NCRCG 2026 Q2 Report: How Cyber Policy Becomes Action

Cyber policy is usually written at national level. Cyber risk is managed somewhere less tidy: inside a small business with no security team, through an outsourced IT provider, or among suppliers several steps removed from the organisation setting the rules.

The National Cyber Resilience Centre Group's Q2 2026 Impact Report offers a useful view of how that gap can be closed.

The network now has 33,764 members across nine regional Cyber Resilience Centres. Around 900 SMEs join each month, 76% of engagement is with organisations employing fewer than 50 people, and microbusinesses account for 46% of membership.

The more interesting story is how those businesses are being reached.

Cyber support works through trusted relationships

The CRCs are working through organisations that SMEs already know: banks, trade associations, customers, distributors, professional advisers and MSPs.

L'Oréal has made cyber learning available to more than 7,000 salons and briefed around 95 business managers to introduce it through their existing relationships. The network has also worked with Care England, accountancy bodies, charities, community foundations, logistics groups and the Pet Industry Federation.

More than 1,300 care-sector SMEs have joined a regional centre following a series of webinars. Work with ICAEW and the Institute of Financial Accountants could open routes to more than 15,000 accountancy firms, many of which advise their own small-business clients.

This is a more credible way to reach smaller organisations than expecting every owner to follow government cyber policy unaided. A salon may listen to its business manager. A charity may respond to its funding network. An SME may act when its accountant, customer or IT provider explains the risk in terms it recognises.

The report says 23% of respondents to National Ambassador supply-chain campaigns subsequently register with a CRC. Registration is only an early step, but it suggests that trusted delivery can move businesses from awareness towards action.

The delivery model behind the Cyber Resilience Pledge

This work now sits alongside the government's Cyber Resilience Pledge.

Signatories commit to make cyber a board responsibility, join the NCSC's Early Warning service, audit Cyber Essentials coverage and take a risk-based approach to requiring certification across their supply chains. They must also encourage the same actions among suppliers and publish annual progress. CyberSmart was among the first organisations to sign. (GOV.UK)

The pledge sets a clear direction. The NCRCG report shows how that direction can be made practical.

Writing Cyber Essentials into procurement policy is relatively straightforward. Applying it across a mixed supplier base is harder. Some suppliers will need little help. Others may not understand what is being asked, know where to start or have anyone available to manage the work.

The campaigns described in the report combine a clear expectation with sector-specific communication and a route into support. That may be the difference between another compliance email and a supplier taking action.

This work builds on a wider government and NCSC effort to make Cyber Essentials a more common supply-chain requirement. In 2024, six leading banks committed to expand its role in their supplier risk processes, and the NCSC has since published a supply-chain playbook encouraging organisations to use the scheme as a practical baseline. (GOV.UK)

The wider cyber policy environment is moving the same way

The Cyber Security and Resilience Bill places more weight on supply-chain security, including the role of digital providers and critical suppliers. The policy behind it is explicit that vulnerabilities in one organisation can cascade into essential services and that more entities need to be brought within the UK's regulatory framework. (GOV.UK)

MSPs are central to this for smaller businesses. They often administer customer networks, identities, backups and devices. That access allows them to raise standards across many clients, but it can also concentrate risk.

The report includes a useful example from FOS.net, an IT provider that first used Cyber PATH services in its own business and then referred nine customers for independent assessments and training.

Those assessments gave customers a clearer view of their weaknesses, feeding into later conversations with FOS about what support they needed.

That relationship may become increasingly important: independent assessment to identify gaps, followed by continuing support from the provider already managing the environment.

Frontier AI increases the pressure to act

The report refers to AI through work with Logistics UK on automation, robotics and the future of industry. The wider government discussion is now moving quickly towards the effect of frontier AI on cyber offence and defence.

The NCSC's recent assessment is that advanced models will make it easier, faster and cheaper to find and exploit weaknesses that previously required more skill or effort. Its response is not to abandon existing controls, but to raise security baselines: reduce unnecessary exposure, patch rapidly, monitor for malicious activity and respond quickly when it is found. (National Cyber Security Centre)

Cyber Essentials fits directly into that argument. Its five technical controls provide a common baseline, while the latest requirements came into force in April 2026. (National Cyber Security Centre)

The UK is also developing Cyber Shield, a national-scale approach intended to use agentic AI to identify, reduce and resolve cyber risk at machine speed. The NCSC describes it as a collaborative, sovereign defence capability rather than a single government system. (National Cyber Security Centre)

Cyber Shield and the NCRCG operate at different levels, but they respond to the same problem. National AI-enabled defence can improve detection and response. It cannot compensate for weak passwords, unpatched systems or poor access controls across thousands of smaller suppliers.

Frontier AI raises the cost of slow adoption, not the redundancy of basic cyber security.

Cyber PATH connects resilience with skills

Cyber PATH was supporting 87 students through 36 university partners at the end of June.

During Q2, students helped 29 SMEs complete 37 technical and non-technical services, including vulnerability assessments, web application assessments and policy reviews. A further 878 people from 318 SMEs attended remote awareness sessions, with nine more delivered in person.

The programme connects two problems often discussed separately: SMEs need affordable access to cyber expertise, while students need practical experience before employers will trust them with cyber roles.

Supervised delivery gives students real work and provides SMEs with services they might otherwise postpone. It is a practical form of workforce development rather than training in isolation.

CyberSmart LIVE in the wider model

The report also covers CyberSmart LIVE, held in Manchester and London in May.

The events brought together MSPs, regional CRCs and National Ambassadors. Representatives from the CRC Network spoke at both, while CGI, Sir Robert McAlpine and Logistics UK joined panel discussions.

Med and Zeenat Jeewoth also shared their experience of cyber crime publicly for the first time, placing the effect on a small business owner alongside the policy and technology discussion. CyberSmart is also supporting the National Ambassador Volunteer Day programme, which connects staff with regional CRC activity and local business communities.

That is part of the same wider approach: using commercial networks, regional policing and trusted relationships to reach organisations that are otherwise difficult to engage.

Turning intent into action

The report is more than a record of events, memberships and training sessions. It describes part of an emerging delivery system for national cyber resilience.

Government is setting expectations through the Cyber Resilience Pledge, Cyber Essentials and the Cyber Security and Resilience Bill. The NCSC is developing AI-enabled national defence through Cyber Shield while urging organisations to raise their security baseline before frontier AI widens the gap between well-defended and poorly defended networks. (National Cyber Security Centre)

The NCRCG is working on the difficult middle layer: reaching smaller organisations, translating national policy into sector-specific action and connecting businesses with people who can help.

Larger organisations can influence suppliers. Trade bodies and advisers can translate policy into the language of a sector. MSPs can implement and maintain controls. Regional CRCs provide trusted support, while Cyber PATH adds supervised capacity and work experience.

This is increasingly what ecosystem resilience looks like in practice. It depends on shared standards, trusted routes to support and larger organisations taking some responsibility for the resilience of the networks around them.

The timing is significant. Frontier AI is increasing the speed of attack. Regulation is extending responsibility through supply chains. The government is asking boards to treat cyber risk as a business issue and to use Cyber Essentials more systematically with suppliers.

The UK is beginning to join these elements together: national direction, AI-enabled defence, baseline certification, regional delivery and shared responsibility across government, policing and industry.

The NCRCG's Q2 report provides a useful view of that model already operating. It is turning intent into action at the point where national policy most often struggles to land: among the smaller organisations on which the wider economy depends.

-Jamie Akhtar, CEO and Co-Founder of CyberSmart