The Cyber Resilience Pledge, launched by the Department for Science, Innovation and Technology (DSIT), brings together government and industry to encourage practical action against growing cyber threats.
The Pledge commits signatory organisations to three concrete actions, one of which is to audit Cyber Essentials coverage across their supply chains and to register for a new Cyber Essentials Supplier Check Tool within two months of signing.
What could this mean for you as an SMB?
The pledge has been designed primarily for medium and large organisations (firms including M&S, Nationwide, ITV, Microsoft UK and Cloudflare are some of the first to pledge). However, organisations of any size in any sector can sign the pledge.
Plus, when large organisations signs the pledge, they commit to requiring Cyber Essentials certification from their supply chains. So if your business supplies goods or services to any organisation likely to sign, certification is no longer optional. It will be a firm procurement condition from yourselves.
What’s in the pledge?
The voluntary pledge asks signatories to take 3 concrete actions to improve their cyber security:
-
Making cyber security a board-level responsibility, by implementing the Cyber Governance Code of Practice and ensuring all board members complete the NCSC’s Cyber Governance Training
-
Registering for the NCSC’s free Early Warning service, a tool that alerts organisations to potentially suspicious activity on their networks
-
Taking a risk-based approach to requiring the government-backed Cyber Essentials certification across their supply chain
Here’s a copy of the pledge in full so you can see what your large customers are signing up for and how you fit into their committment:
1. Make cyber a Board responsibility
a. Implement all actions within the Cyber Governance Code of Practice.
b. Ensure all board members undertake the NCSC’s Cyber Governance Training within 3 months and then on an annual basis.
2. Sign up to Early Warning
a. Register for the Early Warning service within one month of signing the pledge.
3. Require Cyber Essentials across supply chains
a. Register to the Cyber Essentials Supplier Check Tool within 2 months of signing the pledge.
b. Ensure that a comprehensive audit of Cyber Essentials coverage has been conducted across our entire supply chain and that it is presented to and discussed by the Board.
c. Take a risk-based approach to requiring Cyber Essentials across our supply chain (which may include requiring it from all suppliers). If Cyber Essentials is not required for certain suppliers, the board will ensure that this decision aligns with our organisations risk appetite and strategy and that adequate assurance is obtained through other means.
In addition to the above 3 actions, we commit to take the following steps:
- Encourage these actions within our own supply chains – we will strive to engage with our suppliers to understand and better manage the cyber security risks that they are exposed to through their supply chain and encourage adoption of the above measures.
- Publish the signed pledge declaration on our website – within 2 months, we will publish the signed pledge declaration on our company website. Additionally, we will publish an annual public update, either in our annual report or on our company website, on the steps taken to deliver against the pledge.
Pledging organisations will be asked to publish a signed pledge letter on their website and to provide an annual update on the steps taken to deliver against the pledge.