Ransomware poses one of the most significant operational risks to UK organisations, with recent high-profile attacks causing disruptions to hospitals, taking production lines offline, and even knocking out entire data centres.
The UK government's response to this growing threat is the Cyber Security and Resilience Bill, introduced to Parliament in November 2025. This bill represents the most significant overhaul of UK cyber law since the Network and Information Systems (NIS) Regulations came into force in 2018.
The bill matters for business leaders regardless of whether their organisation was already regulated. It widens the net of who is covered, tightens what's expected of them, and raises the cost of getting it wrong.

The Cyber Security and Resilience Bill does not replace the NIS Regulations outright. Instead, it modernises and extends them. The original framework set a baseline for cyber security across essential services such as energy, transport, health, and water. The bill adds several categories that previously sat outside regulation entirely, including managed service providers, data centres above defined capacity thresholds, and organisations that remotely control large amounts of electrical load on the grid.
Under the bill, regulators gain the power to designate individual suppliers as "critical" even if they don't fit any of the listed sectors. Rather than embedding detailed technical requirements directly in legislation, the UK has opted for a more adaptable structure. Much of the fine detail, such as sector thresholds, reporting criteria, and codes of practice, will follow through secondary legislation and regulatory guidance.
An organisation could be brought into scope if it operates in a sector already covered by the NIS Regulations, provides managed IT services, runs a qualifying data centre, or manages significant electrical loads. Smaller suppliers sometimes assume regulation is a large-enterprise problem, but under the bill's supplier designation powers, a micro-business occupying a pivotal position in a critical supply chain can be pulled into scope directly.
The bill's requirements include tightening incident reporting timelines. Regulated organisations must notify regulators and the National Cyber Security Centre within 24 hours and submit a full written report within 72 hours. What counts as reportable also broadens, including ransomware and "prepositioning" activity.
Supply chain oversight becomes an active duty rather than good practice. Regulated organisations are expected to map dependencies, strengthen supplier contracts, and verify that third parties handling their data meet equivalent resilience standards.
Enforcement also changes shape, with a two-band system tied to global turnover for breaches. The previous three-tier penalty structure is replaced by a two-band system, with up to £17 million or 4% of worldwide turnover for the most serious breaches, and up to £10 million or 2% for lesser infringements.
Underpinning all of this is a shift toward alignment with the NCSC's Cyber Assessment Framework (CAF), which is moving from a voluntary reference point toward something closer to a legal expectation for in-scope organisations.
The bill hasn't yet completed its passage through Parliament, and much of the technical detail will still follow through secondary legislation after Royal Assent. Full implementation isn't expected until the framework is phased in over the following years.
For business leaders, the practical starting point is establishing whether the organisation—or its critical suppliers—falls within scope, and how that might change as the framework develops. Waiting for final guidance before beginning that assessment risks leaving very little runway once the obligations take effect.
To help prepare, a detailed guide covering the Cyber Security and Resilience Bill compliance requirements is available, including how backup and recovery capabilities factor into regulatory expectations.







