


The emphasis on resilience means that providers will have to explain how they would recover from an incident and not simply avoid it. The new regulator of all this, the Information Commissioner’s Office (ICO), will be given teeth, the government indicated. That will mean the ICO will need more resources to meet this expanded, and in many ways, daunting remit.
What this means for enterprises is that the service providers, and probably major data center operators, will have to operate to more consistent standards. Broadly, this is positive, although many will already be working towards those standards under the influence of NIS2 regulations.
In 2024, the NCSC responded to 430 cybersecurity incidents, including 89 it said were rated as “nationally significant.” That included the large ransomware attack on the NHS pathology services provider Synnovis last June that ended up costing an estimated £32.7 million ($42 million) to fix.
The focus on resilience in the cybersecurity sector means that service providers will need to demonstrate their ability to recover from incidents, rather than just avoiding them altogether. The Information Commissioner's Office (ICO) will now have more authority in regulating this area, requiring additional resources to effectively carry out its expanded responsibilities.
For enterprises, this shift means that service providers and data center operators will need to adhere to more consistent standards. While this may be seen as a positive development overall, many organizations are already working towards these standards due to existing NIS2 regulations.
In 2024, the National Cyber Security Centre (NCSC) responded to 430 cybersecurity incidents, with 89 classified as "nationally significant." This included a major ransomware attack on the NHS pathology services provider Synnovis, which resulted in an estimated cost of £32.7 million ($42 million) to resolve.