27 August 2026 | Comment | Article by Jonathan Askin

Cyber Security and Resilience Bill: What does it mean for your organisation?


The UK’s proposed Cyber Security and Resilience Bill marks a significant shift in how cyber risk is regulated. In many respects, the UK is playing catch up bringing its approach closer to more advanced regimes such as the EU’s NIS2 framework. The direction is clear: stricter oversight, broader scope, and materially higher stakes for non-compliance. But what is changing, and why should organisations act now?

What’s the current position?

Currently in the UK, cyber security is governed by the Network and Information Systems Regulations 2018 (NIS Regulations), which implemented the EU’s original NIS Directive into UK law. The regime applies to operators of essential services (e.g. energy, transport, water, health), and certain digital service providers (e.g. cloud platforms, search engines, online marketplaces), who must implement appropriate and proportionate cyber security measures and notify regulators of incidents that significantly impact service continuity (within 72 hours). While it may have been a step forward in 2018, it is now widely viewed as outdated.

What’s changing?

The regime is expanding, expectations are increasing, and the consequences are tougher.

Key developments include:

A wider scope

The regime will apply to a broader range of organisations, including:

  • Medium and large managed service providers;
  • Data centres above certain thresholds;
  • Large-scale electricity load controllers; and
  • “Critical suppliers” whose compromise could disrupt the economy or society.

This reflects clear policy shift. Cyber resilience is no longer confined to traditionally “critical” sectors. A significant change that this the Bill also introduces is the fact that supply chains and service providers are now firmly in scope.

Faster, more onerous reporting

Incident reporting obligations will tighten significantly:

  • 24 hours – initial notification to regulators
  • 72 hours – full incident report

This goes beyond the current position, which focusses on reporting incidents that have already had material impact.

Stronger regulatory powers and enforcement

Regulators will have greater flexibility to respond to emerging threats, alongside a substantial penalty regime, including:

  • Up to £10m or 2% global turnover (less serious breaches) where the person is an ‘undertaking’ (which is expected to be defined in secondary legislation);
  • Up to £17m or 4% global turnover (serious breaches)

Why is this important?

Much like the introduction of the UK GDPR, this Bill signals a significant shift in regulatory expectations. Cyber resilience is no longer just a technical issue, but a core governance and compliance priority for organisations operating in an increasingly interconnected risk environment.

The evolving threat landscape

Cyber-attacks are increasing in both scale and impact, targeting critical infrastructure, financial systems and public services.

International alignment

The UK is seeking closer alignment with global frameworks, particularly the EU’s NIS2 regime. While the UK is not adopting NIS2 wholesale, both frameworks pursue the same outcome: broader coverage, stronger accountability and improved transparency.

Closing regulatory gaps

The current regime under NIS has been criticised for limited scope and inconsistent enforcement. The Bill addresses both.

Who does it affect?

The Bill significantly broadens the category of affected organisations.

Beyond traditional critical sectors, businesses should consider:

  • whether they fall within newly in-scope categories;
  • whether they are part of a critical supply chain; and
  • whether their customers or partners may impose new contractual cyber obligations.

Supply chain risk is a key focus and the Government has indicated that secondary legislation may require organisations to:

  • impose cyber security requirements contractually;
  • carry out supplier assurance and monitoring; and
  • implement continuity and resilience planning.

This has clear implications for commercial contracts, particularly outsourcing and technology agreements.

When do you need to take action?

Now. Although the Bill is still progressing through Parliament, the direction is settled and implementation is expected to follow relatively quickly. More importantly, many of the required measures, particularly regarding governance, reporting and supply chain assurance, cannot be implemented overnight. Delaying preparation creates risks in terms of regulatory exposures, contractual implications, and operational vulnerability.

If you have any questions on the Cyber Security and Resilience Bill, get in touch with our specialist team.

Author bio

Jonathan Askin

Partner
Jonathan Askin is a commercial partner who has more than 20 years’ experience across all aspects of commercial law and has held senior leadership roles at Top 50 UK law firms. His practice covers commercial agreements, data protection, IP and business relationships, with sector experience spanning hospitality and leisure, technology, media and entertainment, gaming, manufacturing, retail, travel, rail, sport and the public sector. He regularly advises on complex commercial arrangements, including supply chain and outsourcing contracts, data and AI governance, and strategic risk allocation.

Disclaimer: The information on the Hugh James website is for general information only and reflects the position at the date of publication. It does not constitute legal advice and should not be treated as such. If you would like to ensure the commentary reflects current legislation, case law or best practice, please contact the blog author.

 

Next steps

We’re here to get things moving. Drop a message to one of our experts and we’ll get straight back to you.

Call us: 033 3016 2222

Message us

"*" indicates required fields

Name*