Why the Cyber Security and Resilience Bill must go further to protect the UK economy
Feature
Cyber security

Chris Dimitriadis, chief global security officer at ISACA, outlines how the Cyber Security and Resilience Bill provides an important foundation for UK cyber governance and where further measures could strengthen national resilience

The Cyber Security and Resilience Bill is currently making its way through UK Parliament. At its core, the Bill is being introduced to update and strengthen the UK’s outdated cybersecurity rules, replacing and expanding the old framework from 2018 to better protect critical infrastructure and essential services from cyberattacks. 

If made law in its current form, it would bring more types of organisations into scope, such as large data centres, managed service providers, and key suppliers, which make up key components of the UK’s digital infrastructure. It will also tighten incident reporting rules and gives regulators and government stronger powers and penalties to enforce security standards.

Ultimately, its overall aim is to make the UK’s digital systems more resilient to evolving threats and keep essential services running safely. There’s no doubt that it is a vital step forward in updating outdated cyber laws.

But as it stands, it doesn’t go far enough. It must go further by expanding its scope, strengthening accountability and mandating resilience testing to fully protect the UK economy from escalating cyber threats.

Why up-to-date legislation is critical for the UK
This is such an important piece of UK legislation, especially in the wake of high-profile cyberattacks which have shown just how devastating cyber incidents can be. Attacks on major UK retailers such as M&S and The Co-op are stark reminders of just how vulnerable the UK’s digital ecosystem has become. They exposed significant weaknesses in digital infrastructure, wiped millions off share prices, and disrupted operations for months at a time. 

Beyond the financial impact, the attacks halted everyday services that people rely on, affecting supply chains and customers, and significantly damaged those business’ reputations. They show that cyber incidents are no longer abstract IT issues but real-world disruptions with huge economic and social consequences. And the threat landscape will only get more severe. As organisations become more digitally connected and increasingly reliant on data, the potential attack surface for cybercriminals continues to expand. ISACA’s State of Cyber 2025 research found that almost two in five (39 per cent) European IT and cybersecurity professionals report that their organisation is experiencing more cybersecurity attacks than this time last year, while a further 27 per cent report facing a similar number of incidents.
This expectation reflects a sense of realism rather than pessimism. Cyber attackers are becoming more sophisticated, while many organisations are struggling to keep pace with evolving threats. Without stronger governance and regulation, these risks will continue to escalate, with far-reaching consequences for businesses, individuals, and public trust. 

In its current form, the Bill does not go far enough
In its current form, the Bill would mean that digital service providers such as cloud platforms and data centres would fall in scope and be subject to closer scrutiny on their cyber resilience. Whilst a step in the right direction, many major private sector employers will remain outside of meaningful cyber regulation and legislation. 

This poses a problem for resilience. Cyber regulation has to date focused on Critical National Infrastructure – when digital systems weren’t so developed, this was logical and sensible to protect the UK economy. But now every large organisation runs on digital infrastructure. Without the right defences, they are all vulnerable to cyberattacks which can disrupt daily life.

Furthermore, the Corporate Governance Code, which sets standards for premium-listed companies, applies to the largest publicly traded companies in the UK, including M&S, but currently the Code only asks that these firms “have regard to” cyber risks and security in their annual reports. It is no surprise, then, that progress has been limited: without robust regulatory requirements, firms that have a major role in the UK economy have been left to identify and justify their own incentives for investing in more resilient systems.

The Cyber Security and Resilience Bill is a critical opportunity to close these gaps. Without stronger standards and clearer accountability, cyber risk will remain a drag on our economy and a growing threat to national security. It is imperative that the Government expands the legislation to make cyber risk a clear part of corporate governance for all major employers – with this in place, cyberattacks are so much less likely to have such an impact.