Cyber security is business survival
The NCSC co-signs Ministerial letter to major British businesses including FTSE 350 companies.

Update April 2026: The Government Cyber Resilience Pledge formally announced
The Pledge invites organisations to make a voluntary public commitment to strengthen their cyber resilience by taking three practical actions:
- Make cyber security a Board responsibility, using the Cyber Governance Code of Practice
- Sign up to the National Cyber Security Centre’s Early Warning service
- Require Cyber Essentials across supply chains
Last week, the NCSC joined Ministers and the NCA in writing to the chief executives and chairs of Britain’s leading businesses – including all FTSE 350 companies.
We called on them as a matter of urgency to take the steps needed to protect their businesses and our wider economy from cyber attacks. Our message is simple: don’t wait for the breach, act now.
This year, we’ve seen some of the UK’s best-known companies face serious disruption to their supply chains and services. Many organisations believe they are unlikely to be hit, but we know that every organisation with digital assets is a potential target to cyber criminals.
The cost of inaction is rising, and the window for preparation is narrowing. Highly significant incidents handled by the NCSC Incident Management team were up 50% in the year to September.
The consequences – legal, financial, and reputational – can be devastating, not to mention the personal impact as the CEO of the Co-op highlighted recently.
Yet, in just three recommended steps, senior leaders can proactively reduce their risk. The concrete actions, our letter details, will immediately create positive impact on companies’ resilience to cyber attacks:
- 1
Make cyber risk a Board-level priority using the Cyber Governance Code of Practice
- 2
Sign up to the NCSC’s Early Warning service
- 3
Require Cyber Essentials in your supply chain
Improving cyber resilience must be a collective endeavour. In our 2025 Annual Review, we have set out why collaboration is at the heart of resilience. We need the joint forces of government and industry to understand the evolving cyber threat landscape and out-compete our opponents.
Leaders must make cyber resilience a business priority for the safeguarding of our prosperity and livelihoods. I strongly encourage CEOs and chairs to act with their Boards to take the next steps today.
Read the Ministerial letter on cyber security in full.
Jon Ellison
NCSC Director of National Resilience
Share and print this article
Written by
