
The UK government’s Cyber Resilience Pledge, formally launched at 10 Downing Street on 7 July 2026, sends a clear message to business leaders: cyber risk belongs on the board agenda, not buried in the IT task list.
More than 60 organisations signed the first wave of the voluntary pledge. It asks signatories to take 3 practical steps: make cyber security a board-level responsibility, sign up to the National Cyber Security Centre’s free Early Warning service, and take a risk-based approach to Cyber Essentials across their supply chains. You can read the official pledge details on GOV.UK.
You do not need to sign the pledge to benefit from it. Those 3 actions are a sensible template for any business. With cyber attacks estimated to cost UK organisations £14.7 billion a year, and the NCSC handling 204 nationally significant incidents in the year to September 2025, the case for board-level ownership is hard to ignore.
What the pledge actually asks for
The Cyber Resilience Pledge is voluntary and does not create new legal duties. It formalises actions ministers first put to company chairs in 2025.
The first action is governance. Organisations are asked to implement the government’s Cyber Governance Code of Practice and ensure board members complete NCSC cyber governance training within 3 months, then repeat it annually.
The second action is early warning. Signatories should register for the NCSC’s free Early Warning service, which alerts organisations to malicious activity that may be affecting their networks.
The third action is supply chain resilience. Businesses should register for the Cyber Essentials Supplier Check Tool, audit Cyber Essentials coverage across suppliers, and take a risk-based approach to requiring certification.
A board-level template you can borrow
| Pledge action | What it means for your board | Practical step |
|---|---|---|
| Own cyber risk at board level | A named director is accountable and cyber appears regularly on the agenda | Board training and a standing risk update |
| Use early warning | Threats affecting your systems are identified sooner | Monitoring and alerts that someone acts on |
| Improve supplier resilience | A weak supplier can become your incident | Audit supplier Cyber Essentials status |
| Measure exposure | Directors see real risk, not vague reassurance | Regular vulnerability reporting |
| Prepare for disruption | The board knows what happens if systems go down | Test the incident and continuity plan |
The reason this matters is simple. When cyber sits only with IT, it competes for budget without anyone senior owning the business risk. A ransomware attack is not just a technical event. It can stop orders, delay payroll, disrupt clients, trigger legal duties and damage trust. An IT manager cannot resolve all of that alone.
What boards should put in place now
Start with a regular cyber item on the board agenda and a named owner. The pledge leans on training for a reason, and the same logic applies across the business. Ongoing cyber security awareness training helps staff recognise phishing, suspicious payment requests and unsafe login prompts before they become incidents.
Boards also need visibility. Regular vulnerability management gives directors a clearer picture of exposed systems, missing patches and unmanaged risk. Routine vulnerability scanning helps track whether fixes are actually happening.
Early warning only helps if someone is watching. A managed SOC service gives your business day-to-day monitoring, while MDR services add people who can investigate and respond when an alert becomes serious. Dark web monitoring plays a similar role by flagging leaked company credentials before criminals use them.
The supply chain action is the one many businesses underrate. Your suppliers’ weaknesses can become yours, especially where they handle data, payments, systems access or customer services. The government says organisations that have mandated Cyber Essentials from third parties have seen up to an 80% reduction in incidents. Boards should ask which suppliers are critical, which hold certification, and what happens if one of them is compromised.
Independent testing matters too. Penetration testing helps prove whether controls work in practice, while a tested business continuity plan shows whether the organisation could keep trading if systems were disrupted.
Frequently asked questions
What is the Cyber Resilience Pledge?
It is a voluntary UK government commitment launched in July 2026. It asks organisations to make cyber a board-level responsibility, use the NCSC Early Warning service, and take a risk-based approach to Cyber Essentials across supply chains.
Is the Cyber Resilience Pledge mandatory?
No. It is voluntary and adds no new legal obligations. Any business can still use the 3 actions as a practical cyber governance framework.
Why should cyber security be a board issue?
Because the impact of an attack is financial, operational and reputational, not just technical. Boards set budgets, priorities and response plans, so they need to own the risk.
Put cyber risk where it belongs
You do not need a Downing Street reception to act on the pledge. If you want help putting cyber risk on your board agenda and getting the fundamentals in place, Northern Star’s managed IT support services in London can turn the pledge’s 3 actions into everyday practice. Call 0800 319 6032 to talk it through.
Focus on Incident Resilience and Security Operations
Protecting your critical assets while maximizing daily output is easier with the right technology partner. The specialist team at Northern Star delivers seamless Microsoft 365 integration and secure Microsoft Azure consulting. We introduce secure automation with Microsoft Copilot consulting in London, prevent human error using cyber awareness courses, and filter malicious threats with email threat protection in London.
Our team safeguards your network with vulnerability scans in London and a live managed security operations center in London paired with MDR services. Should an event disrupt your systems, our cyber incident recovery and tailored business continuity solutions get you back online fast. Contact our London engineers today to discuss your setup.












