Cyber Security Is No Longer an IT Problem: What the UK’s New Cyber Security and Resilience Bill Means for Business Leaders

August 4, 2026

Over the years I’ve shared a laugh with many a senior IT or technical lead as they roll their eyes at the same old tired trope ‘Cyber Security is IT’s problem’. It has the word cyber (see also ‘data’, ‘information’, ‘technology’ et al) in the name, therefore it must be IT’s problem.

It’s because for the longest time, cyber security has been viewed as a primarily technical challenge. If firewalls were in place, patches were being applied, and increasingly, if the business had a basic certification providing assurances around security, then most organisations felt reasonably comfortable that cyber risk was being managed.

That mindset is rapidly changing.

As we see an ever-increasing dependence on digital systems, cloud services, AI agents, and interconnected technology ecosystems, cyber security has evolved from an operational concern into a board-level business risk. Regulators, customers, insurers, and investors are all rightly placing greater emphasis on an organisation’s ability not only to prevent incidents, but to demonstrate resilience when they occur.

The clearest indication of this shift to date is the UK’s proposed Cyber Security and Resilience Bill. With the second reading in the Lords coming next month and looking likely to gain royal assent later this year the Bill represents the most significant reform of UK cyber security regulation since the introduction of the Network and Information Systems (NIS) Regulations in 2018.

And whilst the Bill’s direct obligations may apply to a defined set of organisations, the behaviours it encourages (strong governance, accountability and resilience) are quickly becoming expectations across the wider business community. Organisations may never be directly regulated under the legislation yet still feel its impact through customer requirements, supply chain assurance and procurement scrutiny.

What Is the Cyber Security and Resilience Bill?

The Cyber Security and Resilience Bill is a much needed update to the UK’s cyber regulatory framework and aims to strengthen the resilience of organisations that provide services critical to the economy and wider society. It expands on existing requirements, introducing enhanced oversight, and placing greater emphasis on incident reporting and resilience measures.

Some of the more notable changes include the proposed inclusion of additional digital service providers, managed service providers, data centres, and critical suppliers within the regulatory framework. The Bill also proposes an expansion on reporting obligations and the power held by the regulator, in a reflection of the growing concern around the impact that cyber incidents can have across complex supply chains and interconnected services.

We may yet see further amendments as the Bill continues its journey through parliament, but the message is clear: organisations are increasingly expected to demonstrate that cyber risk is being actively governed, not simply delegated to technical teams. This recognition of cyber security as a core business function is more pronounced than ever.

Why This Matters for all businesses

It’s not safe to assume that because your business isn’t directly mentioned in the scope of the Bill that you wont see the wider affects.

In reality, we are already seeing a shift in the level of scrutiny through procurement exercises, cyber security questionnaires, supplier due diligence assessments, insurance requirements, and customer contracts. This puts greater emphasis on organisations to provide assurances around how they manage data protection and cyber security risks, particularly those handling sensitive categories of data or delivering critical services.

And as we see organisations at the top of the food chain continuing to strengthen their own compliance position in line with this, it’s inevitable that the knock on effect will be felt down the supply chain. Bearing that in mind, the Bill can’t be taken as a piece of legislation purely angled at a defined group, with the wider ecosystem being pulled in the same direction. Cyber resilience is not one departments problem (IT practitioners rejoice!) anymore, it is fast becoming the fundamental business expectation that it should be.

The Shift from Cyber Security to Cyber Governance

That shift is down to Cyber Security no longer being framed as a singularly technical issue. Where before we could often see a fragmented landscape; IT teams managed security controls. Compliance teams managed policies. Legal teams considered regulatory obligations. It pointed to an environment where senior leadership would often only involve themselves when a budget needed sign off, or the proverbial hit the fan.

But now that model is changing, better still, it has to change. The Cyber Security and Resilience Bill is helping to promote a sense of accountability from top to bottom within businesses. What we’re seeing and will continue to see are boards and senior leadership teams being asked different questions than they may have faced under NIS regulations in the past:

How is cyber risk assessed and prioritised?
What oversight exists over key suppliers?
How quickly could the organisation detect and respond to an incident?
What evidence is available to demonstrate effective governance?
How are cyber risks linked to wider organisational objectives?

These are not purely technical questions. They are governance questions, strategy questions, questions that don’t sit neatly within one department anymore.

What Good Governance Looks Like

So it begs the question of senior leadership teams and business owners as to exactly what good cyber governance and strategy encompasses and the answer isn’t as simple as the best tech, or having the biggest budget to throw around.

What businesses now need more than ever is clarity, consistency and accountability across the board when it comes governance and risks associated with cyber. Clear ownership of cyber and information risks, regular risk assessment processes, documented incident response procedures, appropriate oversight of the supply chain, and mechanisms for reporting are fantastic starting points.

But key to this is the recognition of the relationship between cyber security and data protection within an organisation. There’s a reason that the new Bill and existing data protection legislation in the UK is governed by one regulator. Yet these disciplines are still too often seen as separate, it’s the same argument as before, cyber is IT, data protection is legal and compliance and senior leadership aren’t involved properly in either. But what we’re frequently talking about in both areas are the same underlying risks. A cyber incident can quickly become a data protection issue. Likewise, weaknesses in information governance can increase cyber risk exposure. Treating these functions, syphoning responsibility off into different departments can make it harder to see the bigger picture, identifying and managing the risks that matter most.

The value to a business increasingly sits in having a unified approach that considers security, privacy, governance, and resilience as part of a broader risk management framework, and that approach starts with a line coming from the top and filtering down into all parts of an organisation.

Cyber Risk Is Becoming a wider business issue

The real significance of the Cyber Security and Resilience Bill is not the individual requirements it may introduce. It is what the legislation tells us about the direction of travel.

Cyber security is shifting in perception from a purely technical view to a wider question on governance, accountability, and organisational oversight. Greater emphasis is being placed on how organisations understand and act on these areas by regulators, customers, supply chain and other key stakeholders and whether you think your organisation is directly affected by the bill or not is almost immaterial. The expectations are evolving in a much broader sense such that organisations are expected to place weight on cyber security decisions in a business critical sense, not just as something to be shifted onto a department that seems on the surface to serve it best.

Of course that doesn’t mean you’re off the hook IT! But we now need to ask our senior leaders and business owners: If a significant cyber incident occurred tomorrow, could we confidently demonstrate that cyber risk is being governed as a business issue, rather than simply managed as a function of a single department?

By Adam Hobbs
Email: adam.hobbs@clearassure.com