Cyber security can feel like a problem designed for companies with a boardroom, a security team and a large IT budget. For a small business, it is more often the owner-manager, an outsourced IT provider and a handful of busy people trying to keep customers served. That is exactly why the UK government’s Cyber Resilience Pledge matters.
Formally launched at 10 Downing Street on 7 July 2026, the voluntary Pledge asks organisations to make cyber a board responsibility, use the National Cyber Security Centre’s Early Warning service and strengthen supply-chain security through Cyber Essentials. Although it was designed primarily with medium and large organisations in mind, the government says organisations of any size can sign up. (gov.uk)
For an SME, the real opportunity is not to create more paperwork. It is to translate those three commitments into a short, repeatable operating routine: one person accountable, a practical way to spot trouble early, and sensible checks on the suppliers who can disrupt your business or expose your data.
This is not a promise that an attack will never happen. No certification, tool or policy can honestly offer that. Cyber resilience means being harder to compromise, quicker to notice when something is wrong, and more capable of continuing or recovering when disruption occurs. Here is a lean owner-manager checklist to put that principle into action now.
Why the Pledge is relevant to small businesses
A cyber incident is not only a technical failure. It can stop invoices being issued, orders being processed, staff being paid or customers receiving support. It may also expose personal information, undermine a key client relationship or leave a business unable to access its own records at a critical moment.
That is why the government’s Cyber Resilience Pledge focuses on leadership, warning and supply chains rather than on a shopping list of expensive products. These are management issues. The same owner who reviews cashflow, insurance, health and safety and business continuity should also be asking whether the company can withstand a cyber disruption.
The NCSC’s guidance for small organisations makes the point simply: cyber security is everybody’s business, not a task that can be left to one person. It also recommends practical measures around backups, devices, accounts and scams that do not require the owner to become a technical expert. ([ncsc.gov.uk](https://www.ncsc.gov.uk/collection/small-business-guide/small-business-guide-actions?utm_source=openai))
For very small firms, “board-level” oversight does not mean holding a formal quarterly board meeting. It means the proprietor, partners or directors explicitly own the risk, make decisions and review whether the agreed protections are actually working. If you have an IT support company, it can implement technical controls, but it cannot take over your accountability for customer data, business priorities or recovery decisions.
Action one: Put cyber ownership at the top of the business
The first Pledge commitment is to make cyber a board responsibility. Signatories commit to implement the Cyber Governance Code of Practice and ensure board members complete NCSC cyber governance training within three months, then annually. ([gov.uk](https://www.gov.uk/government/publications/cyber-resilience-pledge?utm_source=openai))
An SME does not need to copy a PLC’s governance structure. It does need a named decision-maker and a reliable cadence. Start by appointing one director, owner or senior manager as the cyber lead. Their job is not necessarily to configure systems. Their job is to ensure cyber risk appears on the business agenda, actions have owners and material problems are escalated.
Build a one-page cyber risk register
Keep it useful. List the five to 10 digital services without which you could not operate for a day: email, accounting, payroll, online banking, ecommerce, customer relationship management, cloud storage, phones, production systems and remote access. For each, record the service owner, supplier, administrator account, where its data is backed up and the likely impact if it is unavailable.
Then identify the most realistic failure scenarios. Examples include a fraudulent email causing a payment change, an employee’s Microsoft 365 account being taken over, ransomware encrypting a shared drive, a website host going offline, or a SaaS supplier locking you out after a billing or identity issue. Do not try to model every imaginable attack. Focus on events that would interrupt revenue, delivery, safety, contractual commitments or data protection obligations.
For every risk, agree one or two actions and a deadline. “Turn on multi-factor authentication for all email accounts by 30 September” is far better than “improve email security”. “Test restoration of the finance backup this month” is better than “check backups”. Keep the register in the same place as other management records and review it at least quarterly, or when you adopt a major new system, open a new location, acquire a business or change IT suppliers.
Ask better questions of your IT provider
Outsourcing IT support is sensible for many SMEs, but “our provider handles cyber” is not a management control. Ask for plain-English answers to these questions:
- Accounts: Is multi-factor authentication enabled for email, finance, remote access and administrator accounts? Who has privileged access, and how is it reviewed?
- Updates: Which devices, applications and cloud systems are patched by the provider, and which are our responsibility?
- Backups: What is backed up, how frequently, where is it stored, how is it protected from ransomware, and when was restoration last tested?
- Monitoring: What alerts are monitored outside office hours, and what happens if an alert indicates a compromised account or device?
