ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Preparing for the UK's Cyber Security and Resilience Bill

Matthew Lloyd Davies at Pluralsight explains what businesses need to know about the UK’s new cyber-security Bill

 

As the Cyber Security and Resilience Bill moves through parliament, organisations have a chance to take action early and prepare their workforce for change. Tougher compliance obligations, potential daily fines of up to £100,000 per day and tighter reporting windows signal a sweeping regulatory overhaul.

 

The legislation will widen the regulator’s oversight, give the government stronger enforcement powers and bring UK rules into line with the EU’s NIS2 directive – all of which is designed to foster a safer digital ecosystem at home and abroad. 

 

For modern businesses already battling a surge in supply-chain attacks, third-party breaches, and other vulnerabilities, emphasised by the recent attacks on Marks & Spencer and the Co-op, these measures are a welcome advance. They will help companies reinforce their cyber-defence posture while underscoring the nation’s commitment to cyber-security as a strategic priority. 

 

Success, however, hinges on people as much as technology. Organisations must equip their workforce with the expertise to meet the new compliance demands and strengthen security overall. Broad upskilling across both technical and non-technical roles will be essential. Below, I outline why it matters and the actions leaders should start taking now.

 

Why should businesses care?

Cyber-crime is already costing UK businesses. In 2025 alone, 8.58 million cyber-crimes were reported by UK businesses, with total losses over the past five years reaching £44bn. The threats of operational disruption, reputational damage and financial loss are a constant risk for many organisations.

 

The stakes are set to rise even higher with the introduction of new legislation. Non-compliance could result in fines of up to £100,000 per day or 10% of global annual turnover, whichever is higher.

 

Adding to the complexity, third party involvement in data breaches has doubled over the last year and is now seen in 30% of all cyber-attacks. As a result, beyond public services and utilities, over 1,000 IT service providers and suppliers will soon fall under regulatory scope, requiring companies to assess and ensure the cyber-hygiene of their entire supply chain.

 

Expanded reporting requirements will also raise the bar. Businesses will need to report a broader range of cyber-incidents - including ransomware attacks, network breaches and service disruptions – with strict timelines of 24 hours for initial notification and 72 hours for a full report. As it stands, only four in ten businesses report disruptive breaches outside of their organisation, meaning these new rules will place additional strain on already stretched cyber-security teams.

 

Adapting to these regulations will demand time, resources and operational change - making early preparation essential for avoiding penalties and ensuring readiness.

 

Laying the groundwork for compliance

Despite rising threats, many businesses still lack the necessary talent to respond quickly and effectively to immediate attacks. According to research from the Chartered Management Institute (CMI), just 10% of managers say they have basic cyber-security knowledge such as using secure passwords and identifying phishing attacks.

 

Similarly, Pluralsight research reveals that 45% organisations say they don’t have the right people or skills in place to manage security risks effectively and this isn’t a new issue: cyber-security has been the number one technical skills gap since 2021.

 

Investing in cyber-training isn’t just about avoiding fines, it’s about building resilience. Upskilling staff across all roles, from board members to front-line employees, helps embed cyber-awareness into daily operations and decision-making.

 

Assess and strengthen your security framework

Most organisations already have a data breach reporting procedure that meets GDPR reporting requirements. However, like NIS2, the bill’s proposed reporting obligations will introduce tighter deadlines and a wider scope of incidents. To stay compliant, organisations should conduct a thorough security audit to ensure that their procedures are updated to reflect this.

 

In addition, regular rehearsals of cyber-security incident response – such as red team blue team exercises – are essential to strengthen readiness and improve response effectiveness under pressure.

 

Engage and empower leaders on compliance

Cyber-security oversight must come from the top. Yet, board-level responsibility for cyber-security has been steadily declining from 38% in 2021 to just 27% in 2025. This downward trend is at odds with the direction of the new legislation which places significantly greater accountability on senior leadership. 

 

To meet these expectations, key decision-makers must be fully informed by the regulatory landscape, the organisation’s exposure and their roles in ensuring cyber-resilience. Re-engaging leadership is essential to build a culture of accountability, readiness and proactive risk management. 

 

Tighten supplier contracts

The bill makes supply chain vigilance a board-level issue. Failure to comply with its two-stage incident reporting can expose organisations financially, so prime contractors need watertight language that obligates third parties to raise the alarm and co-operate with any subsequent investigation. Yet, most UK firms are starting from a low base, with only 14% of businesses formally assessing the cyber-risk posed by their immediate suppliers.

 

Contracts therefore need to move beyond generic ‘reasonable endeavours’ wording. In practice, that means inserting a mandatory 24-72-hour breach notification clause that extends to all sub-contractors and mandating evidence of control maturity through certifications such as ISO 27001 or Cyber Essentials Plus.

 

Contractors should also be required to have an up-to-date Software Bill of Materials (SBOM), clear timelines for applying patches, and businesses should hold the contractual right to carry out annual security audits and forensic investigations at no additional cost.

 

Together, these measures give regulated organisations meaningful oversight of third-party resilience, along with the documentation regulators are likely to demand after a breach.

 

Finally, international firms should also align their contract language with NIS2-style obligations already live in the EU. This ensures that a breach at a single supplier triggers a unified incident response across jurisdictions. Framing these updates as commercial value-adds rather than compliance hurdles often help reduce pushback and speeds up contract execution - particularly with managed service providers, who now sit firmly within the scope of the new rules.

 

Build and maintain resilience plans

The bill mandates that businesses develop and maintain comprehensive resilience and recovery plans. These plans should detail how businesses will respond to and recover from cyber-incidents, ensuring minimal disruption to operations and swift restoration of services.

 

Make cyber-security training a priority

Staff training is the most common preventative measure adopted following a cyber-breach in 2025, employed by 32% of businesses. While this is a positive sign, businesses need to be more proactive in providing employees with the skills to navigate a cyber-breach earlier. 

 

IT professionals should be up to date on security certifications and practice with hands-on training. For example, hands-on labs and sandboxes are vital to ensure real-time experience identifying and protecting against simulated attacks.

 

Businesses should not underestimate the importance of non-technical employees having a basic understanding of their role in preventing phishing, social engineering and other cyber-threats. In fact, phishing attacks are the most prevalent and disruptive cyber-breach – and these attacks target individuals regardless of their role or seniority. Building a strong first line of defence starts with empowering every employee to spot and stop threats before they escalate.

 

A strategic opportunity

The new regulations signal a clear move from voluntary to mandatory cyber-security standards. Yet, they also present a strategic opportunity. Organisations that take proactive steps now will not only enhance their resilience and trustworthiness but also gain a competitive edge in staying ahead of evolving cyber-threats.

 


 

Matthew Lloyd Davies is Principal Security Author at Pluralsight

 

Main image courtesy of iStockPhoto.com and putilich


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543