Risk Management and Strategy Cyber security encompasses a key component of Manchester United’s overall enterprise risk management program. Our cyber security program includes, but is not limited to, the following technologies, controls and mitigations: | ● | Monitoring – We have 24/7 security monitoring of our network, systems and data with procedures to respond to cyber security alerts and incidents. |
| ● | Testing – We utilize third-party consultancies and penetration testers who perform independent security testing as well as provide advice and guidance on the implementation of new technologies within the business. We conduct annual cyber security maturity assessments to assess the posture of our cyber security program and identify improvements and risks. |
| ● | Security systems – We have implemented several protective and detective cyber security tools in our IT systems, aligned with best practice. |
| ● | Authentication and authorization – We have policies which define the scenarios by which users, administrators and 3rd parties are granted access to our network, systems and data and monitor compliance to those standards via defined procedures. |
| ● | Training and awareness – We have implemented a robust cyber security training and awareness program for our employees. |
| ● | Governance – We have implemented an information security policy framework which define the policies and procedures around the governance, implementation and ongoing management of our security controls. |
| ● | Third-party risk management – We have implemented a program to manage risks associated with 3rd parties which includes a due diligence and onboarding process depending on the third party’s operational criticality and risk profile. |
| ● | Incident response policy and procedures – We have an incident response policy and procedures to respond to cyber security incidents and alerts in a timely manner. |
Within the last 12 months, we have not identified risks from known cybersecurity threats, including as a result of any prior cyber security incident which has materially affected us, including our ability to deliver our business strategy, finance and operations. Manchester United recognizes the impact that a cyber security incident could have to our brand reputation, operations, finance and compliance to regulatory bodies. Manchester United recognizes the significance that cyber security threats can affect our business and strategy which is outlined in our annual report under our key risk factor A cyber-attack on, or disruption to, our IT Systems or other systems utilized in our operations could compromise our operations, adversely impact our reputation and subject us to liability.
|