Cyber resilience for Ofgem-regulated energy companies

A practical guide for CEOs and CFOs as the energy system becomes more connected and the regulatory baseline rises.

In December 2025, Russian state-linked attackers targeted Poland's energy grid. The UK and its allies later attributed the attack to Russia's FSB Centre 16 and estimated that, had it succeeded, around 500,000 people could have lost electricity. The attackers exploited vulnerable routers and network devices, a reminder that serious disruption does not always require an unusually sophisticated route into an organisation.

The incident came as energy systems across Europe are becoming more digital and distributed. Remote monitoring, smart devices, cloud platforms, battery storage and distributed generation allow the system to operate more efficiently, but also connect organisations and technology that were once more isolated. The UK government's 2026 Energy Sector Cyber Security Strategy describes a sector becoming increasingly digital and interconnected, while the International Energy Agency has warned that connected devices and distributed energy resources expand the number of places an attacker can target.

Regulation is starting to reflect that change. Ofgem and the Department for Energy Security and Net Zero (DESNZ) have proposed baseline cyber requirements for all Ofgem licensees, alongside a review of which organisations should fall within the Network and Information Systems Regulations. The Cyber Security and Resilience Bill, which would update the NIS regime, has passed the Commons and is now in the House of Lords.

For a chief executive or finance director, this is wider than an IT security issue. The questions are operational and financial: what must continue to work, what does it depend on, what would an interruption cost, and how quickly could the company contain an incident and recover?

Three areas deserve particular attention: increasingly connected operations, a rising regulatory baseline, and the growing role of suppliers, software and AI.

Why energy is different

Energy companies face many of the same attacks as other businesses. Criminals steal credentials, exploit vulnerable software, manipulate employees and use ransomware. The difference lies partly in what those attacks can reach.

Energy businesses increasingly operate a mixture of conventional information technology and operational technology (OT), the systems that monitor or control physical equipment. That can include substations, generation equipment, storage assets, remote telemetry and industrial control systems. A failure in ordinary business IT can stop people working or expose information. An incident that reaches operational systems can also interfere with the company's ability to generate, distribute or supply energy safely.

Research from three different sources helps put the risk into context.

There is an important caveat to the Verizon numbers. Its Utilities category follows the North American NAICS classification and is broader than UK electricity and gas, including water and related utilities. It should therefore be read as a view of the wider utility threat rather than a breach rate for Ofgem licensees. The combination of high external activity and a strong espionage motive is nevertheless relevant to an industry operating critical infrastructure.

1. Energy operations are becoming more connected

The commercial case for digitisation is easy to understand. Remote monitoring can reduce site visits, better data can improve maintenance and forecasting, and connected assets make it easier to manage increasingly distributed generation and demand. IBM's 2026 research found that digitally advanced utilities reported 17% faster outage recovery and 14% greater forecasting accuracy, while utilities investing in OT transformation reported 20% faster integration of distributed energy resources. These are survey findings rather than guaranteed returns, but they help explain why greater connectivity is likely to continue.

The security consequence is that each new connection can create another dependency. An energy company may rely on an identity provider to let engineers log in, a telecommunications company to reach remote assets, a cloud platform to collect operational data and specialist suppliers to maintain equipment. An interruption or compromise in any one of them may affect services some distance away from where the original problem occurred.

The IEA describes a similar shift towards the "grid edge". As distributed generation, electric vehicles, storage and connected consumer devices grow, cyber risk becomes less concentrated in a small number of large operators. Digital connections can also create routes through which failures spread between systems.

Segmentation becomes more important

One of the practical answers is segmentation: separating systems so that access to one does not automatically give access to another. If an attacker compromises an employee laptop or corporate cloud account, there should be controls between that environment and systems used to operate physical assets.

This does not mean disconnecting operational technology from everything else. Modern energy systems need data exchange and, in many cases, remote access. The aim is to know which connections exist, why they are necessary and what someone can reach through them. Ofgem and DESNZ specifically identify separation between IT and OT as one of the measures that could supplement the proposed baseline for licensees.

Access control matters for the same reason. Engineers, contractors and equipment suppliers often have legitimate reasons to connect remotely to assets, but those routes should be identifiable, limited and removable. Permanent supplier accounts, shared administrator credentials and remote connections that cannot quickly be disabled make an incident harder to contain.

For boards, five questions cover much of the issue:

Where are our critical boundaries? Understand how corporate IT, cloud services, remote sites and operational systems connect, concentrating first on systems that could affect operations.

Who can cross them? Privileged and remote access should belong to identifiable people, use strong authentication and provide only the access required.

Can supplier access be stopped quickly? The company should be able to withdraw third-party access during an incident.

What happens when systems are unavailable? Critical services need tested recovery arrangements, including scenarios in which corporate IT or a major supplier is unavailable for several days.

Which assets cannot easily be patched or replaced? Operational equipment can remain in service for decades. Where modern controls cannot be applied, the surrounding architecture may need to compensate. The IEA notes that long asset lives leave many electricity systems operating a mixture of modern connected technology and older equipment designed for a much less connected environment.

For a CFO, this gives cyber investment a more useful frame. Instead of asking how much cyber security the company should buy, management can identify specific operational dependencies, estimate the consequence of losing them and compare that exposure with the cost of reducing it.

2. The regulatory floor is rising

The main cyber-specific regulation for critical energy operators today is the Network and Information Systems Regulations 2018. NIS introduced security and incident-reporting requirements for operators of essential services, including parts of the energy sector. The government's 2026 energy cyber strategy acknowledges a limitation in that approach: NIS was designed to cover the most critical operators and does not provide whole-system coverage.

Ofgem already uses the NCSC's Cyber Assessment Framework (CAF) as part of its NIS assurance for downstream gas and electricity, including a sector-specific CAF Overlay. CAF is broader than a basic technical baseline: version 4.0 assesses outcomes across managing security risk, protecting against cyber attack, detecting cyber security events and minimising the impact of incidents. It is designed around essential functions and can cover both IT and operational technology.

That matters because the structure of the energy system is changing. More organisations now generate, store, aggregate or otherwise support energy services, and their importance cannot always be judged simply by company size. Ofgem and DESNZ therefore argue that it is no longer sufficient to focus cyber requirements on a subset of large operators. Their March 2026 consultation proposed a baseline applying to all Ofgem licensees, alongside a review of NIS thresholds and the services covered by the regime.

The broad direction is easier to see as a timeline:

The exact requirements and implementation dates are still being developed, so companies should distinguish policy direction from settled regulation.

Where Cyber Essentials fits

Ofgem and DESNZ have proposed using Cyber Essentials as the starting point for the new baseline. The scheme covers five areas of basic technical security, including secure configuration, access control, malware protection, firewalls and security updates. Cyber Essentials uses a verified self-assessment, while Cyber Essentials Plus adds independent technical testing of the same controls.

Cyber Essentials and CAF play different roles. The proposed Cyber Essentials baseline is intended to raise the minimum level across all Ofgem licensees; CAF is the deeper, outcome-based framework already used in Ofgem's NIS assurance for Operators of Essential Services. For organisations already assessed against CAF, the proposed baseline should therefore be seen as complementary rather than a replacement.

The proposal is more nuanced than simply requiring Cyber Essentials across the energy sector. Ofgem and DESNZ recognise that the scheme is largely designed for conventional IT and that applying its controls to operational technology can be difficult or, in some circumstances, unsuitable. They also identify areas that Cyber Essentials does not cover in depth, including governance, personnel security, supply-chain resilience and incident response and recovery.

One option under consideration is therefore a hybrid: an established Cyber Essentials baseline, supplemented with controls specific to Ofgem licensees. The consultation identifies IT and OT separation, risk assessment, organisational policies and training, supply-chain security, and response and recovery as possible additions. The final model has not yet been set.

For companies, that makes Cyber Essentials Plus a reasonable preparation point for conventional IT, rather than a complete answer to energy resilience. Organisations already subject to NIS or other energy-sector requirements must continue meeting those obligations, while operational technology, recovery and critical supplier dependencies need their own assessment.

3. Suppliers, software and AI are now part of the operational perimeter

An energy company no longer controls everything it needs to operate. Cloud providers host applications and data, telecommunications companies connect remote sites, equipment manufacturers maintain assets, software providers issue updates, and service companies may have privileged access into important systems.

