Decoding the world of cybersecurity

· ·

UK cyber pledge reaches 149 signatories

PwC, DXC Technology and Toyota are among new signatories taking the UK’s voluntary Cyber Resilience Pledge to 149 organisations.

UK cyber pledge reaches 149 signatories
Summary
  • The government's Cyber Resilience Pledge register now lists 149 organisations and was updated on 14 September.
  • PwC, DXC Technology, SCC UK, Toyota (GB), and several other organisations were added on 11 September.
  • Signatories commit to board oversight, NCSC Early Warning, and a risk-based Cyber Essentials approach across supply chains.

The UK government’s Cyber Resilience Pledge has grown to 149 organisations, adding large technology, professional-services, and industrial businesses to a voluntary scheme intended to move basic cyber-resilience commitments into board governance and supply-chain management.

The government’s signatory register, updated on 14 September, records PwC, DXC Technology, SCC UK, Toyota (GB), and several other organisations as joining on 11 September.

The wider list spans financial services, retail, technology, utilities, infrastructure, professional services, and other sectors. It has expanded from 137 organisations recorded in the previous published version to 149.

Organisations signing the pledge make three principal commitments. Cybersecurity is to become a board responsibility through implementation of the Cyber Governance Code of Practice and annual NCSC governance training. Signatories must also register for the NCSC’s Early Warning service and take a risk-based approach to Cyber Essentials across their supply chains.

The supply-chain commitment requires more than encouraging certification. Organisations are asked to register with the Cyber Essentials Supplier Check Tool, audit Cyber Essentials coverage throughout their supply chains, present the findings to the board, and decide whether particular suppliers should be required to hold certification or provide other assurance.

That makes the scheme an attempt to influence commercial behaviour through governance and procurement rather than through statutory enforcement. Large technology providers, professional-services businesses, retailers, manufacturers, and infrastructure operators can expose customers and suppliers through privileged access, shared systems, outsourced operations, data exchanges, and software dependencies.

Requiring boards to examine those relationships pushes cyber risk into procurement and supplier assurance rather than leaving it solely within security functions.

The commitment remains voluntary. Government guidance states that taking the pledge does not guarantee protection against cyber attacks, and its frequently asked questions confirm that there is no formal assurance mechanism comparable with a regulatory regime.

Some actions can nevertheless be checked by government, including registration for Early Warning and the Cyber Essentials Supplier Check Tool. Organisations are also expected to publish their signed declaration and provide an annual public update on progress.

Cyber Insider previously examined the pledge against the UK’s broader cyber-policy programme in Cyber action delay leaves pledge exposed. The initiative operates alongside statutory efforts to strengthen the resilience of essential and digital services.

The distinction between the two approaches is important. Regulation can create enforceable minimum requirements for organisations inside formal scope, while a voluntary programme can reach companies outside those boundaries and use procurement relationships to influence a larger supplier base.

As the register grows, the useful measure of the pledge will move beyond the number of organisations attached to it. The scheme asks companies to make board-level and public commitments that can subsequently be tested against their annual updates, supplier policies, and implementation of the three promised actions.

×