Skip to main content
    Cyber SecurityCompliance

    The UK's new cyber bill doesn't stop at hospitals and power stations

    The Cyber Security and Resilience Bill pulls IT providers and their supply chains into scope – including businesses that assumed none of this applied to them.

    John Howell, CEO
    August 2026
    7 min read

    The Cyber Security and Resilience Bill, introduced to the UK Parliament in November 2025, reads at first like legislation for a different kind of company than yours. It's aimed at hospitals, energy networks, water companies and transport operators – the organisations that keep the country running. If none of those words describe your business, it would be easy to file this under someone else's problem.

    That would be a mistake. For the first time, the Bill also brings the companies that supply IT services into those sectors into scope – including IT management, help desk support and cyber security providers. And it gives regulators new powers to reach further down the supply chain than that, to any supplier judged critical enough to matter.

    What the Bill actually does

    Three changes matter most – and each one widens the circle of businesses that have to prove, rather than assert, that their security is in order.

    IT providers regulated

    Medium and large companies providing IT management, IT help desk support or cyber security services to public and private sector organisations – including the NHS – will be regulated for the first time, with clearly defined security duties to meet.

    Critical suppliers

    Regulators get new powers to designate any organisation a "critical supplier" to the UK's essential services where they meet the criteria – whether that's a company supplying diagnostics to the NHS or chemicals to a water firm. Once designated, they must meet minimum security requirements.

    24 and 72 hours

    Significant or potentially significant incidents must be reported to the regulator and the National Cyber Security Centre within 24 hours, with a full report within 72 hours, and affected customers notified promptly. Enforcement is modernised too, with tougher turnover-based penalties for serious breaches.

    Why now

    The timing isn't abstract. In 2024, attackers reached the Ministry of Defence's payroll system through a managed service provider. The Synnovis attack on NHS pathology services disrupted more than 11,000 appointments and procedures, with costs estimated at £32.7 million. The cyberattack on Jaguar Land Rover in August 2025 halted UK factory production and supply chains, with losses of around £1.9 billion – possibly the costliest breach in the country's history. Cyberattacks now cost the UK economy an estimated £15 billion a year.

    Each of those incidents reached a large, well-defended organisation through something smaller and less scrutinised sitting in its supply chain. That is precisely the gap this Bill is designed to close.

    Each of those incidents reached a large, well-defended organisation through something smaller and less scrutinised sitting in its supply chain.

    What this means if you're an SME

    Two groups of businesses should read this Bill closely. If you provide IT management, help desk or cyber security services to other organisations, the new duties may apply to you directly, depending on your size and who you serve. If you supply goods or services that eventually feed into healthcare, energy, water or transport – even two or three steps removed – expect the organisations above you in that chain to start asking harder questions about your security posture, in tender documents and supplier questionnaires, well before any formal designation arrives.

    In practice, cyber hygiene that used to sit under "good practice" is becoming a contractual requirement for a growing part of the UK economy, and a legal one for a defined slice of it. A genuine incident response plan, with reporting timescales already built in, stops being a nice-to-have. Knowing exactly where you sit in your customers' supply chains – not just who you invoice, but whose supply chain you're actually part of – stops being optional too.

    What to actually do about it

    Start with the basics, because the basics are what this Bill is really asking for.

    Get certified

    Cyber Essentials, and Cyber Essentials Plus where your risk profile warrants it, is the baseline that increasingly shows up in supplier forms and tenders. It's affordable, well understood and a simple way to show you're serious.

    Write a real plan

    Not a policy document nobody has read, but a plan with named owners and the same 24-hour and 72-hour reporting rhythm the Bill sets out – so you're not designing a process under pressure during an actual incident.

    Audit properly

    A cyber security assessment or technical compliance audit, done properly rather than as a box-ticking exercise, is worth commissioning if your business has grown or changed what it supplies since you last had one done.

    Ask upstream too

    Ask your own suppliers the questions you're increasingly being asked yourself. Supply chain security runs in both directions, and the businesses that get ahead of it now will find the formal requirements far less disruptive later.

    Where HowTech stands on this

    We hold Cyber Essentials Plus ourselves, and we treat supply chain security as core to our own cyber security consultancy work, not a bolt-on. If you're trying to work out whether this Bill reaches your business, or what a credible incident response plan actually looks like once it's more than a document, that's a conversation worth having before a supplier questionnaire forces it.

    The person who scopes your work is the person who delivers it – which matters more, not less, when the work in question is your incident response plan.

    Source: Industrial Cyber, "UK Cyber Resilience Bill extends oversight to OT suppliers and managed service providers, raises security baseline", 13 November 2025 – industrialcyber.co

    Is your business in scope?

    We help UK SMEs get Cyber Essentials ready, build incident response plans that hold up under pressure, and answer the supply chain questions their customers are already asking.

    Related insights

    The strategic approach that protects UK SMEs without slowing growth.

    What the Five Eyes warning on frontier AI models means for your business.

    How we take SMEs from first assessment to certification.