The result is a wider operational perimeter. A company can maintain strong security internally and still lose an important service because a supplier is compromised or simply unavailable.

Ofgem is addressing this directly. In June 2026 it published proposed guidance for managing supply-chain security across downstream gas and electricity. The draft uses a risk-based supplier criticality model, recognising that a supplier maintaining operational infrastructure creates a different exposure from one providing a low-impact business service. The consultation closed on 30 June and remains listed by Ofgem as awaiting a decision.

For senior management, supplier risk becomes much easier to understand when expressed in operational terms:

This is also where software risk belongs. A critical application may depend in turn on cloud infrastructure, open-source components and third-party services that the energy company never contracted with directly. Mapping every technical dependency is unrealistic, but companies should understand those attached to their most important services.

AI changes the threat, but mostly by changing speed and scale

AI adds another dimension. The immediate cyber effect is more practical than some discussion of frontier AI suggests.

The NCSC assesses that AI will almost certainly make parts of cyber intrusion more effective and efficient. Attackers are already using it for reconnaissance, vulnerability research, exploit development, social engineering and basic malware development. Through 2027, the NCSC expects AI mainly to increase the volume and impact of existing attack techniques rather than produce fully automated, novel attacks.

That matters particularly where companies are slow to patch. The NCSC expects AI-assisted vulnerability research to shorten further the time between a vulnerability becoming known and attackers exploiting it. It identifies critical infrastructure and supply chains using less secure operational technology as an area of particular exposure.

AI also creates new dependencies inside energy companies themselves. Models and AI-enabled applications increasingly connect to corporate data and, potentially, operational systems. The NCSC warns that this enlarges the attack surface, including through software vulnerabilities, malicious prompts and supply-chain attacks against AI systems.

There is a clear operational upside too. AI is already being explored for forecasting, optimisation, predictive maintenance and network management. Ofgem has decided to launch a 12-month AI technical sandbox, targeting late autumn 2026, so energy companies can test defined uses under regulatory oversight.

The board-level questions are therefore fairly conventional. Which AI services are approved? What company or customer information can employees enter? Which important suppliers have AI embedded in their products? Which decisions require a person to check the result?

Payments, changes to supplier details and changes to operational systems are obvious places to retain independent verification. AI makes convincing emails, documents and voices easier to produce, which makes informal approval processes less dependable.

What should CEOs and CFOs do now?

The regulatory detail will continue to move, but most sensible preparation does not depend on predicting the final Ofgem rules. Start with the handful of services whose loss would cause the greatest operational, customer, financial or regulatory damage, then work backwards through the technology and suppliers required to provide them.

A board should be able to get clear, evidence-backed answers to six questions:

The shift in Ofgem's approach reflects a wider change in the energy system. Smaller operators and distributed assets can now matter to system resilience in ways that were less obvious when generation and control were more concentrated. Ofgem and DESNZ's consultation explicitly recognises that the growing number of organisations participating in the energy ecosystem has changed what should be considered critical.

For leaders, the immediate priorities are already clear: know which services the business cannot afford to lose, the systems and suppliers they depend on, the routes an attacker could use to reach them, and how quickly the company could recover. Regulation will formalise parts of that work over the coming years, but the operational exposure exists today.

NCRCG 2026 Q2 Report: How Cyber Policy Becomes Action

Cyber policy is usually written at national level. Cyber risk is managed somewhere less tidy: inside a small business with no security team, through an outsourced IT provider, or among suppliers several steps removed from the organisation setting the rules.

The National Cyber Resilience Centre Group's Q2 2026 Impact Report offers a useful view of how that gap can be closed.

The network now has 33,764 members across nine regional Cyber Resilience Centres. Around 900 SMEs join each month, 76% of engagement is with organisations employing fewer than 50 people, and microbusinesses account for 46% of membership.

The more interesting story is how those businesses are being reached.

Cyber support works through trusted relationships

The CRCs are working through organisations that SMEs already know: banks, trade associations, customers, distributors, professional advisers and MSPs.

L'Oréal has made cyber learning available to more than 7,000 salons and briefed around 95 business managers to introduce it through their existing relationships. The network has also worked with Care England, accountancy bodies, charities, community foundations, logistics groups and the Pet Industry Federation.

More than 1,300 care-sector SMEs have joined a regional centre following a series of webinars. Work with ICAEW and the Institute of Financial Accountants could open routes to more than 15,000 accountancy firms, many of which advise their own small-business clients.

This is a more credible way to reach smaller organisations than expecting every owner to follow government cyber policy unaided. A salon may listen to its business manager. A charity may respond to its funding network. An SME may act when its accountant, customer or IT provider explains the risk in terms it recognises.

The report says 23% of respondents to National Ambassador supply-chain campaigns subsequently register with a CRC. Registration is only an early step, but it suggests that trusted delivery can move businesses from awareness towards action.

The delivery model behind the Cyber Resilience Pledge

This work now sits alongside the government's Cyber Resilience Pledge.

Signatories commit to make cyber a board responsibility, join the NCSC's Early Warning service, audit Cyber Essentials coverage and take a risk-based approach to requiring certification across their supply chains. They must also encourage the same actions among suppliers and publish annual progress. CyberSmart was among the first organisations to sign. (GOV.UK)

The pledge sets a clear direction. The NCRCG report shows how that direction can be made practical.

Writing Cyber Essentials into procurement policy is relatively straightforward. Applying it across a mixed supplier base is harder. Some suppliers will need little help. Others may not understand what is being asked, know where to start or have anyone available to manage the work.

The campaigns described in the report combine a clear expectation with sector-specific communication and a route into support. That may be the difference between another compliance email and a supplier taking action.

This work builds on a wider government and NCSC effort to make Cyber Essentials a more common supply-chain requirement. In 2024, six leading banks committed to expand its role in their supplier risk processes, and the NCSC has since published a supply-chain playbook encouraging organisations to use the scheme as a practical baseline. (GOV.UK)

The wider cyber policy environment is moving the same way

The Cyber Security and Resilience Bill places more weight on supply-chain security, including the role of digital providers and critical suppliers. The policy behind it is explicit that vulnerabilities in one organisation can cascade into essential services and that more entities need to be brought within the UK's regulatory framework. (GOV.UK)

MSPs are central to this for smaller businesses. They often administer customer networks, identities, backups and devices. That access allows them to raise standards across many clients, but it can also concentrate risk.

The report includes a useful example from FOS.net, an IT provider that first used Cyber PATH services in its own business and then referred nine customers for independent assessments and training.

Those assessments gave customers a clearer view of their weaknesses, feeding into later conversations with FOS about what support they needed.

That relationship may become increasingly important: independent assessment to identify gaps, followed by continuing support from the provider already managing the environment.

Frontier AI increases the pressure to act

The report refers to AI through work with Logistics UK on automation, robotics and the future of industry. The wider government discussion is now moving quickly towards the effect of frontier AI on cyber offence and defence.

The NCSC's recent assessment is that advanced models will make it easier, faster and cheaper to find and exploit weaknesses that previously required more skill or effort. Its response is not to abandon existing controls, but to raise security baselines: reduce unnecessary exposure, patch rapidly, monitor for malicious activity and respond quickly when it is found. (National Cyber Security Centre)

Cyber Essentials fits directly into that argument. Its five technical controls provide a common baseline, while the latest requirements came into force in April 2026. (National Cyber Security Centre)

The UK is also developing Cyber Shield, a national-scale approach intended to use agentic AI to identify, reduce and resolve cyber risk at machine speed. The NCSC describes it as a collaborative, sovereign defence capability rather than a single government system. (National Cyber Security Centre)

Cyber Shield and the NCRCG operate at different levels, but they respond to the same problem. National AI-enabled defence can improve detection and response. It cannot compensate for weak passwords, unpatched systems or poor access controls across thousands of smaller suppliers.

Frontier AI raises the cost of slow adoption, not the redundancy of basic cyber security.

Cyber PATH connects resilience with skills

Cyber PATH was supporting 87 students through 36 university partners at the end of June.

During Q2, students helped 29 SMEs complete 37 technical and non-technical services, including vulnerability assessments, web application assessments and policy reviews. A further 878 people from 318 SMEs attended remote awareness sessions, with nine more delivered in person.

The programme connects two problems often discussed separately: SMEs need affordable access to cyber expertise, while students need practical experience before employers will trust them with cyber roles.

