top of page
shield_bg_smaller_edited.jpg

Stay in the know with Sapphire's industry insights

background_edited_edited.jpg

Cyber Security and Resilience Bill: What It Means for Your Organisation

  • Dec 3, 2025
  • 3 min read
Big Ben and the Houses of Parliament beside Westminster Bridge at orange sunset over the River Thames.

The UK Government is taking decisive steps to strengthen the nation’s cyber resilience with the introduction of the Cyber Security and Resilience (Network and Information Systems) Bill. This bill details significant changes that will impact organisations delivering essential services and their supply chains. Here’s what you need to know.


Why This Matters


Cyber threats are evolving at pace, and the UK’s reliance on digital infrastructure means resilience is no longer optional, it’s critical. The Bill updates the NIS Regulations 2018, expanding their scope and introducing new obligations to ensure organisations can withstand and recover from cyber incidents. This brings the UK closer in line to the NIS2 Directive within the EU.


Key Changes in Detail


  1. Expanded Scope of Regulation


The Bill significantly broadens the range of organisations subject to NIS requirements:

  • Data Centres: Recognised as critical infrastructure due to their role in hosting essential services.

  • Managed Service Providers (MSPs): Now regulated because of their influence over client IT and OT environments.

  • Critical Suppliers: Organisations whose failure could disrupt essential services will face additional scrutiny.


This means businesses that previously operated outside the NIS framework may now need to comply.


2. New Security Duties


  • MSPs and Relevant Digital Service Providers (RDSPs) (including online marketplaces, search engines and cloud computing service providers) must adopt robust risk management practices.

  • Compliance will involve technical and organisational measures aligned with updated codes of practice.

  • The Information Commission will issue guidance to ensure consistency across sectors.


3. Mandatory Incident Reporting


  • Initial notification within 24 hours of detecting a significant incident.

  • Full report within 72 hours, detailing impact and mitigation steps.

  • Organisations must inform affected customers promptly after major incidents.


Failure to meet these timelines could result in regulatory action.


4. Enhanced Information Sharing


  • Competent authorities and CSIRTs gain greater powers to share threat intelligence across borders.

  • This aims to improve national and international coordination during cyber crises.


5. Cost Recovery & Compliance


  • Regulators can impose periodic charges to cover oversight costs.

  • Non-compliance penalties: 

  • Up to £17 million or 4% of global turnover for severe breaches.

  • Daily fines for ongoing violations.


6. National Security Directions


  • The Secretary of State can issue binding directions to mitigate risks.

  • These may include mandatory actions, prohibitions, and inspections.

  • Such directions override conflicting regulatory requirements.


What Should Organisations Do Now?


  1. Assess Your Position Are you an MSP, RDSP, or operate critical infrastructure? If so, review your compliance posture immediately. Consider the latest version of NCSC’s Cyber Assessment Framework (v4.0 at the time of writing). 

  2. Update Incident Response Plans Would your organisation be ready to report a major cyber incident within 24 hours? Ensure you can meet the new 24-hour and 72-hour reporting requirements.

  3. Strengthen Supplier Risk Management Critical suppliers will be under scrutiny—make sure your supply chain is resilient, and expect your clients to take a more thorough look at your security. Third party risk management will be key in understanding and reducing your exposure. 

  4. Budget for Compliance Factor in potential regulatory charges and penalties for non-compliance. Regulators will be able to introduce charges to cover the costs of monitoring compliance, conducting audits, investigations and inspections and enduring that incident reporting obligations are met.


How Sapphire Can Help


At Sapphire, we specialise in helping organisations align with evolving regulatory standards. From gap analysis to managed detection and response, we provide the expertise and tools to keep you compliant and resilient.


Want to understand how this Bill impacts your organisation?

 Don’t wait until regulations catch you off-guard - contact our team today or explore our Cyber Resilience Services.

bottom of page