The Cyber Security and Resilience (Network and Information Systems) Bill is in Lords Committee stage, with further sittings scheduled from 1 September 2026. It would amend the Network and Information Systems Regulations 2018 and introduce provisions concerning the security and resilience of systems used for essential activities.
NEXT ACTIONAsk Legal and Cyber Security to confirm scope, obligations and the relevant amendment text before we develop a policy view.
POLITICAL CONTEXTWhat's being said around this IssueNo linked signals yetView
POLITICAL CONTEXT
What's being said around this Issue
Polling, reporter intelligence and the media agenda linked by Alex.
An approved route from political intelligence to measurable Public Affairs movement.
CURRENT VERSIONStrategy v1 · Draft
Review and amend this draft, or approve it when you are satisfied with the route.
+14
New intelligence has landed since this version. Build a new version when it materially changes the route—not for every headline.
THE OBJECTIVE
Secure a proportionate and workable implementation of the Bill, with clear scope, risk-based duties, realistic transition arrangements and minimal duplication with existing NIS obligations.
The Bill is at Lords Committee stage, with scrutiny resuming on 1 September 2026. We should first establish whether our services, systems or suppliers are in scope, then seek clarity and proportionality where the Bill could affect operations or compliance costs. We do not yet have an approved Northstar position or confirmed external stakeholders.
STRATEGIC ASKS
What needs to be won
Agreed positions and clearly labelled recommendations.
01
Seek clear definitions and guidance on which Northstar services, systems and suppliers fall within scope.
Unclear coverage could create avoidable compliance risk and inconsistent implementation across infrastructure and consumer services.
Confirmed primary evidence: the Bill would amend the Network and Information Systems Regulations 2018 and concerns systems supporting essential activities. Unknown: Northstar’s precise coverage. Recommended ask, pending internal approval.02
Support risk-based, proportionate security, resilience, reporting and assurance duties that reflect the nature and scale of the service.
Requirements that are not calibrated to operational risk could impose unnecessary cost or distract from the most important resilience measures.
Confirmed primary evidence: the Bill is in Lords Committee stage. Unknown: the final substance of duties, enforcement and reporting requirements. Recommended ask, pending Legal, Cyber Security and Operations assessment.03
Seek realistic implementation periods and transition arrangements, including recognition of existing NIS compliance and assurance work.
A workable transition would help maintain resilience while organisations adapt systems, governance, supplier arrangements and reporting processes.
The current issue assessment identifies possible implementation, compliance and operational cost implications. No confirmed implementation period or approved Northstar position yet. Recommended ask, pending impact assessment.04
Support coordinated requirements for critical suppliers and avoid duplicated reporting or assurance obligations.
Northstar’s exposure may extend beyond its own systems to suppliers, but overlapping requirements could increase cost and slow incident response.
The current issue assessment identifies supplier obligations and duplicated compliance as areas requiring review. Northstar’s supplier exposure is not yet confirmed. Recommended ask, pending internal scope assessment.
AUDIENCE MOVEMENT
Who needs to move, and how
Suggested audiences remain recommendations until confirmed.
suggested
Lords Committee members scrutinising the Bill
Examine clauses, amendments and Government responses during Committee stage.
MOVEMENT NEEDED
Recognise the need for clear scope, proportionate duties, realistic transition and coordinated supplier requirements.
APPROACH
Use a short, evidence-led briefing once Northstar’s applicability and operational impacts are confirmed; any correspondence or engagement would require approval.
suggested
UK Government ministers and officials responsible for the Bill
Develop the policy, respond to amendments and shape implementation guidance.
MOVEMENT NEEDED
Clarify coverage and implementation expectations, while accepting the case for risk-based obligations and avoidance of duplicated requirements.
APPROACH
Share practical evidence through approved channels after Legal, Cyber Security and Operations agree the issues and proposed wording.
suggested
Relevant regulators and competent authorities
Interpret or enforce amended NIS requirements and may influence guidance and assurance expectations.
