The UK Government has confirmed the measures that it expects to include in the Cyber Security and Resilience Bill, which it says will be laid before Parliament later this year.
The Cyber Security and Resilience Bill will use the Network and Information Systems (NIS) Regulations 2018 as a starting point and will update this framework to bring more organizations into scope and to broaden out the legislation.
The Policy Statement states that UK resilience is not improving at the rate necessary to keep pace with threats and says that the new measures will address vulnerabilities in cyber defences to minimise the impact of attacks and improve the resilience of critical infrastructure, services, and the digital economy.
Key highlights from the Policy Statement include:
Bringing more organizations into scope
The 2018 NIS Regulations cover five sectors (transport, energy, drinking water, health, and digital infrastructure) and some digital services (online marketplaces, online search engines, and cloud computing services). Twelve regulators (called ‘competent authorities’ in the regulations) are responsible for enforcing the regulations. The Cyber Security and Resilience Bill will broaden out these categories, ‘bringing more entities into scope and putting regulators on a stronger footing so that they can carry out their important duties’.
Particular areas highlighted in the Policy Statement are managed services providers and data centre operators.
Strengthening supply chain security
Currently there is no targeted mechanism to address critical digital supply chain vulnerabilities under the 2018 Regulations. The Cyber Security and Resilience Bill will enable the UK Government to set stronger supply chain duties for operators of essential services (OES) and relevant digital service providers (RDSP). It will also introduce a power for regulators to identify and designate specific high-impact suppliers as ‘designated critical suppliers’ (DCS), bringing them under comparable obligations as OES and RDSP. This will also extend to certain small and micro RDSPs where they play a pivotal role in supporting essential services.
Improving incident reporting
Many significant events go unreported under the current framework, limiting the ability to identify and assess vulnerabilities. The Cyber Security and Resilience Bill ‘will update and enhance the current incident reporting requirements for regulated entities by expanding the incident reporting criteria, updating incident reporting times, streamlining reporting, and enhancing transparency requirements for digital services and data centres’.
Industry comment
Matthew Geyman, Managing Director of Intersys:
“This move aligns the UK with global efforts like the EU’s NIS2 Directive and the US’s CIRCIA, ensuring that MSPs – who have unparalleled access to client systems – meet higher security standards. We’ve seen first-hand the gaps in cyber preparedness, and this bill is a positive step towards a stronger UK cyber readiness baseline. However, with £100K-a-day fines at stake, organizations must act now. The biggest priority isn’t just compliance – it’s resilience. Businesses should be focusing on continuous risk assessment, security monitoring, and enhanced staff training. Cyber Security as a Service will become essential.”
“For the insurance sector, the bill represents both a challenge and an opportunity. Rising cyber threats have driven premium increases and stricter underwriting standards, yet uptake of cyber cover remains low. By compelling organizations to enhance cyber security controls and reporting, this legislation could reduce risk exposure, providing insurers with greater confidence in underwriting cyber and business interruption (BI) policies.”
“The bill may also accelerate discussions around a ‘Cyber Re’ backstop, similar to Pool Re, to protect against systemic cyber risks. Given that supply chain attacks are a key breach vector, insurers will be watching closely how regulatory requirements influence security postures across critical national infrastructure and their wider supply chains.”






