All research
Policy Brief April 2025

This policy brief examines the proposed Cyber Security and Resilience Bill, including managed service providers, supply-chain security, data centres, incident reporting, regulatory powers and accountability.

Topics
Business Resilience, Cyber Regulation, Supply-Chain Security

Overview

This policy brief analyses the UK government’s proposed Cyber Security and Resilience Bill following the April 2025 policy statement and a CSBR expert roundtable.

It considers regulation of managed service providers, supply-chain security, data-centre protection, delegated powers, incident reporting, the role of the ICO and alignment with the EU NIS2 framework.

Download the publication

Open the full publication as a PDF in a new tab.

Download PDF