top of page

The Cyber Resilience Pledge and What It Means for Your Supply Chain

Writer: Fleko
Fleko
Sep 2
2 min read

Cybersecurity is quickly becoming part of the procurement conversation, especially if you supply larger organisations. A contract renewal that used to focus on price, service levels and delivery might now come with questions about how well protected your business actually is, and whether you can prove it. 


That's largely down to the new Cyber Resilience Pledge. Launched at 10 Downing Street in July 2026 by the Department for Science, Innovation and Technology and the National Cyber Security Centre, it already has more than 60 founding signatories, including Marks & Spencer, Nationwide, ITV and Microsoft UK. 


Signatories have committed to putting cyber risk at board level, using the NCSC's Early Warning service, and taking a risk-based approach to asking suppliers to meet Cyber Essentials requirements. That last part is really what matters here if you're a smaller or mid-market business. You don't need to have signed the pledge yourself to feel its effects. Once a large customer starts asking its own suppliers to meet higher security standards, that requirement has a habit of landing on your desk too. 


Why the Cyber Resilience Pledge isn't just a large enterprise problem

A company's security doesn't really stop at its own network anymore. You can have your own systems locked down tight and still end up exposed through a supplier who hasn't done the same.  


There's good reason for the focus. Cyber crime is estimated to cost UK businesses £14.7 billion a year, and the NCSC handled 204 nationally significant incidents in the year to September, up from 89 the year before. M&S's recent cyber attack reportedly cost the business more than £300 million on its own.  


For suppliers, that means Cyber Essentials is starting to feel less like a nice-to-have and more like something that'll come up in the commercial conversation whether you're ready for it or not. 


Join Fleko and IASME to break it down

Fleko and IASME are running a joint webinar on exactly this. The Cyber Resilience Pledge: What Enterprise Expectations Mean for Your Supply Chain event takes place on Wednesday 16 September at 2pm, a quick 30-minute look at what the pledge actually means in practice for small and mid-market businesses. 


Anjali Fowler, Business Engagement Manager at IASME, and Michael Sosinski, CEO of Fleko, will cover what enterprise customers are likely to expect from suppliers, where Cyber Essentials fits into that, and how to get certified without it turning into a whole disruption. 


If you think you might be facing new security requirements from a customer this autumn, it's worth getting ahead of it now rather than finding out at renewal time that there's a box you're suddenly expected to tick. 


Register for the webinar here to hear directly from IASME and Fleko on what the Cyber Resilience Pledge could mean for your supply chain, and how to get ahead of it.  

 
 
 

Comments


bottom of page