Science & Technology

Cyber Resilience Pledge Lets Accountability Hide in a Shared Folder

The voluntary Cyber Resilience Pledge asks organisations to take three actions against cyber attacks, while accountability searches for the shared folder.

Two laughing staff for cyber resilience pledge
A fictional, original illustration of a laptop locking the biscuit tin.

The cyber resilience pledge has arrived with three actions, a voluntary invitation and a clipboard that would like accountability to report for duty before the printer starts behaving strangely.

Cyber resilience pledge in plain terms

On 22 April 2026, the Department for Digital, Culture, Media and Sport and the Department for Science, Innovation and Technology published the voluntary Cyber Resilience Pledge.

It invited organisations to commit to three actions intended to have an immediate positive effect on resilience to cyber attacks. That is a practical aim. It is also a lot of responsibility to place inside one tidy document.

Voluntary is doing some remarkably athletic work here. Organisations may sign up, display their commitment and reassure themselves that the security problem has moved into paperwork. The paperwork can then sit beside the risk register, where both may enjoy a long career without being asked to stop an actual incident.

When accountability shares a folder

The pledge reflects the government’s view that cyber security is a shared responsibility. That sounds sensible until accountability spreads so evenly across an organisation that nobody can find it with both hands and a torch.

A public commitment can still help. It can make good practice easier to identify. It can also make it harder to pretend nobody mentioned the problem. However, a declaration cannot replace working systems, trained staff or consequences for neglect.

That distinction matters. A pledge is not a firewall, although it may be the only security measure that arrives with its own stationery. The cyber resilience pledge asks organisations to take action. It does not make the action happen by itself.

The laptop has watched the pledge being signed and is trying to remain calm. It has changed its password from password to password two. Then it requested board level oversight of the biscuit tin and classified the crumbs as a supply chain risk.

The government offered a pledge against cyber attacks. The laptop offered something stronger. It hid the biscuits in a folder marked urgent, restricted access and definitely not a tempting target. The cyber resilience pledge now has one rival, and it knows exactly where the snacks are.

Source: GOV.UK.

Topics

The Lawn newsletter

Get The Weekly Cut

Three sharp stories. One gem from the archive. Delivered every Friday.

Free. Unsubscribe any time. Read the Privacy Statement

Illustrative edition of The Weekly Cut
Illustrative edition

Read next