The Cyber Security and Resilience Bill: What It Means for UK Businesses
There is a new piece of cyber legislation working its way through Parliament, and a change to Cyber Essentials that has already landed. Between them, they raise the bar for how UK businesses are expected to protect themselves. If you run a company and you have been treating cyber security as a box you ticked once, this is the moment to look again.
The good news is that none of what is coming is unreasonable. Most of it is what a sensible business should be doing anyway. The catch is that “should be doing” and “actually doing” are often two different things, and the gap between them is exactly what attackers rely on.
Here is what is changing, and what it means for you in practical terms.
The Cyber Security and Resilience Bill, in plain English
The Bill is the government’s response to a simple, uncomfortable fact: attacks on UK organisations have got more frequent, more damaging and more expensive. The scale of recent incidents made the point hard to ignore.The Jaguar Land Rover attack, which began in 2025 and halted production for around five weeks, was modelled at a £1.9 billion economic hit. When a single incident costs that much, the case for tighter rules writes itself.
A few things sit at the heart of the Bill:
- A wider net.The Bill expands existing security regulation to cover data centres, managed service providers and critical suppliers.Parts of the economy that were lightly regulated are being pulled in.
- Stronger incident reporting. Businesses in scope will face tougher, clearer duties to report significant incidents quickly, rather than quietly dealing with them and hoping nobody notices.
- A ransom payment ban for some. The government has confirmed it will proceed with a targeted ban on ransom payments by public sector bodies and operators of critical national infrastructure.
Even if your business is not directly named in the Bill, the direction matters. Regulation like this sets the tone for the whole market. Insurers, larger clients and public sector buyers all start expecting the same standards, and they push those expectations down their supply chains. If you sell to anyone who is regulated, their obligations quickly become yours in practice.
The change that affects almost everyone: Cyber Essentials
While the Bill is still moving through Parliament, a change that is already in force affects far more businesses. In April 2026, the Cyber Essentials scheme moved to an updated set of requirements.
The headline change is this. Multi-factor authentication is now mandatory wherever a cloud service supports it. If your business uses Microsoft 365, Google Workspace, or any cloud application, and almost every business does, MFA on those accounts is no longer optional under the scheme.
Why does this matter so much? Because stolen passwords are the way most breaches start. A password on its own is a single lock, and attackers have got very good at picking it, whether by guessing, phishing or buying it from a previous leak. MFA adds a second lock that a stolen password alone cannot open. It is one of the cheapest and most effective defences available, which is exactly why the scheme now insists on it.
Cyber Essentials itself is worth understanding even if nobody is forcing you to get certified. It is a UK government-backed scheme that sets a baseline of sensible security controls. Increasingly it is required to win public sector contracts and to satisfy larger clients, and it is a genuinely useful health check even when it is not contractually demanded. The NCSC’s Cyber Essentials overview sets out what is involved.
AI has changed the attackers’ economics
There is a reason all of this is tightening at once, and it is not just bureaucracy. The people trying to break into your systems have new tools.
Attackers now use AI to make their attacks faster, cheaper and far more convincing. The clumsy phishing email with obvious spelling mistakes is being replaced by personalised, well-written messages, and in some cases synthetic voice calls that impersonate a colleague or a supplier. The technical barrier to running a convincing attack has dropped, which means more attacks aimed at more businesses, including the small and mid-sized ones that used to fly under the radar.
This is the backdrop to the new rules. The defences that were “good enough” a couple of years ago are being outpaced, and the regulation is trying to drag the baseline up to match.
What a sensible business should actually do
Rules and headlines are one thing. Here is what they translate into on the ground.
Turn on multi-factor authentication everywhere it is available. This is the big one, and it is now a Cyber Essentials requirement. Start with email and any account that holds sensitive data or money.
Keep your systems patched and up to date. Unpatched software is an open door. That includes the operating system, which is a live issue right now with Windows 10 support ending. If you are still running older machines, upgrading or replacing them before the security updates stop is a priority, and our computer repairs team can upgrade the machines worth keeping rather than replacing the lot.