Supervised delivery gives students real work and provides SMEs with services they might otherwise postpone. It is a practical form of workforce development rather than training in isolation.

CyberSmart LIVE in the wider model

The report also covers CyberSmart LIVE, held in Manchester and London in May.

The events brought together MSPs, regional CRCs and National Ambassadors. Representatives from the CRC Network spoke at both, while CGI, Sir Robert McAlpine and Logistics UK joined panel discussions.

Med and Zeenat Jeewoth also shared their experience of cyber crime publicly for the first time, placing the effect on a small business owner alongside the policy and technology discussion. CyberSmart is also supporting the National Ambassador Volunteer Day programme, which connects staff with regional CRC activity and local business communities.

That is part of the same wider approach: using commercial networks, regional policing and trusted relationships to reach organisations that are otherwise difficult to engage.

Turning intent into action

The report is more than a record of events, memberships and training sessions. It describes part of an emerging delivery system for national cyber resilience.

Government is setting expectations through the Cyber Resilience Pledge, Cyber Essentials and the Cyber Security and Resilience Bill. The NCSC is developing AI-enabled national defence through Cyber Shield while urging organisations to raise their security baseline before frontier AI widens the gap between well-defended and poorly defended networks. (National Cyber Security Centre)

The NCRCG is working on the difficult middle layer: reaching smaller organisations, translating national policy into sector-specific action and connecting businesses with people who can help.

Larger organisations can influence suppliers. Trade bodies and advisers can translate policy into the language of a sector. MSPs can implement and maintain controls. Regional CRCs provide trusted support, while Cyber PATH adds supervised capacity and work experience.

This is increasingly what ecosystem resilience looks like in practice. It depends on shared standards, trusted routes to support and larger organisations taking some responsibility for the resilience of the networks around them.

The timing is significant. Frontier AI is increasing the speed of attack. Regulation is extending responsibility through supply chains. The government is asking boards to treat cyber risk as a business issue and to use Cyber Essentials more systematically with suppliers.

The UK is beginning to join these elements together: national direction, AI-enabled defence, baseline certification, regional delivery and shared responsibility across government, policing and industry.

The NCRCG's Q2 report provides a useful view of that model already operating. It is turning intent into action at the point where national policy most often struggles to land: among the smaller organisations on which the wider economy depends.

-Jamie Akhtar, CEO and Co-Founder of CyberSmart

The Countdown to DCC Level 0 Starts Now

The MoD has set 31 December 2026 as the deadline for every industry partner to achieve DCC Level 0 certification, five months from now. That reaches every organisation in the supply chain, not just the primes at the top. Five months sounds like plenty of time. It gets tighter fast once you count backwards from scoping, evidence gathering and booking an assessment slot.

What is DCC and what is Level 0?

Defence Cyber Certification is an organisation-wide certification aligned to the MoD's DEFSTAN 05-138, introduced through the Cyber Security Model version 4 (CSMv4) in December 2025. It is delivered through IASME's network of assured Certification Bodies, providing a single, independently assessed route to demonstrating cyber resilience, valid for three years with annual attestation. Certification is open to any organisation, regardless of whether it currently holds or is bidding for a defence contract.

There are four levels (0 to 3), each aligned to the cyber risk profile of the contracts an organisation holds. Level 0 is the entry point, designed for organisations with a very low contract risk profile. It is the baseline that every organisation in the defence supply chain is now expected to reach.

Level 0 has two core requirements: a current Cyber Essentials certification covering all applicable in-scope business-critical systems, and completion of the Level 0 Supplier Assurance Questionnaire assessed against DEFSTAN 05-138.

Who is in scope?

The MoD's ask covers all industry partners, not just prime contractors. Organisations further down the supply chain are also in scope. Prime contractors are expected to encourage their subcontractors to work towards Level 0 and to set appropriate timescales for higher levels where those are required at lower tiers.

The MoD already works with around 12,000 SMEs through its supply chain, which gives a sense of scale. Many of those 12,000 SMEs will need to meet the Level 0 deadline, not just tier-one contractors.

DCC is not currently a legal mandate, but the MoD has asked all partners to achieve Level 0. For organisations with DEFCON 658 in their contracts, DCC becomes a contractual requirement rather than a request. If you're not sure which camp you're in, your prime contractor or customer can tell you. That's the fastest way to find out.

For MSPs managing IT for defence sector clients, the question to ask is whether those clients understand their DCC obligations and have a plan in place to meet them. Many probably don't.

Why five months is shorter than it looks

The MoD used their recent announcement to share a success story: Lockheed Martin became the first company to achieve DCC Level 3, and their EMEA Information Security Officer, James Shortle, gave a detailed account of what preparing for certification actually involved. His opening point was direct: start with scoping. It determines everything that follows. Before gathering evidence or addressing gaps, an organisation needs to understand which systems are in scope, what data is handled, and how its infrastructure maps to the DCC controls. He also noted that engaging early with a certifying body, through IASME, helps avoid misinterpreting how controls apply to your specific organisation.

Five months sounds like plenty of time. But remove the time needed to scope, close gaps, gather evidence and book an assessment slot, and the window to act is measured in weeks, not months.

It's worth noting where DCC sits in the wider picture. The MoD's SME Action Plan, published on 21 July 2026, commits to increasing SME spend by an additional £2.5 billion by summer 2028, a 50% increase on the current £5 billion annual baseline. The plan doesn't reference DCC directly, but it confirms the defence supply chain UK SMEs operate in is growing, not shrinking, which is useful context when weighing up whether certification is worth the effort.

Where the lead time actually goes

The broader message was that even for Lockheed Martin, which already operates a strong internal governance model, scoping proved complex. For organisations approaching DCC for the first time, the process is likely to take longer than expected.

Their security lead's advice went beyond scoping. Get board-level buy-in early, not as a box to tick once assessment is already underway. A similar change is already happening on the Cyber Essentials side: since April, a director's signature on a CE self-assessment commits to maintaining compliance throughout the certification period, not just confirming it was accurate on the day they signed. Since CE certification is a prerequisite for DCC Level 0, organisations that already hold it have that board-level commitment in place before DCC preparation starts. Those that don't are effectively building it in as one of the first steps. Treat Level 0 as a chance to test how the controls apply to your organisation, rather than something to clear quickly and move on from. And start gathering evidence before an assessment is even booked: Level 3 certification alone carries more than 300 requirements, each needing multiple pieces of supporting evidence, which gives some sense of how fast the workload builds once you're past Level 0.

Their security lead's advice also touched on subcontractors further down the supply chain: not every supplier will need Level 2 or Level 3, and there is nothing wrong with treating those as a longer-term goal rather than an immediate requirement. For most organisations, Level 0 is the actual target for December, not a stepping stone to rush past.

What Cyber Essentials means in this context

CE certification covering all applicable in-scope systems is the starting requirement for DCC Level 0. Level 0 certification cannot be granted without it.

That has two practical knock-on effects. Organisations without CE need to give that process its own slot in the timeline, since CE requires its own preparation, submission and assessment before DCC can begin. Organisations that already hold CE but haven't reviewed their scope recently should check they're still compliant and that the certification covers every business-critical system DCC Level 0 needs in scope.

CE and DCC are designed to work together. CE handles the technical controls. DCC builds governance and assurance on top of that. Getting CE in place is still the most immediate, practical step any organisation in the defence supply chain can take right now.

For prime contractors

If your organisation sits above lower-tier suppliers, pushing Level 0 progress down the chain and setting realistic timescales for it is your responsibility under the MoD's ask.

The MoD is specific about sequencing. If a subcontractor needs a level above 0, that work is expected after 31 December 2026, not squeezed in before it. Level 0 is the December priority for the whole supply chain. Higher levels still matter. They're simply scheduled for after December rather than instead of it.

For MSPs with defence sector clients

The DCC deadline creates a direct obligation for many of your clients, and most probably don't know it yet. Some may not know they're in scope at all. The practical first step is helping clients identify whether DEFCON 658 applies to their contracts, what level they're required to achieve, and whether their current CE status is sufficient to begin the DCC process. From there, the route is the same for everyone: Cyber Essentials first, then DCC Level 0 or Level 1, depending on what the contract requires.

Eleanor Fairford, the MoD's Director of Cyber Defence & Risk, described DCC as "a badge of excellence in cyber resilience for all Defence industry partners." Earning it, for most organisations in this supply chain, starts with paperwork rather than ceremony: get Cyber Essentials in place, then work through Level 0 before December.


