Changes to UK cyber regulation could affect more organisations directly and many more through their customers and supply chains. We explain which West Midlands businesses should pay attention and the questions they should be asking now.
Contents
- Contents
- Could the Cyber Security and Resilience Bill Affect Your Business?
- Key Takeaways
- The Bill Is About More Than Individual Organisations
- Not Every Business Will Be Directly Regulated
- Managed Service Providers Deserve Particular Attention
- Supply Chains Are Becoming Part of Cyber Governance
- Incident Notification May Affect Supplier Relationships
- Regulation Makes Asset and Dependency Visibility More Important
- Existing Cyber Controls Remain the Foundation
- Cyber Essentials May Help Demonstrate a Baseline
- Manufacturers Should Consider Digital and Operational Dependencies Together
- Do Not Wait for Regulation to Finalise Every Detail
- Five Questions Businesses Can Ask Now
- Regional Support Can Help Businesses Navigate the Change
- The Commercial Effects May Reach Further Than the Legal Perimeter
Could the Cyber Security and Resilience Bill Affect Your Business?
The Cyber Security and Resilience Bill represents a significant change in the UK’s approach to protecting essential and digital services. Its direct regulatory requirements will apply to particular categories of organisation rather than to every business, but its commercial effects are likely to extend further through technology providers, managed services and supply chains.
That distinction matters for West Midlands SMEs. A business may never become directly regulated under the legislation and still find that an important customer changes its security requirements, introduces new contractual provisions, asks more detailed questions about incidents or expects suppliers to demonstrate stronger cyber controls.
The originating analysis, “The UK Cyber Security and Resilience Bill 2025: What It Means and Why It Matters“, examined the Bill as part of a wider shift towards treating cyber resilience as a systemic issue. For businesses, the practical question is narrower: where could the legislation affect existing responsibilities, customer expectations and supplier relationships, and what preparation is sensible before the final regulatory regime is fully implemented?
The answer depends heavily on the organisation’s role. Businesses providing important digital or managed services need to examine potential direct exposure carefully. Other SMEs should concentrate on whether they supply organisations likely to face stronger resilience obligations and whether their own security arrangements would withstand greater customer scrutiny.
Read the wider regional analysis. The West Midlands Cyber Cluster examines the Cyber Security and Resilience Bill in the context of systemic resilience, supply-chain accountability and the West Midlands economy, in the companion article “The Cyber Security and Resilience Bill: What It Means for the West Midlands”.
Key Takeaways
- The Cyber Security and Resilience Bill expands the UK’s existing cyber-regulatory framework, particularly around important digital and managed services, but it does not place every UK business directly within scope.
- SMEs can nevertheless be affected indirectly when regulated customers strengthen supplier assurance, contractual security requirements or incident-notification expectations.
- Technology businesses and managed service providers should pay particular attention to the legislation because privileged access and digital dependency can make their services important to customer resilience.
- Businesses do not need to wait for every regulatory detail before improving basic controls, understanding critical dependencies and preparing workable incident-response arrangements.
- West Midlands organisations should distinguish carefully between legal obligations that apply directly to them and commercial requirements passed down by customers; the two can overlap, but they are not the same thing.
The Bill Is About More Than Individual Organisations
The UK’s existing cyber-security regulatory framework is substantially based on the Network and Information Systems Regulations 2018, commonly known as the NIS Regulations.
That regime concentrated on operators of essential services and certain digital service providers. Since 2018, however, the way organisations consume technology has continued to change.
Cloud platforms, managed services, outsourced IT and interconnected digital supply chains now perform functions that can be critical to the operation of organisations delivering important services. A security failure inside one technology provider can consequently affect multiple customers.
The Cyber Security and Resilience Bill is intended to update the regulatory framework for that environment.
Its significance lies partly in this change of perspective. Cyber resilience cannot always be managed by protecting individual organisations independently when those organisations depend on shared suppliers and digital infrastructure.
For businesses, this means that dependency matters.
An SME’s relevance to the cyber-resilience regime may be determined not simply by its own size, but by what service it provides, which customers depend on it and what access it possesses.