Manage your devices properly. You should be able to see what is connected to your network, keep it secure, and wipe a device remotely if it is lost or stolen.
Back up your data and test that you can restore it. Ransomware is far less frightening when you have clean, tested backups you can fall back on. A backup you have never restored is not a plan.
Train your team. Most attacks start with a person clicking something they should not. Regular, plain-English training on how to spot a dodgy email or an unusual request is one of the best returns on investment in security.
Know your suppliers. If a supplier has access to your systems or your data, their security is part of yours. The new focus on supply chains in the Bill reflects a real risk.
None of this is exotic. It is basic hygiene, done consistently. The businesses that get breached are rarely the victims of some genius hacker. They are usually the ones who left MFA switched off, skipped a patch, or never tested a backup.
Why most businesses struggle to keep up
If all of that is so straightforward, why do so many businesses fall short? Time and attention, mostly.
Cyber security is not a project you finish. It is an ongoing job that competes with everything else on a busy team’s plate. Patches need applying every month. New starters need setting up securely and leavers need removing promptly. Alerts need watching. Backups need checking. Training needs refreshing. On top of the actual running of the business, it slips.
This is the practical case for managed IT support. Rather than hoping an already-stretched team keeps on top of it, you hand the ongoing work to a partner whose job it is. Patching, monitoring, device management, backups, MFA rollout, user training and the paperwork for Cyber Essentials all get handled as a matter of routine rather than when someone remembers.
Different sectors have their own versions of these obligations. Firms in financial services face operational resilience rules, healthcare organisations handle some of the most sensitive data there is, and schools work to the Department for Education’s standards through our education IT support. The underlying security work is much the same. The specific rules on top of it differ.
Get ahead of it, do not wait to be forced
The businesses that come out of this well are the ones that treat the new rules as a prompt rather than a threat. Getting your MFA on, your patching current, your backups tested and your Cyber Essentials in order is not just about compliance. It is about not being the easy target.
Attackers, like water, take the path of least resistance. If your defences are in reasonable shape, most of them move on to someone softer. That, more than any certificate, is the real point of all this.
Get a free Cyber Essentials 2026 gap check. We will show you where your business stands against the new MFA requirements and the wider expectations, and what to fix first. Call us or request a callback.
Frequently Asked Questions
Q1: What is the Cyber Security and Resilience Bill?
A: It is new UK legislation aimed at strengthening the country’s defences against cyber attacks. It widens existing security regulation to cover more organisations, including data centres, managed service providers and critical suppliers, tightens incident reporting, and includes a targeted ban on ransom payments by public sector bodies and critical infrastructure operators.
Q2: Does the Bill apply to my business?
A: It may not name your business directly, but its effects spread through the market. Insurers, larger clients and public sector buyers tend to adopt the same standards and push them down their supply chains, so the expectations often reach businesses that are not formally in scope.
Q3: What changed with Cyber Essentials in April 2026?
A: The scheme moved to updated requirements. The main change is that multi-factor authentication is now mandatory wherever a cloud service supports it. Since almost every business uses cloud services like Microsoft 365, this affects most organisations seeking certification.
Q4: Why is multi-factor authentication so important?
A: Most breaches start with a stolen password. MFA adds a second check that a stolen password alone cannot pass, so even if a password leaks, the account stays protected. It is one of the cheapest and most effective security measures available.
Q5: How is AI affecting cyber threats?
A: Attackers use AI to make phishing and impersonation faster, cheaper and far more convincing. The tell-tale badly written scam email is being replaced by polished, personalised messages and even synthetic voice calls, which means more convincing attacks aimed at more businesses.
Q6: Do I need Cyber Essentials certification?
A: It is often required to win public sector contracts and to satisfy larger clients, and it is increasingly expected in supply chains. Even where it is not demanded, it is a useful baseline health check that covers the security controls every business should have.
Can a managed IT provider handle all of this for us?
A: Yes. Ongoing security work such as patching, monitoring, device management, backups, MFA rollout, staff training and preparing for Cyber Essentials is exactly what a managed IT provider does day to day, which takes the pressure off an in-house team that is already busy.
