In the recent King’s Speech, which sets out the legislative programme for the upcoming Parliamentary session, the UK Government set out plans for a Cyber Security and Resilience Bill. This will aim to strengthen the UK’s cyber defences to ensure that critical infrastructure and the digital services that companies rely on are secure.
In background briefing notes published alongside the King’s Speech, the Government explained more about the Cyber Security and Resilience Bill, including the following:
The Bill will strengthen UK defences and ensure that essential digital services are protected, for example by expanding the remit of the existing regulation, putting regulators on a stronger footing, and increasing reporting requirements to build a better picture in government of cyber threats.
The existing UK regulations reflect law inherited from the EU and are the UK’s only cross-sector cyber security legislation. They have now been superseded in the EU and require urgent update in the UK to ensure that the UK infrastructure and economy is not comparably more vulnerable. [This implies that the legislation may be along the lines of the EU NIS2 regulations].
The Bill will make crucial updates to the legacy regulatory framework by:
- Expanding the remit of the regulation to protect more digital services and supply chains. These are an increasingly attractive threat vector for attackers. This Bill will fill an immediate gap in UK cyber defences.
- Putting regulators on a strong footing to ensure essential cyber safety measures are being implemented. This would include potential cost recovery mechanisms to provide resources to regulators and providing powers to proactively investigate potential vulnerabilities.
- Mandating increased incident reporting to give government better data on cyber attacks, including where a company has been held to ransom – this will improve understanding of the threats and alert regulators about potential attacks by expanding the type and nature of incidents that regulated entities must report.






