Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»UK Cyber Security and Resilience Bill takes a step forward (Page 3)
Cyber resilience

UK Cyber Security and Resilience Bill takes a step forward

November 13, 202511 Mins Read
A UK flag with digital overlay.

The UK Cyber Security and Resilience Bill was introduced in Parliament on 12th November. These proposed laws cover certain digital and essential services including healthcare, transport, energy, and water.

According to the UK Government, under the proposals:

  • Medium and large companies providing services like IT management, IT help desk support, and cyber security to private and public sector organizations like the NHS will be regulated for the first time. Because they hold trusted access across government, critical national infrastructure, and business networks, they will need to meet clear security duties. This includes reporting significant or potentially significant cyber incidents promptly to government and their customers, as well as having robust plans in place to deal with the consequences.
  • Regulators will be given new powers to designate critical suppliers to the UK’s essential services, such as those providing healthcare diagnostics to the NHS or chemicals to a water firm, where they meet the criteria. This would mean they would have to meet minimum security requirements, shutting down gaps in supply chains criminals could exploit, which could cause wider disruption.
  • Enforcement will include turnover-based penalties for serious breaches.
  • The Technology Secretary gets new powers to instruct regulators and the organizations they oversee to take specific, proportionate steps to prevent cyber attacks where there is a threat to UK national security.

Organizations in scope will need to report more harmful cyber incidents to their regulator and the National Cyber Security Centre (NCSC) within 24 hours, with a full report within 72 hours.

More details

Industry comments provided to Resilience Forward

Mayur Upadhyaya, CEO, APIContext:

“As regulatory frameworks like DORA highlight, resilience is about more than uptime. It’s about understanding the full digital supply chain: cloud dependencies, DNS behaviour, and the APIs that connect everything together. To manage that risk, we need to lift the bonnet and proactively test what’s under the surface. Without checks across third-party infrastructure, even minor disruptions can cascade into major outages, as demonstrated recently by prominent cloud providers. The UK’s Cyber Security and Resilience Bill is a step in the right direction, but operational resilience must include continuous testing, not just better incident reporting.”


Darren Guccione, CEO and Co-Founder, Keeper Security:

“The introduction of the UK Cyber Security and Resilience Bill marks a decisive step toward further strengthening the nation’s digital defences. Expanding the scope of existing NIS regulations to cover managed service providers, data centres, and other essential digital services reflects the reality that the UK’s critical infrastructure is only as secure as the weakest link in its digital supply chain.

The bill’s success will ultimately depend on the practicalities of its execution. Regulation in isolation doesn’t stop breaches, and organizations need adequate funding, support, and the appropriate technical solutions to ensure effective operational security. The majority of successful attacks still begin with compromised credentials, over-privileged accounts or weaknesses in third-party access. Addressing these fundamentals through robust identity and privileged access management should be a top priority for any organization falling within the bill’s remit.

The Cyber Security and Resilience Bill has the potential to modernise the UK’s approach to protecting its essential services and assets that citizens rely on, but it must be accompanied by an equal focus on persuading organizations to act swiftly and effectively – and providing the resources they need to do so. Building resilience isn’t about more compliance paperwork, it’s about ensuring every privileged session, every credential and every supplier connection is adequately protected with full visibility, security and control.”


Ev Kontsevoy, CEO, Teleport:

“The Cyber Security and Resilience Bill is going to motivate companies to transform how they secure access to critical infrastructure. Compliance will mean navigating through accumulated audit toil, making sense of patchworks of VPNs, shared credentials, and SSH keys that never expire.

“The Bill is not just another box-ticking exercise, but a perfect opportunity to transition from identity and access architectures based on secrets and vaults to one that is identity-based, coupled with just-in-time access that removes audit toil, accelerates users and engineers, and defends against attacks that target secrets compromise.

“This approach eliminates the risk of credential misuse and ensures that access is authorized only when work is being performed. Companies that take this step will meet compliance, and end up with stronger, leaner, and far more resilient security foundations that can additionally be readily extended to AI infrastructure.”


Mike Smith, Partner – Security, TXP:

“Further protections for vital infrastructure cannot come soon enough. With a recent spate of high-profile cyber attacks and outages hitting key industries, third- and fourth-party security can’t be ignored.

“With so many different companies providing IT management, IT help desk support, and cyber security to private and public sector organizations, like the NHS, attack surfaces have expanded. As a result, suppliers of all sizes must provide stronger assurances about their own security standards, so these new laws are a welcome first step.

“Ultimately, those companies that fail to meet required security levels or protect citizen data risk losing contracts. By conducting, security initiatives, such as red teaming and penetration testing, and developing robust processes around reporting, suppliers can be more proactive in safeguarding their own attack surfaces and as a consequence the security of their customer”.


Charlotte Wilson, head of enterprise, Check Point Software:

“The Government’s proposed updates are a welcome step towards creating greater accountability and commonality across the cyber security landscape. By bringing managed service providers and data centres into scope, the measures will help break down silos and encourage stronger collaboration across industries, ensuring cyber security is no longer seen as the sole responsibility of the CISO, but a shared board-level priority.

These reforms not only strengthen our collective resilience but also enable organizations to focus on maintaining business continuity, rather than treating security as an isolated function. However, for the proposals to be truly effective, we need to see stronger powers for the ICO and NCSC to compel boards to take action when risks are identified, alongside stricter governance around the procurement and oversight of outsourced third parties handling data. While nation-state threats remain a key concern in critical national infrastructure, many high-profile breaches have originated from weaknesses within outsourced supply chains; an area that must be governed with the same rigour as internal operations.”


