
The UK government is updating the rules that protect essential services from cyber attacks. The Cyber Security and Resilience Bill, introduced to Parliament in late 2025, aims to strengthen the existing Network and Information Systems (NIS) Regulations, which date back to 2018.
The details may still change as the Bill progresses, so treat this as an overview rather than legal advice. Even so, the direction of travel is clear, and it is worth understanding how it could affect your business.
Why the law is changing
Recent years have seen serious attacks on hospitals, local councils, retailers and the suppliers that support them. In several cases, criminals did not attack the target directly. They went through an IT provider or supplier with access to many organisations at once.
The existing rules did not cover many of these suppliers. The new Bill is designed to close that gap.
Who is likely to be affected
The Bill builds on the current NIS framework, which already applies to operators of essential services such as energy, transport, water and healthcare, along with some digital service providers. The proposals extend the scope to include:
- Managed service providers, such as IT support and security companies with access to client systems
- Data centres above a certain size
- Critical suppliers whose disruption could seriously affect an essential service
Most small businesses will not be regulated directly. However, if you supply larger organisations, public sector bodies or essential services, you may find their security expectations of you increase.
What it could require
The main themes in the Bill include:
- Faster incident reporting, with an early notification expected within 24 hours of a significant incident
- Wider reporting, covering incidents that could have caused harm, not just those that did
- Stronger regulator powers to set requirements, investigate and issue penalties
- Greater focus on supply chain security
What this means for smaller businesses
Even if the law never applies to you directly, its effects will flow down the supply chain. Expect customers to ask more questions about your security, request evidence such as Cyber Essentials certification, and include security clauses in contracts.
Practical steps to take now
You do not need to wait for the final legislation to improve your resilience:
- Get the basics right. Multi-factor authentication, regular updates, secure configuration and reliable backups stop most attacks.
- Know your systems. Keep an up to date list of your devices, software, data and suppliers.
- Plan for incidents. Write a simple response plan covering who to call, how to contact customers and how to restore systems.
- Check your IT provider. Ask how they secure their own access to your systems and how they would alert you to an incident.
- Test your defences. Use vulnerability scanning or penetration testing to find weaknesses before attackers do.
How we can help
We help businesses across Dartford and north Kent strengthen their security and prepare for growing supply chain expectations. If you would like a clear picture of where you stand, get in touch for a security review.