UK businesses commit to NCSC cyber pledge
- More than 60 UK businesses committed on July 7 to the government's Cyber Resilience Pledge, a voluntary scheme tying cyber oversight to boards. - The pledge gives signatories three months to complete NCSC board training and one month to join Early Warning, with annual public updates. - Companies sign by filing a declaration with DSIT and publishing it online; guidance and the declaration were updated July 7.
More than 60 businesses in Britain have signed up to the UK government’s Cyber Resilience Pledge, a voluntary program launched publicly on July 7 that asks companies to make cyber security a formal board responsibility. The Department for Science, Innovation and Technology, the National Cyber Security Centre and minister Liz Kendall said founding signatories include M&S, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte LLP, Accenture UK, Vodafone Group and VodafoneThree. The launch took place at 10 Downing Street, according to the government’s press release. The pledge is built around three actions: board-level accountability, use of the NCSC’s Early Warning service and stronger cyber controls in supply chains. Government guidance says the scheme was announced by the Security Minister at the CyberUK conference in Glasgow on April 22, 2026, and formally launched in the summer with a public list of signatories. (gov.uk) ### What are companies actually promising to do? The July 7 declaration says each signatory commits to “make cyber a Board responsibility” by implementing all actions in the Cyber Governance Code of Practice and ensuring all board members complete the NCSC’s Cyber Governance Training within three months, then annually. The same declaration also requires companies to register for Early Warning within one month of signing. (gov.uk) The government’s information pack says signatories must also register for the Cyber Essentials Supplier Check Tool within two months, conduct a comprehensive audit of Cyber Essentials coverage across their supply chain, and present that audit to the board. If a company does not require Cyber Essentials for some suppliers, the board is expected to ensure that decision matches the organisation’s risk appetite and strategy and is backed by other assurance. (gov.uk) ### What is the board training the pledge refers to? The NCSC says its Cyber Governance Training is designed for boards and directors and is aligned with the Cyber Governance Code of Practice. The training package includes an introduction and five interactive modules covering risk management, strategy, people, incident planning, response and recovery, and assurance and oversight. (assets.publishing.service.gov.uk) Each module takes about 20 minutes, according to the NCSC, and the package was developed with input from non-executive directors and government subject-matter experts. The agency says the training is intended to help directors govern cyber risk “without delving into the technical detail.” ### Why is the government pushing this now? The July 7 press release says cyber-attacks cost UK organisations an estimated 14.7 billion pounds a year and that more than 5 million cyber crimes were committed against UK firms last year. (ncsc.gov.uk) The same release says the NCSC handled 204 nationally significant incidents in the year to September, up from 89 the year before. The government’s guidance says ministers had already written to chief executives and chairs of leading UK companies, including the FTSE 350, urging them to take the three actions now formalised in the pledge. The information pack describes the pledge as a way to “formalise” those earlier requests and give organisations a public mechanism to show they have adopted them. (gov.uk) ### What has to be disclosed after signing? The declaration says signatories must publish the signed pledge on their website within two months. It also says they will publish an annual public update, either in their annual report or on their website, describing the steps taken to deliver the pledge. The GOV.UK guidance says organisations that want to sign should return the signed declaration to the DSIT cyber security team. (assets.publishing.service.gov.uk) The government’s published declaration and guidance were both updated on July 7, 2026, the same day the first wave of companies was announced. (gov.uk 1) (gov.uk 2)