That is particularly important for technology companies whose teams may be small but whose systems or administrator accounts can affect much larger organisations.
Not Every Business Will Be Directly Regulated
One of the easiest mistakes when discussing new cyber legislation is to imply that every company will suddenly acquire the same statutory obligations.
That is not the purpose of the Bill.
The regime is designed around specified organisations, services and dependencies. Whether an individual business falls within scope depends on the legislation’s definitions and the organisation’s circumstances.
Businesses should therefore avoid treating general summaries as a substitute for determining their own position.
For many ordinary SMEs, the legislation’s most immediate significance is unlikely to be direct regulation. It will instead arise through relationships with customers or suppliers that are within the regulatory perimeter.
This distinction is important because direct legal obligations and customer requirements have different sources.
A regulated customer may decide that it needs stronger assurance from an important supplier. The resulting contractual requirement may be entirely legitimate and commercially significant, but that does not automatically mean the supplier has itself become a regulated entity under the Bill.
Understanding which type of requirement is being imposed helps the business respond appropriately.
Where direct regulatory status is uncertain or commercially important, organisations should obtain suitable professional or legal advice rather than relying on general guidance.
Managed Service Providers Deserve Particular Attention
Managed service providers occupy an important position in modern business infrastructure.
An MSP may administer customer networks, manage cloud environments, maintain security systems or hold credentials with substantial privileges. A compromise of the provider can therefore create a route into several customers simultaneously.
This concentration of access explains why managed services have become an important part of the UK’s developing cyber-regulatory approach.
For West Midlands technology businesses providing managed services, the practical implication is that cyber security increasingly forms part of the service being sold, whether or not the company describes itself as a cyber-security provider.
A customer granting administrator access is making a significant trust decision.
Providers should therefore understand how privileged accounts are protected, whether multi-factor authentication is enforced, how customer environments are separated, what activity is logged and how access is removed when employees leave or responsibilities change.
Incident handling is equally important.
If a provider discovers that a privileged account has been compromised, affected customers may need information quickly enough to protect their own systems. A technically effective response that does not include timely customer communication can leave downstream organisations exposed.
These are sensible practices regardless of final regulatory status. The Bill increases their significance by placing greater policy emphasis on the digital dependencies through which disruption can spread.
Supply Chains Are Becoming Part of Cyber Governance
The Cyber Security and Resilience Bill forms part of a broader shift towards understanding cyber security through dependencies rather than organisational boundaries.
National business evidence shows why this remains challenging.
The 2025/26 Cyber Security Breaches Survey found that only 15% of businesses reviewed cyber risks associated with their immediate suppliers and 6% considered their wider supply chains.
The proportion increased markedly with business size. Twelve per cent of microbusinesses and 22% of small businesses reviewed immediate supplier risks, compared with 30% of medium-sized and 48% of large businesses.
This difference has practical implications for SMEs.
Larger organisations are more likely to examine their dependencies and therefore more likely to ask suppliers questions about cyber security. Regulation can strengthen that incentive where the customer is expected to understand and manage risks associated with important services.
An SME may consequently encounter more detailed procurement questionnaires, contractual security clauses, requirements to notify customers of incidents or expectations around recognised security standards.
These effects will not be uniform.
A supplier providing a low-risk commodity service creates a different dependency from a software provider processing sensitive information or an IT company holding administrator access. Customer requirements should therefore be proportionate to the risk created by the relationship.
SMEs should similarly understand where they sit within customer operations. The more difficult the service would be to replace, the greater the access involved or the more significant the consequences of disruption, the more likely cyber assurance is to become commercially important.
Incident Notification May Affect Supplier Relationships
Cyber incidents create an information problem as well as a technical one.
A business may discover suspicious activity without immediately knowing its full extent. Investigation takes time, but customers potentially affected by the incident may need enough information to assess their own exposure.
Regulatory regimes therefore place importance on incident reporting and notification.
For suppliers, this can translate into contractual expectations even where the supplier is not itself directly subject to the same statutory reporting requirement as its customer.
