Don’t do SECURITY. Do business SECURELY.

Cyber Security and Resilience Bill introduced to Parliament

The UK Government has introduced legislation to modernise and expand the NIS Regulations.

The Cyber Security and Resilience (Network and Information Systems) Bill has been introduced to Parliament, updating and expanding the UK NIS Regulations 2018.

Key proposals

  • Bringing managed service providers and data centres into scope.
  • Powers for regulators to designate critical suppliers to essential services.
  • Faster incident reporting: an initial notification within 24 hours and a full report within 72 hours.
  • Stronger regulator powers and higher penalties, linked to turnover.
  • Powers for the Government to update the regime through secondary legislation.

Much of the detail will come through secondary legislation, and the NCSC Cyber Assessment Framework is expected to play a central role. IT and security service providers with privileged access to client systems should start assessing their likely obligations now.

Source: Cyber Security and Resilience (Network and Information Systems) Bill (UK Parliament)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights