Skip to main content

Cyber Security & Resilience Bill: What It Means for UK Organisations

Media Did You Just Receive a Text from Yourself? Learn What Smishing Scams to Expect

Cyberattacks are no longer only an IT problem.

An attack on a hospital, energy provider, transport network, data centre or technology supplier can disrupt services used by thousands of people and businesses.

The UK Government has therefore introduced the Cyber Security and Resilience (Network and Information Systems) Bill. The proposed legislation is intended to strengthen the security and operational resilience of essential services, digital providers and important technology supply chains.

The Bill would update and expand the existing Network and Information Systems Regulations 2018, commonly known as the NIS Regulations. These regulations already place cybersecurity and resilience duties on certain organisations operating essential and digital services.

However, the Bill is not limited to the organisations traditionally associated with critical national infrastructure. It will also affect managed IT providers, data centres and suppliers whose failure could cause serious disruption.

Even businesses that are not directly regulated may experience increased cybersecurity requirements from customers, insurers, regulators and supply-chain partners.

Is the Cyber Security and Resilience Bill Already Law?

As of 21 July 2026, the Cyber Security and Resilience Bill is still progressing through Parliament and is not yet law.

The Bill completed its House of Commons stages in June 2026. It received its second reading in the House of Lords on 14 July 2026, with the Lords committee stage scheduled to begin on 1 September 2026. The wording and requirements could therefore still change before the Bill receives Royal Assent.

Many of the detailed technical requirements will also be introduced through secondary legislation and regulatory guidance after Royal Assent.

Organisations should therefore monitor the Bill’s progress while beginning to prepare for the direction of travel.

Why Is New Cybersecurity Legislation Needed?

The existing NIS Regulations were introduced in 2018.

They currently apply to operators of essential services in sectors including:

* Energy
* Transport
* Healthcare
* Drinking water
* Digital infrastructure

They also cover certain digital services, including online marketplaces, online search engines and cloud computing services.

Organisations within scope must take appropriate and proportionate measures to protect the network and information systems used to provide their services. They must also report incidents that significantly disrupt those services.

However, technology and cyber threats have changed significantly since 2018.

Businesses and public services now rely heavily on cloud platforms, managed IT providers, interconnected supply chains and third-party data centres. An attack against one important supplier can therefore affect many organisations at the same time.

The Government’s reforms are intended to address these dependencies, improve incident reporting and give regulators stronger enforcement powers.

Which Organisations Will Be Affected?

The Bill does not regulate every UK business.

Its main focus is on organisations that provide essential or important digital services and the technology suppliers on which those services depend.

The expanded regime is expected to cover several new categories.

Managed Service Providers

Many organisations outsource some or all of their IT management to a managed service provider.

A managed service provider may be responsible for:

* IT support
* Remote monitoring
* Microsoft 365 management
* Backup management
* Network administration
* Firewall management
* Endpoint security
* Cloud management
* Security monitoring
* Incident response

These providers often have privileged access to their customers’ devices, networks, data and cloud services.

This access can make managed service providers attractive targets. A successful attack against one provider could potentially give criminals access to several customer environments.

Under the Bill, medium and large businesses meeting the definition of a relevant managed service provider will be brought within the NIS regulatory framework.

They will be required to register with the Information Commission, manage risks to the systems used to provide their services and report significant incidents. The legislation is intended to cover providers offering ongoing IT management where they connect to or otherwise access a customer’s network and information systems.

Small and micro managed service providers will generally be exempt from this specific measure. However, they may still be brought into scope if they are designated as a critical supplier.

Data Centres

Data centres support a significant part of the UK’s digital economy.

They host and support systems containing emails, business applications, financial records, customer information and public-sector data.

The Bill will classify data infrastructure as a relevant NIS sector and qualifying data centres as essential services.

Data centres meeting the proposed thresholds will need to:

* Notify and provide information to Ofcom
* Implement appropriate security controls
* Manage physical and operational risks
* Maintain service resilience
* Report significant incidents
* Inform affected customers where required

The Government currently proposes that data centres with a rated IT load of at least one megawatt will be in scope. Enterprise data centres used solely for their owner’s requirements would have a proposed threshold of at least ten megawatts.

These thresholds and other details could be changed through secondary legislation.