MOVEMENT NEEDED
Apply consistent, proportionate expectations that recognise existing controls and avoid duplicated reporting.
APPROACH
Map the relevant authorities after scope is confirmed; no external contact is proposed until ownership and approval are clear.
suggested
Relevant sector peers, suppliers and trade bodies
Provide comparable implementation evidence and may shape collective policy discussion.
MOVEMENT NEEDED
Surface common concerns on scope, supplier obligations, reporting and transition without weakening cyber resilience standards.
APPROACH
Test whether credible sector evidence exists and use only validated, non-confidential material in any approved engagement.
SEQUENCED PLAN
From position to progress
Only actions from an approved strategy can enter Work.
1
Immediately; before the 1 September 2026 Committee sitting where possible.
1. Establish the exposure
Determine whether the Bill materially affects Northstar and identify the provisions that matter most.
Complete a rapid scope assessment against services, systems, suppliers and current NIS obligations
This is the critical missing fact and will determine whether external intervention is justified and what it should seek.
Legal, Cyber Security and Operations · Before 1 September 2026
Available after approval
Review the Bill text and Committee papers for scope, duties, reporting, enforcement and implementation provisions
The Bill’s detailed implications and proposed amendments have not yet been established.
Public Affairs and Legal · Before each relevant Committee sitting
Available after approval
Prepare an impact summary covering operational, compliance, supplier and financial implications
Decision-makers need quantified or clearly described impacts before approving an external position.
Operations, Cyber Security, Legal and Finance · Within one week of the scope assessment
Available after approval
2
Early September 2026, after the initial scope assessment.
2. Agree the Northstar position
Turn the internal assessment into an approved, evidence-backed set of asks.
Draft a one-page position covering preferred outcomes, fallback options and any red lines
Northstar has no approved position on this issue, so external engagement should not precede internal agreement.
Public Affairs with Legal, Cyber Security and Operations · Within three working days of receiving the assessment
Available after approval
Secure senior approval for any external engagement or correspondence
All external engagement remains proposed and subject to human approval.
Public Affairs · Before contact with any external audience
Available after approval
Validate evidence claims and remove unsupported assumptions from the briefing
The strategy must distinguish confirmed requirements from possible impacts and avoid overstating Northstar’s exposure.
Legal and relevant technical owners · Before approval
Available after approval
3
From 1 September 2026 through Committee stage and implementation discussions.
3. Influence scrutiny and implementation
Use approved evidence to shape Committee scrutiny, Government responses and subsequent guidance.
Submit approved briefing points to relevant institutional audiences through agreed channels
The strongest intervention will be targeted at the provisions that the internal assessment shows could materially affect Northstar.
Public Affairs · After approval and ahead of relevant debates or amendments
Available after approval
Track amendments, Government responses and emerging implementation detail after each sitting
The policy risk is rising and the final obligations may change during scrutiny.
Public Affairs with Legal · After each confirmed Committee sitting
Available after approval
Update the leadership recommendation when material changes affect scope, duties or transition
Senior decisions should reflect the latest legislative position and confirmed operational exposure.
Public Affairs · As required during Committee stage
Available after approval
4
Once scope and likely requirements are sufficiently clear.
4. Prepare for delivery
Ensure Northstar can respond promptly if the Bill passes or obligations become clearer.
Create an internal readiness plan for governance, reporting, assurance, suppliers and implementation costs
A readiness plan converts policy monitoring into practical risk management.
Cyber Security, Operations, Legal and Finance · Following confirmation of likely requirements
Available after approval
Identify any guidance or secondary legislation issues requiring further policy intervention
Important operational detail may sit outside the primary Bill.
Public Affairs and Legal · During implementation planning
Available after approval
MEASURES
How we will know
1
Northstar has a documented and approved assessment of whether its services, systems and suppliers fall within scope.
Completed before any substantive external engagement.
Evidence: Internal Legal, Cyber Security and Operations assessment.
2
The approved position reflects confirmed impacts and contains specific asks on scope, proportionality, transition and duplication.
Approved in early September 2026, subject to the assessment timeline.
