The UK’s Cyber Security and Resilience Bill: what it means for your organisation

Young man using a computer at his desk in a modern office

Cyber threats are evolving faster than ever.

In the year to September 2025, the National Cyber Security Centre (NCSC) managed 429 cyber incidents, almost half of which were classified as nationally significant. That's more than double the previous year. Meanwhile, cyber attacks are estimated to cost UK businesses £14.7 billion annually

The UK remains one of Europe's most targeted countries for cyber crime. In response, the government is introducing the Cyber Security and Resilience (Network and Information Systems) Bill, the most significant update to UK cyber regulation in nearly a decade.

The Bill passed through the House of Commons in June 2026 and is currently progressing through the House of Lords, with Royal Assent expected later this year.

For many organisations, this isn't just another compliance exercise. It represents a shift in how cyber resilience is managed, governed and enforced across the UK economy.

Why is the law changing?

The current Network and Information Systems (NIS) Regulations 2018 provided an important foundation for cyber resilience. However, the threat landscape has changed significantly since then.

Attackers increasingly target managed service providers (MSPs), technology partners and supply chains as a route into larger organisations and critical services. As a result, cyber resilience can no longer be viewed solely through the lens of your own systems.

The new Bill reflects this reality. It expands the range of organisations covered by regulation, introduces tougher reporting requirements and gives regulators stronger enforcement powers.

In short, organisations will be expected to identify cyber risks earlier, respond faster and take greater responsibility for risks throughout their supplier ecosystem.

Could your organisation be affected?

If your organisation relies on critical digital infrastructure, provides technology services or supplies regulated businesses, there is a strong chance the new requirements will affect you in some way.

Organisations already in scope

  • Essential service operators, including organisations in energy transport, health, drinking water and digital infrastructure.
  • Digital service providers, including cloud computing providers, online marketplaces and search engines. 

Organisations newly coming into scope

  • Managed service providers (MSPs). Medium and large MSPs will be regulated for the first time. This includes organisations delivering services such as ongoing IT support, helpdesk services and managed security services. The Information Commissioner’s Office (ICO) is expected to act as the regulator.
  • Data centres. Data centres with a capacity of 1MW or above will be classified as essential services and regulated by Ofcom.
  • Large load controllers. Organisations managing electrical demand at scale, including those supporting smart technologies such as electric vehicle charging infrastructure.
  • Designated critical suppliers. Organisations can be brought into scope regardless of sector or size where government determines that disruption could have significant national impact.

Not directly regulated, but still affected

Even if your organisation is not directly regulated, the Bill could still have significant consequences.

  • SMEs supplying regulated organisations. Expect increased customer scrutiny. Demonstrating cyber resilience is likely to become a commercial requirement, with customers seeking evidence through certification, assessments and contractual obligations.
  • UK organisations operating in the EU. While the Bill broadly aligns with the EU's NIS2 Directive, there are important differences. Organisations operating across both jurisdictions should prepare for dual compliance requirements.

What are the biggest changes?

Faster incident reporting

Organisations will be required to:

  • Submit an initial notification within 24 hours
  • Submit a fuller report within 72 hours
  • Share incident information with the NCSC

Importantly, reporting obligations extend beyond incidents that have already caused disruption. Significant cyber intrusions and ransomware events may also need to be reported.

Greater transparency for customers

Data centres, digital service providers and MSPs will be required to notify affected customers following significant cyber incidents.

Supply chain accountability

Organisations will be expected to understand, assess and manage cyber risks across their supplier networks, not just within their own operations.

Stronger enforcement powers

The Bill introduces a two-tier penalty framework:

  • Up to £10 million or 2 per cent of global annual turnover for less serious breaches
  • Up to £17 million or 4 per cent of global annual turnover for more serious failures, including failures to report incidents or meet security obligations
  • Ongoing penalties of up to £100,000 per day for continued non-compliance

For larger organisations, turnover-based fines could significantly exceed the headline figures.

Phased implementation

Some measures are expected to take effect shortly after Royal Assent. Others, including new requirements for MSPs, data centres and designated critical suppliers, will be introduced through secondary legislation.

Five practical steps to take now

Waiting for final implementation dates could leave you on the back foot. Taking action now will make future compliance significantly easier.

1. Confirm whether you're in scope

The scope of regulation is expanding. MSPs, data centres and organisations supporting regulated sectors should assess their position now.

2. Review your supply chain

Map critical suppliers and understand where cyber dependencies exist. Equally, consider what evidence of resilience your customers may soon expect from you.

3. Test your incident response capability

Could you identify, assess and report a material cyber incident within 24 hours?

Many organisations struggle to meet that timeframe. Tabletop exercises can help expose weaknesses before a real incident occurs.

4. Strengthen your cyber credentials

Frameworks such as Cyber Essentials and ISO 27001 provide a strong foundation. They can also help demonstrate diligence to regulators, customers and business partners.

5. Put cyber resilience on the board agenda

Cyber risk is no longer solely an IT concern.

The Bill reinforces expectations around governance, oversight and accountability. Boards should be confident they understand their organisation's cyber risk exposure and response arrangements.

Don't wait for the legislation to take effect

Although implementation will be phased, the direction of travel is already clear.

Organisations that start preparing now will be in a much stronger position than those waiting for regulatory deadlines to arrive.

A practical gap analysis can help identify areas requiring attention, whether that's governance, reporting processes, supplier oversight or incident response capability. Addressing these issues incrementally is typically more effective, less disruptive and less costly than a last-minute compliance programme.

Just as importantly, improving cyber resilience is about more than avoiding regulatory penalties. It's about protecting operations, supporting customers and building confidence in an increasingly complex threat landscape.
 

How Howden Risk Advisory can help

Navigating new cyber regulation can feel complex, particularly where the scope and implementation timetable continue to evolve.

Howden is helping organisations understand their obligations, assess preparedness and strengthen resilience before new requirements take effect.

Whether you need support determining whether you're in scope, reviewing supply chain exposures, testing incident response plans or undertaking a readiness assessment, our specialists can help.

To get in touch, please fill out the simple form below

Alternatively, if your enquiry relates to an urgent risk incident, please call 0345 076 2288.


If you are an existing client of Barnett Waddingham or Risk Evolves, who have now joined us to form Howden Risk Advisory, please get in touch with your usual contacts, or for any urgent risk incidents, please call 0345 076 2288.

Request a callback?

Our Website Terms and Conditions and Privacy Notice includes information on the scope of our service and how we will handle your data.

 

What to do if you are experiencing financial difficulties

We recognise that the current economic conditions are putting pressure on many households and businesses. At Howden, we are committed to finding ways to assist our customers who may require additional support during these times.

If you’re currently facing financial difficulty, please speak to us about your insurance policies by:-

-contacting your Howden Service Team; 
-calling Howden on 0207 545 2800;
-using the Enquiry form.

CAPTCHA