M&S backs UK cyber resilience pledge for suppliers
Thu, 9th Jul 2026
Marks & Spencer has signed the UK government's Cyber Resilience Pledge, becoming one of the first companies to back the voluntary scheme.
The pledge asks organisations to make cyber security a board-level responsibility, sign up to the National Cyber Security Centre's Early Warning service, and take a risk-based approach to requiring Cyber Essentials across their supply chains.
The initiative shifts the focus from formal compliance to broader resilience, as ministers seek to encourage businesses to strengthen their cyber defences without introducing a mandatory regime.
Jon Abbott, Chief Executive Officer at ThreatAware, said the voluntary model could prove more effective than a compulsory programme if companies treat it as an operational commitment rather than a paper exercise.
"Voluntary action is the perfect starting point, as a mandatory pledge can quickly become another compliance tick-box exercise that businesses are chasing in a long list of mandates. We've seen with Cyber Essentials that self-accreditation has its limits because organisations claim compliance that can't actually be evidenced. A voluntary pledge creates peer pressure and moves the conversation from 'are we compliant' to 'are we resilient'? Seeing a smaller group of organisations genuinely action the pledge will be more effective than a mandated programme that everyone signs and nobody operationalises," Abbott said.
Supply chain risk
A central part of the pledge is its focus on suppliers, reflecting concern that breaches increasingly spread through third-party networks and software providers rather than through direct attacks on a target organisation alone.
Abbott cited incidents involving SolarWinds, Kaseya and MOVEit as examples of how a single compromise can affect large numbers of downstream businesses in a short period.
"The attacker's front door is increasingly your supplier's back door, as we have seen with SolarWinds, Kaseya and MOVEit. A single compromise can cascade through thousands of downstream organisations within hours. A risk-based approach to Cyber Essentials across the supply chain matters because not every supplier represents the same risk," he said.
He said the risk-based model should lead companies to apply greater scrutiny to higher-risk suppliers rather than the same level of assurance across every vendor.
"Risk-based means asking harder questions to those suppliers. The problem the pledge doesn't address is that Cyber Essentials is self-accredited, so even when you require it, you're trusting the supplier is doing what they say," Abbott said.
Board oversight
The pledge also seeks to place greater responsibility for cyber security with boards, an area where many security teams have long struggled to secure sustained attention from senior decision-makers.
Abbott said the discussion needs to focus less on technical products and more on measurable evidence that controls are in place and working across an organisation's systems.
"It's important that we stop talking about controls and start talking about evidence. Boards don't need to know which EDR you've deployed; they need to know what percentage of your estate it's actually running on, and how you'd prove that under audit or after an incident," he said.
Many organisations still find it difficult to provide that level of proof, particularly when trying to map what devices they own, what software is running, and whether their existing tools are deployed consistently, Abbott added.
That gap between policy and proof is likely to be one of the main tests of the government's new approach. While the pledge outlines a set of actions, it does not guarantee that a company can demonstrate the real-world effectiveness of its controls.
Boards want direct visibility of cyber posture rather than reassurance based on policy statements alone, Abbott said.
"It's less about reassurance; the board wants visibility. If you can provide them with a dashboard they can understand, the conversation can change overnight," he said.
He added that organisations making progress with boards tend to present a clearer picture of their cyber hygiene, including where weaknesses remain and how they plan to address them.
"The pledge assumes you know what you've got and that the controls you've bought are doing their job. In reality, most organisations can't answer either question with confidence," Abbott said.
The broader challenge for businesses is that many serious cyber incidents still stem from weaknesses in routine security practice rather than unusually advanced attacks, making basic oversight and verification a continuing concern.
"The truth is that the breaches we're seeing aren't failures of sophistication, they're failures of basic hygiene at scale. Any pledge that doesn't address 'can you prove it' leaves the most important question on the table," he said.