Cyber Security and Resilience Bill: Essential Risk Guide
The Cyber Security and Resilience Bill brings managed service providers, data centres and designated critical suppliers into cyber regulation for the first time. Even businesses that are never regulated directly will feel it, because their IT supplier acquires a regulator, a 24-hour incident reporting clock and turnover-based fines. This guide covers where the Bill has reached in Parliament, the four-part managed service provider test, the customer notification duty most buyers miss, the two penalty bands, and the five questions worth putting to your provider before your next renewal.