TodayWorkThe Bill is now moving through Lords Committee
Needs team input

The Bill is now moving through Lords Committee

Linked to Cyber Security & Resilience

OwnerAlex
Next deadlineNo date
Outputs2
THE BRIEF ALEX IS WORKING FROM

The Bill would amend the Network and Information Systems Regulations 2018 and could create new security and resilience duties for organisations within scope. We need to establish whether any Northstar operations are covered and whether the emerging requirements could affect compliance, costs or delivery resilience. Recommended actions: 1. Ask Legal and IT/Operations to confirm whether any Northstar services or systems fall within the Bill’s scope. 2. Prepare a short internal briefing covering likely duties, governance implications and implementation risks. 3. Monitor the Lords Committee sittings from 1 September for amendments affecting scope, reporting or enforcement.

Current next move ↓
Alex’s proposed approach
  1. Ask Legal and IT/Operations to confirm whether any Northstar services or systems fall within the Bill’s scope.
  2. Prepare a short internal briefing covering likely duties, governance implications and implementation risks.
  3. Monitor the Lords Committee sittings from 1 September for amendments affecting scope, reporting or enforcement.
Keep working with Alex

Ask for a revision, another briefing format, a deadline change or give Alex the missing evidence. The conversation stays attached to this job.

Continue this work with Alex →
WHAT NEEDS TO HAPPEN NOW

Answer 2 evidence questions

Alex has completed the useful work possible without guessing and will continue from the answer.

ALEX’S LATEST READNeeds team input
Ask Alex about this work →

I've prepared Internal Brief: Cyber Security and Resilience (Network and Information Systems) Bill as a draft.

IssueCyber Security & Resilience
ConfidenceConfirmed
Progress3 of 5 steps
PROGRESS

The next step

3 / 5

Alex keeps the full plan underneath this simple view.

!
CURRENT STEPAssess Northstar scope

We need to establish whether any Northstar services, essential activities, network and information systems or relevant suppliers fall within the Bill’s scope.

View full workplan5 steps
Confirm parliamentary positionCompleted

The Cyber Security and Resilience (Network and Information Systems) Bill is in Lords Committee stage. Sittings are scheduled for 1, 3, 7 and 9 September 2026; the Bill has not been defeated or withdrawn.

Prepare first-pass internal briefCompleted

Prepared an internal briefing covering the confirmed legislative position, potential duties, likely governance considerations and the main implementation risks, with clear limits where Northstar-specific facts are not yet confirmed.

!
Assess Northstar scopeWaiting

We need to establish whether any Northstar services, essential activities, network and information systems or relevant suppliers fall within the Bill’s scope.

NEEDS INPUTLegal, IT/security, Compliance and Operations
Provide input →
!
Assess operational and financial impactWaiting

The likely effect on compliance workload, technology investment, incident reporting and delivery resilience cannot yet be assessed from the Bill’s parliamentary information alone.

NEEDS INPUTIT/security, Operations and Finance
Provide input →
Set up parliamentary monitoringPrepared

Monitoring should focus on amendments and debate concerning scope, designation of essential activities, security and resilience duties, incident reporting, regulator powers, enforcement and implementation timing across the four scheduled Committee sittings.

NEEDS YOU

2 things Alex needs

2 open

Each request is kept short. Give Alex the answer directly and the work can continue.

!
WaitingLegal, IT/security, Compliance and Operations

Assess Northstar scope

Please provide a coordinated view of potentially in-scope services and systems, current NIS Regulations coverage, relevant suppliers and any know…

View other requests1
!
WaitingIT/security, Operations and Finance

Assess operational and financial impact

Please identify likely implementation activities, resource requirements, resilience risks and any material cost or delivery assumptions if the Bi…

OUTPUTSDrafts and briefingsReview, share or continue from the latest versions.
2 current
ALEX CAN ALSO HELPMore ways to move this workCreate a brief or ask Alex to continue from the current evidence.
Open
ALEX CAN DO THIS NOWKeep this Work Item moving
SOURCE & SUPPORTING EVIDENCECyber Security and Resilience (Network and Information Systems) Bill
View
SourceUK_PARLIAMENT · Primary
ConfidenceConfirmed
Published25 Aug 2026

Current stage: Committee stage. Current House: Lords. Originating House: Commons.

Open official source ↗