WorkPeers propose stronger cyber competence standards alongside the resilience BillInternal brief: proposed cyber competence standards
Draft · Internal Brief · v1

Internal brief: proposed cyber competence standards

Initial assessment of the Lords signal, its possible relevance to Northstar and the evidence required before forming a policy position.

Audience Public Affairs teamPurpose Progress the approved Public Affairs workplanType Core
Back to Work →
You are viewing v1.This version is retained for history.Open current v2
ALEX’S HANDOFF

Ready for your judgement

The issue remains material, but we cannot yet assess the proposed competence standards or Northstar’s exposure. I’ve prepared a first-pass internal brief and set out the evidence needed from Legal, Cyber Security, Operations and HR.

RECOMMENDED NEXT MOVE

Ask Legal and Cyber Security to confirm scope, obligations and the relevant amendment text before we develop a policy view.

INTERNAL WORKING DOCUMENTInternal Brief
Prepared by Alex · v1

Purpose

To assess whether proposals for stronger cyber competence standards alongside the Cyber Security and Resilience (Network and Information Systems) Bill could affect Northstar Group plc.

What has changed

Baroness Northover raised the issue during Lords consideration of the Bill on 7 September 2026. The source identifies a proposal concerning stronger cyber competence standards, potentially including expectations for regulated organisations to use appropriately qualified cyber professionals.

The source currently available is a Hansard contribution record. It does not include the amendment wording, the Government’s response, whether the amendment was pressed to a decision, or the subsequent procedural position. The substance and legal effect of the proposal therefore remain unconfirmed.

Why this matters to Northstar

Northstar is a UK-wide infrastructure and consumer services business with a large frontline workforce and projects dependent on timely planning and consenting decisions. If any of its activities fall within the Bill’s regulated sectors, new competence expectations could affect:

  • the roles responsible for cyber security, incident response, operational technology and resilience;
  • qualification, accreditation or continuing professional development requirements;
  • recruitment and retention of specialist cyber personnel;
  • training expectations for operational and frontline teams with security responsibilities;
  • oversight of relevant suppliers and outsourced service providers; and
  • evidence needed to demonstrate compliance to regulators or competent authorities.

This could become a skills and compliance issue rather than a purely technical policy change. The scale and timing of any impact cannot yet be assessed.

Current assessment

  • Relevance: high enough to continue active work, given the link to the live Bill and the potential effect on regulated operators.
  • Confidence: the Lords contribution is confirmed, but the precise proposal and its status are not.
  • Northstar exposure: not yet confirmed.
  • Position: no approved organisational position has been recorded.
  • External engagement: none prepared or authorised at this stage.

Evidence required

  1. The amendment text and debate outcome, including any Government response and relevant statements about implementation.
  2. Confirmation from Legal and Cyber Security of potentially in-scope Northstar activities, entities, systems, suppliers and existing NIS obligations.
  3. An Operations and HR baseline covering relevant cyber roles, qualifications, training, vacancies and capability gaps.
  4. Any existing internal policy, assurance or audit findings relevant to cyber competence and resilience.

Recommended internal sequence

First, verify the amendment and Bill timetable. In parallel, Legal and Cyber Security should map regulatory scope and current obligations, while Operations and HR establish the workforce baseline. Public Affairs can then assess whether the proposal warrants internal advocacy, stakeholder engagement or simply continued monitoring.

Decision point

No policy position should be agreed until the proposal’s text and status, Northstar’s regulatory exposure and the current skills baseline are confirmed.

COLLABORATIONComments & handoffs

Keep feedback with the draft so Alex and the team can act on the same version.

0 open

No review comments yet.

Viewers can read comments but cannot add or resolve them.