Cybersecurity Policy Report, U.K. Parliament Readies Bill to Update Cybersecurity Law, (Nov 12, 2025)
Cybersecurity legislation introduced today in the United Kingdom’s Parliament aims to improve U.K. cyber defenses and protect essential services like health care, utilities, and transport, according to the U.K.’s Department for Science, Innovation, and Technology (DSIT).
The Cyber Security and Resilience Bill would reform and add to the existing Network and Information Systems (NIS) Regulations 2018 and, according to a news release, would “deliver a fundamental step change in the UK’s national security—making essential and digital services more secure in the face of cyber criminals and state actors.”
The bill would make crucial updates to the legacy regulatory framework by expanding the remit of the regulation to protect more digital services and supply chains, putting regulators on a strong footing to ensure essential cyber safety measures are being implemented and mandating increased incident reporting to give government better data on cyber attacks.
Importantly, organizations that fall within the scope of the bill would be required to report significant cyber incidents within 24 hours to both their regulator and the National Cyber Security Centre. A full report is required within 72 hours of the incident to ensure support can be provided more quickly and to “help build a stronger national picture of cyber threats,” DSIT said.
The bill “represents a step change in how the government protects people in an increasingly dangerous world” and will “deliver greater economic stability, protect businesses and working people from the impact of cyberattacks, and support further investment into the UK’s cyber security sector,” DSIT said.
News: InternationalLegislation DataSecurity