For organisations in the defence supply chain: CyberSmart is an IASME-accredited DCC certification body, assessing organisations for Level 0 and Level 1 certification. We confirm your scope, get you Cyber Essentials certified if you're not already, and take you through DCC certification ahead of the December deadline.

For MSPs with defence sector clients: CyberSmart gives you the DCC expertise and certification capability to support defence sector clients directly, from confirming scope and completing Cyber Essentials through to Level 0 or Level 1 assessment.

Start your DCC journey

"Note to self" phishing scams explained: 2026 Update

Phishing scams have been around almost as long as email has existed. The first recorded use of the technique was in the mid-1990s, when a group of hackers posed as AOL employees and used email and instant messaging to steal users' passwords and account credentials.

For most of the intervening decades, phishing remained fairly easy to recognise. Poor grammar, suspicious links, generic greetings: these were the tells security training taught people to look for. The advice worked, mostly, because the scams were unsophisticated.

That has changed. According to the UK Cyber Security Breaches Survey 2025/26, phishing affected 38% of UK businesses in the past year and accounted for more than half of all attacks experienced by organisations that were hit. Awareness is higher than ever. Rates of attack are too.

And since this blog was first published, the landscape has shifted. The scam itself works the same way. What has changed is how convincing it has become.

What do we mean by "note to self"?

Most email providers let you send a message to yourself from within your account. It appears in your inbox as a note, a reminder you have left for yourself. Useful, ordinary, unremarkable.

Cybercriminals have found a way to weaponise it.

How do note-to-self phishing scams work?

The key detail is that you can only send a note to yourself from inside the same email account. That is the crux of the scam.

A cybercriminal uses email spoofing to make a message appear to come from your own address, then sends it to you claiming to have breached your account. The email appears, to you, like a note you have sent to yourself. The message typically demands a ransom, usually in cryptocurrency, in exchange for deleting compromising files or data the sender claims to have obtained. A strict deadline is given, say 48 hours, after which the hacker threatens to leak the material or share it with your contact list.

Here is the crucial part: the cybercriminal does not actually have access to your account. There is no compromising data. They have simply spoofed your email address, and are counting on the shock of that to get you to act before you think clearly.

Here is what one looks like;

What is email spoofing?

Every email contains a header: a code snippet that carries information about the message, including the sender, recipient, and tracking data. Cybercriminals have learned to manipulate this.

The sophisticated approach involves forging the fields in the header that the recipient actually sees, making the email appear to come from a legitimate sender. This is possible because the Simple Mail Transfer Protocol (SMTP) that governs email transmission has no built-in mechanism for authenticating email addresses. Sophisticated spoofs can bypass standard email security filters, particularly where email authentication protocols such as DMARC are not properly configured. It is the approach typically used for note-to-self scams, which is what makes them effective.

The more common approach is to register an email domain that closely resembles the one being impersonated, for example CEO@m3gacorporation.com rather than CEO@megacorporation.com. More common, less convincing, and usually easier to catch with a careful look at the sender's address.

What has changed in 2026

When this blog was first published, note-to-self scams were effective primarily because of the panic they induced. The email appeared to come from you, which was alarming enough, but the ransom message itself was often generic and sometimes poorly written.

That is no longer a reliable way of identifying the scam.

According to Hoxhunt's 2026 Phishing Trends Report, which is based on analysis of their own platform data, AI-generated phishing surged from around 4% of all phishing attacks in November 2025 to 56% in December, a 14-fold increase in a single month. By early 2026 it had stabilised at roughly 40%.

The ICO published guidance in May 2026 on protecting organisations from AI-powered cyber threats, outlining five steps in response to a threat landscape that is changing faster than security training has kept pace with.

The practical effect is that the visual tells phishing awareness training relied on are largely absent from AI-generated messages. Perfect grammar, natural phrasing, and plausible context are now within reach of any attacker using a consumer-grade AI tool. Applied to note-to-self scams, this means the ransom message is likely to be fluent and convincing. It may reference your name, your job title, or details scraped from your public LinkedIn profile. The underlying mechanism is unchanged. The email is still spoofed, the attacker still has no access to your account, but the message no longer looks like a scam.

This is why the step-by-step verification below matters more in 2026 than it did in 2025. You cannot rely on the quality of the writing to tell you whether the threat is real.

How to spot a note-to-self scam

The note-to-self scam has a reliable tell that AI cannot remove. Here is how to work through it.

1. Do not panic

If you receive an email like this, your immediate instinct will probably be alarm. That is exactly what the attacker is counting on. Creating a sense of urgency is one of the most common and effective social engineering techniques in existence. Do not pay, do not click any link, and do not delete anything until you have worked through the steps below.

It can help to use the Stop, Look, Think approach: stop before acting, look at what the email is actually telling you, and think critically before responding. Tell yourself that nine times out of ten, this is a scam, not a real compromise.

This is more important now than it was a year ago. AI-generated messages are more convincing, which means the urge to act quickly is stronger. Pause anyway.

2. Check the sender's email address

Does the address exactly match your own? If the attacker has used the less sophisticated spoofing approach, there will be a subtle difference: an extra character, a different domain. Look carefully.

If the address appears identical to yours, it is likely a more sophisticated spoof. Move to step three.

3. Check your sent folder

This is the definitive check, and AI cannot change it.

A note to self can only be sent from inside your email account. If the email in your inbox does not appear in your sent folder, it was not sent from your account. It is a spoof. The sender has no access.

This step works regardless of how convincing the message is. No AI-written ransom demand changes what is or is not in your sent folder.

4. Check the IP address of the sender

If you want additional confirmation, check the sender's IP address. A message genuinely sent from inside your account would carry the IP address of the mail server associated with your email. A spoofed message will not.

To check in Gmail: open the email, click the three vertical dots, and select "Show original."

To check in Outlook: open the email, go to File, then Properties, and look at the Internet headers.

Once you have the raw header, a tool like MXToolbox's Email Header Analyser will parse it and identify the originating IP address.

Note: if you use a virtual private network (VPN), this step will not give a reliable result, as VPNs mask the IP address associated with your connection.

5. Flag it and move on

Once you are confident the email is a scam (and after step three you should be), report it as spam to your email provider and delete it. There is nothing else to do.

Why training still matters

The checks above are straightforward when you know to apply them. The problem is that most people do not.

According to Hiscox's 2026 small business risk survey, 38% of UK SMEs named cyber attacks as the risk most likely to keep them awake at night, placing it above inflation, economic downturn, and legal claims. Yet the UK Cyber Security Breaches Survey shows that staff training rates have not kept pace with either the volume or the sophistication of attacks. Awareness of the threat and knowledge of what to do when it arrives are not the same thing.

Note-to-self scams are a useful illustration of that gap. The scam is completely neutralised by checking your sent folder. But if the first response is panic, that check often does not happen. AI-generated messages are increasingly effective at inducing exactly that response.


Want to know more about how to protect your business from phishing? CyberSmart Learn gives your team the training to recognise attacks and respond correctly, rather than reactively. CyberSmart Phish runs simulated phishing campaigns so you can see how your team actually behaves when a convincing attack lands, before a real one does.

MSPs looking to offer phishing awareness and simulation to clients can access both through the CyberSmart partner platform. Explore the partner programme

CyberSmart signs the UK Government Cyber Resilience Pledge

CyberSmart has signed the UK Government Cyber Resilience Pledge, joining other early adopters in committing to practical actions that strengthen cyber resilience across the UK economy.

The pledge, formally launched by the UK Government on 7 July 2026, brings together government and industry to help organisations take meaningful action on cyber security.

It focuses on three areas: making cyber a Board-level responsibility, signing up to the NCSC’s Early Warning service, and taking a risk-based approach to requiring Cyber Essentials across the supply chain.

At CyberSmart, we believe cyber resilience is a shared responsibility. For businesses, partners and suppliers, good cyber security is no longer just a technical issue. It is central to trust, continuity, growth and long-term resilience.

By signing the pledge, CyberSmart has committed to implementing the actions within the Cyber Governance Code of Practice, ensuring Board members complete NCSC Cyber Governance Training, using NCSC Early Warning, and strengthening our approach to Cyber Essentials across our own supply chain.

We have already registered for the NCSC’s Early Warning service and the Cyber Essentials Supplier Check Tool. We are also conducting a comprehensive audit of Cyber Essentials coverage across our supply chain, which will be presented to and discussed by the Board.

