In 2025 Marks and Spencer suffered a ransomware attack that disrupted its online ordering system for several weeks and caused significant operational and reputational damage. In the same year Jaguar Land Rover experienced a serious cybersecurity incident affecting its internal systems. Neither organisation operates in a sector covered by the Cyber Security and Resilience Bill, both would have been entirely outside the scope of the UK’s new flagship cybersecurity legislation even if it had been in force at the time of their attacks.
This is not a minor technical gap. It is a fundamental question about the philosophy of the UK’s approach to cybersecurity regulation. The bill takes the view that regulatory intervention should focus on critical national infrastructure because the systemic consequences of a CNI failure are categorically different from the consequences of a retail or automotive incident. This is a defensible position. It is also increasingly difficult to sustain in an environment where a single successful ransomware attack on a major retailer disrupts supply chains serving millions of consumers.
The Cybercrime Volume Trajectory
The chart below contextualises the legislative response against the scale of the problem it is designed to address. UK reported cybercrime incidents rose from approximately 775,000 in 2020 to more than 1.45 million by March 2026. That is an 88 percent increase over six years against a legislative and regulatory framework that has barely changed since 2018.

Chart 1: UK reported cybercrime incidents 2020 to March 2026 (Source: Action Fraud and ICO data; Bill Gosling analysis)
What the Bill Gets Right
It would be unfair to dismiss the Cyber Security and Resilience Bill as inadequate without acknowledging what it genuinely improves. The extension of regulatory scope to managed service providers is one of the most important changes in the bill and addresses a vulnerability that has been exploited repeatedly. The breach of the Ministry of Defence payroll system via a contractor, the disruption to NHS services via a managed service provider and dozens of other incidents share a common structural feature: the regulated entity was compromised through a supplier that was not itself regulated.
The 24-hour and 72-hour reporting timelines, combined with mandatory dual notification to both the sector regulator and the NCSC, will give the government a significantly better real time picture of the UK threat landscape than it currently has. The NCSC’s ability to respond to and coordinate responses to major incidents depends on being informed quickly. Many organisations currently delay notification because the regulatory consequence of reporting feels worse than the consequence of managing an incident quietly. The new framework removes some of that incentive.
The ransomware payment ban for CNI and public sector organisations is also significant. The government’s consultation made clear that ransomware payments fund further ransomware development and that banning them for the most visible and politically sensitive targets sends a clear signal about the direction of UK policy. The requirement for all organisations to report ransomware incidents regardless of whether they pay is the most important intelligence-gathering provision in the bill.
What the Bill Gets Wrong
The scope limitation is the central weakness. The government’s stated rationale for focusing on CNI sectors is that the risks in those sectors are qualitatively different because a failure in energy, water or finance has systemic consequences. This is true. It is also increasingly incomplete as a framing. A major retailer whose systems are encrypted during the Christmas trading period, a supermarket chain whose logistics software is disrupted and a vehicle manufacturer whose production systems are taken offline all generate economic and social disruption that is systemic in a practical sense even if it does not appear on a regulatory list.
The call from several commentators for a single cybersecurity regulator with cross-sector authority is worth taking seriously. The current model of sectoral regulation produces inconsistent standards, creates gaps at the boundaries between sectors and places the compliance burden disproportionately on organisations that happen to be classified as essential services while their equally significant private sector neighbours operate without equivalent obligations.
The Spending and Governance Gap
| Issue | Current Position | What Needs to Change |
| Scope of regulation | CNI and essential services only | Voluntary frameworks for private sector need stronger uptake incentives |
| Board-level cyber governance | NCSC guidance exists but is not mandatory for most organisations | Cyber Governance Code of Practice should become a comply or explain requirement for all listed companies |
| Regulatory fragmentation | Multiple sector regulators with different standards | Coordination mechanism between regulators needs strengthening under the new bill |
| SME support | Cyber Essentials exists but take-up is low | Cyber Essentials should be required for all public sector supply chain participants not just direct government contractors |
| Incident data quality | Significant underreporting due to fear of regulatory consequences | Safe harbour provisions for self-reporting would improve intelligence quality without reducing accountability |
Table 1: Key gaps in UK cybersecurity policy and governance and what each requires to address them
A More Honest Conversation About What Protection Requires
The UK loses an estimated £15 billion a year to cybercrime. The government has written to the top 350 businesses urging better board governance and has introduced a bill that will improve incident reporting and extend regulatory coverage to managed service providers. These are meaningful steps. They are also not commensurate with the scale of the problem as the cybercrime volume trajectory makes clear.
The honest conversation that UK policy needs to have is about the limits of a voluntary, sector fragmented approach to cybersecurity governance in an environment where the threat has grown by 88 percent in six years and the quarterly board briefing recommended in NCSC guidance is a ceiling rather than a floor for most organisations outside the regulated CNI sectors.
The bill is a step in the right direction. The direction it needs to keep travelling in is clear. The question is whether the political will exists to follow the evidence rather than the path of least resistance in the next legislative cycle.

Leave a Reply