
On 7 July 2026 the government’s Cyber Resilience Pledge was launched at an event at 10 Downing Street attended by a number of business representatives from early signatories to the pledge; including Capita Public Service CEO, Richard Holroyd.
Amanda Finch, CIISec CEO spoke to Luke Beeson, CIISec Chair and CISO of Capita. They discuss what the pledge means for the supply chain, the profile of cyber security in organisations, and where the initiative sits in the regulatory landscape.
AF: We’ve seen a lot of movement in the regulatory landscape recently, where does the Cyber Resilience Pledge fit in?
LB: I think it’s all part of the government’s drive to make people more aware and more responsible for cyber security, which is clearly becoming a greater threat to UK PLC. Over 5 million cyber crimes were committed against UK businesses last year. The pledge is part of a broad UK cyber and AI regulatory shift, including the Cyber Security and Resilience Bill (CSR). The CSR Bill will be the overarching legislation, but whilst that works its way through the parliamentary process the government can roll out a few initiatives like the pledge, which can happen in real time.
AF: Cyber crime has a material impact on our economy, to my mind everything and anything that can be done to raise the bar, and to bring the topic of cyber security onto the board agenda has to be a good thing doesn’t it?
LB: Yes. I’ve grown up in big corporations so cyber security has always been an agenda item at board meetings. I think non-executive directors have become increasingly aware of cyber in the last few years. It’s in the headlines, it’s in the news.
AF: Will we see a change in the dynamic between the Board and their security team at those organisations who have signed the pledge?
LB: The pledge mandates specific cyber governance training from the National Cyber Security Centre, I think that’s a really positive step forward. Boards need to be able to ask the right questions of CISOs, they can only do that if they have good awareness and education. Their job is to hold me and my peers in the industry to account, to make sure that we are doing the right things, we are taking the right steps, we are putting in place the right controls. And as they say, two brains are better than one.
AF: One of the commitments of the pledge is to encourage suppliers to achieve the Cyber Essentials certification or an equivalent baseline. How do you plan to implement this within Capita?
LB: That’s definitely the hardest of the commitments to implement. I don’t interpret this part of the pledge to mean that everybody in your supply chain must have Cyber Essentials. For a global business with international suppliers, enforcing a UK accreditation is not possible. My interpretation is that you demonstrate an intent to strengthen the resilience of your supply chain. Understand who’s in your chain, understand the criticality of those suppliers to the services that you deliver, and then have sustainable mechanisms in place to assure their security and resilience.
AF: With so many large organisations already signed up to the pledge, there is likely to be a great deal of overlap between suppliers in these chains. Hopefully we’ll see a general raising of the bar. After all, that appears to be the government’s intention: encouraging better third-party risk management as opposed to dishing out penalties for non-conformity. I think the point that you raise about criticality of suppliers is important, that’s probably the best place to start, isn’t it?
LB: Certainly among the big corporations we’re all using a small number of big American hyperscaler partners. My experience is that because they are delivering such critical services, they are consistently doing their upmost from a security perspective and market forces will continue to encourage continuous improvement.
AF: At the other end of the supply chain spectrum it won’t be long before cyber security questions are being asked of the sandwich maker or the office florist. Cyber Essentials is probably beyond their reach, but perhaps we can get to a point where the service providers can help; for example, you buy a router out-of-the-box with a Cyber Essentials sticker on the side of it.
LB: Yes, absolutely, it’s about proportion and applicability. Householders don’t have a fire engine on the driveway, for example, but an airport does. Any business can register for the NCSC’s Early Warning service, it’s a free tool that alerts organisations to potentially suspicious activity detected on their networks, effectively giving smaller security teams access to threat intelligence that would otherwise require significant investment to replicate in-house.
AF: What are your final thoughts on the pledge and where cyber sits currently in the government’s long list of priorities?
LB: I think we both agree this is a really well intended government initiative. With my CIISec Chairman’s hat on I would encourage all our Corporate Members to sign up to the pledge for the reasons we’ve discussed. Ultimately, cyber resilience is a shared responsibility. If boards are asking better questions, organisations are strengthening their own controls, and suppliers are being encouraged to improve, the whole ecosystem becomes more secure. That’s exactly what the pledge is designed to achieve.
Further reading:
Gov.uk: Cyber Resilience Pledge
CIISec article: From pledge to practice: Embedding Cyber Essentials across the supply chain