TodayIssuesCyber Security & Resilience
Medium riskMedium opportunityRising

Cyber Security & Resilience

Strategic issue being actively monitored and managed by Alex.

Open work7
Upcoming0
Decisions0
Alex can help from hereChoose a useful next step
ALEX CAN DO THIS NOWStart useful work from this Issue
More ways Alex can help
RECORDManage this issueManage

Archive removes this issue from active views while keeping its history. Permanent deletion is reserved for untouched drafts.

Export record history first
WHERE THINGS STAND

Issue picture

Live

The Cyber Security and Resilience (Network and Information Systems) Bill is in Lords Committee stage, with further sittings scheduled from 1 September 2026. It would amend the Network and Information Systems Regulations 2018 and introduce provisions concerning the security and resilience of systems used for essential activities.

NEXT ACTIONAsk Legal and Cyber Security to confirm scope, obligations and the relevant amendment text before we develop a policy view.
POLITICAL CONTEXTWhat's being said around this IssueNo linked signals yetView
POLITICAL CONTEXT

What's being said around this Issue

Polling, reporter intelligence and the media agenda linked by Alex.

Sources & monitoring →

No relevant political intelligence has been linked to this Issue yet.

ORGANISATION POSITIONPosition gapAlex needs a reviewed position before this can move confidentlyNeeds attention
ORGANISATION POSITION

What we believe

Manage in Brain →
!

Position gap

Alex knows this is a priority but there is no current approved Position attached.

Create position
ISSUE STRATEGY

What we are trying to change

An approved route from political intelligence to measurable Public Affairs movement.

CURRENT VERSIONStrategy v1 · Draft

Review and amend this draft, or approve it when you are satisfied with the route.

+14

New intelligence has landed since this version. Build a new version when it materially changes the route—not for every headline.

THE OBJECTIVE

Secure a proportionate and workable implementation of the Bill, with clear scope, risk-based duties, realistic transition arrangements and minimal duplication with existing NIS obligations.

The Bill is at Lords Committee stage, with scrutiny resuming on 1 September 2026. We should first establish whether our services, systems or suppliers are in scope, then seek clarity and proportionality where the Bill could affect operations or compliance costs. We do not yet have an approved Northstar position or confirmed external stakeholders.

STRATEGIC ASKS

What needs to be won

Agreed positions and clearly labelled recommendations.

01

Seek clear definitions and guidance on which Northstar services, systems and suppliers fall within scope.

Unclear coverage could create avoidable compliance risk and inconsistent implementation across infrastructure and consumer services.

Confirmed primary evidence: the Bill would amend the Network and Information Systems Regulations 2018 and concerns systems supporting essential activities. Unknown: Northstar’s precise coverage. Recommended ask, pending internal approval.
02

Support risk-based, proportionate security, resilience, reporting and assurance duties that reflect the nature and scale of the service.

Requirements that are not calibrated to operational risk could impose unnecessary cost or distract from the most important resilience measures.

Confirmed primary evidence: the Bill is in Lords Committee stage. Unknown: the final substance of duties, enforcement and reporting requirements. Recommended ask, pending Legal, Cyber Security and Operations assessment.
03

Seek realistic implementation periods and transition arrangements, including recognition of existing NIS compliance and assurance work.

A workable transition would help maintain resilience while organisations adapt systems, governance, supplier arrangements and reporting processes.

The current issue assessment identifies possible implementation, compliance and operational cost implications. No confirmed implementation period or approved Northstar position yet. Recommended ask, pending impact assessment.
04

Support coordinated requirements for critical suppliers and avoid duplicated reporting or assurance obligations.

Northstar’s exposure may extend beyond its own systems to suppliers, but overlapping requirements could increase cost and slow incident response.