CyberSmart will also encourage these actions within its own supply chain, working with suppliers to better understand and manage cyber security risks.

Jamie Akhtar, Founder and CEO of CyberSmart, said:

“For years, cyber security has often been treated as a technical problem to solve after the fact. The Cyber Resilience Pledge reflects something we’ve believed for a long time - resilience starts with leadership, good governance and getting the fundamentals right.

We’re proud to be among the first organisations to sign the Pledge. The three commitments are practical, evidence-based steps that any organisation can take today. 

As an ecosystem champion and market leader, we see every day that organisations don’t usually become more secure by buying more technology. They become more secure by consistently applying proven controls, building good habits and making cyber security part of how the business operates.

That philosophy sits at the heart of CyberSmart. Our mission has always been to make effective cyber security accessible to every organisation, particularly SMEs who often face the same threats as large enterprises but with fewer resources.

The Pledge is also an important signal for the wider ecosystem. As National Ambassadors for the National Cyber Resilience Centre Group, we’ve seen first-hand what can be achieved when government, industry and local organisations work together. Improving national resilience isn’t something any single organisation can achieve alone.

For our MSP partners, this is another sign that cyber resilience is becoming a continuous business requirement rather than an annual compliance exercise. Partners have an increasingly important role in helping customers embed good security practices throughout the year, rather than simply preparing for a point-in-time assessment.

Ultimately, resilience is built through thousands of organisations making better decisions every day. The Cyber Resilience Pledge provides a simple framework for doing exactly that.”

CyberSmart’s signed pledge declaration is available on our website, alongside more information about the actions we are taking.

2026 Mid-Year Cyber Review

Six months in: the UK cyber landscape at the halfway point of 2026

Threat volumes are up, new legislation is advancing through Parliament, certification requirements have tightened, and the regulatory expectation behind Cyber Essentials has hardened across government, regulators, and supply chains.

This is CyberSmart's mid-year review, covering the threat data, policy and legislative developments, certification changes, and what it all means for managed service providers heading into H2.

The threat data

Verizon's 2026 Data Breach Investigations Report, based on more than 31,000 security incidents across 145 countries, found that vulnerability exploitation has overtaken credential theft as the most common initial access vector for the first time in 19 years. Exploitation now accounts for 31% of initial access, up from 20% the year before. Credential abuse has fallen to 13%. These are global figures rather than UK-specific data.

The UK Cyber Security Breaches Survey 2025/26 provides the domestic picture. Seven in ten businesses say cyber is a senior management priority. The data shows how far the actions lag behind that. The full breakdown:

  • 43% of UK businesses and 28% of charities reported a breach or attack in the past 12 months
  • For medium businesses the figure rises to 65%, and for large businesses to 69%
  • Phishing affected 38% of businesses and accounted for more than half of all attacks experienced by organisations that were hit
  • Ransomware prevalence roughly doubled year-on-year, from under 0.5% to approximately 1% of businesses, equating to around 19,000 UK organisations
  • Only 30% of businesses carried out a cyber risk assessment
  • Only 25% had a formal incident response plan
  • Only 15% reviewed the cyber risk posed by their immediate suppliers
  • Only 3% require suppliers to hold Cyber Essentials
  • Board-level responsibility for cyber security rose to 31%, reversing a multi-year decline
  • Cyber Essentials certification among businesses rose from 3% to 5%, though around a quarter of businesses report having controls across all five CE areas without holding the certification
  • The proportion of micro businesses able to recover from their most disruptive breach in under a day fell from 92% to 86%

CyberSmart's third annual MSP Survey, conducted with 350 MSP leaders across the UK and Ireland, found that three quarters reported their clients had experienced a breach in the past year. Two in five had dealt with a supply chain incident. Respondents named AI-enabled threats as their top concern, ahead of ransomware and phishing.

Incidents and threat actors

The NCSC recorded 204 nationally significant incidents in the 12 months to September 2025, more than double the 89 from the year before. At CYBERUK 2026 in April, NCSC Chief Executive Richard Horne disclosed that the composition of those incidents had shifted. Where attacks were previously dominated by criminal actors, the majority now originate directly or indirectly from nation states.

On 7 April, the NCSC published an advisory on Russian state-backed activity. The advisory attributed DNS hijacking operations to APT28, also known as Fancy Bear, a group the NCSC links to Russia's GRU Military Unit 26165. The attacks exploit vulnerabilities in SOHO routers, including TP-Link and MikroTik models, to redirect internet traffic through attacker-controlled servers and harvest login credentials including passwords and authentication tokens. The NCSC describes the activity as opportunistic in nature, with attackers casting a wide net before filtering down to targets of intelligence value.

On 23 April, on day two of CYBERUK 2026, the NCSC and 15 international partners published a joint advisory on China-nexus covert networks. State-linked actors are using large networks of compromised devices, principally SOHO routers, firewalls, network-attached storage, and IoT and smart devices, to route malicious activity and evade detection. A full technical advisory and executive summary are available from the NCSC.

In May, the NCSC CTO published a warning about an anticipated surge in software patches across open source, commercial, proprietary, and SaaS products, driven by AI's increasing ability to exploit accumulated technical debt at scale. The NCSC recommends enabling automatic updates wherever available, prioritising internet-facing systems, and replacing or removing from scope any software that can no longer receive security updates.

Speaking at RSAC 2026, Horne referenced economists who attributed the UK's October 2025 negative GDP print to the downstream effects of a single cyber attack on a major manufacturer.

Policy and legislation

The Cyber Security and Resilience Bill completed all Commons stages in the first half of 2026. The Bill received its second reading on 6 January, the same day the government separately published its Cyber Action Plan, a document driven by a new Government Cyber Unit and designed to improve visibility of cyber risks across public services, strengthen central oversight, and enable faster responses to attacks. The Public Bill Committee met from 3 to 24 February and reported by 5 March. Report stage and third reading both took place on 10 June 2026, after which the Bill passed to the House of Lords. Royal Assent is expected later in 2026, though phased implementation means it may not fully come into force until 2028.

The Bill extends the existing NIS regulatory framework to cover managed service providers and data centres for the first time. It introduces tougher incident reporting obligations, a broader definition of regulated entities, and a two-band, turnover-based financial penalties regime that was not available under the existing NIS framework. It represents the most substantial expansion of the UK's cyber regulatory scope since the NIS Regulations were introduced in 2018.

On ransomware, the government confirmed in 2026 that it will proceed with all three proposals from its 2025 consultation: a mandatory incident reporting regime for ransomware attacks, a requirement to notify the government before making a ransom payment, and a ban on ransom payments by public sector bodies and critical national infrastructure operators. These measures are not yet law. In healthcare, supply chain action has moved ahead independently of legislation.

From January, NHS England moved beyond voluntary commitments in its Cyber Security Supply Chain Charter to direct engagement with technology suppliers, contacting them to discuss cyber security controls and requesting supporting evidence where suppliers deliver services critical to patient care or operational continuity.

At CYBERUK 2026 in Glasgow, the government announced £90 million to improve cyber resilience across the economy, directed primarily at small and medium-sized businesses. The Cyber Resilience Pledge launched on 22 April 2026, committing signing organisations to make cyber a board-level responsibility, to sign up to the NCSC's free Early Warning Service, and to require Cyber Essentials across their supply chains. The Minister for Cyber, speaking separately at the New Statesman, confirmed the government's position that Cyber Essentials is the baseline standard for supply chain security across the UK economy.

The UK Energy Sector Cyber Security Strategy was published on 28 May 2026 by the Department for Energy Security and Net Zero, Ofgem, NCSC, and the National Energy System Operator. It sets out strategic objectives and a call to action for organisations operating across the energy supply chain.

In the defence supply chain, Cyber Security Model version 4 launched in December 2025, introducing Defence Cyber Certification (DCC) as the assurance framework for Ministry of Defence suppliers. DCC Level 0 is the minimum certification standard, with higher levels required depending on contract requirements. While DCC is not yet a legal requirement, contracts are already commercially requiring it. The scheme was developed through the Defence Cyber Protection Partnership and is based on NCSC standards, following the Strategic Defence Review's finding that UK Defence carried intolerable levels of cyber risk.

