TodayWorkThe Cyber Security Bill is in Lords Committee stage
Needs team input

The Cyber Security Bill is in Lords Committee stage

Linked to Cyber Security & Resilience

OwnerAlex
Next deadline1 Sept 2026
Outputs1
THE BRIEF ALEX IS WORKING FROM

Northstar is a UK-wide infrastructure and consumer services business, so parts of its operations or suppliers may fall within the Bill’s scope. It could create new cyber-security, incident-reporting, governance, assurance or compliance obligations, with potential cost and implementation implications. The Bill is at an active parliamentary stage, but the supplied text does not yet establish Northstar’s precise coverage or the substance of proposed amendments. Recommended actions: 1. Create a Cyber Security & Resilience issue and assign an internal owner with input from legal, compliance, IT/security and relevant operational teams. 2. Conduct a rapid applicability scan against Northstar’s essential activities, regulated services, critical suppliers and existing NIS Regulations obligations. 3. Review the Bill text and forthcoming Lords Committee proceedings, focusing on scope, duties, enforcement, reporting requirements, supplier obligations and implementation periods. 4. Prepare a short internal briefing identifying likely operational impacts, existing organisational positions and any provisions that may warrant parliamentary engagement. 5. Track the Lords Committee sittings on 1, 3, 7 and 9 September 2026 and capture relevant amendments, Government responses and evidence of implementation timing.

Current next move ↓
Alex’s proposed approach
  1. Create a Cyber Security & Resilience issue and assign an internal owner with input from legal, compliance, IT/security and relevant operational teams.
  2. Conduct a rapid applicability scan against Northstar’s essential activities, regulated services, critical suppliers and existing NIS Regulations obligations.
  3. Review the Bill text and forthcoming Lords Committee proceedings, focusing on scope, duties, enforcement, reporting requirements, supplier obligations and implementation periods.
  4. Prepare a short internal briefing identifying likely operational impacts, existing organisational positions and any provisions that may warrant parliamentary engagement.
Keep working with Alex

Ask for a revision, another briefing format, a deadline change or give Alex the missing evidence. The conversation stays attached to this job.

Continue this work with Alex →
WHAT NEEDS TO HAPPEN NOW

Answer 2 evidence questions

Alex has completed the useful work possible without guessing and will continue from the answer.

ALEX’S LATEST READNeeds team input
Ask Alex about this work →

I've prepared Cyber Security and Resilience Bill: internal briefing as a draft.

IssueCyber Security & Resilience
ConfidenceConfirmed
Progress4 of 6 steps
PROGRESS

The next step

4 / 6

Alex keeps the full plan underneath this simple view.

!
CURRENT STEPIdentify internal evidence gaps

We need confirmation of Northstar’s potentially in-scope services, current NIS obligations, supplier dependencies, cyber governance and incident-reporting arrangements before assessing likely impact.

View full workplan6 steps
Confirm parliamentary status and timetableCompleted

The Bill is in Lords Committee stage, with sittings scheduled for 1, 3, 7 and 9 September 2026. It has passed Commons stages and Lords Second Reading.

Assess what the source establishesCompleted

The Bill would amend the Network and Information Systems Regulations 2018 and address the security and resilience of systems used or relied on for essential activities. The source does not include clause text, amendments, duties or implementation dates.

Prepare applicability scanPrepared

I’ve set out the internal checks needed across essential activities, regulated services, critical suppliers, existing NIS coverage, incident reporting, governance, assurance and implementation readiness.

!
Identify internal evidence gapsWaiting

We need confirmation of Northstar’s potentially in-scope services, current NIS obligations, supplier dependencies, cyber governance and incident-reporting arrangements before assessing likely impact.

NEEDS INPUTLegal, Cyber Security and Operations
Provide input →
Set committee monitoring planPrepared

I’ve prepared a monitoring focus for each Lords sitting: scope, duties, enforcement, reporting, supplier obligations, governance, assurance and implementation timing. Relevant amendments and Government responses should be captured after each sitting.

!
Develop parliamentary positionWaiting

A position on scope, compliance duties or implementation timing should not be developed until the applicability scan and internal evidence review are complete.

NEEDS INPUTHead of Public Affairs with Legal and Cyber Security
Provide input →
NEEDS YOU

2 things Alex needs

2 open

Each request is kept short. Give Alex the answer directly and the work can continue.

!
WaitingLegal, Cyber Security and Operations

Identify internal evidence gaps

Please confirm potentially in-scope services, regulated activities, critical suppliers, current NIS coverage and known compliance gaps before 1 S…

View other requests1
!
WaitingHead of Public Affairs with Legal and Cyber Security

Develop parliamentary position

Please decide whether to develop a parliamentary engagement position once the applicability assessment identifies material operational or impleme…

OUTPUTSDrafts and briefingsReview, share or continue from the latest versions.
1 current
ALEX CAN ALSO HELPMore ways to move this workCreate a brief or ask Alex to continue from the current evidence.
Open
ALEX CAN DO THIS NOWKeep this Work Item moving
SOURCE & SUPPORTING EVIDENCECyber Security and Resilience (Network and Information Systems) Bill
View
SourceUK_PARLIAMENT · Primary
ConfidenceConfirmed
Published24 Aug 2026

Current stage: Committee stage. Current House: Lords. Originating House: Commons.

Open official source ↗