Cyber resilience is becoming a board-level responsibility. For organisations delivering essential services, operating critical infrastructure, or supporting regulated sectors, the UK Cyber Security and Resilience Bill will increase expectations around risk management, incident reporting, supplier oversight, and evidence.
As of 8 September 2026, the Cyber Security and Resilience (Network and Information Systems) Bill is progressing through the House of Lords. It completed its Commons stages on 16 June 2026 and entered the Lords committee stage on 1 September 2026. The final requirements, implementation dates, and sector-specific thresholds may still develop as the legislation progresses and supporting regulations are introduced. (bills.parliament.uk)
Senior leaders should not wait for every detail to be finalised. The most effective preparation starts with understanding where the organisation may be in scope, identifying governance weaknesses, and testing whether existing cyber processes can support faster reporting and stronger evidence.
Why the Bill matters to senior leaders
The Bill is intended to update and expand the UK’s existing Network and Information Systems Regulations 2018. It is designed to strengthen the security and resilience of essential services, extend regulatory oversight, improve incident reporting, and give regulators stronger enforcement powers. It also introduces provisions relating to digital services, data centres, managed services, and critical suppliers. (commonslibrary.parliament.uk)
For boards and executive teams, this means cyber security cannot be treated as a narrow technology issue. The likely impact will extend across:
- Business continuity and operational resilience
- Regulatory reporting
- Supplier and third-party risk
- Executive accountability
- Audit readiness
- Customer and stakeholder communications
- Investment decisions
- Evidence of effective cyber risk management
The key question is not only whether the organisation has security controls in place. Leaders must also demonstrate that those controls are governed, tested, monitored, and improved over time.
Establish whether your organisation is likely to be in scope.
The first step is to create a clear view of the services, systems, and suppliers that could bring the organisation within scope.
The Bill is focused on organisations connected to essential activities and services. It also proposes extending coverage to areas such as data centres, digital services, managed services, and suppliers whose failure could affect a regulated organisation’s ability to provide an essential service. (commonslibrary.parliament.uk)
Leaders should ask:
- Which services are essential to customers, citizens, patients, or national infrastructure?
- Which technology systems support those services?
- Could the organisation be classified as a relevant digital service provider or critical supplier?
- Which external providers have privileged access to important systems?
- Could a supplier failure interrupt an essential service?
- Which regulators or government bodies may have oversight?
- Are UK operations, data, or services connected to wider international groups?
Legal, compliance, risk, technology, procurement, and security teams should jointly lead this review. The IT department should not determine scope alone, as it depends on the organisation’s services, operating model, dependencies, and regulatory relationships.
Secondary legislation and sector-specific guidance may support the Bill's final scope and detailed thresholds. Treat the current position as a planning baseline, not a substitute for legal or regulatory advice.
Give the board a clear view of cyber resilience.
A common weakness in cyber governance is the gap between technical reporting and executive decision-making. Security teams may have extensive data, but boards need clear answers about business exposure, resilience, and the decisions required.
Senior leaders should establish a regular cyber resilience reporting process that covers:
- The organisation’s most important services
- The systems and suppliers that support those services
- Current material cyber risks
- Control effectiveness
- Open remediation actions
- Incident response readiness
- Recovery performance
- Compliance and evidence gaps
- Decisions requiring executive approval
The NCSC Cyber Assessment Framework can provide a useful structure for this work. The CAF is outcome-focused and helps organisations assess how well they manage cyber risks to essential functions. It is designed to support both improvement and demonstration of cyber resilience, rather than operate as a simple tick-box exercise. (ncsc.gov.uk)
Boards do not need every technical detail. They do need confidence that management can identify unacceptable consequences, protect essential services, respond to disruption, and provide evidence of progress.
Test whether incident reporting can meet the new timescales.
One of the most important proposed changes is a two-stage incident reporting process.
A regulated organisation would need to provide an initial notification within 24 hours of becoming aware that a significant incident is taking place. A fuller report would then be required after 72 hours, with the information available to the organisation at that point. The initial notification is intended to act as an early warning and would include basic information such as the organisation’s name, the affected service, and brief incident details. (gov.uk)
This creates a practical challenge. Organisations must identify, assess, escalate, approve, and report incidents while the facts are still developing.
Leaders should test the complete reporting workflow, including:
- How an incident is first detected
- Who decides whether it may be significant?
- How the affected service is identified
- Who has authority to notify the regulator?
- How the NCSC is informed
- How legal, communications, and customer teams are involved
- How information is validated before submission
- How updates are managed after the initial notification
- How the organisation records its decision-making
A tabletop exercise should simulate a serious incident outside normal office hours. Include incomplete information, conflicting evidence, supplier delays, and pressure from customers or the media. The purpose is to test whether the organisation can make a defensible decision quickly, not whether it can confirm every detail immediately.
Improve incident evidence and investigation records.
Fast notification depends on reliable evidence. If security teams cannot quickly establish what happened, which service was affected, when the incident began, and what actions have been taken, reporting will slow and become less consistent.
Organisations should review whether they can collect and preserve:
- Initial detection times
- Alert and event records
- Identity and access activity
- Endpoint and network evidence
- Relevant cloud activity
- System and application logs
- Investigation notes
- Decisions and approvals
- Communications with suppliers
- Containment and recovery actions
- Evidence supporting the final incident assessment
Evidence should be understandable to both technical and non-technical audiences. A board, regulator, auditor, or legal adviser may need to understand the reasoning behind a decision without interpreting raw security data.
