The recent high profile cyber attacks on Marks and Spencer and the Co-op have highlighted the devastating impact a cyber attack can have on an organisation and the importance of managing cyber risk in your supply chain. In this update we look at forthcoming laws and new Government guidance that aim to improve cyber resilience, including businesses and other organisations that rely upon managed service providers and third party software vendors.
Other recent high profile cyber attacks have affected the Ministry of Defence, NHS bodies and local authorities. In 2023, a number of well known charities were the subject of a cyber attack on a third party IT platform used to store information on supporters. Supply chain cyber risk doesn't just apply to an organisation's IT service providers - a cyber attack on a business critical supplier can also be highly damaging. For example, if a manufacturing business suffers a cyber attack on its logistics provider or the supplier of raw materials, then it may be unable to get products to market.
With Marks and Spencer reportedly losing more than £40m a week in sales and the Co-op experiencing widespread disruption to stock availability in store, the potential financial and reputational impact of a cyber attack is clear. In the case of Marks and Spencer, Marks and Spencer confirmed that hackers had gained access to its systems via a third party service provider, providing a timely reminder that organisations need to take a holistic view to cyber risk and focus on governance and supply chain risk.
To help organisations improve their cyber resilience and manage cyber security risk, the Government is proposing to introduce new legislation. This legislation will accompany a number of voluntary codes of practice that have been developed by the Government in conjunction with the National Cyber Security Centre.
Cyber Security and Resilience Bill
Cyber security laws have been in place in the UK since 2018, when the Network and Information Systems Regulations came into effect. These regulations implemented an EU Directive, and impose cyber resilience and reporting obligations on operators of essential services (such as transport, energy, water, and health) and certain digital service providers (DSPs) (cloud computing, online marketplaces and search engines).
Given the limited scope of the regulations, the Government consulted in 2022 on proposals to extend these rules into new sectors, with enhanced obligations around reporting and supply chain flow-down. In parallel, the EU replaced the NIS Directive with NIS2, which extended the rules to a number of new sectors. Member states were obliged to implement by 17 October 2024, though many member states missed this date.
A new Cyber Security and Resilience Bill was announced in the King's Speech in July 2024. Last month, the Secretary of State issued a policy statement providing more detail on what the Bill will cover:
- the extension of cyber security rules to new sectors and entities
- new rules for managed service providers (MSPs) of IT services to other organisations, similar to those rules that currently apply to cloud computing providers
- new supply chain duties for operators of essential services and relevant DSPs
- the ability for the Government to designate certain suppliers as critical suppliers
- improved incident reporting obligations including:
- 24 hour obligation for initial notification
- new obligations in relation to ransomware attacks
- transparency obligations requiring providers of digital services and data centres to alert customers who may be affected by incidents
- the ability for the Government to update the regulatory framework through regulations without needing further primary legislation.
The Government has also said that it is considering extending cyber resilience obligations to data centre operators, following last year's designation of data centres as critical national infrastructure.
The Government hopes that these measures will together improve the cyber posture of organisations across the UK. The extension of cyber resilience obligations to MSPs will in particular help large numbers of businesses, public authorities and third sector organisations that rely on third parties for critical IT services.
It is anticipated that the Bill will be introduced to Parliament in the course of 2025.
Cyber Security Codes of Practice
In addition to new legislation, the UK Government is developing modular codes of conduct to help improve cyber resilience.
These voluntary codes cover cyber governance together with specific cyber security codes of practice for software developers and distributors and the development of AI systems.
Cyber Governance Code of Practice
In April 2025 the Government published its Cyber Governance Code of Practice. The cyber governance code is intended to help boards and directors of public and private sector organisations to understand key cyber governance actions and manage cyber risk.
The code is accompanied by cyber governance training materials and toolkits for boards, which have been developed by the National Cyber Security Centre.
The code provides guidance across five key principles:
- Risk management
- Strategy
- People
- Incident Planning, Response and Recovery
- Assurance and Oversight
The code provides practical guidance for boards on how to put in place governance measures to manage cyber risk within an organisation. The code can be used by boards as a checklist to assess the adequacy of their internal governance arrangements and board oversight.
Software Security Code of Practice
In May 2025 the Government published the Software Security Code of Practice. This code of practice is designed to help improve the security and resilience of software by addressing concerns in relation to avoidable weaknesses in software development and maintenance and poor communication between software suppliers and their customers.
The code focusses on four key themes:
- Secure Design and Development
- Build Environment Security
- Secure Deployment and Maintenance
- Communication with Customers
The code is aimed at senior leaders in a number of different stakeholder groups, including software developers and distributors (including SaaS providers), software resellers, and software developers. Open source developers and maintainers are not a primary audience for the code, but may find some aspects o the code useful.
As with the Cyber Governance Code, the Software Security Code provides senior leaders with a checklist for managing software security risks. The code is supplemented by additional implementation guidance which is aimed at technical teams within software vendors.
While the primary audience for the Software Security Code is software vendors, the Government also hopes that customers will reference the Code when procuring software. For example, vendors will be able to reference compliance with the Code when customers are carrying out diligence on potential vendors, which in turn should help customers to manage their own cyber risk. Customers may also wish to reference the Code in invitations to tender and their supply chain policies.
Code of Practice for the Cyber Security of AI
Finally, in January 2025, the UK Government published a voluntary Code of Practice for the Cyber Security of AI. The AI Cyber Security Code was developed to address the specific cyber security risks with AI as opposed to software. This includes risks in relation to data poisoning (where rogue/incorrect data is deliberately used to damage the AI during LLM training), indirect prompt injection and model obfuscation. It is hoped that the code will help to ensure security by design in the AI supply chain and the adoption of baseline security requirements.
It is intended that the cyber security code will be used to help create a global standard for the cyber security of AI.
The Code of Practice for the Cyber Security is structured around a number of key principles:
- Principle 1: Raise awareness of AI security threats and risks
- Principle 2: Design your AI system for security as well as functionality and performance
- Principle 3: Evaluate the threats and manage the risks to your AI system
- Principle 4: Enable human responsibility for AI systems
- Principle 5: Identify, track and protect your assets
- Principle 6: Secure your infrastructure
- Principle 7: Secure your supply chain
- Principle 8: Document your data, models and prompts
- Principle 9: Conduct appropriate testing and evaluation
- Principle 10: Communication and processes associated with End-users and Affected Entities
- Principle 11: Maintain regular security updates, patches and mitigations
- Principle 12: Monitor your system’s behaviour
- Principle 13: Ensure proper data and model disposal
As with the Software Security Code of Practice, the while the Code of Practice for Cyber Security in AI is primarily aimed at AI developers, organisations using third party AI systems may find the Code useful in assessing and managing risk within their supply chains. The Code can be referenced by customers in ITTs, supplier diligence, contracts and ongoing vendor risk management as part of a wider cyber security strategy.
More information
You can access the codes of practice on the UK Government website:
- Cyber Governance Code of Practice
- Software Security Code of Practice
- Code of Practice for the Cyber Security of AI
If you would like to discuss your organisation's approach to cyber risk, including internal governance, board level oversight and cyber risk in your supply chain, then please get in touch with Martin Sloan or another member of the Brodies Cyber team..
Contributor
Partner