Purpose To establish the current parliamentary position and identify the internal work needed to assess potential implications for Northstar Group plc.
Current position The Cyber Security and Resilience (Network and Information Systems) Bill was introduced in the Commons and has completed Commons stages through Third Reading. It received First Reading in the Lords on 17 June 2026 and Second Reading on 14 July 2026. It is now scheduled for Lords Committee stage on 1, 3, 7 and 9 September 2026. The Bill remains live and has not been withdrawn or defeated.
Confirmed legislative focus The long title states that the Bill would make provision, including amendments to the Network and Information Systems Regulations 2018, concerning the security and resilience of network and information systems used or relied on in connection with essential activities. The parliamentary source does not, by itself, establish the final obligations, the organisations that will be in scope, implementation dates or the likely enforcement model.
Why this matters to Northstar Northstar operates UK-wide infrastructure and consumer services, has a large frontline workforce and depends on timely planning and consenting decisions. If any Northstar services or systems are within scope, the Bill could affect cyber governance, resilience controls, incident management, supplier oversight, assurance activity and delivery planning. The extent of that exposure has not yet been confirmed.
Initial risk areas for assessment
- Whether any Northstar activities meet the relevant definition of essential activities.
- Whether existing NIS Regulations obligations already apply to any Northstar entity, service or system.
- Identification of critical network and information systems, dependencies and important suppliers.
- Board or senior-management accountability, risk-management and assurance requirements.
- Incident detection, reporting and cooperation with the relevant regulator.
- Potential compliance, technology, training and operational resilience costs.
- Interaction with existing cyber, operational resilience, business continuity and supply-chain controls.
- Implementation lead time and any transition arrangements.
Immediate internal actions
- Legal to map the Bill against Northstar’s corporate structure, services and existing NIS obligations.
- IT/security to identify potentially critical systems, dependencies, current controls and material gaps.
- Compliance to identify relevant regulatory interfaces, reporting processes and assurance evidence.
- Operations to assess impacts on frontline services, continuity arrangements and key suppliers.
- Finance to support a cost and resource estimate once the scope assessment is available.
- Public Affairs to monitor all Lords Committee sittings and update the internal brief after each sitting where amendments affect scope, reporting, enforcement or timing.
Current assessment Relevance is high enough to warrant active monitoring and internal preparation. No Northstar-specific conclusion on scope, cost or operational impact should be reached until the requested internal assessment is complete. No external position or correspondence has been prepared or authorised.