Ian Nicholson, Incident Response Head, Pentest People:

“I think the bill is a really welcome step forward. It reflects what most of us in the industry already believe, that the security of our critical national infrastructure depends on the resilience of every single organization that supports it. The focus on stronger standards and faster reporting feels absolutely right to me. The first 24 hours after an incident often determine how things play out, so speed really does matter.

Most organizations have the best intentions, but they often lack visibility of their supply chains or the ability to act quickly when something goes wrong. This bill should help improve that visibility and raise standards across the board. It will also highlight where some organizations still have gaps, and that’s where I see real value. From our side, we see this as an opportunity to help our clients build genuine resilience. It’s no longer just a tick-box exercise. It’s about having well-rehearsed plans, clear escalation paths, and tested communication routes in place.”


Jamie Akhtar, CEO and Co-Founder, CyberSmart:

“Although we probably have a way to go before the bill is passed into law, this is still a big day for cyber security in the UK. If everything included in the bill were to be enacted, it would signal a huge step forward in the UK’s cyber resilience. For example, managed service providers, who provide much of the country’s IT and cyber security backbone, are set to be regulated for the first time. This is alongside other steps such as strengthening the ICO, enhanced regulatory powers for the state, and tougher turnover-based penalties to be brought in for serious offences.

This also follows the recent letter from government ministers to business leaders and FTSE 350 firms, urging them to strengthen their cyber defences to face down the growing range of threats targeting the UK’s leading organizations.

What we’re seeing is a government that has recognised the huge threats posed by cybercrime to the country’s critical national infrastructure and economic health, resulting in tougher cyber security-based responses across society as a result. While it’s not a remedy for the threat, it is a huge step in the right direction.”


Tim Pfaelzer, General Manager & Senior Vice President, EMEA, Veeam:

“The UK’s Cyber Security and Resilience Bill reflects the urgency of the threats currently being faced. Attacks aren’t just becoming more frequent and sophisticated, they are also becoming more targeted, going straight to CNI and their supporting supply chains to maximise damage. I’d encourage organizations to see this for what it is; not just a new compliance hoop to jump through in an already saturated regulatory landscape, but a call to work more collaboratively within their supply chains, and to embrace greater accountability.

Ultimately, introducing regulation is only half the battle. Ensuring that organizations buy-in to the new mandate, hold themselves accountable, and embrace new requirements on third-party risk management and incident reporting, is the next major hurdle.”


Ric Derbyshire, Principal Security Researcher, Orange Cyberdefense:

“The introduction of the Cyber Security and Resilience Bill is a welcome step towards strengthening and protecting the UK’s critical national infrastructure. Crucially, an area it focuses on is the complex nature of supply chains that support CNI. It’s easy for organizations to fall into the trap of thinking of their supply chains in the narrow terms of those immediately connected to them. By bringing new classes of service providers into scope, from managed service providers and data centre operators to suppliers whose goods and services support critical systems, the CSRB broadens the reach of national cyber regulation. 

This shift encourages organizations involved in CNI to recognise that security and resilience rely on an interdependent ecosystem, rather than a simple chain. The bolstered oversight and reporting powers introduced through the Bill represent a significant step-change in accountability.


Dray Agha, senior manager of security operations,  Huntress:

“The UK is finally catching up to the scale of modern cyber threats. This Bill signals that resilience is now a matter of national security, not a box-ticking exercise. By pulling managed service providers into scope, the Government is targeting one of the most exploited weak links in the digital supply chain; a move long overdue after years of attackers abusing trusted IT partners. 

The 24-hour reporting window raises the bar for transparency, forcing organizations to treat cyber incidents like any other public safety emergency, which requires rapid response and clear communication. Stronger penalties and proactive oversight mean complacency is no longer affordable: companies that invest early in security visibility, threat detection, and tested response plans will be the ones still standing when the dust settles.”


Trevor Dearing, Director of Critical Infrastructure, Illumio:

“Security across the public sector is too fragmented and a move towards a more centralised plan will be beneficial for establishing a unified security posture that is better suited to defending against cyber threats.

Third-party providers form the lifeblood of government departments. Cybercriminals will always target the weakest link in the chain to gain access to more valuable systems. A risk-based approach to security is key to achieving this, ensuring that the most threatened services receive the most resources.

The shift from reporting only successful breaches to reporting all cyber incidents is long overdue and will drive rapid improvements in how organizations protect their most critical assets and respond to attacks.

Granting the Technology Secretary new powers to ensure that regulators and organizations monitor or isolate high-risk systems is a smart move. The goal must be to reach a point where organizations can contain and limit the impact of attacks before they cripple essential services, isolating critical systems helps to achieve this.

Whilst it is understandable that the Government is introducing tougher penalties for poor security practices, it is equally important that sufficient support is provided to help organizations achieve compliance. The Government must ensure that investment is made in supporting organizations, particularly those with limited budgets.”

UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleThe governance gap: organizations are sleepwalking into an AI-generated crisis
Next Article Enterprise resilience trends explored in new Grant Thornton survey

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
UK Resilience Academy logo

Wargaming in a Resilience Context

August 18, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?