UK Cyber Resilience and Security Bill 2025: What Every Board Director Must Know | INFORMD Executive Briefing

UK Cyber Resilience and Security Bill 2025: What Every Board Director Must Know

Informd BriefingCyber & ResilienceJune 2025Board level

UK Cyber Resilience and Security Bill 2025: What Every Board Director Must Know

The Cyber Security and Resilience Bill represents the most significant overhaul of UK cyber law since NIS 2018. It extends mandatory security obligations to new sectors, expands the incident reporting window, and — for the first time — places explicit duties on board directors. Here is what non-executive directors, audit committee chairs, and C-suite officers need to understand before this becomes law.

Why this Bill matters at board level

For a decade, cyber security has been framed as an IT function. The Cyber Security and Resilience Bill changes that framing permanently. By placing mandatory duties on organisations providing critical services and digital infrastructure, and by requiring incident reporting to government, Parliament is signalling that cyber failure is now a board governance failure.

The Bill was announced in the King’s Speech in July 2024 and was formally introduced to Parliament on 12 November 2025 and passed its committee stages in early 2026, with Royal Assent expected in late 2026. Organisations covered by the existing Network and Information Systems (NIS) Regulations 2018 should assume they are in scope, as should a significantly wider universe of digital service providers, managed service providers, and supply chain operators.

What the Bill does

1. Extends the scope of mandatory obligations

The existing NIS framework covered operators of essential services (energy, water, transport, health, financial infrastructure) and relevant digital service providers. The new Bill materially expands this to include:

  • Managed service providers (MSPs) — a major change given MSPs sit across the supply chains of thousands of regulated entities
  • Data centres classified as critical national infrastructure
  • Downstream digital infrastructure providers previously outside NIS scope
  • Supply chain organisations providing critical services to in-scope entities

If your organisation supplies services to financial institutions, critical infrastructure operators, or central government departments, assume the Bill could bring you into scope even if you are not currently regulated under NIS.

2. Strengthens incident reporting obligations

Under current NIS Regulations, incidents must be reported to competent authorities “without undue delay.” The Bill mandates a 24-hour initial notification window for significant incidents, with a full report required within 72 hours — broadly aligning UK law with the EU’s NIS2 Directive.

The definition of a reportable incident is also expected to expand beyond purely technical breaches to include incidents that materially disrupt the provision of essential or digital services, even where personal data is not involved.

3. Introduces supply chain security duties

One of the most operationally complex elements of the Bill is its focus on supply chain risk. In-scope organisations will be required to assess, document, and manage the cyber risks posed by their third-party suppliers. This mirrors the DORA approach in financial services but extends it across critical sectors.

Boards should expect their audit committees to receive annual supply chain cyber risk assessments, not just internal security posture reviews.

4. Grants government enhanced investigatory and enforcement powers

The Bill grants competent authorities new powers to investigate cyber posture proactively — not just in response to incidents. This includes access to security documentation, audit rights, and the ability to direct remediation. Enforcement fines are expectoperate on a two-tiered model: for standard breaches, the greater of £10 million or 2% of global turnover; for serious or repeated breaches, the greater of £17 million or 4% of worldwide turnover.

The board governance implications

The Bill does not include a provision naming individual directors as personally liable — unlike, say, the SMCR in financial services. However, the combination of expanded enforcement powers, increased fines, and explicit requirements for organisational cyber risk management creates a strong governance expectation that boards have active oversight of cyber security.

The FCA, PRA, and NCSC have all published guidance making clear that cyber risk should appear on board agendas as a standing item. The Bill accelerates this expectation into law for sectors beyond financial services.

For listed companies, the UK Corporate Governance Code 2024 already requires boards to oversee and manage material risks. Cyber is now explicitly within scope of Provision 29 (internal controls declaration) following FRC guidance. A board that cannot demonstrate active oversight of cyber risk is exposed both under the Bill and under the Code.

The regulator’s expectation, stated plainly: “The board should not be receiving cyber updates once a year in a format they cannot interrogate. Cyber risk should be a standing agenda item, reported in terms the board can act on, with clear accountability for management response.” — NCSC/FCA joint guidance, 2024.

What ‘good’ board-level cyber governance looks like

The NCSC’s Cyber Security Toolkit for Boards (2023, updated 2024) sets out six principles for board engagement with cyber risk. Under the Bill’s regulatory backdrop, these effectively become the expected standard. Boards should be able to demonstrate:

  1. A named individual on the board (or directly accountable to the board) responsible for cyber risk
  2. Regular cyber risk reporting in a format the board can interrogate — not just RAG status slides
  3. A tested incident response plan that the board has reviewed
  4. Supply chain cyber risk visible at board level, not just at operational level
  5. A cyber risk appetite statement approved by the board
  6. Evidence that cyber risk has been considered in major strategic decisions (M&A, new product launches, digital transformation programmes)

Sector-specific considerations

Financial services

Regulated firms already face cyber obligations under DORA (for EU-facing operations), the FCA’s PS21/3 (operational resilience), and PRA SS2/21. The Cyber Resilience Bill sits alongside these — it does not replace them. Firms should assess whether the Bill’s expanded scope captures any group entities (particularly managed service providers within the group) that are currently outside DORA and FCA scope.

Healthcare

NHS trusts and private healthcare providers operating critical infrastructure are already in NIS scope. The Bill’s most significant impact in healthcare is the 24-hour reporting requirement, which will require significant operational change for organisations whose current incident response protocols are built around a 72-hour or longer window.

Professional services and supply chain

Law firms, accountancy firms, and technology consultancies that serve in-scope critical infrastructure organisations may find themselves brought into scope as “supply chain” entities under the Bill. This is new territory and boards in these sectors should seek legal advice on whether the Bill’s obligations apply.

Key dates and milestones

  • July 2024 — Bill announced in King’s Speech
  • H1 2025 — Consultation on scope and implementation details
  • Late 2025 / Early 2026 — Expected Royal Assent
  • TBC — Commencement regulations setting compliance dates (likely 6–12 months after Royal Assent)

Organisations in scope should treat the pre-commencement period as the implementation window. Waiting until the Bill receives Royal Assent before acting will leave insufficient time to meet obligations, particularly for supply chain risk management and incident response planning.

Board action checklist

What to do before the Bill receives Royal Assent

  • Confirm whether your organisation (and group entities) are in scope — seek legal advice if uncertain
  • Review current incident reporting procedures: can your organisation meet a 24-hour notification window?
  • Commission a supply chain cyber risk assessment if one has not been completed in the last 12 months
  • Ensure the board receives a cyber risk briefing that is actionable — not just technical dashboards
  • Review cyber risk appetite statement and confirm it is board-approved
  • Add cyber resilience obligations under the Bill to your regulatory change horizon
  • Confirm your incident response plan is tested and the board knows its role in a cyber incident
For audit committee chairs

Questions to ask management at the next audit committee meeting

  • Is the organisation in scope for the Cyber Security and Resilience Bill? If uncertain, what legal review is planned?
  • What is the current average time from incident detection to regulatory notification? Can we meet 24 hours?
  • Has supply chain cyber risk been formally assessed and reported to this committee?
  • What is the status of our Cyber Essentials or ISO 27001 certification?
  • Have we tested our incident response plan in the last 12 months? What did it find?

Informd briefs senior executives on regulatory change as it happens — plain-language analysis, board-level checklists, and downloadable templates.

See plans →

Similar Posts