Digital Content Editor, Eve Goode speaks with Florian Pouchet, Head of Cybersecurity and Operational Resilience UK and Partner, Wavestone.
What does the Cyber Security and Resilience Bill mean for UK business in practice?
For organisations already subject to NIS1 as existing operators of essential services, the Bill means stricter reporting deadlines, stronger regulatory scrutiny, increased fines for non-compliance and a requirement to consider the wider supply chain and the risks it presents.
In practice, even those organisations already operating under NIS1 will need to review incident-reporting processes, tooling and escalation routes so that fast detection, triage and reporting are possible.
Contractual clauses with customers and sub-suppliers will also need attention, enabling information to be gathered and reported quickly when required.
For newly in-scope organisations, like MSPs and designated critical suppliers, the priority is to understand where they sit within critical supply chains.
They need to map the services and systems that support essential or digital services, introduce more formal cyber-governance, develop efficient incident-notification methodologies and map their critical functions accordingly.
Are organisations ready for the Bill’s tougher incident-reporting deadlines?
Readiness is mixed. Larger and international organisations already subject to NIS2 have a head start because of the similarities between the two pieces of legislation.
They are more likely to have established cyber-governance, incident-response processes and regulatory reporting mechanisms in place already.
Organisations without those arrangements may struggle with the tighter reporting timelines and the tooling needed to support them.
This is likely to be particularly challenging for small and micro providers.
The Government and the NCSC and are taking action to help.
For smaller organisations, widely accessible frameworks such as the Cyber Assessment Framework are likely to provide the most practical route towards preparedness.
The effect will also extend beyond entities directly in scope.
Organisations that rely on third-party IT providers or critical digital infrastructure are likely to face increased due-diligence requirements, contractual changes and stronger expectations around supply-chain cyber-assurance.
International companies serving UK customers may also be captured where their services underpin UK essential functions.
Why do so many businesses still struggle to identify their critical dependencies?
Large organisations often struggle because their activities are divided extensively across different functions. Individual teams may understand their own responsibilities, but no single team has a complete view of the end-to-end process.
As a result, mapping activities and dependencies can become quite an investigation.
The challenge is compounded by complex and fast-changing chains of technology, suppliers and outsourced providers.
Organisations may have visibility of their direct suppliers, but much less of the sub-suppliers, managed service providers, cloud platforms, SaaS tools, data centres and operational technology systems on which those services depend.
Even where dependencies are clear, defining what is critical remains subjective.
Every business line may, in good faith, see its own activity as essential.
However, proper prioritisation requires clear assumptions and scenarios around what the organisation needs to survive, and for how long.
Approaches such as Minimum Viable Company can help. Starting from “nothing”, organisations identify the minimum set of services needed to run the business.
This creates a more practical basis for distinguishing core operational needs from less critical activity.
Will the UK’s approach to cyber-regulation strengthen resilience or create uncertainty?
Overall, regulation is an effective tool for increasing resilience.
Wavestone’s own cyber-benchmark shows that regulated industries have higher average maturity than non-regulated industries.
By closing the regulatory gap that has existed since NIS1, the Bill will increase reporting expectations and centralise incident notification through the NCSC.
This should enable a central repository of live and near-miss incidents affecting the UK and, ideally, enhance resilience.
Expanding the entities in scope also provides a more realistic view of what makes up British critical national infrastructure.
That broader view is important to preserving national resilience and reflects the wider ecosystem supporting essential and digital services.
Are businesses moving too quickly to adopt agentic AI without the right security controls?
The push to deploy AI agents is strong, and not all security controls or guardrails can be ready in time given the pressure to adopt them.
The pace of deployment can exceed the pace at which the appropriate controls are developed and made available.
Identity and Access Management illustrates the issue.
Standards for what good security looks like for AI agents are still being written, let alone implemented in traditional IAM solutions and platforms.
For many clients, that is the main limitation: they cannot implement the right security controls where those controls do not yet exist in a mature, deployable form.
This is not necessarily a matter of organisations disregarding security.
Rather, it is an inability to implement controls that are still emerging.
There is also a positive perspective.
Compared with earlier technology waves such as cloud, security is not arriving as late.
In the past, security often had to catch up after adoption had accelerated.
With AI, it is engaging earlier, even while standards, guardrails and controls continue to mature.