Certification changes

Cyber Essentials introduced a new question set, Danzell, in April 2026, replacing the previous Willow set. The two biggest changes are a hard auto-fail on multi-factor authentication for cloud services, and a stricter interpretation of the 14-day patching window for high and critical vulnerabilities. Cloud scoping has also been tightened. Both the MFA and patching requirements existed under Willow, but Danzell removes the interpretive flexibility that some organisations had been using to pass certification without fully meeting the intent of the controls.

The ICO stated in May 2026 that it expects organisations using or storing personal data to have the five Cyber Essentials controls in place, explicitly linking CE compliance to data protection obligations.

CE is now mandatory for public sector contracts over £5 million, required across the MOD supply chain under the DCC framework, and a condition for NHS Supply Chain suppliers handling NHS data, where Cyber Essentials Plus is the required level. The Cyber Resilience Pledge extends that further, asking signing organisations to require CE across their own supply chains.

CyberSmart's NIS2 compliance research found that only 16% of businesses consider themselves fully NIS2 compliant. The Cyber Security and Resilience Bill will impose comparable obligations once passed. For businesses that fall in scope, the compliance gap is likely to be substantial.

What it means for MSPs going into H2

Across the first half of 2026, the threat picture, legislative environment, and certification requirements have all moved in the same direction. Incident volumes are up, with the majority of nationally significant incidents now attributed to nation-state activity. The Cyber Security and Resilience Bill is advancing toward Royal Assent and will bring MSPs into regulatory scope for the first time. Danzell has raised the bar on CE certification. And the ICO, the government, and the Cyber Resilience Pledge have each explicitly named CE as the expected baseline.

For MSPs, the second half of the year brings concrete pressures. Client patch postures need to meet the 14-day Danzell requirement at scale. CE certifications need to accurately reflect client controls following the question set change. Clients operating in the defence supply chain need to understand their DCC obligations. And client cyber insurance needs to reflect the risk profile that the survey data now describes.

The fundamentals that address most of this have not changed: Cyber Essentials, consistent patch management, MFA, staff training, and supply chain visibility. What has changed is the weight of expectation behind them.

Behind every statistic and update in this review are businesses that need better cyber support than they currently have. CyberSmart is built to help MSPs do that at scale: Cyber Essentials certification across client estates, patch and vulnerability management that keeps clients compliant with Danzell's 14-day requirements, and security awareness training that addresses the human risk behind so many of the breaches the survey data describes.

Become the MSP your clients need right now.

The #1 Breach Entry Point and What MSPs Should Do About It

Vulnerability Exploitation: The #1 Breach Entry Point

For the first time in 19 years, stolen credentials are no longer the most common way attackers gain access to organisations. According to Verizon's 2026 Data Breach Investigations Report, which draws on analysis of more than 31,000 security incidents across 145 countries, vulnerability exploitation now accounts for 31% of initial access vectors, up from 20% the previous year. Credential abuse has fallen to 13%.

The reason for the shift is in the remediation data. Only 26% of critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalogue were fully remediated by organisations in Verizon's dataset during 2025, down from 38% the year before. The median time to patch rose to 43 days, up from 32. At the same time, both the NCSC and Verizon's own analysis point to exploitation cycles accelerating, with AI shortening the gap between a vulnerability being disclosed and it being weaponised. Remediation is slowing down at the same time that exploitation is speeding up.

The patch wave the NCSC is warning about

In May 2026, NCSC Chief Technology Officer Ollie Whitehouse set out a clear argument: AI is now capable of exploiting technical debt across the software ecosystem at scale. The result, he argues, will be a forced correction: a high volume of updates across open source, commercial, proprietary, and SaaS products that organisations will need to apply quickly and across their entire stack. He calls it a patch wave, and the NCSC's message is that organisations should be preparing for it now, not when it arrives.

The practical recommendations are clear: identify and minimise internet-facing attack surfaces first, enable automatic updates wherever they are available, and operate with an update-by-default policy. For third-party applications and embedded devices where automatic patching is available, the NCSC's position is that it should be switched on. Where it is not, organisations need processes capable of handling frequent, scaled patching without introducing disruption to operations.

There is also a harder point buried in the guidance. Patching will not always be enough. Where systems are end-of-life and cannot receive updates, they need to be replaced or removed from scope entirely. Internet-facing legacy systems with no update path are, in the NCSC's assessment, among the highest-risk exposures an organisation can carry, and the patch wave will not fix them.

That volume of incoming patches lands directly on top of a requirement that is already in place.

What Cyber Essentials requires

Cyber Essentials already has a hard patching requirement. Software rated high or critical severity must be patched or mitigated within 14 days of an update becoming available. Unsupported software with no available updates must be removed from scope or replaced. This is a pass/fail condition for certification, and it applies to the full in-scope estate, including third-party applications.

The DBIR's remediation figures put that requirement in sharp relief. A median patching time of 43 days across Verizon's global dataset suggests a significant gap between how most organisations currently approach patching and what CE demands. These are not UK-specific figures, and they describe a broad dataset rather than CE applicants specifically. But the direction is clear, and the 14-day window is not a soft target.

In May 2026, the ICO stated it expects organisations handling personal data to have the five Cyber Essentials controls in place. The government named CE as the supply chain baseline in its Cyber Resilience Pledge at CYBERUK 2026. The patching requirement has always been part of the scheme. What is changing is the weight being placed on it from outside.

For MSPs, that external pressure lands directly on how they deliver patch management to clients.

Why this matters for MSPs specifically

Patch management across multiple client environments at a 14-day cadence cannot be run manually. The volume is too high, the software estates are too varied, and the consequences of missing a critical update are now serious enough that it cannot be treated as a background task. For MSPs managing ten, twenty, fifty, or even more clients, the only realistic path to consistent compliance is automation.

The third-party application layer is where the gap tends to be largest. Standard RMM tooling handles OS patching adequately in most cases, but third-party software across Windows and macOS frequently falls outside that coverage. The NCSC explicitly identifies this as part of the attack surface that needs to be addressed, and it is the area where manual processes are most likely to slip.

Visibility matters as much as the patching itself. Knowing precisely what is running across each client environment, which vulnerabilities are present, and how to prioritise remediation is what makes patch management a service rather than a best-effort. Without that visibility, MSPs cannot demonstrate to clients, auditors, or supply chain customers that the 14-day window is being met.

That evidence is increasingly being asked for. The ICO expects CE controls to be in place across organisations handling personal data. The government has set CE as the supply chain baseline. Clients operating inside larger supply chains are facing increasing scrutiny of their security posture, and the expectation that it is actively managed and evidenced is part of that.

Most SME clients cannot build this capability themselves. The tooling, automation, and ongoing management required is exactly what a well-equipped MSP provides. The question worth asking, as the regulatory pressure increases and the patch wave approaches, is whether your current patch management capability can actually demonstrate compliance at scale.


CyberSmart Patch gives MSPs deeper coverage across hard-to-patch third-party applications, with automatic updates, full scheduling control, and clear visibility over vulnerabilities that standard RMM tooling often overlooks.

CyberSmart Vulnerability Manager (CSVM) provides continuous scanning, prioritised remediation insights, and audit-ready reporting across all client environments, so the evidence of compliance is always there when it is needed.

Cyber Essentials Just Had a Big Week

Last week at CYBERUK 2026 in Glasgow, Security Minister Dan Jarvis announced a £90 million government investment in cyber resilience, formally launched the Cyber Resilience Pledge, and named Cyber Essentials as a central pillar of the government's response to the growing threat to UK businesses. This week, the Danzell question set comes into effect, introducing significant changes to how Cyber Essentials assessments are conducted.

The context behind the speech

The CYBERUK speech did not come out of nowhere. A month earlier, NCSC CEO Richard Horne had been making the same case at RSAC. In his keynote address, he described cyber defence in terms of near, mid, and far space. The near space, he said, is every organisation getting the basics right consistently across their networks and supply chains: "behaviours that we refer to as Cyber Essentials."

He put a number behind it: the UK recorded negative economic growth in October last year, which Horne linked in part to the downstream effects of a single cyber attack on a major manufacturer. One attack, one supply chain.

Jarvis's speech in Glasgow was, in some ways, the policy response to that diagnosis. The government's own Pledge Information Pack puts the average cost of a significant cyber attack at almost £195,000 per business, scaling to an estimated £14.7 billion annually across the UK economy. The full detail of how the £90 million investment will be allocated is expected when the National Cyber Action Plan is published later this summer.

