{"id":2569,"date":"2025-04-01T19:11:25","date_gmt":"2025-04-01T19:11:25","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=2569"},"modified":"2025-04-01T19:11:25","modified_gmt":"2025-04-01T19:11:25","slug":"the-uks-cyber-security-and-resilience-bill-will-boost-standards-and-increase-costs","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=2569","title":{"rendered":"The UK\u2019s Cyber Security and Resilience Bill will boost standards \u2013 and increase costs"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p>If you\u2019re a UK enterprise, this might not be good news: extra investment by infrastructure providers to meet the demands of the government\u2019s forthcoming Cyber Security and Resilience Bill is likely to raise the cost of some services.<\/p>\n<p>This looks like the inevitable outcome of a bill, previewed in a policy statement by the government this week, which will affect a wide tranche of infrastructure companies for the first time. This includes, by the government\u2019s own estimates, up to an additional 1,100 managed service providers, 64 data center operators, and an unspecified number of smaller companies in the digital supply chain.<\/p>\n<p>The government acknowledges that, if implemented in full, this will impose new costs, which means that the business customers using those providers will face higher bills at some point.<\/p>\n<p>Many of these providers are not currently subject to existing cybersecurity legislation governing critical national infrastructure, primarily the Network and Information Systems Regulations 2018 (UK). The new legislation will bring the UK more into line with the regulation\u2019s EU successor, <a href=\"https:\/\/www.csoonline.com\/article\/574111\/eu-council-adopts-nis2-directive-to-harmonize-cybersecurity-across-member-states.html\">NIS2<\/a>.<\/p>\n<p>\u201cWhile we expect this measure to have associated costs related to security improvements and compliance, these investments will position MSPs as trusted and reliable partners in the cyber security landscape,\u201d the <a href=\"https:\/\/www.gov.uk\/government\/publications\/cyber-security-and-resilience-bill-policy-statement\/cyber-security-and-resilience-bill-policy-statement\">government\u2019s policy statement said<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">What will the bill change?<\/h2>\n<p>As well as broader oversight, the bill will impose tougher reporting requirements, requiring companies to notify the UK\u2019s National Cyber Security Centre (NCSC) of a significant incident within 24 hours. The definition of \u2018significant\u2019 will include anything compromising data, as well as, significantly, supply chain attacks affecting customers (<a href=\"https:\/\/www.csoonline.com\/article\/2140487\/snowflake-no-breach-just-compromised-credentials-say-researchers.html\">stand up Snowflake<\/a>).<\/p>\n<p>The emphasis on resilience means that providers will have to explain how they would recover from an incident and not simply avoid it. The new regulator of all this, the Information Commissioner\u2019s Office (ICO), will be given teeth, the government indicated. That will mean the ICO will need more resources to meet this expanded, and in many ways, daunting remit.<\/p>\n<p>What this means for enterprises is that the service providers, and probably major data center operators, will have to operate to more consistent standards. Broadly, this is positive, although many will already be working towards those standards under the influence of NIS2 regulations.<\/p>\n<h2 class=\"wp-block-heading\">Why is it needed?<\/h2>\n<p>In 2024, the NCSC responded to 430 cybersecurity incidents, including 89 it said were rated as \u201cnationally significant.\u201d That included the large <a href=\"https:\/\/www.csoonline.com\/article\/2138778\/london-hospitals-face-days-of-disruption-after-ransomware-attack-on-supply-chain-partner.html\">ransomware attack<\/a> on the NHS pathology services provider Synnovis last June that ended up costing an estimated \u00a332.7 million ($42 million) to fix.<\/p>\n<p>\u201cLast year\u2019s cyber attack on a supplier to NHS hospitals in London caused more than 11,000 acute outpatient appointments and elective procedures to be postponed. Some of those people will have waited months to be seen,\u201d said the Secretary of State for the Department for Science, Innovation and Technology, Peter Kyle. \u201cI will not allow this to continue. We must take decisive action to deliver effective and enduring change.\u201d<\/p>\n<p>And this isn\u2019t just a problem for the public sector; last year\u2019s <a href=\"https:\/\/www.gov.uk\/government\/statistics\/cyber-security-breaches-survey-2024\/cyber-security-breaches-survey-2024\">Cyber Security Breaches Survey<\/a> found that half of UK businesses suffered some form of cyberattack in the last 12 months, equivalent to seven million incidents.<\/p>\n<p>To illustrate the peril, the government pointed out that a hypothetical cyber attack directed at an energy company in the southeast of England could \u201cwipe over \u00a349 billion [$63 billion] from the wider UK economy.\u201d<\/p>\n<p>Putting a lid on this kind of disruption requires legislation to compel providers to act, while offering a target to aim for in terms of compliance.<\/p>\n<p>The full demands of the bill have yet to be revealed. Right now, all that affected organizations know is its general outline and broad scope. When it is published in full, the detail will be pored over at length.<\/p>\n<p>\u201cOne of the key announcements is the introduction of MSPs falling into the scope of the regulation. Small and medium sized enterprises depend on managed service providers for every aspect of their IT and their security posture,\u201d said David Ferbrache, managing director of UK technology consultancy Beyond Blue. \u201cMaking sure MSPs take security seriously can make a massive difference to those SMEs.\u201d <\/p>\n<p>However, Ferbrache was less sure about the new role given to the ICO as regulator. \u201cThe extension of the role of the ICO to regulate a wide range of digital services is a major change in scope. Care will be needed to not create conflicts of interest or distract from their key role as our national data protection authority,\u201d he said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>If you\u2019re a UK enterprise, this might not be good news: extra investment by infrastructure providers to meet the demands of the government\u2019s forthcoming Cyber Security and Resilience Bill is likely to raise the cost of some services. This looks like the inevitable outcome of a bill, previewed in a policy statement by the government [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":2570,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-2569","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/2569"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2569"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/2569\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/2570"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}