The current issue assessment identifies supplier obligations and duplicated compliance as areas requiring review. Northstar’s supplier exposure is not yet confirmed. Recommended ask, pending internal scope assessment.
AUDIENCE MOVEMENT

Who needs to move, and how

Suggested audiences remain recommendations until confirmed.

suggested

Lords Committee members scrutinising the Bill

Examine clauses, amendments and Government responses during Committee stage.

MOVEMENT NEEDED

Recognise the need for clear scope, proportionate duties, realistic transition and coordinated supplier requirements.

APPROACH

Use a short, evidence-led briefing once Northstar’s applicability and operational impacts are confirmed; any correspondence or engagement would require approval.

suggested

UK Government ministers and officials responsible for the Bill

Develop the policy, respond to amendments and shape implementation guidance.

MOVEMENT NEEDED

Clarify coverage and implementation expectations, while accepting the case for risk-based obligations and avoidance of duplicated requirements.

APPROACH

Share practical evidence through approved channels after Legal, Cyber Security and Operations agree the issues and proposed wording.

suggested

Relevant regulators and competent authorities

Interpret or enforce amended NIS requirements and may influence guidance and assurance expectations.

MOVEMENT NEEDED

Apply consistent, proportionate expectations that recognise existing controls and avoid duplicated reporting.

APPROACH

Map the relevant authorities after scope is confirmed; no external contact is proposed until ownership and approval are clear.

suggested

Relevant sector peers, suppliers and trade bodies

Provide comparable implementation evidence and may shape collective policy discussion.

MOVEMENT NEEDED

Surface common concerns on scope, supplier obligations, reporting and transition without weakening cyber resilience standards.

APPROACH

Test whether credible sector evidence exists and use only validated, non-confidential material in any approved engagement.

SEQUENCED PLAN

From position to progress

Only actions from an approved strategy can enter Work.

1
Immediately; before the 1 September 2026 Committee sitting where possible.

1. Establish the exposure

Determine whether the Bill materially affects Northstar and identify the provisions that matter most.

Complete a rapid scope assessment against services, systems, suppliers and current NIS obligations

This is the critical missing fact and will determine whether external intervention is justified and what it should seek.

Legal, Cyber Security and Operations · Before 1 September 2026
Available after approval
Review the Bill text and Committee papers for scope, duties, reporting, enforcement and implementation provisions

The Bill’s detailed implications and proposed amendments have not yet been established.

Public Affairs and Legal · Before each relevant Committee sitting
Available after approval
Prepare an impact summary covering operational, compliance, supplier and financial implications

Decision-makers need quantified or clearly described impacts before approving an external position.

Operations, Cyber Security, Legal and Finance · Within one week of the scope assessment
Available after approval
2
Early September 2026, after the initial scope assessment.

2. Agree the Northstar position

Turn the internal assessment into an approved, evidence-backed set of asks.

Draft a one-page position covering preferred outcomes, fallback options and any red lines

Northstar has no approved position on this issue, so external engagement should not precede internal agreement.

Public Affairs with Legal, Cyber Security and Operations · Within three working days of receiving the assessment
Available after approval
Secure senior approval for any external engagement or correspondence

All external engagement remains proposed and subject to human approval.

Public Affairs · Before contact with any external audience
Available after approval
Validate evidence claims and remove unsupported assumptions from the briefing

The strategy must distinguish confirmed requirements from possible impacts and avoid overstating Northstar’s exposure.

Legal and relevant technical owners · Before approval
Available after approval
3
From 1 September 2026 through Committee stage and implementation discussions.

3. Influence scrutiny and implementation

Use approved evidence to shape Committee scrutiny, Government responses and subsequent guidance.

Submit approved briefing points to relevant institutional audiences through agreed channels

The strongest intervention will be targeted at the provisions that the internal assessment shows could materially affect Northstar.

Public Affairs · After approval and ahead of relevant debates or amendments
Available after approval
Track amendments, Government responses and emerging implementation detail after each sitting

The policy risk is rising and the final obligations may change during scrutiny.