This is where AI-assisted cyber intelligence can support, but not replace, human judgement. Harvey® AI can help security teams investigate activity, prioritise relevant information, summarise findings in plain English, and create a more consistent record of decisions. The purpose is to help people work faster and more clearly while keeping human oversight, approval, and accountability in place.
Strengthen supplier assurance
The Bill’s focus on critical suppliers reflects a wider change in cyber risk management. Organisations are increasingly judged not only on their own controls, but also on the resilience of the services and providers they depend on.
Supplier assurance should move beyond annual questionnaires. Leaders should identify suppliers that could affect essential services and assess them by business impact.
Important questions include:
- What service does the supplier support?
- What would happen if that service became unavailable?
- Does the supplier have privileged or remote access?
- How quickly must the supplier notify the organisation of an incident?
- Can the supplier provide relevant evidence?
- Are recovery objectives tested?
- Are subcontractors involved?
- Where is data stored and processed?
- Can access be removed quickly when the contract ends?
- Does the contract support investigation, audit, and regulatory cooperation?
Contracts should define incident notification responsibilities, cooperation requirements, evidence access, recovery expectations, and rights to review security performance. Procurement and legal teams should work closely with security and operational resilience leaders to ensure these obligations are practical and enforceable.
Align preparation with the NCSC Cyber Assessment Framework.
Organisations should avoid creating a separate compliance programme that sits apart from everyday cyber risk management. A better approach is to align existing governance, security, resilience, and reporting activities with a recognised framework.
The NCSC CAF provides four high-level objectives and 14 principles, supported by contributing outcomes and Indicators of Good Practice. It can help organisations assess areas such as governance, risk management, protective security, detection, response, and recovery. (ncsc.gov.uk)
Leaders can use the CAF to:
- Define the organisation’s essential functions.
- Identify unacceptable business consequences.
- Assess current control maturity.
- Prioritise improvement activities
- Assign ownership for each outcome.
- Record evidence and management decisions
- Report progress to the board.
- Support conversations with regulators and auditors
Apply the CAF proportionately and in the context of the organisation’s sector, risk profile, and essential services. It should support better decisions rather than become a compliance exercise disconnected from operational reality.
Build an evidence-led compliance process.
Compliance readiness depends on more than having policies. Organisations must show that controls are operating and that leaders understand the remaining risks.
An evidence-led process should connect:
- Policy requirements
- Control owners
- Technical data
- Risk assessments
- Incident records
- Supplier reviews
- Testing results
- Remediation actions
- Executive approvals
- Audit evidence
Evidence should be current, attributable, and easy to retrieve. If an organisation relies on manual spreadsheets, disconnected tools, or informal email trails, it may struggle to demonstrate control effectiveness under regulatory scrutiny.
Continuous monitoring can help identify exceptions earlier and reduce pressure during audits or regulatory reviews. It can also help security and compliance teams focus on material issues instead of spending excessive time collecting information from multiple systems.
A practical 90-day preparation plan
Leaders can begin with a focused programme over the next three months.
Days 1 to 30: Understand exposure
- Identify essential services and supporting systems.
- Map critical suppliers and technology dependencies.
- Review likely regulatory scope.
- Confirm executive and operational owners.
- Compare current arrangements with the NCSC CAF.
- Identify gaps in incident escalation and reporting.
Days 31 to 60: Test operational readiness
- Run a 24-hour notification tabletop exercise.
- Test the 72-hour reporting workflow.
- Review log retention and evidence availability.
- Assess supplier incident notification processes.
- Confirm contact details for regulators, the NCSC, legal advisers, and key partners.
- Review board reporting and decision-making processes.
Days 61 to 90: Improve and demonstrate
- Prioritise the most important resilience gaps.
- Update incident response and supplier contracts.
- Create a central evidence register.
- Assign accountable owners and target dates.
- Report progress to the board.
- Schedule recurring assurance reviews and exercises.
This approach creates momentum without requiring the organisation to wait for every final piece of guidance.
What should boards ask now?
The following questions can help directors and senior executives understand whether the organisation is preparing effectively:
- Do we know which services are essential?
- Do we understand our likely obligations and regulatory relationships?
- Can we identify a significant incident quickly?
- Can we notify the right authority within 24 hours?
- Can we provide a fuller report after 72 hours?
- Do we know which suppliers could disrupt essential services?
- Can we produce reliable evidence of control operation?
- Are incident decisions documented and approved?
- Have we tested our response outside normal working hours?
- Can we explain our cyber resilience position in clear business language?
If the answers are unclear, the organisation has an opportunity to improve before enforcement expectations become more demanding.
Turn regulatory preparation into resilience improvement
The Cyber Security and Resilience Bill should not be approached as a narrow compliance deadline. It provides a reason to improve how the organisation understands cyber risk, protects essential services, manages suppliers, responds to incidents, and reports to the board.
Leaders that prepare early will be better placed to reduce disruption, strengthen governance, and make more informed investment decisions. They can also demonstrate that cyber resilience is an active management responsibility, supported by evidence and linked to business outcomes.
Jointly lead this reviewSecQube® helps regulated organisations turn complex security data into clear, actionable intelligence. With Harvey® AI, security and compliance teams can accelerate investigations, improve evidence collection, support executive reporting, and strengthen the value of existing Microsoft security investments, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Entra ID, and Microsoft Azure.