A regulated organisation cannot manage its own reporting obligations effectively if an important supplier waits too long to disclose an incident that affects the customer’s systems or services.
SMEs should review important contracts with this possibility in mind.
What constitutes a notifiable security incident? Who must be contacted? Within what period? Does the obligation begin when compromise is confirmed or when it is suspected? What information must be supplied?
These details matter because vague commitments can become difficult to interpret during an actual incident.
Businesses should also ensure that somebody inside the organisation knows which customers have specific notification requirements. Contractual obligations hidden inside procurement documents are of little operational value if the incident-response team does not know they exist.
Regulation Makes Asset and Dependency Visibility More Important
Businesses cannot manage resilience effectively without knowing which systems and suppliers support important activities.
This sounds straightforward, but digital dependency can become difficult to see.
A business may rely on a cloud identity provider to access several other services. A managed IT provider may possess administrator credentials across the organisation. A specialist application may depend on infrastructure operated by another supplier. A manufacturer may require remote engineering support to maintain production equipment.
An incident affecting one component can therefore have consequences elsewhere.
The practical starting point is to identify important business services and work backwards.
Which technology supports them? Which suppliers provide that technology? Who can access it? Where is important information held? What happens if the system or supplier becomes unavailable?
This exercise is valuable even for organisations with no direct regulatory exposure.
It supports incident planning, supplier management, insurance discussions and business continuity. It also makes future customer-assurance questions considerably easier to answer.
For smaller organisations, the result does not need to be an elaborate enterprise architecture model. A maintained record of critical systems, suppliers, owners and recovery dependencies can provide substantial practical value.
Existing Cyber Controls Remain the Foundation
New legislation can create an impression that organisations need an entirely new category of security control.
For many businesses, the immediate priorities are much more familiar.
Important accounts should be protected with multi-factor authentication. Systems should be maintained and updated where possible. Administrative access should be restricted. Important data should be recoverable. Staff should know how to report suspicious activity, and the organisation should have a workable process for handling an incident.
The 2025/26 Cyber Security Breaches Survey shows that implementation remains uneven.
While 81% of businesses reported malware protection and 74% reported both cloud backups and password policies, only 47% used multi-factor authentication. Thirty per cent had conducted a cyber risk assessment during the previous year, and only 25% maintained a formal incident-response plan.
These gaps matter because regulatory resilience ultimately depends on operational capability.
A business can possess detailed policies and still struggle during an incident if nobody knows who has authority to act, critical supplier contacts are unavailable or recovery arrangements have never been tested.
SMEs should therefore resist the temptation to begin with regulatory documentation before establishing the controls and processes that documentation is supposed to describe.
Cyber Essentials May Help Demonstrate a Baseline
Cyber Essentials can provide a useful foundation for businesses anticipating greater customer scrutiny.
The scheme does not establish compliance with the Cyber Security and Resilience Bill, nor should certification be represented as doing so.
Its value is narrower.
Cyber Essentials provides a recognised baseline covering common technical controls and can give customers evidence that a supplier has addressed fundamental areas of security.
Adoption is increasing. The 2025/26 Breaches Survey found that 5% of businesses held Cyber Essentials, compared with 3% in the previous year. Among small businesses, certification increased from 5% to 12%, while adoption among large businesses rose from 21% to 35%.
For SMEs operating in supply chains where certification is increasingly requested, obtaining it can therefore support both security improvement and commercial readiness.
Businesses with more complex risks may need to go further.
A managed service provider with privileged customer access, a manufacturer operating connected industrial technology or a software company processing sensitive information may require additional controls appropriate to those activities.
The principle remains proportionality: establish a credible baseline, then strengthen it according to the consequences associated with the organisation’s services and dependencies.
Manufacturers Should Consider Digital and Operational Dependencies Together
For West Midlands manufacturers, cyber resilience can extend beyond conventional IT.
Production environments increasingly depend on connected machinery, industrial software, remote maintenance and external engineering providers. An incident affecting one of those dependencies can create operational consequences even where corporate systems remain unaffected.
