Cyber Resilience Pledge: What UK CISOs Must Decide Now | INFORMD Executive Briefing

Cyber Resilience Pledge: What UK CISOs Must Decide Now

The UK government’s voluntary Cyber Resilience Pledge asks signatories to make cyber security a board-level responsibility, join the NCSC’s Early Warning service, and require Cyber Essentials certification across their supply chain. CISOs now need a recommendation ready for the board.

According to the UK government, nationally significant cyber incidents more than doubled in 2025, driven partly by hostile states and criminals running automated AI systems to find and exploit vulnerabilities. Alongside the Pledge, the government has committed £90 million over three years, delivered through the Department for Science, Innovation and Technology and the National Cyber Security Centre, to strengthen cyber resilience among small and medium-sized businesses specifically.

What does signing the Cyber Resilience Pledge actually commit an organisation to?

Three concrete obligations. First, cyber security becomes an explicit board-level responsibility, not something delegated entirely to the CISO or IT function — the board must be able to demonstrate active oversight. Second, signatories must register for the NCSC’s free Early Warning service, which flags malicious activity affecting an organisation’s network. Third, and most consequential for larger enterprises, signatories must require Cyber Essentials certification across their supply chains — meaning every material supplier and vendor needs to hold or obtain the government-backed baseline certification.

Executive Action:

  • Brief the board on what “explicit board-level responsibility” for cyber means in practice for meeting cadence and reporting
  • Register for the NCSC Early Warning service ahead of any formal Pledge commitment
  • Map which suppliers currently lack Cyber Essentials certification before signing

Why is the government pushing AI-powered cyber defence cooperation now?

The government is calling on frontier AI labs — named specifically as Anthropic, OpenAI and Google DeepMind — to deepen cooperation with UK government on AI-enabled cyber defence, with the stated goal of building capabilities that can autonomously identify and address vulnerabilities at a speed and scale no human team can match. This reflects a wider shift in thinking: attackers are already using automated AI systems to find and exploit vulnerabilities faster than manual patching cycles can respond, so defenders need equivalent automation, not just more headcount.

Executive Action:

  • Assess whether current vulnerability management can match the speed of automated attack tooling
  • Evaluate AI-assisted vulnerability scanning and patching tools against current manual processes
  • Track how the government’s AI lab cooperation develops for enterprise-relevant tooling

What does the supply chain Cyber Essentials requirement mean in practice?

For a large enterprise with hundreds or thousands of suppliers, requiring Cyber Essentials certification across the supply chain is a significant procurement and vendor management undertaking, not a one-off compliance checkbox. CISOs need to work with procurement to build certification into contract renewal and onboarding processes, with a realistic timeline for existing suppliers to achieve certification rather than an immediate hard cut-off that disrupts operations. This should be sequenced against existing third-party risk assessment processes rather than run as a separate parallel programme.

Executive Action:

  • Build Cyber Essentials certification into supplier onboarding and contract renewal, not a standalone exercise
  • Set a realistic phased timeline for existing suppliers to certify
  • Integrate the requirement with existing third-party risk assessment workflows

Should every organisation sign the Pledge, or only smaller businesses?

The £90 million funding is explicitly targeted at small and medium-sized businesses, but the Pledge itself is open to organisations of any size, and larger enterprises signing sends a clear signal to the market and to their own supply chains about expected security baselines. For large organisations already meeting or exceeding ISO 27001 and operating mature board reporting on cyber risk, signing is largely a formalisation of existing practice. For organisations still building board-level cyber oversight, the Pledge provides a useful external forcing function to get there.

Executive Action:

  • Assess current board cyber oversight maturity against the Pledge’s requirements before deciding to sign
  • Use the Pledge as a forcing function to formalise board-level cyber reporting if gaps exist

CISOs preparing a board recommendation can use INFORMD’s AI governance test and project review checklist to benchmark current maturity, and the technology strategy review template to structure the board paper. INFORMD’s executive briefings library is tracking the Pledge and related cyber resilience measures.

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.

What is the UK Cyber Resilience Pledge?

A voluntary government scheme requiring signatories to make cyber security a board-level responsibility, register for the NCSC’s Early Warning service, and require Cyber Essentials certification across their supply chains.

How much funding is behind the UK’s cyber resilience push?

The government has committed £90 million over three years, delivered through DSIT and the NCSC, specifically to strengthen cyber resilience among small and medium-sized businesses.

Which AI companies is the UK government asking to help with cyber defence?

The government has specifically called on Anthropic, OpenAI and Google DeepMind to deepen cooperation on AI-enabled cyber defence capable of autonomously identifying and addressing vulnerabilities at scale.

Is the Cyber Resilience Pledge mandatory?

No, it is voluntary. Organisations of any size can sign, though the associated £90 million funding is targeted specifically at small and medium-sized businesses.

Similar Posts