The Cyber Resilience Pledge is an initiative developed by DSIT and NCSC that asks organisations to commit to treating cyber risk as a business risk (by making cyber a board responsibility), signing up to Early Warning, and requiring Cyber Essentials across their supply chains. In this article, RB Consultancy Ltd Managing Director Remo Belisari explains why the company became an early signatory alongside organisations such as Marks & Spencer, Nationwide and Microsoft, and why stronger supply chain security and cyber resilience matter more than ever as AI-enabled threats grow in speed and scale.
Introduction
Imagine arriving at work on a Monday morning and finding that your team can’t access their systems, process orders or access email, while senior leaders are demanding answers.
A supplier has suffered a cyber-attack and that disruption has spread into your organisation. Nobody knows how long the outage will last. Customers are becoming frustrated. Staff are creating workarounds. Revenue is being impacted by the hour.
This isn’t a hypothetical scenario.
Recent cyber incidents affecting major UK organisations have shown how quickly disruption can spread through supply chains and how operational problems can escalate into financial, reputational and customer service issues.
The threat is increasing and hostile cyber activity in the UK is growing more intense, frequent and sophisticated. Security incidents can cause significant financial and social harm to UK businesses and people.
The challenge is becoming even greater as advances in artificial intelligence help attackers increase the speed, scale and sophistication of cyber-attacks.
This is why the Cyber Resilience Pledge is so important.
The Department for Science, Innovation and Technology (DSIT) is urging organisations to take action to ensure they are protected. The Pledge is also backed by the National Cyber Security Centre and is aimed at having an immediate positive impact on your organisation’s cyber resilience:
- Make cyber a Board responsibility
- Sign up to Early Warning
- Require Cyber Essentials across supply chains
These messages have been sent previously – the ministerial letter on cyber security to FTSE 350 organisations requested these actions in October 2025. The Cyber Resilience Pledge is different. It asks organisations to commit to delivering on these requests, driving greater action, accountability and delivery.
That’s one of the key reasons why RB Consultancy signed the Pledge – alongside organisations including Marks & Spencer, Nationwide, Vodafone and Microsoft. This makes RB Consultancy one of the early signatories and demonstrates our commitment to helping strengthen cyber resilience across UK organisations and supply chains.
The Pledge recognises cyber risk as a business risk, with leadership awareness, understanding and engagement all being key. On a personal level, I see the difference leadership can make in every client engagement I am involved in – leadership support drives urgency, priority, speed and success.
The Cyber Resilience Pledge also recognises the importance of supply chain security. With many organisations investing in security measures within their own environment, suppliers can often be overlooked, introducing additional cyber risk. Recent security incidents have demonstrated that attackers don’t always need to target an organisation directly. Compromising a trusted supplier can create disruption across multiple organisations and supply chains.
This is where Cyber Essentials plays such a key and important role. As the UK’s most widely recognised cyber security certification scheme, it provides a practical baseline of security controls that help organisations defend against the most common forms of cyber-attack. The focus of the scheme relates to five technical controls of anti-malware protection, firewalls, secure configuration, user access control and security update management. By encouraging greater adoption of Cyber Essentials throughout supply chains, the pledge has the potential to improve resilience well beyond individual organisations and raise the standard of cyber resilience across the UK.
The Pledge also highlights how cyber resilience is a shared responsibility. Businesses rely on suppliers, technology providers, outsourced services and connected systems. A weakness in one organisation can quickly become a problem for many others. Action is therefore being requested – to strengthen resilience for organisations and the UK as a whole.
By signing the pledge, organisations are making a visible commitment to customers, partners, investors and suppliers that cyber resilience is being treated as a business priority.
As an NCSC Assured Cyber Advisor and IASME Certification Body, RB Consultancy Ltd is actively helping organisations understand cyber risk, strengthen their resilience and achieve certification. There are many benefits of Cyber Essentials that can support an organisation with protection and growth. As an Assessor for the Cyber Essentials scheme, I see first-hand how the implementation of security measures can make such an immediate difference and can act as a springboard for organisations to implement further improvements.
I therefore believe the Cyber Resilience Pledge is a positive step in the right direction. I encourage more organisations to choose to get involved and take meaningful action to strengthen their resilience against the cyber threats we all face.
Cyber Resilience Pledge: https://www.gov.uk/government/publications/cyber-resilience-pledge
Cyber Resilience Pledge Signatories: https://www.gov.uk/government/publications/cyber-resilience-pledge-list-of-signatories
NCSC Early Warning Service Blog: https://rbconsultancyltd.co.uk/free-cyber-security-resource-ncsc-early-warning/
Cyber Essentials Services: https://rbconsultancyltd.co.uk/cyber-essentials/
This blog is written by Remo Belisari (ChCSP), Managing Director of RB Consultancy Ltd. He is a Chartered Cyber Security Professional and NCSC Assured Cyber Advisor. Remo holds certifications in CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance and Defence Cyber Certification (DCC). He has supported organisations across the UK, Europe, Asia and North America throughout his career in IT and cyber security. His work includes helping a Fortune 500 company in the USA and over 125 organisations across the UK. The views in this blog are his own. They do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliates. The content is for general information only.














