The government’s Cyber Resilience Pledge officially launched this week, with ministers co-signing a letter to every FTSE 350 chair and chief executive urging them to sign up. The response was underwhelming — fewer than 15 of Britain’s 350 largest listed companies had joined at launch, eight months after that letter first went out. The headline story is one of big business dragging its feet. But buried under the disappointing sign-up numbers is a genuinely useful, entirely free three-point checklist that applies just as well to a 12-person company as it does to a FTSE giant.

If you run an SME, the pledge isn’t really aimed at you — but the three things it asks large companies to commit to are exactly what smaller businesses should be doing anyway, and none of them cost anything.

What the pledge actually asks for

Strip away the political framing and the pledge boils down to three concrete commitments. First, making cyber security a board-level (or, for a smaller business, an owner-level) responsibility rather than something quietly delegated to “whoever’s good with computers.” Second, registering for the NCSC’s free Early Warning service, which flags if your organisation’s internet-facing systems show signs of compromise or vulnerability — a free monitoring service most eligible businesses have simply never signed up for. Third, taking a risk-based approach to requiring Cyber Essentials certification from suppliers, rather than assuming a vendor’s security is fine because they’re bigger than you.

None of these three things require a big budget or a security team. They require someone senior actually owning the decision, five minutes to register for a free NCSC service, and a habit of asking suppliers one direct question before signing a contract.

Why the muted response is actually the lesson here

It’s tempting to read “only 15 FTSE 350 firms signed up” as proof the pledge doesn’t matter. The more useful reading is the opposite: even organisations with dedicated security teams and compliance budgets are treating basic cyber hygiene as optional right up until something forces the issue. For an SME without that infrastructure, waiting for a formal government scheme to prompt action isn’t a strategy — the three asks above are worth adopting on your own timeline, pledge or no pledge.

Registering for NCSC Early Warning takes a few minutes on the NCSC website and costs nothing. Naming one person — even if that’s you — as explicitly responsible for cyber security decisions removes the ambiguity that lets basic gaps slide for months. And when you’re choosing a new supplier, especially one who’ll touch your customer data or systems, asking whether they hold Cyber Essentials is a fair, low-friction question that tells you a lot about how seriously they take security.

Where this fits with the wider picture

This pledge sits alongside a steady drumbeat of NCSC warnings this year — about hostile-state activity, supply chain exposure, and router-based attacks — all pointing the same direction: basic hygiene measures, done consistently, close off the majority of realistic attack paths for a smaller business. If your own setup could use a proper look rather than a guess, a service like KeepSafe is built specifically to monitor for incidents and give SMEs the kind of visibility bigger firms are only now being nudged towards adopting formally.

The takeaway

You don’t need to wait for a government pledge to do what it asks. Register for NCSC’s free Early Warning service this week, put one named person in charge of cyber security decisions, and start asking new suppliers about Cyber Essentials before you sign. All three are free, all three take minutes, and all three close real gaps — regardless of whether you’re on the FTSE 350 or not.