Draft · Internal Brief · v1

Internal Brief: Cyber Security and Resilience (Network and Information Systems) Bill

First-pass briefing for Public Affairs, Legal, Compliance, IT/security and Operations ahead of Lords Committee stage.

Audience Public Affairs teamPurpose Progress the approved Public Affairs workplanType Core
Back to Work →
ALEX’S HANDOFF

Ready for your judgement

The Bill has reached Lords Committee, with four sittings scheduled from 1–9 September 2026. I’ve prepared a first-pass internal brief and a scope-assessment framework. We still need Legal, IT/security and operational input before we can judge whether Northstar services or systems are in scope, or quantify any compliance and resilience impact.

RECOMMENDED NEXT MOVE

Obtain a coordinated scope assessment from Legal, IT/security, Compliance and relevant operational teams before the first Lords Committee sitting on 1 September. I’ll then update the brief and track amendments on scope, incident reporting, governance and enforcement.

INTERNAL WORKING DOCUMENTInternal Brief
Prepared by Alex · v1

Purpose To establish the current parliamentary position and identify the internal work needed to assess potential implications for Northstar Group plc.

Current position The Cyber Security and Resilience (Network and Information Systems) Bill was introduced in the Commons and has completed Commons stages through Third Reading. It received First Reading in the Lords on 17 June 2026 and Second Reading on 14 July 2026. It is now scheduled for Lords Committee stage on 1, 3, 7 and 9 September 2026. The Bill remains live and has not been withdrawn or defeated.

Confirmed legislative focus The long title states that the Bill would make provision, including amendments to the Network and Information Systems Regulations 2018, concerning the security and resilience of network and information systems used or relied on in connection with essential activities. The parliamentary source does not, by itself, establish the final obligations, the organisations that will be in scope, implementation dates or the likely enforcement model.

Why this matters to Northstar Northstar operates UK-wide infrastructure and consumer services, has a large frontline workforce and depends on timely planning and consenting decisions. If any Northstar services or systems are within scope, the Bill could affect cyber governance, resilience controls, incident management, supplier oversight, assurance activity and delivery planning. The extent of that exposure has not yet been confirmed.

Initial risk areas for assessment

  • Whether any Northstar activities meet the relevant definition of essential activities.
  • Whether existing NIS Regulations obligations already apply to any Northstar entity, service or system.
  • Identification of critical network and information systems, dependencies and important suppliers.
  • Board or senior-management accountability, risk-management and assurance requirements.
  • Incident detection, reporting and cooperation with the relevant regulator.
  • Potential compliance, technology, training and operational resilience costs.
  • Interaction with existing cyber, operational resilience, business continuity and supply-chain controls.
  • Implementation lead time and any transition arrangements.

Immediate internal actions

  1. Legal to map the Bill against Northstar’s corporate structure, services and existing NIS obligations.
  2. IT/security to identify potentially critical systems, dependencies, current controls and material gaps.
  3. Compliance to identify relevant regulatory interfaces, reporting processes and assurance evidence.
  4. Operations to assess impacts on frontline services, continuity arrangements and key suppliers.
  5. Finance to support a cost and resource estimate once the scope assessment is available.
  6. Public Affairs to monitor all Lords Committee sittings and update the internal brief after each sitting where amendments affect scope, reporting, enforcement or timing.

Current assessment Relevance is high enough to warrant active monitoring and internal preparation. No Northstar-specific conclusion on scope, cost or operational impact should be reached until the requested internal assessment is complete. No external position or correspondence has been prepared or authorised.

COLLABORATIONComments & handoffs

Keep feedback with the draft so Alex and the team can act on the same version.

0 open

No review comments yet.

Comments stay internal to this organisation.