Purpose
To brief senior leadership on the Cyber Security and Resilience (Network and Information Systems) Bill and the immediate internal work required to establish Northstar's exposure.
What matters now
The Bill is at Lords Committee stage, with further sittings scheduled from 1 September 2026. It would amend the Network and Information Systems Regulations 2018 and introduce provisions concerning the security and resilience of systems used for essential activities. The immediate priority is not external engagement; it is establishing which Northstar activities, systems and obligations could be affected and whether current controls are sufficient.
Current position
Northstar has not yet agreed an approved position on the Bill. No conclusion has been reached on its detailed operational, compliance or cost impact. Public Affairs should therefore support internal assessment and maintain a watching brief rather than imply a settled external view.
Why this matters to Northstar
Northstar is a UK-wide infrastructure and consumer services business with a large frontline workforce and projects dependent on timely planning and consenting decisions. Any changes affecting the security or resilience of systems used for essential activities could have implications for operational continuity, incident preparedness, supplier arrangements, governance, reporting and delivery confidence. The scale and materiality of those implications remain to be confirmed.
Risks
- Northstar may have an incomplete view of which activities or systems fall within scope.
- New or amended duties could require changes to controls, assurance, reporting or accountability.
- Gaps in incident response, supplier oversight or operational resilience could become more material if requirements are strengthened.
- Parliamentary changes may progress before a coordinated internal assessment is complete.
- External commentary without an agreed position could create avoidable policy and reputational risk.
Opportunities
- Use the Bill's progress to bring Legal, IT/security, Compliance and Operations together around one scope assessment.
- Identify resilience improvements that support continuity across critical services and frontline operations, regardless of the final legislative outcome.
- Establish a clear evidence base for any future parliamentary or stakeholder engagement.
Decisions required
- Confirm the executive owner for the cross-functional assessment.
- Agree the scope of systems, activities, suppliers and business processes to be reviewed.
- Confirm the risk appetite for any identified control or resilience gaps.
- Decide whether Public Affairs should prepare engagement lines once the internal position is agreed.
Recommended next steps
- Obtain the coordinated scope assessment from Legal, IT/security, Compliance and Operations before 1 September 2026.
- Map potentially affected activities and systems against existing NIS obligations and resilience controls.
- Record material gaps, owners and proposed mitigations.
- Review the Bill's committee progress after the September sittings and update leadership on any substantive changes.
- Do not send external correspondence or make commitments until an approved position is agreed.