Cyber-attacks are costing UK businesses an estimated £14.7bn annually. From ransomware to supply chain compromises, the threat landscape is more complex and hostile than it has ever been. The average significant incident now costs nearly £195,000 per business; and the consequences extend well beyond the financial, affecting operations, reputation, and the trust of the people and organisations who depend on you.
For a company like Apexiar, building platforms used in regulated, safety-critical environments, that context matters enormously. Our customers operate in fire and rescue, rail, energy, and public sector environments where data integrity and operational continuity are not optional. Cyber resilience is not a feature we bolt on; it is fundamental to how we build and operate.
Signing the UK Government's Cyber Resilience Pledge is a natural extension of that commitment.
What Is the Cyber Resilience Pledge?
The UK Government's Cyber Resilience Pledge provides a clear, actionable framework for organisations to strengthen their cyber posture. It focuses on three core commitments.
1. Making Cyber a Board-Level Priority
Cyber security is elevated to a strategic issue, not a purely technical one. This requires adoption of the Cyber Governance Code of Practice, and completion of NCSC Cyber Governance Training by all board members; initially within three months, then annually.
2. Registering for Early Warning
Organisations register for the NCSC Early Warning service, which provides timely alerts about potential malicious activity affecting their networks; enabling faster detection and response before incidents escalate.
3. Strengthening Supply Chain Security
Recognising that supply chain vulnerabilities are one of the most significant and under-addressed risks, organisations commit to using the Cyber Essentials Supplier Check Tool, auditing supplier cyber security coverage, and taking a risk-based approach to requiring Cyber Essentials certification from suppliers.
In addition, signatories agree to encourage similar practices across their own supply chains and to publish their pledge with annual updates on progress.
Why This Matters for Our Customers
The organisations we work with are responsible for critical infrastructure and public services. They need to know that the technology platforms underpinning their operations are built and maintained to a standard that matches their own obligations.
Signing this pledge is part of how we demonstrate that. It is a public commitment, with accountability built in; not a private assurance that sits in a contract and never gets revisited.
The NCSC has been clear that widespread adoption of these measures will significantly improve resilience at both organisational and national levels. We agree. And we want to be part of that effort; not just as a supplier, but as an active participant in making the UK's digital infrastructure more secure.
What This Means for Apexiar
The commitments in the pledge are consistent with the direction we have already been taking. Cyber governance is discussed at board level. We are already working through the NCSC's recommended training programme. And we have always applied a risk-based lens to our supplier relationships.
What signing the pledge does is formalise that; making our commitments explicit, measurable, and open to scrutiny. We will publish our annual progress updates, and we will hold ourselves to the standard we are asking others to meet.
We also intend to use this as a prompt to raise the bar across our supply chain. We are a relatively small company, but our platform touches large, complex organisations. The security of what we build is only as strong as the chain of trust that supports it.
Why We Think More Companies Should Sign
The pledge is not onerous. It does not require organisations to overhaul their entire security posture overnight. What it does is create a baseline; a set of clear, proportionate commitments that any organisation, regardless of size, can work towards.
Cyber resilience is increasingly a commercial requirement, not just a regulatory one. Customers and partners want to know their supply chain is secure. Demonstrating that you have signed up to a government-backed framework is a straightforward and credible way to show that you take it seriously.
If you are considering signing the pledge and would like to discuss how we have approached it, get in touch. We are happy to share what we have learned.
Our Commitment
Apexiar builds platforms that regulated industries trust with their most critical operational data. Signing the UK Government's Cyber Resilience Pledge is consistent with that responsibility; and it is a commitment we are proud to make publicly.
We look forward to sharing our progress.
