WorkLords Committee stage resumes on 1 September for cyber resilience legislationCyber Security and Resilience Bill: Lords Committee Brief
Draft · Internal Brief · v1

Cyber Security and Resilience Bill: Lords Committee Brief

Internal preparation for the Lords Committee stage beginning 1 September 2026. No external communication or commitment has been made.

Audience Public Affairs teamPurpose Progress the approved Public Affairs workplanType Core
Back to Work →
ALEX’S HANDOFF

Ready for your judgement

The Bill is scheduled for four Lords Committee sittings from 1 September. I’ve prepared a first-pass internal brief, but we still need a coordinated scope assessment before we can judge Northstar’s exposure or settle a position.

RECOMMENDED NEXT MOVE

Obtain a coordinated scope assessment from Legal, IT/security, Compliance and Operations before 1 September.

INTERNAL WORKING DOCUMENTInternal Brief
Prepared by Alex · v1

Executive assessment

The Cyber Security and Resilience (Network and Information Systems) Bill is entering four scheduled Lords Committee sittings from 1 September 2026. It may increase security and resilience duties for systems used or relied on in connection with essential activities. This is potentially relevant to Northstar’s infrastructure businesses, but our exposure has not yet been confirmed.

Confirmed position

  • Short title: Cyber Security and Resilience (Network and Information Systems) Bill.
  • The Bill originated in the Commons and has completed Commons stages, including Report stage and Third Reading on 16 June 2026.
  • It received Lords First Reading on 17 June and Second Reading on 14 July 2026.
  • Lords Committee stage is scheduled for 1, 3, 7 and 9 September 2026.
  • Its stated purpose is to amend the Network and Information Systems Regulations 2018 and make provision concerning the security and resilience of network and information systems used or relied on for essential activities.
  • The Bill is not recorded as withdrawn or defeated.

Why this matters to Northstar

Northstar operates UK-wide infrastructure and consumer services and has projects dependent on timely planning and consenting decisions. If any group activities or supporting systems fall within the Bill’s essential-activity scope, potential consequences could include:

  • additional cyber-security and resilience duties;
  • changes to incident notification or reporting processes;
  • increased governance, assurance and documentation requirements;
  • operational changes across critical systems, suppliers or service arrangements; and
  • implementation and compliance costs.

These are potential implications only. We should not quantify exposure or describe specific duties until the relevant provisions and Northstar’s scope have been assessed.

Immediate internal questions

  1. Which Northstar entities, services and operational activities could fall within the Bill’s essential-activity scope?
  2. Which network and information systems support those activities, including material third-party or supply-chain dependencies?
  3. What NIS Regulations obligations already apply, and where are current controls, reporting lines and assurance arrangements held?
  4. Would the Bill alter incident thresholds, notification timescales, accountability or enforcement exposure for any Northstar operation?
  5. What implementation work, resource and cost could follow if Northstar is in scope?
  6. Are there operational or sector-specific concerns that should inform monitoring of Lords amendments?

Current assessment

Relevance: High enough to maintain active work because Northstar has infrastructure operations and the Bill concerns essential activities.

Confidence: Confirmed as a live parliamentary development; low on company-specific impact because no internal scope assessment has yet been completed and detailed Committee papers were not available.

Position: No approved organisational position has been recorded. We should first establish the practical scope and impact before considering any policy response.

Monitoring priorities for Committee stage

Track amendments and debate concerning:

  • the definition and designation of essential activities and relevant operators;
  • security and resilience duties and technical standards;
  • incident reporting and notification requirements;
  • senior management or governance responsibilities;
  • regulators’ powers, compliance notices and enforcement; and
  • transitional arrangements, implementation dates and proportionality for existing operators.

Decision and next step

No external engagement is proposed at this stage. Legal, IT/security, Compliance and Operations should provide a coordinated scope assessment before the first sitting on 1 September. Public Affairs can then update this brief, assess any amendments and identify whether an approved position or further internal work is needed.

COLLABORATIONComments & handoffs

Keep feedback with the draft so Alex and the team can act on the same version.

0 open

No review comments yet.

Comments stay internal to this organisation.