Today›Work›The Cyber Security Bill is in Lords Committee stage
Needs team input
The Cyber Security Bill is in Lords Committee stage
Linked to Cyber Security & Resilience
OwnerAlex
Next deadline1 Sept 2026
Outputs1
THE BRIEF ALEX IS WORKING FROM
Northstar is a UK-wide infrastructure and consumer services business, so parts of its operations or suppliers may fall within the Bill’s scope. It could create new cyber-security, incident-reporting, governance, assurance or compliance obligations, with potential cost and implementation implications. The Bill is at an active parliamentary stage, but the supplied text does not yet establish Northstar’s precise coverage or the substance of proposed amendments.
Recommended actions:
1. Create a Cyber Security & Resilience issue and assign an internal owner with input from legal, compliance, IT/security and relevant operational teams.
2. Conduct a rapid applicability scan against Northstar’s essential activities, regulated services, critical suppliers and existing NIS Regulations obligations.
3. Review the Bill text and forthcoming Lords Committee proceedings, focusing on scope, duties, enforcement, reporting requirements, supplier obligations and implementation periods.
4. Prepare a short internal briefing identifying likely operational impacts, existing organisational positions and any provisions that may warrant parliamentary engagement.
5. Track the Lords Committee sittings on 1, 3, 7 and 9 September 2026 and capture relevant amendments, Government responses and evidence of implementation timing.
Create a Cyber Security & Resilience issue and assign an internal owner with input from legal, compliance, IT/security and relevant operational teams.
Conduct a rapid applicability scan against Northstar’s essential activities, regulated services, critical suppliers and existing NIS Regulations obligations.
Review the Bill text and forthcoming Lords Committee proceedings, focusing on scope, duties, enforcement, reporting requirements, supplier obligations and implementation periods.
Prepare a short internal briefing identifying likely operational impacts, existing organisational positions and any provisions that may warrant parliamentary engagement.
Keep working with Alex
Ask for a revision, another briefing format, a deadline change or give Alex the missing evidence. The conversation stays attached to this job.
I've prepared Cyber Security and Resilience Bill: internal briefing as a draft.
IssueCyber Security & Resilience
ConfidenceConfirmed
Progress4 of 6 steps
PROGRESS
The next step
4 / 6
Alex keeps the full plan underneath this simple view.
!
CURRENT STEPIdentify internal evidence gaps
We need confirmation of Northstar’s potentially in-scope services, current NIS obligations, supplier dependencies, cyber governance and incident-reporting arrangements before assessing likely impact.
View full workplan6 steps
✓
Confirm parliamentary status and timetableCompleted
The Bill is in Lords Committee stage, with sittings scheduled for 1, 3, 7 and 9 September 2026. It has passed Commons stages and Lords Second Reading.
✓
Assess what the source establishesCompleted
The Bill would amend the Network and Information Systems Regulations 2018 and address the security and resilience of systems used or relied on for essential activities. The source does not include clause text, amendments, duties or implementation dates.
→
Prepare applicability scanPrepared
I’ve set out the internal checks needed across essential activities, regulated services, critical suppliers, existing NIS coverage, incident reporting, governance, assurance and implementation readiness.
!
Identify internal evidence gapsWaiting
We need confirmation of Northstar’s potentially in-scope services, current NIS obligations, supplier dependencies, cyber governance and incident-reporting arrangements before assessing likely impact.
I’ve prepared a monitoring focus for each Lords sitting: scope, duties, enforcement, reporting, supplier obligations, governance, assurance and implementation timing. Relevant amendments and Government responses should be captured after each sitting.
!
Develop parliamentary positionWaiting
A position on scope, compliance duties or implementation timing should not be developed until the applicability scan and internal evidence review are complete.
NEEDS INPUTHead of Public Affairs with Legal and Cyber Security