Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Synnovis Finally Issues Breach Notification After 2024 Ransomware Atta

November 13, 2025

U.S. Prosecutors Indict Cybersecurity Insiders Accused of BlackCat Ransomware Attacks

November 13, 2025

Quantum Route Redirect Phishing Kit Democratizes Cyber-Attacks

November 13, 2025
Facebook X (Twitter) Instagram
Thursday, November 13
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»UK Government Finally Introduces Cyber Security and Resilience Bill
Cyber Security

UK Government Finally Introduces Cyber Security and Resilience Bill

Team-CWDBy Team-CWDNovember 13, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The UK government introduced its long-awaited Cyber Security and Resilience Bill to parliament this morning, promising that it will help bolster national security and protect the economy.

The proposed legislation aims to upgrade the UK’s Network and Information Systems (NIS) Regulations 2018, which were based on the EU’s NIS Directive. The latter has since been updated to NIS2, which introduces strict new baseline security requirements for operators of essential services (OES).

The UK equivalent includes the following proposals:

  • Managed service providers (MSPs) will be regulated for the first time, bringing an additional 900-1100 firms into the scope of the law
  • Regulators will be given powers to designate critical suppliers that must meet minimum security standards
  • New duties (to be confirmed in secondary legislation) will require OES to manage supply chain risks
  • OES will need to meet “proportionate and up-to-date security requirements” drawn from the NCSC Cyber Assessment Framework (CAF)
  • Incident reporting criteria will be expanded, and initial reporting will be required no later than 24 hours after an incident followed by a full report within 72 hours. Digital and data center providers will be required to notify customers
  • The powers of the Information Commissioner’s Office (ICO) will be enhanced, enabling it to identify the most critical digital service providers and adopt a proactive approach to assessing cyber risk
  • Regulators will be able to recover costs through a new fee regime
  • Data center providers and those managing “the flow of electricity to smart appliances” will be brought into scope
  • Tougher, turnover-based penalties will be brought in for serious offenses

Read more on the Cyber Security and Resilience Bill: UK Government Set to Introduce New Cyber Security and Resilience Bill.

Matt Houlihan, VP government affairs, Europe, Cisco, said British organizations urgently need new regulation to protect them from sophisticated cyber-attacks and AI threats.

“The success of this bill will rely on clarity and practical timelines to help organizations implement the necessary measures effectively. We’d also urge the government not to miss an important opportunity to tackle the growing risks from unsupported, end-of-life equipment – a persistent weak point in UK infrastructure that too often leaves organizations exposed,” he added. 

“By working alongside and collaborating with industry, the government has the opportunity with this bill to meet the complex cybersecurity needs of UK organizations by providing clear, proportionate guidance, grounded in the practical realities of securing the UK’s cyber landscape.”

A Long Time Coming

Although the bill still needs to be debated in parliament, it is already nearly two years since the NIS2 directive came into force, although some EU member states have still not ratified it.

Since then, the UK has suffered multiple serious breaches impacting critical infrastructure and services, including the ransomware attack on NHS supplier Synnovis, and a state-sponsored cyber-espionage effort that compromised information on all Ministry of Defence staff.

According to government figures the average cost of a “significant cyber-attack” is now over £190,000 – which the government claimed amounts to £14.7bn a year across the entire economy, or 0.5% of national GDP. 

“As a nation, we must act at pace to improve our digital defenses and resilience, and the Cyber Security and Resilience Bill represents a crucial step in better protecting our most critical services,” said NCSC boss Richard Horne.

“Cybersecurity is a shared responsibility and a foundation for prosperity, and so we urge all organizations – no matter how big or small – to follow the advice and guidance available at ncsc.gov.uk and act with the urgency that the risk requires.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCyber-Insurance Payouts Soar 230% in UK
Next Article Best Practices for SAP Identity Framework Migration
Team-CWD
  • Website

Related Posts

Cyber Security

Best Practices for SAP Identity Framework Migration

November 13, 2025
Cyber Security

What Is Vibe Coding? Collins’ Word of the Year Spotlights AI’s Role an

November 12, 2025
Cyber Security

China-Aligned UTA0388 Uses AI Tools in Global Phishing Campaigns

November 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest News

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202512 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views

The risks of unsupported IoT tech

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202512 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views
Our Picks

Look out for phony verification pages spreading malware

September 14, 2025

In memoriam: David Harley

November 12, 2025

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2025 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.