The UK Government has published its long awaited Cyber Security and Resilience (Network and Information Systems) Bill, which will update cyber security laws in the UK. If passed, the Bill will expand cyber resilience obligations to new sectors and entities, introduce new incident reporting obligations and grant new powers to the Government and regulators. In this update we summarise the key provisions of the Bill.

Background

The UK's current cyber security laws, the Network and Information Systems Regulations 2018, implemented EU wide rules under the NIS Directive.  

The NIS Regulations impose cyber resilience and incident reporting obligations on operators of essential services (energy, transport, health, water and digital infrastructure) and certain digital service providers (online marketplaces, search engines and cloud providers). Compliance is regulated by sector specific regulators. 

Those laws are now seven years old and have not kept pace with evolving cyber threats, including the increasing dependence on third party IT service providers and wider supply chain risk and the impact that a cyber attack can have on critical national infrastructure and the wider economy. 

In the EU, the NIS Directive has been replaced by NIS2, which was due to be implemented by member states by 17 October 2024. NIS2 expands cyber resilience obligations to a number of new sectors. 

The Cyber Security and Resilience (Network and Information Systems) Bill will amend the NIS Regulations to expand their scope and introduce a number of new power and duties.

What sectors and entities will be in scope under the Cyber Bill?

Under the Bill, cyber resilience obligations will be expanded to cover more sectors and entities, including:

  • Data centres - medium and large and enterprise data centres
  • Managed service providers - service providers that provide IT services to other organisations
  • Large load controllers - entities that manage electrical loads to and from smart appliances (for example off peak EV charging)
  • Designated critical suppliers - entities that are designated by relevant sector regulators as being critical suppliers to that sector (the Government gives the example of a 2024 cyber attack on a major provider of pathology services to the NHS which led to substantial disruption and the cancellation of 11,000 appointments at hospitals, GP surgeries and clinics)

However, the Bill does not propose bringing manufacturing and food and drink within scope (as has been done under NIS2). This is despite high profile cyber attacks this year on Jaguar Land Rover, Marks and Spencer and the Co-op. The Office for National Statistics last month identified disruption to manufacturing at Jaguar Land Rover as a factor in slower economic growth in the UK, while the cyber attack on the Co-op in particular had a major impact on the supply of food in a number of remote areas of the UK, including many Scottish islands.

Enhanced reporting obligations and regulatory powers

Under the NIS Regulations, regulated entities must notify incidents to the relevant regulator within 72 hours. Under Bill, this will change to an obligation to submit an initial notification within 24 hours and a full notification within 72 hours. The intention is that earlier notification will enable better and more coordinated responses to cyber incidents - particularly those that affect (or could affect) multiple entities.

The Bill will also introduce new customer notification obligations on data centres, managed service providers and digital service providers.

Regulators will have enhanced enforcement powers, including an increase in maximum fines to the greater of £17m or 10% of turnover. This will be accompanied by new powers in relation to information sharing and cost recovery powers.

What powers will the Cyber Bill grant to Government?

The Government considers that the NIS Regulations do not enable it to respond quickly to evolving threats, The Bill will therefore provide for new powers, including:

  • the ability for the Government to make changes to the laws via secondary legislation
  • the ability for the Government to "direct" regulators and regulated entities to respond to imminent threats

Does the Cyber Bill include the proposed prohibition on ransomware payments?

No. The Bill does not include the proposed prohibition on public authorities and certain other bodies from making ransomware payments.  Following a consultation exercise earlier this year, the Government is continuing to develop its proposals for a ban.

When will the Cyber Bill come into force?

The Bill is currently making its way through Parliament and is likely to be passed in the first half of 2026. The Government proposed that enhanced government powers will come into force on day 1, with certain regulatory powers coming into force in month 2. The rest of the Bill will be enacted through secondary legislation. The Government recognises that there will need to be a phased approach to the newly regulated sectors and services and industry consultation.

Preparing for the Cyber Bill

Organisations currently subject to the NIS Regulations should review the proposed changes, including the enhanced incident reporting obligations. Organisations that may be brought within scope should think about their current approach to cyber resilience and what they need to do to prepare, including updates to internal policies and how they manage cyber risk within their supply chains.

You can view the Bill on the UK Parliament website.

If you would like to discuss the Cyber Security and Resilience Bill and how it might apply to your organisation or your organisation's approach to cyber resilience, please contact a member of the Brodies Cyber team.

Contributors