All good things come to those who wait. At the time of writing, the Cyber Security and Resilience Bill (CSRB) was awaiting its committee stage in the Lords, at the beginning of September. The hope is that it will become law this year, after many delays. It promises to widen the group of in-scope organisations, strengthen incident response requirements, and introduce new baseline security expectations, among other things.

But perhaps more interesting is what comes next. What does the bill tell us about where regulatory expectations are heading? And what can organisations (including those not currently in scope) do to pre-empt what may be coming down the line?

The Big Shift

The bill’s biggest signal of what’s to come lies in its title. This is about repositioning cyber from a siloed function aligned to IT to one that sits at the heart of the organisation. At the same time, it foregrounds resilience as the goal of security teams, rather than simply keeping the bad guys out and meeting an arbitrary list of technical controls.

Resilience in these terms means accepting that breaches will happen – how could they not in a world in which powerful AI is collapsing the exploitation window and helping threat actors to upskill across multiple disciplines? The key is to ensure the organisation can continue to operate while containing the threat and recovering as quickly as possible.

This makes cyber a bigger boardroom conversation because it speaks to the concerns that animate business leaders. Operational risk, business continuity, financial and reputational damage.

“The new requirements of the bill will mean that cybersecurity and resilience have to be seen by boards as a critical strategic issue, not just a discrete IT challenge,” James Morris, director of non-profit the CSBR, tells IO (formerly ISMS.online).

“It means that customer expectations will be raised in terms of a focus on security and resilience in the procurement process and in the ongoing delivery of product and services. Cybersecurity and resilience issues need to be front and centre of governance considerations and given top priority in strategic board discussions.”

This message is consistent across government. Its Cyber Governance Code of Practice asserts that cyber risk is business risk and that directors need to govern it effectively. Security leaders will manage the day-to-day risks and controls, but the board must take ownership of risk oversight and assurance. The Cyber Resilience Pledge similarly speaks directly to business leaders. Organisations signing up must complete governance training, commit to using the NCSC’s Early Warning service, and require Cyber Essentials across their supply chains, as well as publishing annual updates.

In short, the expectations from government are become increasingly clear, and resilience is front and centre.

What Might Come Next?

With this in mind, it’s also useful to understand how the CSRB regime may evolve. The truth is that it’s still way more limited in scope than NIS2. But crucially, it gives the secretary of state the power to update the framework to bring new sectors and sub-sectors into the regime, as well as change the responsibilities and functions of its regulators. The implication is clear: if your sector isn’t covered today, don’t assume it will remain exempt tomorrow.

“During passage, there was some pressure to go further, with retail and manufacturing raised as obvious omissions,” Axians UK crisis and cyber resilience specialist, Dennis Martin, tells IO. “They didn’t make it this time, but given the past few years of attacks on retailers, I’d expect this argument to return in September.”

The CSRB’s supply chain stipulations will also bring a new swathe of organisations indirectly in scope, by forcing larger organisations they do business with to manage third-party risk more rigorously. It also empowers the secretary of state to designate any supplier whose failure could create significant disruption to a regulated entity.

“Regulators are increasingly focused on how critical services are delivered across interconnected supply chains, meaning resilience can no longer be assessed solely within the four walls of an organisation,” Eversheds Sutherland partner, Dave Hughes, tells IO. “Effective oversight of key suppliers and third parties, supported by ongoing monitoring and clear contractual expectations, is becoming an essential component of demonstrating cyber resilience.”

It’s worth bearing in mind too that the CSRB will bring with it a new set of expectations about what best practice cybersecurity and resilience means from a technical control perspective. The NCSC’s Cyber Assessment Framework (CAF) will be a key document here, so any organisation keen to future-proof their cyber and compliance strategy should take note.

And one last big change: the CSRB will empower regulators to provide continuous regulatory oversight of in-scope organisations, in a departure from today’s incident-driven model. This is theoretical at present and will depend on many factors, not least the funding and capacity of regulators. But it signals that the government increasingly expects compliance to be something that must be continuously managed.

Connected and Continuous

Experts agree. “Static annual compliance is obsolete when threat actors don’t wait for an audit. Should the CSRB become law as it currently stands, cloud providers, datacentres and MSPs can be audited before an incident occurs, not only at regular scheduled times or after an attack,” explains Axians UK’s Martin.

“In addition, the bill demands a 24-hour early warning followed by a 72-hour full report to both the sector regulator and the NCSC, with customer notification required in some circumstances. This demands continuous monitoring. Without continuous visibility of your network, you will not be able to notify the required organisations in time.”

Aben Pagar, head of digital risk consulting at Konexo, concurs. “Continuous monitoring and assurance are becoming increasingly important as regulators move beyond point-in-time compliance assessments,” he tells IO. “Organisations need ongoing visibility of risks, control effectiveness and resilience outcomes. Those that can demonstrate continuous oversight, testing and improvement are likely to be better positioned than those relying solely on periodic compliance exercises.”

Not only must organisations move their compliance programs away from point-in-time snapshots of posture, but they should also think more clearly about the overlaps that exist between historically siloed functions, Pagar adds.

“Organisations are recognising that cyber resilience does not exist in isolation. Issues such as AI governance, privacy, data protection and technology risk are increasingly interconnected, requiring a more holistic approach to governance and risk management,” he argues.

A mature approach like this which uses continuous compliance as a springboard to resilience is still a long way off for many organisations, according to the most recent government Cyber security breaches survey. But there’s no doubt that this is the direction regulators are moving in.

The CSRB’s Morris describes resilience as “both a technical and a cultural issue” for businesses.

“Notwithstanding the requirements of the new legislation, organisations need to concentrate on embedding a resilience mentality and culture at the heart of their business processes,” he concludes.

“This means strategic resilience planning at a board level and then a coherent cascade into the operations of the business, with clear plans and accountabilities for key resilience operations.”

Better start planning now.

Expand Your Knowledge

Blog: How Ransomware Became a Business Resilience Problem

Podcast: Phishing for Trouble S2 E10: Built to Last: How Compliance Enables Business Resilience

Webinar: Master Supply Chain Compliance