Cloudflare signs UK Cyber Resilience Pledge as founding member

The UK government has launched its Cyber Resilience Pledge, a voluntary framework designed to get organizations to commit to basic cybersecurity governance, board-level accountability, and supply chain security coverage. Cloudflare has joined the pledge’s founding cohort of signatories, continuing its work with the Department of Science, Innovation and Technology (DSIT), the National Cyber Security Centre, and other partners.

The pledge’s core principles—democratizing security, leadership accountability, and radical transparency—align closely with Cloudflare’s existing approach. Rather than representing a new set of commitments, the framework validates security practices Cloudflare has promoted for over a decade.

The threat landscape behind the pledge

The pledge arrives amid elevated cyber risk. In the first quarter of 2026, Cloudflare’s global network blocked an average of 234 billion cyber threats per day. The company recently mitigated a hyper-volumetric DDoS attack peaking at 31.4 Tbps. By the end of 2025, the UK had become the sixth-most targeted location globally for DDoS attacks, with threat actors increasingly focusing on application-layer services in financial services, aviation, and regional government infrastructure.

This trend is consistent with the UK Cyber Security Breaches Survey, which found that 43% of surveyed British businesses and 28% of charities suffered a cyber incident in the past year.

Frontier AI models are also reshaping the security landscape by lowering the barrier to entry for attackers, enabling more automated vulnerability scanning and more convincing phishing campaigns. Cloudflare recently published a defensive architecture for frontier cyber models that applies the same principle: security must evolve as quickly as the threats companies face. The harness architecture—from ML-based attack scoring to Zero Trust access controls—is available to customers today.

The pledge recognizes that collective defense is critical: most breaches still exploit well-understood gaps such as unpatched systems, weak access controls, or poor vendor oversight. Encouraging organizations to close those gaps through enhanced governance, monitoring, and implementation is a necessary starting point.

What cyber resilience actually means

Cyber resilience is increasingly recognized as a core business requirement. Customers expect services to be available, responsive, and trustworthy, even when the operating environment becomes more challenging due to increased attacks, outages, abuse, or complexity.

Resilience isn’t just about recovering after something goes wrong. It’s about designing security systems and operating models that can proactively track threat signals, absorb disruptions, and adapt. Security controls are what make resilience real.

Architectural principles for resilient security

Security as default, not a product tier

Cloudflare has offered baseline security protections to all users since its founding. It was the first to offer SSL certificates to all users, and it protects vulnerable voices through programs like Project Galileo and the Athenian Project. Its free plan includes unmetered DDoS protection regardless of attack size, duration, or volume, along with access to a global CDN and DNSSEC.

These capabilities historically required expensive hardware and specialist security teams. The pledge’s goal of raising the cyber resilience floor across the UK economy only works if small businesses, local authorities, public services, and startups can afford to participate.

The network as sensor

Cloudflare directly peers with more than 13,000 networks globally, so it sees attack patterns as they emerge. Threat intelligence collected in one part of the network can be turned into protection elsewhere in seconds. A threat detected during an attack on a customer in Singapore can become a rule protecting a customer in Sheffield moments later.

Eating our own cooking

Customers benefit from the same security products that safeguard Cloudflare’s own systems. Cloudflare employees use Access and Gateway to reach internal applications, and every request to an internal system requires hard key-based multi-factor authentication, posture checks, and cryptographically verified identity tokens. Security is tested on Cloudflare’s own infrastructure first.

Transparency and response

When security incidents or zero-day vulnerabilities emerge, Cloudflare publishes technical postmortems on its blog, sharing indicators of compromise and architectural retrospectives. After a significant outage last fall, the Code Orange effort mobilized engineering teams to rebuild for resilience, designing systems to “fail small” and building new tooling to enforce safer configuration changes.

Meeting the pledge commitments

Board responsibility and governance

Cloudflare’s Board of Directors treats cyber risk oversight as a core responsibility. The Board receives cybersecurity briefings from the Chief Security Officer on at least a quarterly basis, including direct threat briefings. The Audit Committee also receives quarterly briefings on enterprise risk management, with a specific focus on cyber risks and the process for reviewing and mitigating them.

Supply chain security and Cyber Essentials

Cloudflare requires critical suppliers to adhere to rigorous international security certifications, primarily ISO 27001 and SOC 2 Type II. These frameworks explicitly require firewalls, secure configurations, user access controls, malware protection, and patch management—the five core pillars of the UK’s Cyber Essentials program.

Cloudflare will adopt DSIT’s Cyber Essentials Supplier Check Tool for localized supply chain validation within the UK. For global suppliers where UK Cyber Essentials is not a practical certification, Cloudflare will accept equivalent international certifications like ISO 27001 as sufficient verification of robust security posture.

A continuous practice

Cyber resilience is not a one-time pledge but a continuous practice of building systems that fail safely, recover quickly, and learn to improve. For organizations across the UK, it means making cybersecurity a business-critical priority with leadership buy-in, teams that understand the threats, and supply chains managed for risk.

Cloudflare built its platform on the belief that security and resilience should be universal—available to both the smallest developer and the largest enterprise. The company stands with DSIT and the other signatories of this pledge, continuing its work to elevate cyber resilience across the UK.