Large Load Controllers

The Bill will also bring large load controllers into scope.

These organisations manage electrical demand from connected devices, such as systems used to control electric vehicle charging during periods of peak demand.

As the UK becomes increasingly dependent on connected energy systems, a cyberattack against a large load controller could potentially affect the stability of the electricity network.

The Bill is therefore intended to introduce additional cybersecurity and resilience requirements for qualifying providers.

Critical Suppliers

One of the most important changes is the proposed ability for regulators to designate certain organisations as critical suppliers.

A supplier could be considered critical where it provides goods or services to a regulated organisation and disruption to that supply could significantly affect the economy or the day-to-day functioning of UK society.

A regulator would also consider whether the service could realistically be sourced elsewhere and whether the risk could be addressed through other regulations.

A designated supplier could then become subject to mandatory cybersecurity duties, regulatory inspections and enforcement action.

This means some businesses may become regulated because of the importance of the service they provide, even when their organisation would not otherwise fall within one of the main regulated sectors.

What Security Measures Will Organisations Need?

Regulated organisations will be expected to take appropriate and proportionate technical and organisational measures to manage cybersecurity and resilience risks.

The exact requirements will depend on the organisation, service, sector and level of risk.

However, businesses are likely to need to demonstrate controls in areas such as:

* Risk assessment
* Access management
* Multi-factor authentication
* Vulnerability management
* Security patching
* Endpoint protection
* Network security
* Secure configuration
* Data protection
* Backup and recovery
* Business continuity
* Incident response
* Supplier management
* Security monitoring
* Employee awareness
* Physical security

The focus is not only on preventing attacks.

Organisations will also need to consider how they will continue delivering important services when an incident occurs.

Cyber resilience means being able to prepare for, respond to and recover from an attack while limiting the impact on customers and service users.

New 24-Hour Incident Reporting Requirement

The Bill proposes significant changes to the way cyber incidents are reported.

Regulated organisations would be required to provide an initial notification within 24 hours of becoming aware of a reportable incident.

A more detailed report would then need to be submitted within 72 hours.

The National Cyber Security Centre would receive incident information at the same time as the relevant regulator.

The initial notification is intended to be relatively brief. It would generally identify:

* The affected organisation
* The service involved
* Basic information about the incident

The fuller report would include available information about:

* When the incident occurred
* Whether it is continuing
* The nature of the attack
* Its actual or likely impact
* Whether another regulated organisation was involved
* Information that may help the regulator respond

This is a significant operational requirement.

An organisation cannot meet a 24-hour reporting deadline if it does not know who will assess the incident, contact the regulator and approve the notification.

Incident response responsibilities will need to be agreed before an attack occurs.

More Incidents May Become Reportable

Under the current regime, reporting is primarily focused on incidents that cause significant disruption.

The Bill would broaden reporting so that certain attacks may need to be reported before serious disruption has occurred.

This could include an attacker gaining access to a critical system and positioning themselves to cause future damage, even where the organisation is still operating normally.

Reportable incidents may therefore include:

* Ransomware attacks
* Unauthorised network access
* Pre-positioning within systems
* Serious data compromises
* Spyware
* Attacks affecting system integrity
* Incidents likely to create significant disruption

The proposed reporting test considers factors such as the number of users affected, duration, geographical reach, service disruption and whether the confidentiality, authenticity, integrity or availability of data has been compromised. Further thresholds will be set through secondary legislation and regulator guidance.

Customers May Need to Be Informed

Relevant digital service providers, managed service providers and data centres may also be required to notify customers who are likely to have been affected by a significant incident.

This is intended to allow customers to take protective action.

For example, an affected customer may need to:

* Reset administrator passwords
* Revoke active sessions
* Block compromised connections
* Investigate suspicious activity
* Isolate devices
* Restore data
* Notify its own customers
* Contact its insurer
* Report the incident to another regulator

Providers will need reliable records showing which customers use each system and which organisations may be affected when an incident occurs.

Stronger Enforcement and Larger Fines

The Bill will reform the enforcement structure used under the NIS Regulations.

The Government proposes a simplified two-band penalty system.

For more serious breaches, the maximum penalty would be the higher of £17 million or 4% of the regulated organisation’s worldwide turnover.

