The Cyber Resilience Pledge Is a Welcome Step. The Mid-Market Will Need Help to Keep Up.
Compliance

The Cyber Resilience Pledge Is a Welcome Step. The Mid-Market Will Need Help to Keep Up.

21 July 20268 min read

Earlier this month, the UK government launched the Cyber Resilience Pledge with more than sixty founding signatories. The list reads like a directory of British corporate life: Marks & Spencer, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte, Accenture UK, Vodafone. First trailed at CYBERUK in Glasgow in April, alongside £90 million of government funding, the pledge is the visible edge of a broader shift in how the state expects organisations to treat cyber security.

It is a voluntary scheme, and its core commitments are ones no responsible security leader would argue with. Signatories commit to making cyber security a board-level responsibility, guided by the Cyber Governance Code of Practice, and to having their board members complete the NCSC's Cyber Governance Training. Announcing the pledge, Technology Secretary Liz Kendall framed the change plainly: cyber resilience has moved from being an IT matter to a business imperative.

That framing is right, and the pledge is a genuinely good thing - a clear, government-backed statement of what strong cyber governance now looks like, made by the sort of organisations others take their cue from. What it does not do, because no voluntary pledge could, is supply the capability it assumes each signatory already has. For most of the firms that put their name to it, that is no obstacle. For a large group of businesses sitting just outside the room, it is where the real work begins.

The direction of travel is no longer ambiguous

The pledge is one part of a wider set of developments that, taken together, describe a consistent trajectory. The Cyber Security and Resilience Bill cleared report stage in June and is now before the House of Lords, placing the NCSC's Cyber Assessment Framework on a firmer statutory footing and introducing accountability for organisations in scope. Alongside it, the confirmed ban on ransom payments by public sector bodies and critical national infrastructure operators removes a negotiating option and, with it, an assumption that quietly underpinned a lot of incident planning, while the April 2026 update to Cyber Essentials has refreshed the baseline technical controls that a great many contracts and insurers now treat as a minimum.

Read individually, each of these is a discrete policy, but read together they point in one direction: accountability for cyber risk is moving to the board, and it is moving whether or not any given organisation has decided to move with it. The pledge is the softest instrument in that set - it carries no penalty and nobody is compelled to sign - yet it is worth paying attention to precisely because it describes, in the government's own words, what good governance is now expected to look like. It is a statement of the standard the rest of the framework is built to enforce.

The pledge assumes a capability that many organisations do not have

Look closely at what the commitments actually require, and an assumption becomes visible.

"Making cyber security a board-level responsibility" presupposes that someone in the organisation can translate cyber risk into the language a board makes decisions in - pounds, probabilities, trade-offs, and consequences. Board members completing governance training presupposes that they will then have someone to bring the resulting questions to. The Cyber Governance Code of Practice describes what boards should oversee; it does not, and cannot, supply the person who does the overseeing on their behalf.

For the pledge's signatories, none of this is an issue. Marks & Spencer, Nationwide, Vodafone and their peers already have a Chief Information Security Officer and a security function reporting into them, so the pledge asks them to formalise and strengthen something they already possess. For a firm with an established CISO, board-level responsibility is largely a matter of tightening reporting lines and raising the quality of the conversation, because the scaffolding is already there.

That is the quiet fact at the centre of an otherwise excellent document: it was written for organisations that already have the thing it asks for. The commitments are eminently achievable for a household name with a security team, and considerably harder for a firm that has neither - not because those firms are less committed, but because they have no one positioned to carry the commitment.

The mid-market faces the same expectations without the same resources

Consider the organisation in the middle - a firm of, say, fifty to five hundred staff, large enough to hold sensitive data, run critical systems, and sit inside the supply chains of much bigger companies, but not large enough, in most cases, to employ a full-time CISO. This is the mid-market, and it is where the pledge's assumption quietly breaks down.

The expectations do not scale down with headcount. A three-hundred-person business handling customer data and payment flows is subject to the same regulatory direction, the same insurer requirements, and the same customer scrutiny as a much larger one, yet what it typically lacks is anyone whose job it is to own the response. "Board-level responsibility" becomes a meaningful phrase only when someone can convert it into risk decisions, budgets, and reporting; absent that person, it remains an aspiration the board cannot act on - a line in a governance document that describes an accountability no one in the building is equipped to discharge. The board is told it is responsible without being told how to be.

The Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses reported a breach or attack in the previous twelve months. The most severe incidents remain concentrated among larger organisations, but the trend that matters here is a different one: mid-market firms are increasingly targeted, often precisely because attackers understand that they carry meaningful data and access without carrying the defensive maturity of a FTSE 100 business. The gap between expectation and capability is not a theoretical concern but the place where a growing share of incidents now happen.

