This policy brief examines the proposed Cyber Security and Resilience Bill, including managed service providers, supply-chain security, data centres, incident reporting, regulatory powers and accountability.