Public Affairs with Legal · After each confirmed Committee sitting
Available after approval
Update the leadership recommendation when material changes affect scope, duties or transition

Senior decisions should reflect the latest legislative position and confirmed operational exposure.

Public Affairs · As required during Committee stage
Available after approval
4
Once scope and likely requirements are sufficiently clear.

4. Prepare for delivery

Ensure Northstar can respond promptly if the Bill passes or obligations become clearer.

Create an internal readiness plan for governance, reporting, assurance, suppliers and implementation costs

A readiness plan converts policy monitoring into practical risk management.

Cyber Security, Operations, Legal and Finance · Following confirmation of likely requirements
Available after approval
Identify any guidance or secondary legislation issues requiring further policy intervention

Important operational detail may sit outside the primary Bill.

Public Affairs and Legal · During implementation planning
Available after approval
MEASURES

How we will know

1
Northstar has a documented and approved assessment of whether its services, systems and suppliers fall within scope.

Completed before any substantive external engagement.

Evidence: Internal Legal, Cyber Security and Operations assessment.
2
The approved position reflects confirmed impacts and contains specific asks on scope, proportionality, transition and duplication.

Approved in early September 2026, subject to the assessment timeline.

Evidence: Signed-off internal briefing and position note.
3
Parliamentary or Government scrutiny reflects the practical issues identified by Northstar, including scope, reporting, supplier duties or transition.

At least one relevant issue is raised, clarified or addressed through an approved intervention.

Evidence: Committee papers, Government responses, amendments or published guidance.
4
Emerging guidance recognises existing NIS controls and sets clear, proportionate implementation expectations.

Improvement visible in relevant guidance or official implementation communications.

Evidence: Published guidance, consultation material or regulator communications.
5
Northstar has an agreed readiness plan with identified owners for any material new obligations.

Completed once likely requirements and implementation timing are sufficiently clear.

Evidence: Approved internal plan and ownership record.
RISKS & GAPS

What could weaken the plan

Northstar may not be in scope, making premature external engagement disproportionate or damaging.

Complete the rapid applicability assessment before seeking an external position or contact.

The Bill or amendments may change during Committee stage.

Monitor each confirmed sitting and refresh the recommendation when material provisions change.

Public advocacy could be perceived as resistance to stronger cyber resilience.

Frame asks around clarity, proportionality, risk-based implementation and effective resilience, not weaker standards.

Internal teams may not provide timely or consistent evidence.

Set a short assessment deadline, nominate functional owners and escalate missing inputs to senior leadership.

New duties may overlap with existing regulatory or contractual requirements.

Map current NIS, regulatory, assurance and supplier obligations before finalising the position.

EVIDENCE GAP · Legal, Cyber Security and OperationsWhether any Northstar service, system or activity is within the Bill’s essential-activity or other relevant scope.

This determines the strategic importance of the Bill and whether Northstar needs direct policy engagement.

EVIDENCE GAP · Public Affairs and LegalThe Bill’s detailed provisions and any Committee amendments on duties, enforcement, reporting, suppliers and implementation periods.

The precise asks may change materially as Lords scrutiny progresses.

EVIDENCE GAP · Cyber Security and OperationsNorthstar’s current NIS compliance, resilience controls and assurance arrangements relevant to the proposed duties.

This will establish the likely implementation burden and support any case for recognition of existing controls.

EVIDENCE GAP · Finance and OperationsPotential financial and operational costs, including supplier and reporting impacts.

Cost and delivery evidence is needed to prioritise asks and support proportionate implementation arguments.

EVIDENCE GAP · Public AffairsRelevant regulators, Government contacts, sector bodies and existing relationships.

No known stakeholders or relationships are currently recorded, so an engagement route cannot yet be selected.

