Performanta signs the UK Government’s Cyber Resilience Pledge

We have signed the Cyber Resilience Pledge, committing to board-level accountability, earlier threat intelligence and a higher standard across our supply chain. Here is what we have signed up to, and what it changes for the organisations that rely on us.
Performanta has signed the UK Government’s Cyber Resilience Pledge, joining more than 130 organisations that have committed to raising the standard of cyber resilience across British business and the supply chains that connect it.
The pledge was launched at 10 Downing Street in July 2026 by the Department for Science, Innovation and Technology, working with the National Cyber Security Centre. It asks organisations to move cyber security from a technical function to a governed, board-owned discipline. The scale of the problem behind it is stark: UK firms now face over five million cyber crimes a year, roughly one every six seconds, and the NCSC handled 204 nationally significant incidents in the last year, up from 89 the year before.
What we have committed to
The pledge sets out three actions. We have signed up to all three:
Making cyber security a board-level responsibility, by implementing the Cyber Governance Code of Practice. Every member of our board completes the NCSC’s Cyber Governance Training, and cyber risk is governed at board level with the same rigour as financial and operational risk.
Registering for the NCSC’s free Early Warning service. This gives us earlier sight of threats and vulnerabilities affecting our own estate, feeding directly into how we protect our customers.
Taking a risk-based approach to requiring the government-backed Cyber Essentials certification across our supply chain. We are auditing certification coverage across our suppliers and applying proportionate requirements based on the risk each relationship carries.
Why we have signed
We are a security provider. That means we sit inside the supply chain of every organisation we serve, with privileged access to the environments we defend. The question a board should ask of any supplier in that position is a simple one: who holds you to account, and against what standard?
Signing the pledge answers that in public. It puts our own governance on the record, against a benchmark set by government rather than one we wrote for ourselves.
It also matches how we think about the work. Performanta exists to protect people where data matters most. That kind of safety is a governed outcome which depends on someone at the top of the organisation owning the risk, on warnings arriving early enough to act on, and on the standard holding all the way through the chain of suppliers who can reach your data. Those are precisely the three things the pledge asks for.
“Signing this pledge publicly confirms our commitment to the standard we provide for the organisations we protect. Cyber safety is not something you can deliver to a customer while treating it as an IT problem in your own house. It must be owned at the board, evidenced, and extended to everyone you depend on. That is the commitment we have made, and we expect to be held to it.” Guy Golan, Chief Executive Officer, Performanta
What it means for our clients
Three things become visible for the organisations we work with.
You gain assurance about us. Our board accountability, our threat intelligence position and our supply chain standard are now matters of public record. For clients in regulated sectors, and for anyone running third-party risk assessments on their security provider, that is one more piece of evidence already on the table.
You gain earlier intelligence. Early Warning strengthens what we see. What we see shapes what we detect, and what we detect shapes how quickly we act on your behalf.
You gain a partner who has done it. The pledge asks organisations to implement the Cyber Governance Code of Practice and to get their supply chain in order. Those are two of the hardest conversations a security leader has to take to a board. We have now had them internally, and we can help you have them: mapping your governance against the Code, preparing board-ready reporting on cyber risk, and building a proportionate Cyber Essentials position across your suppliers.
What it means for our partners
We will be raising the pledge with our own suppliers and asking them to consider signing. Resilience only compounds when it travels. A commitment that stops at our own perimeter would be worth very little to the clients whose environments sit on the other side of it.
“Resilience is governed before it is engineered. The Cyber Governance Code of Practice matters because it gives boards a language for cyber risk that they already use for every other risk they own. Signing this pledge is Performanta putting itself on the same footing we recommend to every board we advise.” Sarah Armstrong-Smith, Chief Strategy Officer, Performanta
Read the declaration
Our signed declaration is in. If you would like to talk through what board-level cyber governance looks like in your organisation, or where to start on supply chain assurance, get in touch.



