Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Can football conquer the US? Why culture is key this World Cup

      GettyImages 2281127577 featuring a significant news event or business setting, capturing key moments and interactions

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Can football conquer the US? Why culture is key this World Cup

      GettyImages 2281127577 featuring a significant news event or business setting, capturing key moments and interactions

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      The best places to eat sandwiches in Lisbon, from bifanas to pregos

      Bifana do Afonsos famous bifana sandwich showcasing tender pork in a freshly baked roll with savory sauce.

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Wednesday 12 November 2025 3:35 pm  |  Updated:  Wednesday 12 November 2025 3:36 pm

Labour tightens cyber rules after JLR and M&S breaches

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
AI is also reshaping the cyber threat landscape

The government has introduced its long-awaited cyber security and resilience bill to parliament, promising to toughen the UK’s defences against the growing wave of cyberattacks on businesses and public services.

Ministers say the new legislation represents a ‘step change’ in national security, with the aim of protecting vital services such as energy, water and healthcare from disruption.

It follows a string of high-profile incidents in recent months, including the attack on NHS contractor Synnovis which led to more than 11,000 cancelled medical appointments and caused losses of over £30m.

Science, Innovation and Technology secretary Liz Kendall said the bill would mean “fewer cancelled NHS appointments, less disruption to local services and businesses, and a faster national response when threats emerge.”

The reforms update and expand the Network and Information Systems (NIS) Regulations 2018, extending regulation to cover more digital infrastructure and key suppliers.

For the first time, these companies will be required to meet minimum security standards, report major incidents within 24 hours and have response plans in place.

Regulators like Ofwat or NHS Improvement will also gain new powers to direct companies to take “specific, proportionate steps” to prevent attacks, including isolating high-risk systems when threats emerge.

A widening net for regulation

The new rules come as the cost of cyberattacks continues to mount.

Government research suggests major breaches now cost the UK economy nearly £15bn a year, or about 0.5 per cent of GDP.

Industry figures have broadly welcomed the bill’s ambitions but cautioned that its success will depend on clarity and enforcement.

Ric Derbyshire, principal security researcher at Orange Cyberdefense, said the bill “encourages organisations involved in critical national infrastructure to recognise that security and resilience rely on an interdependent ecosystem, rather than a simple chain”.

Read more

UK ministers tell UK businesses to ‘step up’ cyber defences

The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”

Others struck a more cautious note, with Kristina Holt, Managing Associate at law firm Foot Anstey, warning that “the introduction of this Bill is by no means a guarantee of security or certainty”.

She added that its impact “will depend on whether significant resource is actually allocated for its enforcement.”

Trevor Dearing, director of critical infrastructure at Illumio, welcomed the shift to require reporting of all cyber incidents, not just successful breaches, calling it “long overdue.”

But he also emphasised that “whilst it is understandable the government is introducing tougher penalties for poor security practices, it is equally important that sufficient support is provided to help organisations achieve compliance.”

Cybersecurity as national security

The legislation’s timing reflects a shift in government thinking about cyber resilience as part of national security and economic stability.

The UK’s National Cyber Security Centre (NCSC) recorded over 200 ‘nationally significant’ attacks in the past year, while companies such as Jaguar Land Rover and Marks & Spencer have faced serious operational disruption.

Dr Richard Horne, chief executive of the NCSC, described the bill as a ‘crucial step’ in protecting critical services amid a “complex and evolving threat landscape.”

Others, like Matt Houlihan, vice president of government affairs at Cisco, said the framework was overdue but must be “practical and clear” to work.

“The success of this bill will rely on clarity and practical timelines”, he said, adding that government should address risks from outdated, end-of-life systems that “too often leave organisations exposed.”

With the cost of cyberattacks mounting and the country’s reliance on digital infrastructure deepening, industry leaders agree the bill is an important move, but one that will require consistent follow-through.

As Carla Baker of Palo Alto Networks put it: “A supply chain is only as strong as its weakest link. The government must now ensure this legislation gives businesses the clarity and confidence to strengthen theirs.”

Read more

NHS gives Palantir wider access to patient data amid growing backlash

NHS healthcare professionals in a hospital setting discussing patient care plans, wearing uniforms and medical equipment v...

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • Cyber
  • cyber bill
  • cyber industry
  • cyberattack
  • data breach
  • DSIT
  • JLR
  • Labour
  • Marks and Spencer

Trending Articles

  • KPMG’s Summer Friday half-day rollback signals deeper woes for Big Four giants

  • Inflation expectations at record high in interest rates signal

  • London Tech Week sums up everything wrong with UK tech

  • KPMG report on AI found riddled with AI hallucinations

  • UK economy falters as deeper damage to growth to come

More from CityAM

  • UK ministers tell UK businesses to ‘step up’ cyber defences

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • NHS gives Palantir wider access to patient data amid growing backlash

    Tech
    NHS healthcare professionals in a hospital setting discussing patient care plans, wearing uniforms and medical equipment v...
  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • Starmer scrambles to make savings in bid to boost defence spending

    Politics
    Keir Starmer discussing UKs defense strategy with BAE Systems executives in a formal meeting setting
  • UK businesses struggle with triple threat of costs, cyber risks and stagnant growth

    Prof Services
    London office workers collaborating on AI and tech projects, surrounded by computers and digital interfaces in a modern wo...
  • The King’s Speech was overshadowed by the Westminster clown show

    Politics
    The King's Speech
  • Kainos shares lift as revenue surges on bumper NHS contract wins

    Tech
    Without the specific content and context from the article, its challenging to generate an accurate alt text. Please provid...
  • Top spook says Russia ‘relentlessly targeting’ UK infrastructure 

    Tech
    GCHQ headquarters at dusk with illuminated windows, showcasing the iconic circular building amidst a vibrant evening sky.
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • News
  • Markets & Economics
  • Politics
  • Opinion
  • Life&Style
  • Personal Finance

Follow us for breaking news and latest updates

  • Facebook
  • X
  • Instagram
  • LinkedIn
Copyright 2026 CityAM Limited