The government has tabled new laws to strengthen cyber defences for essential public services like healthcare, drinking water providers, transport and energy.
The Cyber Security and Resilience Bill, which was introduced to Parliament yesterday (12 November), strengthens national security and protects the UK’s growth by boosting cyber protections for the services that people and businesses rely on every day.
Under the proposals, medium and large companies providing services like IT management, IT help desk support and cyber security to private and public sector organisations like the NHS, will be regulated for the first time.
Regulators will also be given new powers to designate critical suppliers to the UK’s essential services, such as those providing healthcare diagnostics to the NHS or chemicals to a water firm, where they meet the criteria; enforcement will be modernised, including tougher turnover-based penalties for serious breaches, so cutting corners is no longer cheaper than doing the right thing; and the technology secretary will be given new powers to instruct regulators and the organisations they oversee to take specific, proportionate steps to prevent cyber attacks where there is a threat to UK national security.
Liz Kendall, science, innovation, and technology secretary said: “Cyber security is national security. This legislation will enable us to confront those who would disrupt our way of life. I’m sending them a clear message: the UK is no easy target. We all know the disruption daily cyber attacks cause. Our new laws will make the UK more secure against those threats. It will mean fewer cancelled NHS appointments, less disruption to local services and businesses and a faster national response when threats emerge.”
Responding to the news, Dave Adamson, solutions director at Creative ITC, said: “With the introduction of the Cyber Security and Resilience Bill to Parliament, the UK government has highlighted cyber security as a national priority. For AEC organisations, especially those delivering critical national infrastructure projects, this is a wake-up call to reinforce defences and embed resilience for the long term. Cyber risk must be a board-level issue, integrated into strategic planning and governance. Leaders should follow the Cyber Governance Code of Practice and ensure their IT security teams sign up for the NCSC’s free Early Warning service to receive malicious activity alerts for their organisation.
“AEC firms need a culture of continuous monitoring. Complementing stretched IT and cyber teams, partnering with specialists ensures effective, round-the-clock defence measures. This should include 24/7, enterprise-wide IT visibility with expert insight to reduce false positives and minimise disruption. Known vulnerabilities should also be tracked and patched promptly to close gaps before attackers exploit them. Implementing robust multi-factor authentication (MFA) across all access points will also limit exposure to risk.
“Cyber resilience doesn’t stop at your own network. The bill recognises that supply chains are often the weakest link. Enforce strong security standards across partners, setting Cyber Essentials certification as a minimum requirement for all suppliers. Third-Party Risk Management (TPRM) solutions further strengthen resilience, monitoring risks across supply chains for rapid remediation.”


