• Sectors we work in banner(2)

    Quick Reads

A new Cyber Security and Resilience Bill

Following on from our Cyber Roundtable post, as part of the King’s Speech on 17 July 2024, the Government announced plans for a new Cyber Security and Resilience Bill (the Bill). The Bill will be introduced to Parliament in 2025. 

Background

We have seen increasing levels of cyber attacks on institutions from the NHS to the Ministry of Defence, demonstrating the importance of the UK’s cyber defences to protect essential services and businesses. The ransomware attack on NHS England in June 2024 resulted in over 10,000 outpatient appointments and 1,693 elective procedures being postponed across a number of UK hospitals. The total cost of these attacks and the associated impact on citizens, supply chains and the economy run to billions of pounds. 

While there are cyber security regulations in force, such as the NIS Regulations 2018, these need to be strengthened to reflect the increasing scale of risk. The Department for Science, Innovation and Technology has said, ‘laws have not kept pace with technological change’, and the UK needs ‘swift action to address the vulnerabilities and protect our digital economy to deliver growth’.

Details of the Bill

The Bill, which will apply UK-wide, will make the following updates to the regulatory framework:

  • broaden the regulatory scope to offer better protection for digital services and supply chains;
  • require increased incident reporting to give the Government better data on cyber attacks;
  • empower regulators to ensure essential cyber safety measures are being implemented.

The above updates will help by:

  • addressing immediate vulnerabilities and preventing similar copycat attacks which target essential services and businesses;
  • leading to a better understanding of cyber threats and helping earlier detection of potential attacks by expanding regulated entities’ obligations to report various types of incidents; 
  • including provisions for regulators to potentially recover costs (to fund their operations) and to proactively investigate potential cyber weaknesses.

Impact on Businesses

By identifying immediate vulnerabilities, the Bill could improve communication across essential services and businesses and create more pro-active messaging about attack risks. At our recent roundtable on Cyber, we heard about business confusion caused by the number of training vendors and detection technologies available. Targeted endorsement of training providers and technologies by regulators coupled with joined-up communication about best practice, could improve confidence and thereby business investment. This could also lead to a more inclusive UK-wide approach to ransomware response. 

The Bill will also encourage businesses to focus on proactively managing vulnerabilities, and ensuring suitable training and investment is made into an embedded cyber security road map. This should reduce business interruption and the consequential impact to supply chains. 

Finally, a more proactive and joined-up approach should lead to fewer debilitating cyber attacks and greater confidence for essential services and businesses on a national and global scale. 

Impact on the Public

A stronger and more joined-up approach to UK cyber security reduces the risk that personal and sensitive information will be leaked, giving the public greater reassurance around personal data. 

Next Steps

The Bill will be introduced to Parliament in 2025. The Government will work with key stakeholders to gather input on the content of the Bill, with further announcements to be made in due course.

Our thinking

  • Women in Leadership: Resilience in Entrepreneurship

    Events

  • Drapers quotes Kerry Stares on the potential for a review of the Modern Slavery Act 2015

    Kerry Stares

    In the Press

  • EU Design Legislation Updates

    Matthew Clark

    Insights

  • The EU Omnibus: resetting the rules on sustainability due diligence

    Kerry Stares

    Insights

  • The Times and Daily Mail quote Dan Pollard on new changes to the Employment Rights Bill

    Dan Pollard

    In the Press

  • Extra Time: The business of women’s football in Africa

    Sarah Johnson

    Podcasts

  • Singaporean Court Declines to Revisit SIAC Registrar’s Administrative Decision

    Thomas R. Snider

    Insights

  • Unlocking Capital: The Strategic Art of Selling Loans

    James Walton

    Insights

  • Ilona Bateson speaks at an event hosted by TheIndustry.fashion on the challenges and opportunities for fashion retailers in 2025

    Ilona Bateson

    In the Press

  • Paul Arathoon writes for City AM on rising executive pay at large listed companies

    Paul Arathoon

    In the Press

  • What do the proposed changes to business property relief mean for Investors and Entrepreneurs and their businesses?

    Mary Perham

    Insights

  • Swiss Anti-Corruption Laws: A Guide to Bribery Offences, Compliance, and Penalties

    Daniela Iselin

    Insights

  • The Good, the Bad and the Ugly - the inheritance tax Consultation on agricultural and business property

    Sarah Wray

    Quick Reads

  • Building, Property Wire and Building Design quote Michael O'Connor on the government's latest Grenfell inquiry report

    Michael O'Connor

    In the Press

  • Passage of the English Arbitration Act 2025 into Law

    Thomas R. Snider

    Insights

  • Mary Bagnall writes for FMCG CEO on the recent Thatchers v Aldi court ruling

    Mary Bagnall

    In the Press

  • A Ray of Light for Developers - High Court provides some comfort in recent injunction case

    Georgina Muskett

    Insights

  • Joanne Searle and Ciara McEwen write for The Carer on what the Labour government is doing for the future of social care

    Joanne Searle

    In the Press

  • Further jurisdictional transposition of the ISSB Standards, this time in Hong Kong

    Shirley Fu

    Insights

  • Up In The AI: Gen AI and In-house Teams

    Joe Cohen

    Podcasts

Back to top