The Pledge also does not arrive in a vacuum. Since April 2025, Procurement Policy Note 01/25 has made Cyber Essentials mandatory for all public sector suppliers bidding on contracts over £5 million. The Defence Cyber Certification scheme, which came into force in December 2025, requires CE as the baseline across all four certification levels for MOD suppliers. In healthcare, NHS Supply Chain requires Cyber Essentials Plus from suppliers handling NHS data or providing IT and digital services, under PPN 014. The Pledge builds on that existing architecture rather than starting from scratch.

What the Pledge actually commits organisations to

The Cyber Resilience Pledge went live on 22 April, the same day as the CYBERUK speech. It formalises a ministerial letter sent to FTSE 350 companies and other major organisations back in October 2025.

Signing organisations commit to three specific actions.

Make cyber a board responsibility. Implementing the Cyber Governance Code of Practice and ensuring all board members complete the NCSC's Cyber Governance Training within three months of signing, then annually.

Sign up to Early Warning. Registering for the NCSC's Early Warning service within one month. It is free, takes around five minutes to set up, and flags potentially suspicious activity on the organisation's network.

Require Cyber Essentials across supply chains. This is the one most directly relevant to anyone reading this. Signing organisations must register for the Cyber Essentials Supplier Check Tool within two months of signing, conduct a comprehensive audit of CE coverage across their entire supply chain, present those findings to the board, and take a risk-based approach to requiring CE from suppliers. The Pledge Pack is explicit that this may include requiring it from all suppliers, and that where it is not required, the board must ensure that decision aligns with their risk appetite and that assurance is obtained by other means.

Signatories also commit to publishing the signed declaration on their website and providing an annual public update on progress.

The Pledge is voluntary. But signing organisations are listed publicly, and the government has said it will seek opportunities to recognise those that implement the actions. The Pledge Pack also notes that where organisations have mandated Cyber Essentials from their third parties, they have seen up to an 80% reduction in cyber incidents. That is the commercial logic the government is leaning on to drive adoption.

*Worth noting: the Pledge does not require signing organisations to hold Cyber Essentials certification themselves, though the government encourages it. The specific focus of this action is on driving CE uptake through supply chains rather than requiring it of larger organisations directly.

The Pledge lands directly on MSP clients

The supply chain action in the Pledge is not abstract. When a major organisation commits to auditing CE coverage across its supplier base and presenting findings to its board, that audit lands on the SMEs and IT service providers in its supply chain. MSPs are the ones who will field the questions, and the commercial and regulatory pressure building behind that conversation is growing.

As our Founder, Jamie Akhtar, wrote recently, MSPs have moved well beyond traditional IT support. They are embedded operators inside the digital infrastructure of thousands of organisations, with privileged access that makes them a compelling upstream target. A single compromised MSP can cascade across an entire client base. That is not a theoretical risk.

The Cyber Security and Resilience Bill, currently progressing through Parliament, will bring an estimated 900-1,100 MSPs into regulatory scope: those with 50 or more employees and turnover exceeding €10 million. That means registering with the Information Commission (IC) (formerly the Information Commissioner’s Office, or ICO), maintaining appropriate security measures, and reporting incidents.

77% of MSP leaders globally already report increased scrutiny of their security credentials from customers and prospects, and that was before the Pledge existed. As major organisations take on these commitments and begin auditing their supply chains, that scrutiny is likely to increase further. Cyber Essentials is the most straightforward way to answer the question when it comes.

Frontier AI is making the basics more important, not less

Frontier AI refers to the most advanced AI systems currently available: models that can reason, write code, automate tasks, and assist with complex work including cyber operations.

In his CYBERUK 2026 keynote, Richard Horne said frontier AI is already enabling the discovery and exploitation of existing vulnerabilities at scale, exposing where cyber fundamentals are still missing: patching, legacy systems, and vulnerable code. In a separate NCSC post on AI and cyber defence, the NCSC made the Cyber Essentials point directly: AI will make it easier, faster, and cheaper to discover and exploit weaknesses, and government-backed certifications like Cyber Essentials give organisations confidence that critical disciplines are being practised.

For SMEs and MSPs, that brings the argument back to basics. MFA, patching, secure configuration, access control, and malware protection are not frontier controls. They are the controls that keep the front door shut. As AI makes weak points easier to find and exploit, Cyber Essentials becomes more important, not less.

What Danzell actually changed

The Danzell question set is now live. Glen Patrick, our Head of Cyber Audit, has written a full breakdown of every change. The short version: the five core controls are unchanged, but three conditions now result in automatic assessment failure where previously they did not.

MFA on cloud services. If MFA is available on a cloud service and has not been enabled, the assessment fails immediately. This applies whether MFA is free, included, or only available as a paid option. There is no partial credit for having it enabled on some services but not others.

Patching operating systems and firmware. High-risk or critical updates must be applied within 14 days of release. Missing this is now an automatic failure.

Patching applications. The same 14-day window applies to applications, including associated files and extensions.

Cyber Essentials Plus has been tightened too. Organisations can no longer pass an audit by remediating only the devices included in a sample. Fixes must be applied across the entire in-scope estate. The verified self-assessment also needs to be complete before CE Plus testing begins.

For the full picture, read our blog post or download our Danzell guide.

What to do with all of this

The NCSC handled over 200 nationally significant incidents last year, more than double the year before. Jarvis cited ransomware attacks on children's nurseries, compromised logistics systems, and a recent incident involving Jaguar Land Rover. The point he was making: this is not a future problem. It is here, and it moves through supply chains.

For MSPs, the immediate priority is getting ahead of the Danzell changes before the first renewal cycle surfaces them. Sweep MFA across all client cloud services now. Verify that patching processes meet the 14-day requirement across the full estate, not just the devices most likely to be sampled. If any clients are due for CE Plus, make sure the VSA is complete before the audit is booked. The preparation conversation needs to happen earlier than it used to.

On the Pledge: if your clients sit in regulated industries, public sector supply chains, or any organisation likely to be in scope of DSIT's outreach, start the CE conversation now. The opportunity is bigger than one-off supplier checks: large organisations will need supplier assurance as a programme, with visibility of CE and CE+ coverage, critical supplier mapping, and scaled support to uplift suppliers. CyberSmart works with MSPs to deliver that end-to-end at scale.

For SMEs, the position is fairly simple. Cyber Essentials is the most accessible way to demonstrate your security controls meet a recognised government standard. The declaration is already public on gov.uk. Any buyer that signs commits to auditing their supply chains for CE coverage.

As Jarvis put it directly: “basic cyber hygiene is no longer optional, but the baseline, the absolute minimum we should expect of any serious organisation operating in the modern economy.” The scheme now enforces that more rigorously than it did before.

How CyberSmart can help

As the UK's leading Cyber Essentials certification body, this is squarely what we do.

For MSPs, we support the full certification lifecycle: fast, supported CE and CE+ with unlimited resubmissions and expert guidance, Active Protect for year-round compliance monitoring between certifications, patch management to keep client estates inside the 14-day Danzell requirement, and CSVM for continuous vulnerability visibility. If clients are coming to you with Pledge-related questions about their supply chain, we can help you answer them.

For SMEs, getting certified with CyberSmart takes as little as 24 hours. The platform guides you through the assessment, an IASME-accredited auditor reviews it, and eligible organisations receive £25,000 free cyber insurance on certification.

Find out more about getting certified with CyberSmart.

CyberSmart Partners with Renaissance

Dublin, Ireland – 22/04/2026 – Renaissance and CyberSmart Partner to Deliver Complete Cyber Confidence for SMEs

Renaissance has announced a strategic partnership with CyberSmart, a UK-based cybersecurity provider focused on delivering continuous protection, compliance, and cyber risk management for small and medium-sized enterprises (SMEs).

This collaboration brings CyberSmart’s cybersecurity solutions to a wider market, spanning real-time threat detection, vulnerability management, compliance assurance, and cybersecurity awareness training. Designed for simplicity and scalability, the platform provides 24/7 protection across desktop and mobile environments, supporting modern IT infrastructures including remote working and bring-your-own-device (BYOD).

Fully compatible with existing systems, CyberSmart enhances security without adding complexity. Its ability to provide continuous visibility, automated patching, and audit-ready compliance aligned with standards such as Cyber Essentials Plus, ISO 27001, and NIS2 enables organisations to proactively manage cyber risk while reducing operational overhead.