For less serious breaches, the maximum would be the higher of £10 million or 2% of worldwide turnover. The detailed definition of turnover will be set through secondary legislation.

More serious failures are expected to include breaches of security duties and incident-reporting requirements.

Regulators would consider factors such as:

* The severity of the failure
* Action taken to reduce the impact
* Previous non-compliance
* The effect on service users
* The organisation’s cooperation
* The wider consequences of the incident

The purpose of these penalties is intended to encourage organisations to treat cybersecurity as an essential business responsibility rather than an optional IT expense.

Greater Powers for Government and Regulators

The Bill would give the Government and sector regulators additional powers.

Regulators may be able to:

* Request information
* Inspect systems and premises
* Assess compliance
* Interview relevant employees
* Issue enforcement notices
* Require security improvements
* Impose financial penalties
* Share relevant incident information

The Secretary of State would also receive powers to direct regulated organisations to take necessary and proportionate action where an imminent or active cyber threat creates a national security risk.

These powers are designed to allow the Government to respond more quickly to serious and emerging threats.

What Does the Bill Mean for Organisations Outside Its Direct Scope?

Many UK businesses will not be directly regulated under the Bill.

However, that does not mean they will be unaffected.

Regulated organisations will need greater assurance that their suppliers are secure.

This may result in customers asking suppliers to provide:

* Cybersecurity policies
* Cyber Essentials certification
* Penetration-testing reports
* Vulnerability-management records
* Incident response plans
* Backup and recovery information
* Business continuity plans
* Details of subcontractors
* Security questionnaires
* Evidence of employee training
* Information about previous incidents
* Contractual incident-reporting commitments

A regulated customer may also require suppliers to notify it quickly when an incident occurs.

Cybersecurity expectations may therefore flow down through contracts and supply chains.

A small business providing an important service to the healthcare, energy, transport, water or digital infrastructure sectors may need to meet higher standards even when it is not directly regulated.

What Should UK Organisations Do Now?

The Bill is still passing through Parliament, but organisations should not wait until the final requirements take effect before reviewing their security.

Establish Whether You May Be in Scope

Start by understanding the services your organisation provides.

Consider whether you are:

* An existing operator of essential services
* A digital service provider
* A data centre operator
* A managed service provider
* A large load controller
* An important supplier to a regulated organisation

Managed service providers should pay particular attention to whether they provide ongoing management of customers’ IT systems and have access to those systems.

Businesses should also identify whether their customers could regard them as an essential or difficult-to-replace supplier.

Identify Your Critical Systems

Create an accurate record of the technology used to deliver your important services.

This should include:

* Servers
* Cloud platforms
* Microsoft 365
* Business applications
* Network equipment
* Firewalls
* Remote access systems
* Backup platforms
* Data storage
* Third-party integrations
* Operational technology
* Supplier-managed services

You should understand what would happen if each system became unavailable.

This will help your organisation prioritise its security investment and recovery planning.

Review Your Cybersecurity Risks

A formal cybersecurity risk assessment should identify:

* Which systems are most important
* What information they contain
* Who can access them
* How an attacker may gain access
* Which vulnerabilities exist
* What security controls are already in place
* How quickly systems could be recovered
* Which suppliers create dependencies
* What the consequences of an incident would be

The assessment should be reviewed regularly and whenever major systems or suppliers change.

Strengthen Access Controls

Stolen passwords remain a common route into business systems.

Organisations should make sure that:

* Multi-factor authentication is enabled
* Administrator access is restricted
* Separate administrator accounts are used
* Former employee accounts are removed
* Shared accounts are avoided
* Passwords are securely managed
* Unusual sign-ins are monitored
* Remote access is properly protected
* Access is reviewed regularly

Privileged access should be treated as a particularly high risk.

An attacker who compromises an administrator account may be able to disable security controls, access confidential data and disrupt multiple systems.

Improve Patch and Vulnerability Management

Known vulnerabilities should be identified and corrected promptly.

Patch management should cover:

* Computers
* Laptops
* Servers
* Firewalls
* Network switches
* Web browsers
* Remote access tools
* Cloud applications
* Third-party software
* Mobile devices

Organisations should be able to demonstrate which devices are fully updated and which have missing or failed patches.

