The latest developments in the Cyber Security and Resilience Bill
The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to the House of Commons in November 2025 and completed all Commons stages on 16 June 2026. The Bill was subsequently introduced in the House of Lords on 17 June 2026 and received its Second Reading on 14 July 2026. It is now awaiting Committee Stage scrutiny in the House of Lords, which is scheduled to begin on 1 September 2026.
In essence, the Bill updates the Network and Information Systems Regulations 2018, extending and strengthening the UK's cyber regime for essential and digital services in response to a marked rise in serious incidents. The National Cyber Security Centre recorded 204 nationally significant incidents in the past year, more than double the number recorded in the previous 12 months, providing the backdrop against which this legislation has been fast-tracked.
Key changes under the new cyber security regime
- Wider scope: Medium and large managed service providers, together with UK data centres, are brought into the regime for the first time and designated as essential infrastructure.
- Faster reporting: A light-touch notification will be required within 24 hours of a significant incident, followed by a full report within 72 hours, with both the NCSC and the relevant regulator informed.
- New 'near miss' reporting duties: Obligations will extend beyond confirmed breaches to include certain incidents that could have caused significant disruption.
- Supply chain duties: In-scope organisations will need to manage cyber risk within their supplier base through contractual requirements, security checks and continuity planning. This means that even businesses outside the regime's direct scope may face new obligations flowing down from customers.
- Stronger enforcement: Regulators, including the ICO and Ofcom, will gain powers to levy fines of up to £17 million or 4% of global turnover, alongside cost-recovery powers for their own enforcement activities.
How the Bill could reshape cyber risk and insurance programmes
For risk and insurance managers, the Bill raises a number of practical questions that are worth addressing well ahead of implementation:
- Regulatory defence and fines: Existing cyber policies vary significantly in how they respond to regulatory investigation costs and civil fines, while the insurability of fines will continue to depend on applicable law and public policy considerations. With penalties reaching up to 4% of global turnover, this is a limit and policy wording issue worth revisiting.
- Incident response timelines: The new 24 and 72-hour reporting requirements compress the timeframe within which forensic investigations, legal advice and notifications need to be mobilised. Policies should be reviewed to ensure breach-response service levels and panel-provider capacity can meet the new timetable.
- Supply chain and contingent business interruption: As cyber due diligence requirements flow down through supply chains, contractual risk transfer and cyber cover for key suppliers and MSPs will come under greater scrutiny from customers. Gaps in cover may become a commercial issue as well as a compliance concern.
- Underwriting information: Insurers are likely to seek more detailed information on alignment with the NCSC Cyber Assessment Framework, incident-reporting processes and third-party risk management as the regime beds in. Early preparation should support more favourable renewal discussions.
- Named risk within contracts: For MSPs and data centres newly designated as essential infrastructure, this presents a natural opportunity to review the adequacy of limits, definitions of "cyber event", and any war or state-actor exclusions, given the Bill's national security focus.
- Directors' and Officers' exposure: With cyber risk elevated to board-level, statutorily recognised risk, directors' existing duties to promote the success of the company and exercise reasonable care, skill and diligence take on greater significance. A poorly governed breach, inadequate oversight, the absence of a board reporting line for cyber risk or ignored NCSC guidance may be easier to characterise as a failure of duty in hindsight, even though the Bill does not impose direct liability on directors. As a result, the likelihood of scrutiny and potential D&O claims may increase following a significant cyber incident.
How organisations can prepare for the new cyber security regime
Nothing in the Bill is final, and full implementation remains some way off. However, the direction of travel is sufficiently clear to justify action now.
We would recommend using the period before Royal Assent to assess whether your business, or any of your key suppliers, is likely to fall within scope; pressure-test incident response arrangements against the proposed 24 and 72-hour reporting requirements; and review insurance programmes against the exposures outlined above.
We're tracking the Bill's progress through the Lords closely and will provide a further update once the final text and implementation timetable become clearer.
Contact us
If you'd like to discuss how these developments may affect your programme or your clients' supply chains, please contact us on 07572 104 029 or ProFin@thecleargroup.com.