saturday, 10 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Why Provision 29 is raising the bar for board accountability

by Guru Writer
August 26, 2026
in Opinions & Analysis
Why Provision 29 is raising the bar for board accountability

Businessman login with fingerprint scanning technology. fingerprint to identify personal, security system concept

Share on FacebookShare on Twitter

By Tim Williams, CEO at Quod Orbis

Under the 2024 UK Corporate Governance Code, the revised Provision 29 requires boards to demonstrate that their material internal controls are working effectively. Every business has hundreds of controls, however material controls have the potential to create an immense operational, security or regulatory impact. The message behind this latest update is that it’s no longer enough to be compliant on paper, and boards – now more than ever – must provide consistent evidence that is timely, accurate, reliable and capable of surfacing risks.

In the past, it was easier for businesses to claim they had good internal controls, but Provision 29 has changed the game. It calls for businesses to maintain assurance that their controls work across finance, compliance and reporting, and be able to validate their claims with real-time, accurate data.

Regulations usually demand annual, point-in-time, reporting exercises, however, the Financial Reporting Council is explicit that this new framework should not be seen as a periodic compliance exercise, but instead as an integral part of the company’s day-to-day business and governance processes.

Security teams face a new era of accountability 

Provision 29 places greater responsibility on IT, security teams and the board when it comes to reporting the effectiveness of their internal controls. Teams have become accustomed to conducting infrequent manual data collections that provide a small snapshot of their entire system that becomes out of date the moment you have it. But businesses are now expected to have visibility over their controls throughout the year, not just before a review, and having accurate and timely data gives teams greater confidence that the decisions they are making today reflect the current risk exposure of their business.

Reporting and gathering data in silos is a hard task, especially when boards have to manually reconcile five conflicting reports, indicating varying levels of risk. Shared reporting architecture resolves this, providing greater collaboration between risk, internal audit and compliance teams, which is invaluable for verifying whether businesses have truly achieved organisational resilience., Provision 29 need not be a burden, but instead an opportunity to gain better visibility of how their controls are performing and improve their overall security posture and cyber resilience. While most boards comply, the most resilient are explaining their findings, and disclosing their reports properly.

Annual testing is no longer enough 

Businesses are reassessing their existing risk management strategies to make sure they are robust enough to provide the evidence boards need to report with confidence. Annual reporting cannot keep up with businesses operating in complex digital ecosystems, made up of cloud platforms, traditional infrastructure and third-party suppliers.

When you take a car in for its annual MOT, the mechanic only reports on the problems that exist there and then. What an MOT can’t do is warn of potential faults that may arise as soon as you leave the garage. The same logic applies to annual testing of security controls. What was deemed effective a few months ago may not be now, especially as many businesses keep evolving their systems and exposing them to new risks.

Businesses need continuous visibility to understand how their control environment changes over time. By relying on annual reports, businesses risk making important decisions based on a snapshot of information that becomes outdated the second it’s extracted. They thereby move forwards with a false sense of security over their entire system.

Getting ahead of the risk

Most businesses know what internal controls they have, but lack the visibility into whether they are operating effectively. Closing that gap means pinpointing where their internal controls are situated across their estate and what potential risks they could be exposed to.

Continuous assurance lets businesses monitor their internal controls in real-time, allowing them to identify degraded systems, know how long the exposure existed and explain what was done to resolve it. When security, IT, risk and compliance teams have consistent visibility over their internal controls, they can prioritise their efforts on strengthening resilience and preparing for risks before they arise. Imagine knowing that your car’s headlight is going to go out before it does?

This continuous visibility also helps teams communicate with the board. When it comes to reporting, Provision 29 can give boards greater confidence when they sign the declaration as it encourages a more evidence-led view of whether controls are operating as they should. Continuous monitoring reinforces this confidence by providing teams and boards with timely, accurate data rather than manual and sporadic assessments. Think of it as a navigation system rather than a handbrake. A handbrake only stops you from rolling backwards while a navigation system shows you the road ahead, warns you of the hazards you cannot yet see and keeps you moving towards where you want to go. The guidance provided through Provision 29 is designed to give businesses the confidence to move forward and know exactly where they stand.

ShareTweet
Previous Post

Iran-Linked Hackers Blamed for UK Energy Cyberattack

Next Post

Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers

Recent News

Attackers exploit AhsayCBS backup flaws to deploy disguised crypto miners

Attackers exploit AhsayCBS backup flaws to deploy disguised crypto miners

October 9, 2026
WorkNest Launches WorkNest Secure to Expand Cybersecurity and Compliance Services

WorkNest Secure Achieves CREST STAR-FS Accreditation for Red Teaming

October 8, 2026
Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

October 8, 2026
Filigran event

Filigran announces speakers for first THREAD event

October 8, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol