
The rules are changing, and the cost of getting caught out is no longer small.
The Cyber Security and Resilience Bill — widely known as the NIS Bill — is progressing through Parliament and is expected to become law in 2026. It directly regulates a wider range of organisations than before, including medium and large managed service providers, data centres, and businesses designated as "critical suppliers." For these, the penalties are severe: up to £17 million or 4% of global turnover for serious breaches, plus up to £100,000 per day for failing to fix a known failure.
You may not be directly regulated — but your customers increasingly will be. The Bill introduces supply-chain cascade reporting, meaning regulated organisations must account for breaches at their suppliers too. In practice, that means the businesses you sell into are already starting to push contractual security requirements, supplier assessments, and evidence demands down onto companies like yours. If you can't answer those questions when they're asked, you risk losing the contract — not because you're breaking the law, but because you can't prove you're not the weak link.
Alongside this, the Cyber Governance Code of Practice now expects named board-level accountability for cyber risk — not delegated to IT, and not informal. Boards that can't demonstrate this are increasingly exposed, both to regulators and to the clients asking harder questions before they sign.
This free, 5-minute assessment tells you exactly where you stand — and where the gaps are.
15 questions covering board-level risk management, strategy, people, incident planning, assurance, AI governance, and NIS supply-chain readiness. You'll get an instant headline score, followed by a full pillar-by-pillar breakdown sent to your inbox — so you know precisely what to fix first, rather than guessing.