v3.26.3
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Jun. 30, 2026
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

Risk Management and Strategy

Cyber security encompasses a key component of Manchester United’s overall enterprise risk management program. Our cyber security program includes, but is not limited to, the following technologies, controls and mitigations:

●Monitoring – We have 24/7 security monitoring of our network, systems and data with procedures to respond to cyber security alerts and incidents.
●Testing – We utilize third-party consultancies and penetration testers who perform independent security testing as well as provide advice and guidance on the implementation of new technologies within the business. We conduct annual cyber security maturity assessments to assess the posture of our cyber security program and identify improvements and risks.
●Security systems – We have implemented several protective and detective cyber security tools in our IT systems, aligned with best practice.
●Authentication and authorization – We have policies which define the scenarios by which users, administrators and 3rd parties are granted access to our network, systems and data and monitor compliance to those standards via defined procedures.
●Training and awareness – We have implemented a robust cyber security training and awareness program for our employees.
●Governance – We have implemented an information security policy framework which define the policies and procedures around the governance, implementation and ongoing management of our security controls.
●Third-party risk management – We have implemented a program to manage risks associated with 3rd parties which includes a due diligence and onboarding process depending on the third party’s operational criticality and risk profile.
●Incident response policy and procedures – We have an incident response policy and procedures to respond to cyber security incidents and alerts in a timely manner.

Within the last 12 months, we have not identified risks from known cybersecurity threats, including as a result of any prior cyber security incident which has materially affected us, including our ability to deliver our business strategy, finance and operations. Manchester United recognizes the impact that a cyber security incident could have to our brand reputation, operations, finance and compliance to regulatory bodies. Manchester United recognizes the significance that cyber security threats can affect our business and strategy which is outlined in our annual report under our key risk factor A cyber-attack on, or disruption to, our IT Systems or other systems utilized in our operations could compromise our operations, adversely impact our reputation and subject us to liability.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Cyber security encompasses a key component of Manchester United’s overall enterprise risk management program.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block] Within the last 12 months, we have not identified risks from known cybersecurity threats, including as a result of any prior cyber security incident which has materially affected us, including our ability to deliver our business strategy, finance and operations.
Cybersecurity Risk Board of Directors Oversight [Text Block]

Cybersecurity Governance

Our Board of Directors oversees risks from cybersecurity threats as part of its broader oversight of enterprise risk management and has delegated to the Information Security Committee (“the Committee”) oversight of cybersecurity risks, including oversight of management’s implementation of our cybersecurity risk management program. The Committee is comprised of our Executive Leadership Team (“ELT”) and the Head of Information Security provides regular updates to the Committee on cybersecurity risks, the status of key security initiatives, material findings from assessments and testing, and any significant cybersecurity incidents, along with proposed risk mitigation strategies and action plans.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Information Security Committee (“the Committee”)
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] the Head of Information Security provides regular updates to the Committee on cybersecurity risks, the status of key security initiatives, material findings from assessments and testing, and any significant cybersecurity incidents, along with proposed risk mitigation strategies and action plans
Cybersecurity Risk Role of Management [Text Block] Our Interim Chief Information Officer and Head of Information Security are principally responsible for overseeing our cyber security program, and report regularly to our Chief Financial Officer and Chief Executive Officer.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Interim Chief Information Officer and Head of Information Security
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Interim Chief Information Officer’s experience includes leading major technology and security initiatives involving multiple business functions, with responsibility for governance, risk management and delivery outcomes.The Head of Information Security’s experience includes various roles across consultancy, specializing in security strategy, risk management, governance and data privacy, combined with having achieved various qualifications including CISSP (Certified Information Systems Security Professional)
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true