

Due to be introduced later in 2025, the Bill will introduce mandatory cybersecurity requirements for around 1,000 service providers and extend new protections to over 200 data centres, recognising their importance to the UK’s innovation ecosystem, particularly in artificial intelligence.
Under the proposed measures, more organisations and their suppliers will be required to implement robust cyber security practices, including improved risk assessments, stronger data protection, and enhanced network defences. Regulators will also be granted expanded powers to enforce compliance and demand greater incident reporting, enabling the government to build a clearer picture of emerging cyber risks.
The move comes as cyber threats continue to intensify. The National Cyber Security Centre (NCSC) managed 430 cyber incidents in the 12 months to September 2024, 89 of which were classed as nationally significant. Government research also found that half of UK businesses experienced a cyber breach in the past year.
Technology Secretary Peter Kyle said the Bill forms a core part of the government’s Plan for Change, designed to drive economic growth through greater digital resilience.
“Economic growth is the cornerstone of our Plan for Change, and ensuring the security of the vital services which will deliver that growth is non-negotiable,” Kyle said.
“This legislation will help make the UK’s digital economy one of the most secure in the world — giving us the power to protect our services, our supply chains, and our citizens.”
Andy Ward, SVP International at Absolute Security, welcomed the government’s focus on the supply chain, saying “Supply chains are only as strong as their weakest link. Malicious actors only need one entry point — an unpatched endpoint, for example — to breach a network. A comprehensive cyber resilience strategy, not just technology tools, is key.”
Ward emphasised the importance of centralised visibility across networks and endpoints to detect threats early and act decisively before data is compromised.
Mike Hellers, Product Development Manager at the London Internet Exchange (LINX), called for the Bill to support redundancy strategies that help maintain uptime and operational resilience.
“Building a redundant network encourages uptime and security. At LINX, we offer two independent fabrics in the London Metro area to maximise availability and protect against disruption.”
The Bill will also play a vital role in reinforcing public trust in essential services such as hospitals, utilities, and emergency services, which are increasingly reliant on digital systems and interconnected supply chains.
Once implemented, the Cyber Security and Resilience Bill is expected to establish the UK as a global leader in digital security, protecting both the infrastructure that underpins the economy and the data privacy of millions of citizens.
The UK government is preparing to introduce the Cyber Security and Resilience Bill, a significant piece of legislation aimed at enhancing the country's digital defences and protecting critical national infrastructure from increasing cyber threats. Scheduled for release later in 2025, the Bill will impose mandatory cybersecurity requirements on approximately 1,000 service providers and offer additional protections to over 200 data centres, acknowledging their significance to the UK's innovation ecosystem, particularly in artificial intelligence.
The proposed measures will require more organizations and their suppliers to implement robust cybersecurity practices, including better risk assessments, enhanced data protection, and stronger network defences. Regulators will also be granted expanded powers to enforce compliance and request increased incident reporting, allowing the government to gain a clearer understanding of emerging cyber risks.
This initiative comes as cyber threats continue to escalate, with the National Cyber Security Centre (NCSC) managing 430 cyber incidents in the 12 months leading up to September 2024, 89 of which were deemed nationally significant. Government research also revealed that half of UK businesses encountered a cyber breach in the past year.
Technology Secretary Peter Kyle emphasized that the Bill is a crucial component of the government's Plan for Change, aimed at fostering economic growth through enhanced digital resilience. He stated that ensuring the security of vital services is essential for economic growth and that the legislation will help establish the UK's digital economy as one of the most secure globally.
Industry experts, such as Andy Ward from Absolute Security and Mike Hellers from the London Internet Exchange (LINX), welcomed the government's focus on supply chain security and redundancy strategies to maintain operational resilience. Ward stressed the importance of centralized visibility across networks and endpoints to detect threats early, while Hellers highlighted the benefits of building redundant networks to maximize availability and protect against disruptions.
The Cyber Security and Resilience Bill is expected to reinforce public trust in essential services like hospitals, utilities, and emergency services, which rely increasingly on digital systems and interconnected supply chains. Once implemented, the legislation aims to position the UK as a global leader in digital security, safeguarding both the economy's infrastructure and the data privacy of millions of citizens.