HomeInsightsCyber Security: Government launches Cyber Resilience Pledge

The Government has launched its ‘Cyber Resilience Pledge’, encouraging businesses encouraging businesses to make a public commitment to tackle cyber security threats.

The National Cyber Security Centre (NCSC) estimates that a cyber crime is committed every 6 seconds in the UK. The number of these deemed to be ‘nationally significant’ is rising, and it is estimated that a significant cyber-attack costs a UK business an average of £200,000.

Against that backdrop, and with cyber threats expected to grow in scale, frequency, and sophistication as AI develops, cyber security has become a major focus for the Government in recent months. Earlier in the year, for example, we discussed (here) an open letter to business leaders warning them of the growing risks, and encouraging them to take steps to protect themselves.

The Cyber Resilience Pledge represents a further way to encourage medium and large organisations to take cyber security more seriously, asking signatories to make three specific commitments:

  1. Make cyber security a Board responsibility. This is a constant refrain from the Government: cyber threats should not be treated as purely an ‘IT’ problem and delegated accordingly: they must be addressed at board level, and the Pledge commits organisations to ensure all board members undertake the NCSC’s Cyber Governance Training on an annual basis, and that they implement all the recommendations in the Cyber Governance Code of Practice.
  2. Sign up to Early Warning. Within one month of signing the Pledge, organisations must sign up the NCSC’s Early Warning service which sends alerts of potential cyber attacks on their network.
  3. Require Cyber Essentials across supply chains. This is a certification scheme developed by the NCSC designed to prevent the most common internet-based cyber security threats. Organisations are expected to ensure that a comprehensive audit has been conducted across their entre supply chain, taking a risk-based approach to whether Cyber Essentials certification should be required of suppliers.

Commenting on the launch of the Pledge, Technology Secretary, Liz Kendall, said:

Cyber attacks can disrupt services, put customers’ data at risk and have a real impact on the bottom line. As AI makes these threats more sophisticated and easier to launch, no organisation can afford to stand still. That’s why we’re working with businesses to help them strengthen their defences. The steps in this Pledge are practical, achievable and proven to make a difference. Today’s signatories are leading the way, and I encourage organisations across the UK to follow their example”.

To read more, click here.