
C3IA signs the UK Government’s Cyber Resilience Pledge
C3IA is proud to have signed the UK Government’s new Cyber Resilience Pledge, joining more than 60 organisations across the UK in making a clear commitment to strengthening cyber defences and improving cyber resilience across the wider economy.
The Pledge was formally launched at 10 Downing Street on 7 July 2026 at an event hosted by Secretary of State for Science, Innovation and Technology, The Rt Hon Liz Kendall MP. C3IA was represented by Rupert Irons, Commercial Director, who attended alongside representatives from other signatory businesses.
For C3IA, signing the Pledge is a natural extension of the work we do every day. Cyber resilience is not simply about having the right technology in place. It is about leadership, awareness, preparedness and accountability. It is also about recognising that the security of one organisation can have a direct impact on many others, including customers, suppliers, partners and the wider economy.
What is the Cyber Resilience Pledge?
The Cyber Resilience Pledge is a voluntary public commitment that brings together government and industry to help improve cyber security across the UK. It is designed to encourage organisations to take practical, proven steps that strengthen their own resilience, while also raising standards across supply chains.
The need for action is clear. According to the government’s launch announcement, more than five million cyber crimes were committed against UK firms last year, while the annual cost of cyber attacks to UK organisations is estimated at £14.7 billion. The National Cyber Security Centre also handled 204 nationally significant incidents in the year to September, up from 89 the previous year.
At the same time, the threat is evolving. Artificial intelligence is creating new opportunities for defenders, but it is also changing the way attackers operate, helping them move faster and identify weaknesses more easily. Against that backdrop, cyber resilience is no longer something businesses can treat as a future priority. It is a business-critical issue now.
The Pledge focuses on three practical actions.
Making a cyber board-level responsibility
The first commitment is to make cyber security a board responsibility by implementing the Cyber Governance Code of Practice and ensuring board members complete the NCSC’s Cyber Governance Training.
This is an important shift. Cyber risk is business risk, with the potential to affect operations, finances, reputation, legal obligations and customer trust. By placing cyber firmly on the board agenda, organisations can make resilience part of strategic decision-making rather than treating it as a purely technical issue.
Signing up to the NCSC Early Warning service
The second commitment is to register for the National Cyber Security Centre’s free Early Warning service.
This service helps organisations identify potentially suspicious activity affecting their networks. Early visibility gives businesses a better chance to investigate and respond before an issue becomes more serious. No organisation can prevent every threat, but faster detection and response can make a significant difference to the impact of an attack.
Taking a risk-based approach to Cyber Essentials across the supply chain
The third commitment is to take a risk-based approach to requiring the government-backed Cyber Essentials certification across supply chains.
Cyber Essentials sets out fundamental controls to protect against common cyber threats. It provides a clear baseline for good cyber hygiene and is a practical way for organisations to reduce risk. Applied across the supply chain, it also helps raise the minimum standard of security among suppliers, partners and service providers.
Why this commitment matters to C3IA
As an NCSC assured cyber security consultancy, C3IA has a responsibility that goes beyond our own systems and processes. Our clients trust us to help them understand risk, build resilience and make informed decisions about their security. Signing the Cyber Resilience Pledge reinforces our commitment to applying the same principles within our own organisation that we advocate for others.
It also reflects a wider belief: cyber resilience is strongest when it is shared. The UK’s security depends on organisations of all sizes taking sensible, proportionate action to protect themselves and those they work with. That includes leadership teams treating cyber as a strategic priority, employees being alert to threats, and suppliers being held to appropriate standards.
Rupert Irons, Commercial Director at C3IA, said:
“Signing the Cyber Resilience Pledge is an important statement of intent for C3IA. As a cyber consultancy, we have a responsibility to lead by example, not only in how we protect our own organisation, but in how we support our clients to strengthen their resilience too.
“Cyber security is no longer something that can be viewed in isolation. It is a board-level issue, a supply chain issue and, ultimately, a business continuity issue. We are pleased to stand alongside other UK organisations in supporting practical action that will help raise standards and protect the wider economy.”
Turning commitment into action
The Cyber Resilience Pledge is a positive step because it is focused on practical action. It recognises that improving cyber security is not about one organisation, one sector or one technical solution. It requires leadership, collaboration and a shared commitment to raising standards.
For C3IA, this means continuing to help organisations move from awareness to action. Good cyber resilience is built through clear accountability, practical controls, informed leadership and a willingness to keep improving as threats evolve.
By signing the Pledge, C3IA is reaffirming its commitment to those principles, both for our own organisation and for the clients we support.
Cyber threats will continue to change, but the fundamentals remain clear: understand the risk, take ownership, strengthen defences and work together to build a more resilient UK economy.