The UK government has launched a voluntary Cyber Resilience Pledge at 10 Downing Street, asking companies to elevate cybersecurity to a board-level responsibility, enroll in the National Cyber Security Centre’s Early Warning service, and push suppliers toward Cyber Essentials certification or an equivalent baseline. The initiative includes a 30/60/90-day timetable for organizations to register for warning services, assess supplier coverage, and implement the Cyber Governance Code of Practice with annual board training. More than 60 organizations signed at launch, including over 20 of the government’s 39 strategic suppliers and companies such as Aviva, London Stock Exchange Group, Marks & Spencer, and Capita.
The rollout drew scrutiny because uptake among major British firms was limited, with fewer than 15 FTSE 350 companies joining despite ministers having written to every FTSE 350 chair and chief executive months earlier. The pledge has no enforcement mechanism, raising questions about whether it is primarily a public commitment ahead of possible future regulation through the proposed Cyber Security and Resilience Bill. The launch comes as cyber incidents continue to rise in the UK, with attacks estimated to cost organizations £14.7 billion annually and the NCSC reporting 204 nationally significant incidents in the year to September 2025, up from 89 the previous year.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
At launch, more than 60 organizations signed the pledge, including over 20 strategic government suppliers and companies such as Marks & Spencer, Aviva, and London Stock Exchange Group.
On 2026-07-07, the UK government launched its voluntary Cyber Resilience Pledge at 10 Downing Street to make cybersecurity a board-level responsibility and promote use of NCSC Early Warning and supplier assurance measures.
UK ministers wrote to every FTSE 350 chair and chief executive eight months before the launch, urging them to join the forthcoming Cyber Resilience Pledge.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechrepublic.com
Open sourcetheregister.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.