<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=7129060&amp;fmt=gif">

Cyber security has never been higher on the UK business agenda — and in July 2026, the government gave that urgency a name. The Cyber Resilience Pledge, launched at 10 Downing Street alongside founding signatories like M&S, Nationwide and Microsoft UK, asks organisations to publicly commit to strengthening their defences.

We're proud to say Netitude has now signed on the dotted line. Read on for more:

Contents

Tags

Share:

arrow arrow arrow

Earlier this month, the UK government launched its Cyber Resilience Pledge at 10 Downing Street - a voluntary commitment inviting organisations to take three practical steps to strengthen their cyber defences. Founding signatories included the likes of M&S, Nationwide, ITV, Microsoft UK and Cloudflare.

We've now added Netitude to that list. And while signing felt like a natural step for us, it's worth explaining what the pledge is, what it commits us to, and — more importantly — what it means for the businesses we look after.

What is the Cyber Resilience Pledge?

The Cyber Resilience Pledge is a voluntary public commitment, launched by the government on 7 July 2026 as part of its wider National Cyber Action Plan. Rather than introducing new regulations, it asks organisations to formally commit to three concrete actions that have an immediate, positive impact on their resilience to cyber attacks.

It was designed with medium and large organisations in mind, but it's open to businesses of all sizes — and that matters, because cyber resilience is increasingly a shared responsibility that runs the length of a supply chain, not something that stops at your own front door.

The backdrop is sobering. Cyber attacks are estimated to cost UK organisations around £14.7 billion a year, and the average significant attack on an individual UK business now costs almost £195,000. The National Cyber Security Centre (NCSC) handled 204 nationally significant incidents in the year to September, up from 89 the year before. The threat isn't slowing down — and as AI makes attacks easier to launch, it's only accelerating.

The three commitments

Signing the pledge means formally committing to three actions:

1. Making cybersecurity a board-level responsibility: Cybersecurity is no longer an IT issue to be delegated and forgotten — it's a business risk that belongs in the boardroom, using the government's Cyber Governance Code of Practice as the framework.

2. Registering for the NCSC's free Early Warning service: This is a genuinely useful, free service that flags suspicious activity on your network — things like malware infections and vulnerabilities — before they escalate into something serious. It's one of the most practical, no-cost steps any business can take.

3. Taking a risk-based approach to Cyber Essentials across the supply chain: This means using the government-backed Cyber Essentials certification to manage the risk from suppliers and partners — ensuring the businesses you rely on meet a baseline security standard too.

Close-up of Adam Harling signing Netitude's Cyber Resilience Pledge declaration

Why we signed

Here's the honest truth: none of this was new territory for us.

With Cyber Essentials, Cyber Essentials Plus, ISO 27001 and our NCSC Cyber Advisor status already in place, we were most of the way there long before the pledge existed. Cybersecurity has been board-level at Netitude for years, and helping clients get and stay certified is a core part of what we do. Signing on the dotted line simply made official a standard we already hold ourselves to.Can you 

But there was a bigger reason. The pledge was aimed primarily at large corporates — the M&S and Nationwide end of the scale. We think that's exactly why an SME-focused managed IT provider should sign it. If we're advising businesses across Somerset, Bristol and the Southwest to take cyber resilience seriously, the least we can do is hold ourselves to the same standard we're recommending to them. Practising what we preach isn't a slogan — it's the whole point.

What it means for the businesses we work with

This is the part that actually matters if you're a client or considering becoming one.

The standards we commit to in this pledge are the same ones we help our clients achieve. Board-level cyber governance, early warning of threats, supply-chain security through Cyber Essentials — these aren't things we've just signed up to in principle; they're services and support we deliver day in, day out.

And it's becoming more relevant by the month. If your business sits in the supply chain of a larger customer — and most do — you're increasingly likely to be asked to evidence your own cybersecurity before contracts are awarded or renewed. When that question comes (and it will), it helps enormously to have an IT partner who has already walked that path, holds the relevant certifications, and can get you audit-ready rather than leaving you to scramble.

Signing the Cyber Resilience Pledge is, in a sense, just us saying out loud what we've always believed: that good cyber security is a business enabler, not a box-ticking exercise — and that the standards we set for ourselves should never be lower than the ones we help our clients meet.

Netitude's signed Cyber Resilience Pledge declaration document with a branded Netitude pen

Should your business sign the pledge?

If you're a business leader reading this and wondering whether to sign, our honest view is: it's worth considering, but only alongside actually doing the things it commits you to. The pledge is a public statement, and it carries the most weight when it reflects genuine practice rather than good intentions.

The three commitments are sensible, achievable steps for almost any organisation — and the NCSC's Early Warning service in particular is free and genuinely valuable, whether you sign the pledge or not. If you'd like help understanding what any of them would mean in practice for your business, that's exactly the kind of conversation we're here for.


Want to strengthen your cyber resilience?

Whether it's getting Cyber Essentials certified, preparing for the security questions your customers are starting to ask, or simply understanding where you stand, we're here to help — with the certifications and independent assessment to back it up. Get in touch for an honest conversation.


Frequently asked questions (FAQs)

  • What is the Cyber Resilience Pledge? The Cyber Resilience Pledge is a voluntary commitment launched by the UK government on 7 July 2026, inviting organisations to take three practical actions to strengthen their cyber defences: making cyber security a board-level responsibility, registering for the NCSC's Early Warning service, and taking a risk-based approach to Cyber Essentials across their supply chain.

  • Is the Cyber Resilience Pledge mandatory? No. It's a voluntary public commitment, not a regulation. It was designed for medium and large organisations but is open to businesses of all sizes.

  • What is the NCSC Early Warning service? It's a free service from the National Cyber Security Centre that alerts organisations to potential security issues on their network — such as malware infections and vulnerabilities — before they escalate. Any UK organisation can register for it.

  • How is the Cyber Resilience Pledge different from Cyber Essentials? Cyber Essentials is a certification that proves an organisation meets a baseline of technical security controls. The Cyber Resilience Pledge is a broader voluntary commitment to three governance and resilience actions — one of which is using Cyber Essentials across your supply chain. In short, Cyber Essentials is a standard you achieve; the pledge is a commitment you make.

arrow

Signing the Cyber Resilience Pledge isn't a milestone we're treating as an end in itself — it's a public marker of a standard we've held for years, and one we'll keep raising. The takeaways worth holding onto are simple: cyber resilience now belongs in the boardroom, not just the IT department; the threat landscape is intensifying, not easing; and increasingly, the businesses that can evidence their security will be the ones winning and keeping contracts.

The pledge's three commitments — board-level responsibility, early warning of threats, and Cyber Essentials across the supply chain — are sensible, achievable steps for almost any organisation, and the NCSC's Early Warning service is free to anyone who wants it. Above all, the standards we commit to for ourselves are the same ones we help our clients meet every day. If the questions this raises about your own resilience feel worth exploring, that's exactly the conversation we're here to have — no jargon, no scare tactics, just an honest view of where you stand. 

arrow

Netitude Industry Insight

24.07.26

We've Signed the Cyber Resilience Pledge: Here's What That Means

#Cybersecurity #Company News
bottom arrow
21.07.26

Why Your AI Projects Keep Stalling (And What to Fix First)

#AI
bottom arrow
15.07.26

Microsoft Teams Telephony: What UK Businesses Need to Know

#Communications
bottom arrow

Subscribe here!

Read our Privacy Policy