Status and legislative purpose
The Cyber Security and Resilience (Network and Information Systems) Bill is in Lords Committee stage, with further sittings scheduled from 1 September 2026. The stated purpose is to amend the Network and Information Systems Regulations 2018 and introduce provisions concerning the security and resilience of systems used for essential activities.
Substantive proposals identifiable at this stage
The available description supports only the following high-level conclusions:
- The existing NIS regulatory framework would be amended.
- The Bill concerns the security and resilience of systems used for essential activities.
- Further parliamentary scrutiny is expected in the Lords Committee stage from 1 September 2026.
The detailed duties, scope changes, thresholds, enforcement provisions, reporting requirements, implementation timetable and treatment of suppliers cannot yet be assessed from the material available.
Comparison with Northstar's position
There is no approved organisational position to compare against. Northstar's potential exposure is also unconfirmed. In particular, we have not established:
- which Northstar activities or systems may be treated as essential;
- whether existing NIS obligations already apply to relevant parts of the business;
- whether current security, resilience, incident-management and supplier controls meet any amended requirements;
- what implementation, assurance or financial burden could arise; or
- whether the Bill creates opportunities to support infrastructure resilience or operational continuity objectives.
Evidence gaps and owners
- Legal: scope of proposed amendments, duties, enforcement and implementation requirements.
- IT/security: affected systems, current controls, incident response, assurance and known gaps.
- Compliance: existing NIS coverage, regulatory mapping, reporting and governance arrangements.
- Operations: essential activities, critical processes, frontline dependencies, suppliers and continuity risks.
- Finance: indicative resource or cost implications once the scope assessment identifies likely changes.
Public Affairs assessment
This is an active and rising issue for Northstar, with medium current risk and opportunity. The immediate public affairs task is to maintain accurate parliamentary monitoring and coordinate the internal evidence base. A substantive external response would be premature because there is no approved position and the detailed legislative content has not been assessed.
Recommended internal line
Northstar is reviewing the Bill's potential implications for the security and resilience of systems supporting essential activities. We are coordinating an assessment across Legal, IT/security, Compliance and Operations and will determine any further position once that work is complete.
This line is for internal alignment only. It must not be issued externally without approval.
Next review point
Reassess following the Lords Committee sittings from 1 September 2026, or sooner if detailed amendments, impact information or departmental guidance materially change the scope.