Manufacturers supplying larger or regulated customers may also experience increased assurance requirements from the other direction.
A customer concerned about continuity may want to understand whether an important component supplier can withstand a disruptive cyber incident. A manufacturer holding sensitive designs or accessing shared customer systems may face additional security requirements because of the information or connectivity involved.
This creates two separate questions.
The first concerns the manufacturer’s own resilience: what technology and suppliers could interrupt production?
The second concerns the manufacturer’s position as a supplier: what cyber risk does it create for its customers?
Considering both provides a more useful view than treating cyber security solely as protection for office IT.
Do Not Wait for Regulation to Finalise Every Detail
Businesses sometimes postpone security improvement because legislation is still developing.
There are good reasons to wait before making assumptions about specific legal duties. Scope, regulatory guidance and implementation arrangements matter, and organisations should not claim compliance with requirements that have not yet been fully established.
The same caution does not apply to basic resilience.
A business does not need final regulatory guidance before introducing multi-factor authentication, understanding privileged access, testing backups, identifying critical suppliers or preparing an incident-response process.
These measures address existing business risk and are likely to remain useful regardless of the precise regulatory position.
The distinction is therefore between preparing for resilience and predicting compliance.
Businesses can improve resilience now while continuing to monitor the legislation and seeking specialist advice where direct obligations may apply.
That approach reduces the risk of either doing nothing until a deadline approaches or investing heavily in speculative compliance activity that later proves unnecessary.
Five Questions Businesses Can Ask Now
For SMEs trying to determine whether the Bill deserves immediate attention, a small number of business questions can establish the likely priority.
First, does the organisation provide managed, digital or technology services that customers depend on to operate important systems?
Second, does it hold privileged access to customer environments, sensitive information or infrastructure?
Third, does it supply organisations operating in sectors where cyber resilience is subject to significant regulatory or operational scrutiny?
Fourth, do existing customer contracts contain cyber-security or incident-notification requirements that the business has not tested operationally?
Finally, could the organisation explain and evidence its security controls if an important customer asked for assurance tomorrow?
The answers will not determine legal scope, but they can identify whether the commercial consequences of the changing regulatory environment deserve attention.
A business answering yes to several of these questions has a stronger reason to examine the legislation and its customer relationships in more detail.
Regional Support Can Help Businesses Navigate the Change
Regulatory change is particularly difficult for smaller organisations because legal, technical and commercial questions can become intertwined.
A business may need to determine whether it is directly in scope, understand what a customer is asking for, improve technical controls and find suitable expertise. Those are different problems and may require different sources of support.
The West Midlands Cyber Hub can help regional organisations navigate that landscape by connecting businesses with relevant cyber expertise, programmes, events and wider support.
National guidance should remain the authoritative source for the developing regulatory regime, while appropriate legal or specialist advice may be necessary where an organisation needs to determine its own obligations.
The regional role is to make the route from understanding the issue to finding practical assistance easier to navigate.
The Commercial Effects May Reach Further Than the Legal Perimeter
The Cyber Security and Resilience Bill should not be presented as legislation that suddenly regulates every West Midlands SME.
Its wider significance is subtler.
The Bill reflects a growing recognition that cyber resilience depends on networks of organisations, technology providers and suppliers. When important services rely on external businesses, the security of those businesses becomes relevant even when they sit outside the formal regulatory boundary.
For SMEs, that creates both responsibility and opportunity.
Businesses that provide important digital services or privileged access should expect greater scrutiny of how they manage security. Suppliers to regulated organisations may encounter stronger contractual and assurance requirements. Companies able to demonstrate proportionate cyber maturity may find those requirements easier to satisfy than competitors that begin preparing only when a customer asks.
The appropriate response is therefore not regulatory alarm.
It is to understand where the business sits within important digital and commercial dependencies, establish a defensible security baseline and ensure that contractual promises about resilience and incident response can actually be delivered.
As the UK’s cyber-resilience regime develops, those capabilities are likely to matter well beyond the organisations named directly in legislation.