The proposed Cyber Security and Resilience Bill (CSRB) has been through a series of drafts over the years but now appears to be on its final run to approval.
Revealed at the start of the year, and receiving its first reading in the House of Commons in early November, the CSRB aims to put regulators in a better position to ensure best practices are implemented. It will also introduce mandatory reporting requirements for ransomware attacks.
The Bill proposes amendments to the Network and Information Systems Regulations 2018 concerning the security and resilience of network and information systems used or relied upon in connection with the delivery of essential activities.
Specifically, the CSRB will provide guidance on how to strengthen UK defences against cyber-attacks, better protect essential and critical services, and deliver a fundamental step change in the UKโs national security. The promise: it will make โessential and digital services more secure in the face of cyber-criminals and state actors who want to disrupt our way of lifeโ.
What you need to know about the Cyber Security and Resilience Bill (CSRB)
The major updates in the Cyber Security and Resilience Bill include:
- Expanding the remit of the regulation to protect more digital services and supply chains, addressing an immediate gap in defences and helping prevent attacks similar to those experienced by critical public services.
- Putting regulators on a stronger footing to ensure essential cyber safety measures are being implemented, including potential cost-recovery mechanisms to resource regulators and new powers to proactively investigate potential vulnerabilities.
- Mandating increased incident reporting to give the government better data on cyber-attacks, including cases where a company has been held to ransom, in order to improve understanding of the threats.
Speaking to TechFinitive after reviewing the version read in November, James Morris, Chief Executive of the CSBR – not to be confused with the CSRB – said that his main observation was a shift in tone. Part of that due to events. Over the 15 months of drafting, there have been โmajor breaches of some of our large companies – Marks & Spencer, JLR, Co-op – and other threatsโ.
He noted that the language was โquite hardโ regarding the importance of the Bill in the context of national security, and that economic resilience was emphasised much more.
โSo I think thereโs a slight hardening in the language,โ he said. โBut in terms of the actual proposals, thereโs nothing in there that is surprising compared with what we knew from what they published in that policy statement.โ
Morris also argued that โeven if we created the most perfect bill that you can imagine around cybersecurity and resilience, itโs not going to solve all of our problems, because legislation can be quickly out of date”.
Measures are being introduced as part of the Bill, including an increase in the powers of the Information Commissionerโs Office to establish a new division, the Information Commission, which will be responsible for enforcing the Bill once it becomes law.
This new Information Commission will be tasked with performing a whole new series of roles and exercising a range of new powers to make that part of the regulatory framework work effectively.
Morris said this will โrequire new resourcing and a new skill set, because, you know, thatโs quite a significant part of this new regulatory regime that needs to be thought through and made to work without it being a kind of bureaucratic obstacle to effectivenessโ.
Some of his comments suggested a feeling that the CSRB does not go far enough, particularly in failing to block ransomware payments or prescribe how business resilience should be achieved.
Morris said that โthe Bill needs to go hand in hand with a much more mobilised debate about resilience and what it means for companiesโ. He argued that a societal effort is needed to elevate the conversation around cybersecurity and resilience – especially the resilience element – and help people understand the threats we face and what they can do to mitigate them in their day-to-day lives.
โThatโs what the JLR and other breaches have shown: that there needs to be much more focus on these issues as a central conversation within organisations, which I think has started, but this Bill could be a catalyst for further change,โ he said.
Final steps for the Cyber Security and Resilience Bill
The next steps will see the Bill receive a second reading, during which a debate will also take place, before it moves to committee stage for amendments to be tabled. After that, it will return to the Commons for a third reading. Once passed, it will go to the Lords for the same process.
โItโs not a bill that Iโm expecting [much] opposition to,” said Morris. “Thereโs a broad consensus that we need to be doing this kind of stuff.โ
So the Bill is unlikely to face political opposition, but it will face industry scrutiny regardless of the outcome. Its main challenge is how much society has changed since the Bill was initially drafted, and what has happened – and will continue to happen – while these readings take place, potentially shifting attitudes towards resilience.
Related articles