ACTIVE WORK

What Alex and the team are doing

All work →
Waiting

Peers propose stronger cyber competence standards alongside the resilience Bill

The proposal could create new expectations for regulated organisations to use qualified cyber professionals. We need to establish whether Northstar activities are in scope and whether this creates a skills, training or compliance issue.

AlexNo hard deadline
Waiting

Government backs cyber standards but rejects placing the UK Cyber Security Council on a

The Bill may bring new training and professional-standard requirements through secondary legislation, while Northstar’s cyber skills pipeline and regulated activities remain to be checked.

AlexNo hard deadline
Waiting

Lords committee scrutiny resumes on 1 September for the cyber resilience bill

The Bill could create new resilience and security obligations for systems supporting essential activities, with potential compliance implications for our infrastructure operations.

AlexNo hard deadline
Waiting

The Cyber Security and Resilience (Network and Information Systems) Bill is in Lords Committee stage, with further sittings scheduled from 1 September 2026. It

Northstar is a UK-wide infrastructure and consumer services business, so parts of its operations or suppliers may fall within the Bill’s scope. It could create new cyber-security, incident-reporting, governance, assurance or compliance obligations, with potential cost and implementation implications. The Bill is at an active parliamentary stage, but the supplied text does not yet establish Northstar’s precise coverage or the substance of proposed amendments.

AlexDue 1 Sept
Waiting

Cyber Security & Resilience: leadership briefing

Prepare a concise internal Public Affairs briefing for senior leadership on Cyber Security & Resilience. Lead with what matters now, the organisation's current position, risks and opportunities, upcoming decisions, and recommended next steps. This is an internal draft only.

AlexNo hard deadline
Waiting

Lords Committee stage resumes on 1 September for cyber resilience legislation

The Bill could impose additional security and resilience duties on systems supporting essential activities, with potential operational and compliance costs for our infrastructure businesses.

AlexNo hard deadline
Waiting

The Bill is now moving through Lords Committee, with further sittings from 1 September. I’ll check what it could mean for our systems and essential activities b

The Bill would amend the Network and Information Systems Regulations 2018 and could create new security and resilience duties for organisations within scope. We need to establish whether any Northstar operations are covered and whether the emerging requirements could affect compliance, costs or delivery resilience.

AlexNo hard deadline
FORWARD LOOKWhat's comingNo upcoming milestones recordedView
FORWARD LOOK

What's coming

Open calendar →

No upcoming milestones.

ALEX ACTIVITYRecent issue intelligence8 recent updates in the audit trailView
ALEX ACTIVITY

Recent issue intelligence

8 recent actions
Triage Completed

Parliamentary question puts national resilience on the Cabinet Office agenda

20 Sept 2026
Triage Completed

Parliamentary committee scrutiny noted; no live deadline or immediate action is required

20 Sept 2026
Triage Completed

Parliamentary committee scrutiny continues on an unidentified Bill

20 Sept 2026
Triage Completed

Government resists an AI kill-switch amendment in the cyber resilience bill debate

20 Sept 2026
Colleague Follow Up Queued

I'm following up on Agree position and leadership decisions for Cyber Security & Resilience: leadership briefing because Senior leadership is the next person Alex needs to keep this moving.

18 Sept 2026
Colleague Follow Up Queued

I'm following up on Confirm organisational scope and exposure for Cyber Security & Resilience: leadership briefing because Legal, IT/security, Compliance and Operations is the next person Alex needs to keep this moving.

18 Sept 2026
Colleague Follow Up Queued

I'm following up on Confirm Northstar scope and exposure for Lords Committee stage resumes on 1 September for cyber resilience legislation because Legal, IT/security, Compliance and Operations is the next person Alex needs to keep this moving.

18 Sept 2026
Colleague Follow Up Queued

I'm following up on Assess operational and financial impact for The Bill is now moving through Lords Committee, with further sittings from 1 September. I’ll check what it could mean for our systems and essential activities b because IT/security, Operations and Finance is the next person Alex needs to keep this moving.

18 Sept 2026