Cyber Advisory Briefing - July 2026

Cyber Security Is Becoming a Supplier Requirement

The biggest shift in cyber security this month is not a new technology.

It is a change in expectations.

On 7 July 2026, the UK Government formally launched the Cyber Resilience Pledge, a voluntary initiative encouraging organisations to improve cyber resilience and strengthen security across their supply chains. More than 60 organisations signed the pledge at launch, including major UK brands such as Marks & Spencer, Tesco, Harrods, Whitbread and Nationwide.

A key commitment within the pledge is for organisations to adopt a risk-based approach to requiring Cyber Essentials throughout their supply chains. Signatories are also encouraged to assess supplier cyber resilience and improve governance at board level.

For many SMEs, this may be the clearest indication yet that cyber security is evolving from an IT concern into a commercial requirement.

"The next evolution of cyber security is assurance. Increasingly, customers want evidence that organisations can manage cyber risks effectively before they are trusted with access, data or contracts."

The Cyber Resilience Pledge: A Signal of Changing Expectations

The Cyber Resilience Pledge requires organisations to:

  • Make cyber security a board responsibility

  • Register for the NCSC Early Warning service

  • Assess Cyber Essentials coverage across their supply chains

  • Take a risk-based approach to requiring Cyber Essentials from suppliers

While the pledge is voluntary, it provides a strong indication of the direction many organisations are now taking. Large enterprises are increasingly expected to understand and manage cyber risks beyond their own networks, including those affecting suppliers and business partners.

What This Highlights

Many SMEs assume cyber security requirements mainly affect large organisations.

The reality is often quite different.

When enterprise organisations improve governance, they frequently seek greater assurance from the businesses they rely upon. This can include supplier assessments, security questionnaires, evidence of controls and recognised certifications.

Supply Chain Risk in Practice

Canvas Breach Affects Millions

A recent breach involving Instructure's Canvas platform demonstrated how a single supplier incident can create widespread downstream impact.

According to industry reporting, the breach generated more than half of all breach notifications issued during the first half of 2026. The incident affected educational organisations that relied upon Canvas and reignited concerns about third-party cyber risk.

While the incident was centred primarily on North American educational organisations, the lesson is universal.

Organisations do not always suffer cyber incidents because they have been hacked directly.

Increasingly, the route to compromise is through a trusted supplier, software provider or service partner.

SME Takeaway

The question is no longer:

"Are we likely to be attacked?"

Increasingly it may become:

"Can we demonstrate to customers that we take cyber security seriously?"

Businesses that can answer this confidently may find themselves better positioned when bidding for work, responding to supplier due diligence requests and renewing contracts.

UK Business Metrics

43%

Of UK businesses reported experiencing a cyber breach or attack during the previous 12 months.

65%

Of medium-sized UK businesses reported experiencing a cyber breach or attack during the previous 12 months.

Plain-English Threat Analysis

Cyber criminals continue to target the systems businesses trust most. This month saw active exploitation of vulnerabilities affecting remote access technologies and collaboration platforms used by organisations worldwide.

In plain English, many attacks are no longer forcing their way through the front door. Instead, they are exploiting weaknesses in the locks, keys and trusted systems that organisations depend upon every day.

Palo Alto GlobalProtect Authentication Bypass (CVE-2026-0257)

Security researchers observed ransomware operators exploiting a vulnerability affecting Palo Alto GlobalProtect VPN platforms. The flaw allowed attackers to bypass authentication controls and establish unauthorised VPN connections on vulnerable systems. Qilin ransomware affiliates have been linked to exploitation activity.

What This Means

VPN technology is often deployed to improve security.

However, when vulnerabilities exist within the platform itself, those same protections can become the attack path.

If your organisation uses GlobalProtect, ensure vendor guidance and patching recommendations have been reviewed.

Microsoft SharePoint Server Vulnerabilities

July also saw active exploitation of multiple SharePoint Server vulnerabilities. Security agencies warned that attackers were chaining flaws together to move from initial access to complete compromise of affected environments.

What This Means

Think of SharePoint as a digital filing cabinet containing valuable business information.

If attackers gain access, the objective is rarely the filing cabinet itself.

The objective is obtaining the keys to everything connected to it.

Organisations hosting on-premises SharePoint environments should prioritise patching and review exposure immediately.

What This Means for UK SMEs

Many SMEs occupy critical positions within larger supply chains.

Historically, customers focused primarily on price, quality and delivery capability.

Today, cyber resilience is increasingly becoming part of that conversation.

The Cyber Resilience Pledge formalises this trend. Signatories are committing to improve cyber governance and take a risk-based approach to Cyber Essentials within their supply chains. While this does not create mandatory requirements for every supplier, it signals the direction of travel for supplier assurance in the UK.

Organisations that prepare early are likely to find future procurement, supplier assessments and customer assurance conversations significantly easier.

Three Actionable Takeaways for SMEs

1. Review Customer Expectations

Check contracts, supplier questionnaires and procurement frameworks for cyber security requirements. Understand what customers may already be asking for and what they could ask for in future.

2. Assess Your Cyber Essentials Readiness

Cyber Essentials remains one of the most widely recognised methods of demonstrating baseline cyber security controls. Identifying gaps now is easier than being asked to prove compliance later.

3. Treat Cyber Security as a Board-Level Risk

Cyber security should no longer sit exclusively within IT. Directors and business owners should regularly review cyber risks, supplier dependencies and resilience plans as part of wider business governance.

Final Observation

Recent government initiatives continue to reinforce a simple message:

Cyber resilience is becoming a business responsibility rather than solely a technical one.

The organisations best positioned for future opportunities are likely to be those that view cyber security not just as protection against attacks, but as evidence of operational maturity and trustworthiness.

Praxium Cyber Advisory is a monthly briefing providing plain-English cyber risk intelligence for UK SMEs, business owners and decision-makers.

Previous
Previous

Cyber Advisory Briefing - August 2026

Next
Next

Cyber Advisory Briefing - June 2026