- Incident response: Who do we call first, what is included in the contract, and what response times apply?
- Leaving or changing provider: How do we retain access to domains, cloud tenants, documentation, backup data and administrator credentials?
The government’s governance code recommends clear ownership, regular reporting and metrics aligned to cyber strategy and risk appetite. For a small business, a monthly one-page dashboard can be enough: percentage of users protected by multi-factor authentication, overdue critical updates, backup-test status, unresolved high-risk supplier issues, phishing reports and any open incidents. ([gov.uk](https://www.gov.uk/government/publications/cyber-governance-code-of-practice/cyber-governance-code-of-practice?utm_source=openai))
Make recovery planning a leadership task
Prevention matters, but resilience is proven during recovery. Create a compact incident and recovery plan before you need one. It should include the mobile numbers for the owner, IT provider, key cloud suppliers, insurer, bank relationship manager and legal or data protection adviser. Keep an offline copy: a plan stored only in the affected email or shared drive is not much use during an account takeover or ransomware event.
Set out immediate authority levels. Who can approve shutting down a compromised device? Who can instruct the bank to pause payments? Who speaks to customers? Who decides whether a website is taken offline? Speed matters, and uncertainty wastes the first critical hours.
Also specify your minimum viable business operation. A trades business may need customer contact details, job schedules and a way to take payment. A manufacturer may need production recipes, stock information and access to logistics partners. A professional services firm may need client files, secure communications and a way to meet filing deadlines. Identify the manual workarounds you could use for 24, 48 and 72 hours.
The NCSC’s Small Business Guide to Response and Recovery covers preparation, identification, resolution, reporting and lessons learned. Its wider resilience guidance also stresses testing recovery plans rather than merely writing them. ([ncsc.gov.uk](https://www.ncsc.gov.uk/collection/small-business-guidance–response-and-recovery?utm_source=openai))
Schedule a 45-minute tabletop exercise. Present a scenario: “At 8.30am on Monday, every staff member receives a message from the managing director’s account asking for urgent payroll changes, while the real director cannot log in.” Walk through who does what, in what order, and which information is missing. Update the plan immediately afterwards. This inexpensive exercise often reveals bigger gaps than another policy document.
Action two: Use NCSC tools to detect problems earlier
The Pledge’s second action is to register for NCSC Early Warning within one month of signing. It is a free service for UK organisations that sends notifications of potential malicious activity, vulnerabilities and exposed services associated with the organisation’s registered internet assets. ([gov.uk](https://www.gov.uk/government/publications/cyber-resilience-pledge?utm_source=openai))
Early Warning is valuable because small firms rarely have a security operations centre watching their systems all day. It can provide a prompt to investigate an exposed service, malware indication or suspicious network activity before the issue grows. But it is an alerting service, not a guarantee of protection and not a substitute for patching, secure configuration, backups or managed monitoring. The NCSC explicitly says organisations remain responsible for their own networks and data. ([ncsc.gov.uk](https://www.ncsc.gov.uk/information/proactive-notifications-service?utm_source=openai))
Register it properly, then assign an alert owner
Registration requires a MyNCSC account, your organisation name, public IP addresses and domain names, plus contact details for the people who should receive alerts. The NCSC says the sign-up process can take around five minutes, but the operational work begins after the confirmation email arrives. ([ncsc.gov.uk](https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning?utm_source=openai))
Use a shared, role-based inbox where possible, such as security@ or italerts@, with at least two people able to access it. If your IT provider receives the alerts, make sure a business contact does too. Agree a service-level expectation: an alert must be acknowledged, assessed and logged within a defined period, with urgent alerts escalated immediately.
Maintain a simple asset list alongside this. Include internet domains, public websites, cloud accounts, VPNs, remote-management tools and the supplier responsible for each. You cannot investigate an alert quickly if nobody knows whether the identified domain is an old marketing microsite, a current customer portal or an unmanaged legacy service.
Use the free basics before buying more technology
Tools work best when combined with disciplined basics. Enable multi-factor authentication, particularly for email, finance, administrator and remote-access accounts. Use a password manager and remove accounts promptly when staff or contractors leave. Ensure devices receive security updates and that endpoint protection is installed and managed. Train people to pause before acting on unexpected payment, password-reset or document-sharing requests.
Backups deserve special attention. A backup that cannot be restored is only a hope. Keep copies separated from everyday user access, protect backup credentials, and test a restoration of a meaningful file set or critical system on a planned schedule. Record how long restoration took and whether the restored data was complete. That gives you a realistic recovery target rather than an assumption.
