Board responsibility
Strengthen cyber security governance and ensure cyber risk remains a board-level responsibility.
Our commitment to strengthening cyber resilience across Socura, our supply chain and the wider UK

Cyber security is a shared responsibility. Strong security starts with organisations taking ownership of their own resilience, while also recognising the role that suppliers, partners and the wider ecosystem play in keeping businesses and essential services secure.
With this in mind, Socura has signed the UK Government’s Cyber Resilience Pledge, committing to a series of practical actions designed to strengthen cyber resilience across our own organisation and supply chain.
The voluntary pledge was developed by the UK Government and industry and formally launched in July 2026. It asks organisations to take three specific steps to strengthen their cyber resilience, while also encouraging these actions across their supply chains and publishing their signed declaration.
The first commitment is about ensuring cyber security has the appropriate level of leadership and oversight.
As a signatory, Socura has committed to implementing the actions set out in the Cyber Governance Code of Practice and ensuring that all members of our Board undertake the National Cyber Security Centre’s Cyber Governance Training within three months of signing, and annually thereafter.
Cyber security is not simply a technical responsibility. Effective governance means understanding the risks, making informed decisions and ensuring that security remains part of wider business planning.
Socura has also committed to registering for the NCSC’s Early Warning service within one month of signing the pledge.
The service provides UK organisations with notifications about potential malicious activity affecting their networks, helping them identify threats and take action where appropriate.
For a cyber security provider that operates around the clock, this complements the work our teams already do to monitor, investigate and respond to potential threats.
The third commitment focuses on the security of the organisations and suppliers that businesses rely on.
Socura has committed to registering for the Cyber Essentials Supplier Check Tool within two months of signing the pledge, carrying out a comprehensive audit of Cyber Essentials coverage across our supply chain and taking a risk-based approach to requiring Cyber Essentials from suppliers.
Supply chain security is an important part of building genuine cyber resilience. Organisations can have strong internal controls, but their wider exposure also depends on the security practices of the suppliers and partners they work with.
As a UK-based cyber security provider delivering 24/7 Managed Detection and Response, Socura sees first-hand the importance of being prepared to detect, investigate and respond to cyber threats.
But resilience is about more than technology and monitoring. It also requires good governance, effective security controls and clear responsibility across an organisation.
For Socura, signing the Cyber Resilience Pledge is a natural extension of that approach. It reflects our belief that improving cyber resilience is something organisations need to take seriously at every level, while also working together to raise standards across the wider supply chain.
Andrew Kays, CEO of Socura, said:
“Cyber resilience isn’t something any organisation can achieve alone. It requires leadership from the board, good security practices throughout the supply chain and collaboration across industry and government.
At Socura, our purpose is to give organisations the confidence that someone is always watching, protecting and ready to respond. Signing the Cyber Resilience Pledge is a natural extension of that commitment and of our belief that raising cyber security standards collectively will help create a safer and more resilient UK.”
As part of the pledge, organisations commit to encouraging the actions within their own supply chains and publishing their signed pledge declaration on their website. The declaration also sets out a commitment to publish an annual public update on the steps taken to deliver against the pledge.
To find out more about the Cyber Resilience Pledge, including the full commitments for participating organisations, visit the UK Government’s Cyber Reslience Pledge Guidance.