Unsupported systems should be replaced or isolated.

Test Your Backups

Backups are essential for recovering from ransomware, system failure and data loss.

However, a backup is only useful when it can be restored.

Your organisation should confirm:

* What information is backed up
* How frequently backups run
* Where copies are stored
* Whether attackers could delete them
* Who can access the backup platform
* How long data is retained
* How quickly systems can be recovered
* When restoration was last tested

At least one backup copy should be isolated or otherwise protected against alteration by an attacker.

Update Your Incident Response Plan

A regulated organisation may need to submit its initial notification within 24 hours.

Your incident response plan should therefore identify:

* Who receives security alerts
* Who decides whether an incident is reportable
* Who contacts the regulator
* Who informs the NCSC
* Who communicates with customers
* Who contacts the cyber insurer
* Who preserves evidence
* Who manages technical recovery
* Who communicates with employees and suppliers
* Who has authority to make urgent decisions

Contact details should be available even when normal email or IT systems are unavailable.

The plan should be tested through practical exercises rather than remaining as an unread document.

Review Your Suppliers

Organisations should understand which third parties have access to their data and systems.

Review:

* Managed IT providers
* Cloud providers
* Software suppliers
* Data centres
* Backup providers
* Telecommunications suppliers
* Security providers
* Payment processors
* Industry-specific platforms
* Subcontractors

Supplier contracts should explain cybersecurity responsibilities, access controls, incident reporting, data handling and what happens when the relationship ends.

You should also know whether important suppliers have tested business continuity and incident response plans.

Maintain Evidence of Compliance

Cybersecurity controls should be documented.

Organisations may need to provide evidence showing:

* Risk assessments
* Security policies
* Patch reports
* Access reviews
* Backup test results
* Incident records
* Employee training
* Supplier assessments
* Vulnerability scans
* Business continuity exercises
* Board-level reviews
* Actions taken to correct weaknesses

Security should not exist only as an informal understanding within the IT department.

Regulators, customers and insurers may expect evidence that controls are consistently managed.

Does Cyber Essentials Help?

Cyber Essentials is not a replacement for the requirements of the Cyber Security and Resilience Bill.

However, it provides a useful baseline for protecting organisations against common internet-based attacks.

The scheme focuses on five technical areas:

* Firewalls
* Secure configuration
* Security update management
* User access control
* Malware protection

The National Cyber Security Centre describes Cyber Essentials as the minimum cybersecurity standard recommended by the Government for organisations of all sizes.

Businesses seeking to improve their security can use Cyber Essentials as one part of a wider programme covering incident response, backups, monitoring, business continuity and supplier risk.

Cybersecurity Must Become a Leadership Responsibility

The Cyber Security and Resilience Bill reinforces an important message: cybersecurity cannot be left entirely to the IT department.

Senior leaders need to understand:

* The organisation’s most important systems
* The consequences of losing them
* The main cybersecurity risks
* Whether recovery plans have been tested
* Which suppliers create dependencies
* How incidents will be reported
* Whether suitable investment is available
* Who is accountable for improvements

Cybersecurity decisions affect operational continuity, customer confidence, regulatory compliance and the organisation’s reputation.

They must therefore form part of wider business planning and risk management.

How Hamilton Group Can Help

Hamilton Group helps UK organisations improve their cybersecurity, operational resilience and regulatory readiness.

We can help with:

* Cybersecurity risk assessments
* Microsoft 365 security reviews
* Multi-factor authentication
* Conditional Access
* Managed endpoint protection
* Security patching
* Vulnerability management
* Firewall and network security
* Secure backups
* Disaster recovery planning
* Incident response plans
* Cybersecurity awareness training
* Supplier security reviews
* Cyber Essentials support
* IT documentation
* Managed IT support

We can review your existing systems, identify potential weaknesses and help create a practical improvement plan.

Although the final requirements of the Bill may continue to develop, organisations can act now by strengthening their security, documenting their controls and making sure they can respond quickly when an incident occurs.

Call Hamilton Group today on 0330 043 0069 to discuss how we can help improve your organisation’s cybersecurity, resilience and readiness for future regulatory requirements.

This article provides general information and should not be treated as legal or regulatory advice. Organisations should obtain specialist advice about their specific obligations.