Through this partnership, Renaissance will offer CyberSmart’s solutions to enterprises, MSPs, and MSSPs seeking to strengthen their security posture while simplifying cybersecurity management. The collaboration also enables partners to deliver scalable monitoring, training, and cyber insurance services together, helping clients manage cybersecurity more effectively.

Michael Conway, Managing Director of Renaissance, commented:

“CyberSmart enables us to deliver a simpler, more proactive approach to cybersecurity. It helps our customers stay secure while reducing complexity across their IT environments.”

Jamie Akhtar, CEO and Co-Founder of CyberSmart, added: 

“Our mission is to make cybersecurity accessible and effective for every organisation, no matter the size, especially as the threat and regulatory landscape continue to shift. For example, our recent research revealed that only 1 in 4 businesses say they are fully NIS2 compliant, despite the initial 2024 compliance deadline. This is largely down to budgetary and resource constraints, as well as general confusion. As leaders turn to MSPs and MSSPs for cost-effective cyber support, partnering with Renaissance allows us to bring clarity and confidence to businesses across Ireland at scale and with ease, helping them remain secure and compliant."

About CyberSmart

CyberSmart is a UK-based cybersecurity provider dedicated to delivering Complete Cyber Confidence to SMEs and the organisations that serve them worldwide. Trusted by over 7,000 businesses, CyberSmart helps organisations protect their people, processes, and technology through continuous threat detection, vulnerability management, compliance assurance, and cybersecurity awareness training. Its solutions support modern working environments across desktop and mobile devices, enabling businesses to reduce cyber risk, maintain compliance, and operate securely in an increasingly complex digital landscape.

About Renaissance 

Renaissance has been a trusted partner to Irish resellers and their customers for over 30 years. With the introduction of 35+ new, cutting-edge, and industry-leading Cyber Security and Compliance solutions in Ireland over the past five years, Renaissance has created a security ecosystem linking its Vendors, Value Added Resellers and End Users. Renaissance has built its reputation by offering leading-edge market technologies, excellent pre/post sales service to its extensive network base, and an ongoing desire to bring added value to its customers. The Renaissance team has founded and continues to run the Cyber Expo & Conference Ireland, now in its eighth year. For more information, please visit https://www.renaissance.ie  

Media Contact 

Michael Conway | mconway@renaissance.ie | +(353) 1 280 9410 

Director, Renaissance

Situating MSPs in the Modern Supply Chain

Situating MSPs in the Modern Supply Chain

Supply chain cyber risk is a defining security challenge of modern business. Research suggests that the average small and medium-sized business (SMB) in Europe has nine times more suppliers than employees, with a median of 800 suppliers. As for larger enterprises, the supply chain can be made up of thousands of organisations of varying sizes. With such complex connectivity between organisations of all sizes, it’s clear that supply chain risk is no longer a theoretical concern, rather one that business leaders must deal with head on. 

While we’ve made progress in recognising that risk is shared across ecosystems, we still haven’t fully reckoned with the role of one of its most critical components: Managed Service Providers (MSPs).

The Changing Role of the MSP

MSPs have evolved far beyond their traditional remit. They are no longer just providers of IT support, instead they are embedded operators within the digital infrastructure of thousands of organisations. The 2025 CyberSmart MSP Report found that 60% of customers now expect their cybersecurity and IT infrastructure, which is a big responsibility. As trusted partners, they manage endpoints, control identity layers, deploy security tooling and increasingly act as outsourced security teams for time and resource strapped SMEs. 

Managed compliance is becoming the next evolution of managed security. IT providers have moved from break-fix to managed services to managed security, and are now entering the era of compliance as a service.

In many cases, MSPs have a significant level of access to customer organisations. That level of access fundamentally changes the risk equation.

Attackers understand the value of targeting an MSP. Rather than targeting individual organisations, they are increasingly looking upstream as a way to achieve scale. A single compromise can cascade across an entire client base. It’s efficient, repeatable and, with a sharp rise of AI-enabled attack techniques, becoming even easier to execute. 

Supply chain security only works if responsibility is clearly assigned and proportionate to risk, not just broadly shared.

Regulatory Gaps and The Cyber Security Resilience Bill 

Whilst MSPs sit at the centre of the ecosystem, from a regulatory and standards perspective, they remain under-defined.

The UK’s Cyber Security and Resilience Bill, however, represents a positive step forward, particularly in its recognition that cyber risk extends beyond individual organisations and into the wider supply chain. MSPs that employ at least 50 people and have a turnover exceeding €10 million will be regulated, placing approximately 1,100 MSPs within its scope (for context, the UK is home to 12,867 MSPs, according to DSIT, as of 2025). What does this mean for those MSPs? 

If an MSP falls into scope, it must be registered with the Information Commissioner’s Office (ICO). The MSP must have appropriate and proportionate security measures in place to mitigate risk and any incidents must be reported to the ICO. 

However, it still lacks specificity when it comes to MSPs at large. They are implicitly included, but not explicitly addressed as a distinct and high-impact category. MSPs are not just another supplier. Their level of privilege, access and operational responsibility sets them apart. Treating them as part of a broad supplier base risks missing the systemic impact they can have, both positive and negative.

Shifting Expectations and Accountability

Whilst frameworks like Cyber Essentials, ISO 27001 and various best-practice guidelines are valuable, they are not designed specifically for MSPs. They don’t fully account for the multi-tenant environments MSPs operate in, the scale at which they deploy changes or the downstream risk they carry on behalf of their clients. 

What’s emerging, therefore, is a growing case for something more tailored, like a dedicated standard or certification framework for MSPs.

Not as an additional compliance burden, but as a necessary evolution of how we manage systemic cyber risk. CyberSmart’s 2025 MSP Report found that customers (or potential customers) are already scrutinising the security of MSPs they partner (or are considering partnering) with. In fact, 77% of MSP leaders globally said scrutiny of their businesses’ security capabilities has increased, suggesting that MSP customers are more aware than ever of the importance of good cyber credentials in a potential partner. A dedicated framework would make this unofficial good practice and due diligence on the part of the end customer more official, shifting the burden of responsibility and accountability from end user to MSP and standardising good cyber hygiene. 

A well-designed MSP framework would set a clear baseline for security controls, operational processes and incident response expectations. It would recognise the unique role MSPs play and provide a mechanism for validating that they are operating at an appropriate level of maturity. 

For customers, particularly SMEs, it would bring much-needed transparency. Selecting an MSP would no longer be a leap of faith based on marketing claims, but a decision grounded in verifiable security standards. This is especially important for SMEs that don’t have the time, knowledge or resources to carry out this research themselves.

For MSPs, it would help professionalise the sector further. Those already investing in robust security practices would be able to differentiate, while the broader market would be lifted through clearer expectations. If MSPs are regulated, will customers choose those that are over those that are not? Put it this way: If you had to choose from two high street banks, one that was regulated and one that was not - which would you pick? Regulation could have significant implications for the market - accelerate consolidations and a “race to the top” to meet the thresholds. Alternatively, and more likely, smaller MSPs will still voluntarily comply and demonstrate it through CAF assurance.

And for policymakers, it would offer a scalable way to strengthen national cyber resilience without placing unrealistic demands on individual businesses.

MSPs as Critical Infrastructure

We need to stop treating MSPs as an edge case in supply chain discussions and start recognising them as critical infrastructure in their own right. That means bringing them into the centre of regulatory frameworks, not leaving them implied within broader categories.

It also means acknowledging that the threat landscape is shifting faster than our governance models. 44% of MSP leaders note that emerging AI threats are the biggest threat to the MSP they work for. The unknown of these attacks raises the stakes significantly. However, MSPs have always been at the forefront of change, with a strong history of supporting customers through uncertain times. These professionals have scale and expertise unmatched by SME IT teams, and, with increasing digital complexity, they are well placed to help those organisations without security and technical skills to navigate change.

Ultimately, improving supply chain security is about recognising the industries and areas that matter most. MSPs are a critical cornerstone of many supply chains and leaving them behind when it comes to regulation poses significant security risk. 

If we want to build a more resilient digital economy, we need to ensure that the organisations with the greatest reach and influence are held to the highest and most appropriate standards. Anything less leaves a gap that attackers will continue to exploit. 

MSPs are often seen as the weakest link, let's make them the strongest line of defence. 

-Jamie Akhtar, CEO & Co-founder of CyberSmart