If an incident may involve personal data, preserve a clear timeline and record decisions. The ICO says organisations must report notifiable personal data breaches without undue delay and, where feasible, within 72 hours of becoming aware of them. Not every incident is reportable, but every suspected breach needs prompt assessment and a record. ([cy.ico.org.uk](https://cy.ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/?utm_source=openai))
Action three: Treat supplier security as part of buying well
The third Pledge action is to require Cyber Essentials across supply chains. Signatories commit to register for the Cyber Essentials Supplier Check Tool, audit coverage and apply a risk-based approach to requiring certification. ([gov.uk](https://www.gov.uk/government/publications/cyber-resilience-pledge?utm_source=openai))
This is especially relevant to SMEs because a supplier may hold your customer data, host your website, process payments, manage your devices, run your payroll or provide the software that underpins daily work. A weakness at one of those suppliers can become your business interruption, even when your own staff have done everything right.
Cyber Essentials is the UK government’s minimum baseline standard for cyber security. The NCSC supply-chain playbook advises buyers to use the level of operational, financial, reputational or data risk associated with a supplier when deciding whether certification should be required or whether other evidence of equivalent controls is appropriate. ([ncsc.gov.uk](https://www.ncsc.gov.uk/information/cyber-essentials-supply-chain-playbook?utm_source=openai))
Start with a supplier map, not a blanket demand
List suppliers that can access systems, data, funds or essential operations. Then categorise them. A freelance designer with no access beyond a project folder is different from a managed service provider with administrator privileges. A low-risk office stationery supplier is different from a cloud accounting platform or outsourced payroll bureau.
For high-risk suppliers, ask whether they hold a current Cyber Essentials certificate, what data they process, whether they use subcontractors, how they notify customers of incidents and what their recovery arrangements are. For medium-risk suppliers, ask proportionate questions and request evidence of basic controls. For low-risk suppliers, record why a lighter approach is reasonable.
Useful supplier-risk questions include:
- What systems, accounts, customer data or payment information can you access on our behalf?
- Do you hold Cyber Essentials certification, and when does it expire?
- Do you enforce multi-factor authentication for staff with access to our services or data?
- How quickly do you apply critical security updates and notify us of serious vulnerabilities?
- What is your incident-response process, and how soon will you tell us about an event affecting our data or service?
- Where is our data stored, backed up and deleted at contract end?
- Which subcontractors can access our information, and what security obligations apply to them?
- Can we export our data and retain control of key accounts if the contract ends or your service fails?
Put the most important answers into contracts, purchase orders or data-processing terms. A supplier questionnaire filed away at onboarding will not help if there is no obligation to notify you, cooperate during an incident or return your data. Review critical suppliers annually and whenever their access or service changes.
There is a commercial upside too. As larger customers introduce more structured supplier assurance, SMEs with Cyber Essentials and a credible recovery plan can answer procurement questions faster and distinguish themselves from competitors. The Pledge itself is intended to help organisations demonstrate commitment to resilience. ([gov.uk](https://www.gov.uk/government/publications/cyber-resilience-pledge?utm_source=openai))
A practical 30-day owner-manager checklist
- Days 1–3: Name the cyber lead. List critical systems, data, suppliers and key administrator accounts.
- Days 4–7: Turn on multi-factor authentication for email, finance, cloud storage and remote access. Remove stale accounts.
- Week 2: Register for NCSC Early Warning. Set up a shared alert inbox and agree how alerts will be handled.
- Week 3: Verify that backups exist for critical data and perform at least one restoration test. Write down recovery contacts and decision-makers.
- Week 4: Rank critical suppliers by risk. Send the supplier questions, check Cyber Essentials status where appropriate and capture required contractual changes.
- By day 30: Run a short cyber incident tabletop exercise, update the plan and put a quarterly cyber review in the diary.
Conclusion: Make resilience a business habit
The Cyber Resilience Pledge is a useful signal that cyber risk belongs in mainstream business management. For SMEs, the most valuable response is not a complex compliance project. It is consistent leadership, early visibility of threats, tested recovery and proportionate supplier control.
Choose one accountable leader. Register for the NCSC tools available to you. Verify your ability to recover. Ask suppliers the questions that match the risk they represent. Then review progress routinely, just as you would cash, people, quality or health and safety.
Start this week with the 30-day checklist, use the NCSC’s small-business resources, and consider working towards Cyber Essentials. The goal is not perfection. It is to make sure a cyber incident is a manageable interruption rather than an existential event for your business.





