The pledge will reach firms that never signed it

There is a second mechanism by which these expectations arrive at the mid-market's door, and it does not depend on the pledge being voluntary.

This is not merely an implication of the pledge; it is written into it. Alongside the board-level commitment, signatories undertake to take a risk-based approach to requiring Cyber Essentials certification across their supply chains, which turns the whole exercise outward. Every signatory is a large organisation with suppliers, and a firm that has committed to managing its cyber risk will - reasonably, and now as a matter of stated policy - ask those suppliers to evidence their own governance in turn.

That is how a voluntary pledge signed by sixty large companies becomes a set of obligations for thousands of smaller ones. A mid-market firm supplying M&S, or a professional services business working with Deloitte, will be asked to demonstrate that it has cyber governance in place - a risk register, an incident response plan, board oversight, Cyber Essentials certification - regardless of whether it ever heard of the pledge, let alone signed it. The expectations cascade downward through the supply chain, and they arrive as commercial conditions rather than legal ones. You do not have to be in scope of any regulation to lose a contract because you could not answer the questionnaire.

For the mid-market, this is often the more immediate pressure: where the Bill sets a legal floor for organisations in scope, the supply chain sets a commercial floor for everyone else, and it tends to move faster than legislation.

What board-level responsibility actually requires

It is worth being concrete about what these expectations amount to in practice, because the phrase "board-level responsibility" can sound abstract until it is broken into its parts. Meeting it means, at minimum:

  • Owning a risk register that identifies the organisation's material cyber risks and is reviewed and maintained rather than written once and filed.
  • Clear incident response accountability - a named owner, a tested plan, and defined escalation paths, so that the organisation knows who decides what when an incident is live rather than discovering the gaps at 2am.
  • Regular board reporting that translates technical posture into risk terms a board can govern, so that oversight is informed rather than nominal.
  • Supplier assurance - knowing which of your own suppliers carry risk on your behalf, and being able to evidence your posture to the customers who ask.
  • Alignment with the baselines - Cyber Essentials for technical controls, and the Cyber Governance Code of Practice for the governance wrapper around them.
  • None of these require a large team. All of them require someone with the seniority and expertise to own them and the standing to bring them to a board. That is the specific capability the mid-market tends to lack, and it is not a gap that governance training for board members fills. Training a board to ask good questions is valuable only if there is someone competent to answer them.

    The proportionate answer is not a £150,000 hire

    The obvious response - hire a CISO - is, for most mid-market firms, the wrong shape of solution. A full-time Chief Information Security Officer commands £150,000 or more before considering the cost of the team beneath them, and a fifty-to-five-hundred-person business rarely has enough sustained security work to justify a full-time executive. The role would be underused, the cost hard to defend, and the recruitment itself difficult in a market where experienced security leaders are scarce and expensive.

    A fractional or virtual CISO is the proportionate alternative. It provides the same function - an experienced security leader who owns the risk register, holds incident response accountability, reports to the board in terms it can act on, and manages supplier assurance - at a fraction of a full-time hire, scaled to the amount of leadership the organisation actually needs. It gives the board the person the pledge assumes exists: someone who can take "board-level responsibility" and turn it into decisions, budgets, and reporting.

    This is not a workaround. For an organisation of this size, it is frequently the more sensible governance choice on its own terms, quite apart from cost. It matches the level of the resource to the level of the risk.

    Where to start

    The pledge is a useful document even if you never sign it, because it states clearly what the government now considers good governance to look like. That makes it a serviceable measuring stick.

    The practical first step is to assess your current position against the pledge's commitments honestly. Can you point to a maintained risk register? Is there a named owner for incident response, and has the plan been tested? Does your board receive cyber risk reporting it can actually act on, or a technical update it nods through? Could you evidence your governance to a customer who asked tomorrow? Are you aligned with the current Cyber Essentials baseline and the Cyber Governance Code of Practice?

    Where the answer is no, the question is not whether the expectation will reach you. The direction of travel has settled that. The question is whether you would rather build the capability now, deliberately, at a pace of your choosing - or assemble it under pressure, in the middle of a supplier audit or an incident, when the cost of not having it is no longer hypothetical.

    The household names have already answered that question. The pledge simply asks everyone else the same one.

    Share this article

    Richard Midwinter
    CTO
    Richard Midwinter

    Seeking Security Insights for Your Business?

    Our fractional CISOs can help you implement the strategies discussed in this article. Book a call to discuss your security needs.

    Book a Call