Evidence: Signed-off internal briefing and position note.
3
Parliamentary or Government scrutiny reflects the practical issues identified by Northstar, including scope, reporting, supplier duties or transition.
At least one relevant issue is raised, clarified or addressed through an approved intervention.
Evidence: Committee papers, Government responses, amendments or published guidance.
Improvement visible in relevant guidance or official implementation communications.
Evidence: Published guidance, consultation material or regulator communications.
5
Northstar has an agreed readiness plan with identified owners for any material new obligations.
Completed once likely requirements and implementation timing are sufficiently clear.
Evidence: Approved internal plan and ownership record.
RISKS & GAPS
What could weaken the plan
Northstar may not be in scope, making premature external engagement disproportionate or damaging.
Complete the rapid applicability assessment before seeking an external position or contact.
The Bill or amendments may change during Committee stage.
Monitor each confirmed sitting and refresh the recommendation when material provisions change.
Public advocacy could be perceived as resistance to stronger cyber resilience.
Frame asks around clarity, proportionality, risk-based implementation and effective resilience, not weaker standards.
Internal teams may not provide timely or consistent evidence.
Set a short assessment deadline, nominate functional owners and escalate missing inputs to senior leadership.
New duties may overlap with existing regulatory or contractual requirements.
Map current NIS, regulatory, assurance and supplier obligations before finalising the position.
EVIDENCE GAP · Legal, Cyber Security and OperationsWhether any Northstar service, system or activity is within the Bill’s essential-activity or other relevant scope.
This determines the strategic importance of the Bill and whether Northstar needs direct policy engagement.
EVIDENCE GAP · Public Affairs and LegalThe Bill’s detailed provisions and any Committee amendments on duties, enforcement, reporting, suppliers and implementation periods.
The precise asks may change materially as Lords scrutiny progresses.
EVIDENCE GAP · Cyber Security and OperationsNorthstar’s current NIS compliance, resilience controls and assurance arrangements relevant to the proposed duties.
This will establish the likely implementation burden and support any case for recognition of existing controls.
EVIDENCE GAP · Finance and OperationsPotential financial and operational costs, including supplier and reporting impacts.
Cost and delivery evidence is needed to prioritise asks and support proportionate implementation arguments.
EVIDENCE GAP · Public AffairsRelevant regulators, Government contacts, sector bodies and existing relationships.
No known stakeholders or relationships are currently recorded, so an engagement route cannot yet be selected.
ALEX ACTIVITYRecent issue intelligence8 recent updates in the audit trailView
ALEX ACTIVITY
Recent issue intelligence
8 recent actions
Triage Completed
Parliamentary question puts national resilience on the Cabinet Office agenda
20 Sept 2026
Triage Completed
Parliamentary committee scrutiny noted; no live deadline or immediate action is required
20 Sept 2026
Triage Completed
Parliamentary committee scrutiny continues on an unidentified Bill
20 Sept 2026
Triage Completed
Government resists an AI kill-switch amendment in the cyber resilience bill debate
20 Sept 2026
Colleague Follow Up Queued
I'm following up on Agree position and leadership decisions for Cyber Security & Resilience: leadership briefing because Senior leadership is the next person Alex needs to keep this moving.
18 Sept 2026
Colleague Follow Up Queued
I'm following up on Confirm organisational scope and exposure for Cyber Security & Resilience: leadership briefing because Legal, IT/security, Compliance and Operations is the next person Alex needs to keep this moving.
18 Sept 2026
Colleague Follow Up Queued
I'm following up on Confirm Northstar scope and exposure for Lords Committee stage resumes on 1 September for cyber resilience legislation because Legal, IT/security, Compliance and Operations is the next person Alex needs to keep this moving.
18 Sept 2026
Colleague Follow Up Queued
I'm following up on Assess operational and financial impact for The Bill is now moving through Lords Committee, with further sittings from 1 September. I’ll check what it could mean for our systems and essential activities b because IT/security, Operations and Finance is the next person Alex needs to keep this moving.