UK sets out new cyber reporting requirements for critical infrastructure
ID: 97e7c0b9-b0e3-5545-9007-d2c8e29ae765
STIX ID: report--97e7c0b9-b0e3-5545-9007-d2c8e29ae765
Feed Name: The Record from Recorded Future News
The UK government’s proposed Cyber Security and Resilience Bill will expand incident reporting to include any events significantly affecting confidentiality, integrity, or availability; require initial notification within 24 hours and a full report within 72 hours; extend regulation to Managed Service Providers, cloud-based/digital services, and formally designate data centers as critical national infrastructure; introduce stronger supply chain duties (with potential “high-impact supplier” designations); and provide enhanced enforcement tools and flexible regulatory update powers for the Secretary of State, including the ability to direct regulated entities in response to specific cyber threats. The bill aligns with NIS2 where feasible and complements a separate Home Office consultation on ransomware (including public-sector payment bans and mandatory reporting), with introduction to Parliament planned this year.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
