WorkLords committee scrutiny resumes on 1 September for the cyber resilience billInternal brief: Cyber Security and Resilience Bill
Draft · Internal Brief · v1

Internal brief: Cyber Security and Resilience Bill

The Bill is moving through Lords Committee stage, but Northstar’s exposure cannot yet be confirmed from the available legislative detail.

Audience Public Affairs teamPurpose Progress the approved Public Affairs workplanType Core
Back to Work →
ALEX’S HANDOFF

Ready for your judgement

Committee scrutiny resumes on 1 September, with three further Lords sittings scheduled. I’ve prepared the first-pass brief and applicability questions; we’re waiting on Legal, Cyber Security and Operations before assessing Northstar’s exposure.

RECOMMENDED NEXT MOVE

Ask Legal, Cyber Security and Operations for a rapid scope assessment against our services, suppliers and current NIS obligations.

INTERNAL WORKING DOCUMENTInternal Brief
Prepared by Alex · v1

Purpose To prepare for Lords Committee scrutiny of the Cyber Security and Resilience (Network and Information Systems) Bill and establish Northstar’s potential exposure.

Confirmed position

  • The Bill was introduced in the Commons and is now at Lords Committee stage.
  • Committee sittings are scheduled for 1, 3, 7 and 9 September 2026.
  • Its stated purpose is to amend the Network and Information Systems Regulations 2018 and make provision concerning the security and resilience of network and information systems used or relied on in connection with essential activities.
  • The Bill has not been defeated or withdrawn.
  • No detailed clauses, amendments, explanatory material or impact assessment are included in the source reviewed.

Why this matters Northstar operates UK-wide infrastructure and consumer services, including projects dependent on timely planning and consenting decisions. If any activities or systems are brought within scope, the Bill could create additional cyber-security, resilience, governance, incident-management or supplier-related requirements. The immediate issue is scope: we have not yet confirmed which Northstar services, systems or suppliers could be affected.

Initial internal questions Legal:

  • Which Northstar activities may constitute essential activities or otherwise fall within the Bill’s scope?
  • What changes, if any, are expected to the 2018 Regulations and existing obligations?
  • Are there likely duties affecting accountability, enforcement, reporting or implementation timing?

Cyber Security:

  • Which network and information systems support potentially in-scope services?
  • What resilience, risk-management and incident-response controls are already in place?
  • Are there known gaps against current NIS obligations or likely future requirements?

Operations:

  • Which operational services, assets and critical dependencies could be affected?
  • Which suppliers provide systems or services supporting those activities?
  • Could compliance requirements affect delivery, procurement, project timetables or consenting dependencies?

Public Affairs follow-up

  • Monitor the four Committee sittings for amendments and debate on scope, duties, enforcement, incident reporting and supply-chain requirements.
  • Refresh this brief when clause text, amendments or explanatory material are available.
  • Do not develop an external position until the internal applicability assessment and any approved organisational position are agreed.
COLLABORATIONComments & handoffs

Keep feedback with the draft so Alex and the team can act on the same version.

0 open

No review comments yet.

Comments stay internal to this organisation.