The UK’s cyber security landscape is changing, and businesses need to be ready for greater expectations around resilience, reporting and accountability
With the Cyber Security and Resilience Bill progressing through Parliament, the question is not simply what the legislation says, but what it could mean for your organisation.
This guide cuts through the detail, explaining who is likely to fall within scope, what will change in practice and the steps businesses can take now.
What is the Cyber Security and Resilience Bill?
The UK’s current cyber security regulations, the Network and Information Systems (NIS) Regulations, have been in place since 2018, but technology and the risks surrounding it have moved quickly since then.
Organisations are increasingly dependent on cloud services, data centres and external IT providers to keep critical operations running. At the same time, incidents such as the M&S cyber attack have made the commercial impact of cyber disruption difficult to ignore.
The Cyber Security and Resilience Bill is designed to close this gap. Rather than replacing the existing NIS Regulations, it builds on them by bringing more organisations into scope, strengthening oversight and allowing the regulatory framework to adapt as threats change. It follows a similar direction to the EU’s NIS2 Directive, but has been shaped around the UK’s existing regulations and specific cyber security needs.
The Bill was introduced on 12 November 2025 and moved to the House of Lords after clearing the Commons in June 2026. Once passed, the changes will be implemented gradually, with further detail to follow through secondary legislation.
Who does the Cyber Security and Resilience Bill apply to?
The existing NIS Regulations protect the essential and digital services people rely on every day. They currently cover qualifying organisations across energy, transport, health, drinking water and digital infrastructure, along with certain cloud computing services, online marketplaces and search engines.
However, cyber criminals are increasingly using technology providers and shared infrastructure as routes into these essential services. The Bill expands the regime to reflect this risk and reduce the potential for disruption across multiple organisations.
It will bring qualifying data centres, medium and large managed service providers and large load controllers into scope. Regulators will also be able to designate individual suppliers as critical where disruption to their services could significantly affect an organisation already covered.
Businesses outside the Bill’s direct scope may still feel its impact. Regulated customers could introduce stronger security assessments, contractual requirements and requests for evidence of cyber resilience across their supplier networks.
What will the Bill change in practice?
For organisations within scope, the Bill will mean earlier reporting, stronger regulatory oversight and clearer accountability,
Faster incident reporting: Under the current NIS Regulations, an incident generally only needs to be reported once it has significantly disrupted an essential or digital service. The Bill will expand reporting to include harmful cyber breaches that are likely to have a significant impact, even before disruption occurs. Organisations will submit an initial notification within 24 hours, followed by a fuller report within 72 hours.
Stronger regulatory oversight: Regulators will have greater powers to request information, investigate potential noncompliance and take enforcement action when organisations fail to meet their security or reporting duties. Greater information sharing with the National Cyber Security Centre (NCSC) and law enforcement will also help identify wider threats and coordinate responses.
Revised financial penalties: The current three band penalty structure will be replaced with two based on the seriousness of the breach. More serious failures could result in fines of up to £17 million or 4% of worldwide turnover, whichever is higher. Less serious breaches could attract fines of up to £10 million or 2% of worldwide turnover.
Greater supply chain accountability: Regulated organisations will face clearer duties to manage supplier risks through measures such as contractual requirements, security checks and continuity planning. Data centres and managed and digital service providers will also need to notify customers likely to be affected by a breach.
What should UK businesses do now?
Although the Bill is still progressing through Parliament, businesses can prepare now by treating cyber security as a strategic issue, not simply a compliance exercise.
Establish clear incident response procedures: Create and test a plan for identifying, escalating and reporting incidents. Designate those responsible for meeting the proposed 24 and 72 hour deadlines.
Strengthen governance and supplier assurance: Give cyber resilience clear ownership at board level. Id and review their security controls, continuity arrangements and incident notification commitments.
Get ahead of Cyber Essentials certification: Cyber Essentials or Cyber Essentials Plus can demonstrate that important baseline protections are in place. Certification does not guarantee compliance with the Bill, but it can strengthen your security posture and provide assurance to customers and insurers.
Bring in experienced support where needed: If your internal team lacks the capacity or specialist expertise to assess readiness, an experienced technology partner can help identify gaps, establish priorities and coordinate incident response, business continuity and certification preparation.
Prepare for what comes next
New responsibilities do not mean building every process from scratch. Virtuoso works alongside in house IT teams to assess readiness and coordinate incident response, business continuity, monitoring, resilient connectivity and certification support.
We can help turn regulatory requirements into a practical resilience plan for your organisation.
Book a cyber resilience readiness conversation with Virtuoso.
Ready to simplify your IT?
Let’s discuss your goals and challenges - no obligation, just practical advice.
Book a Discovery Call



