Expert sounds the alarm on increased security demands flowing from the new cyber security bill
17th September 2026
A leading IT expert has warned that even small Managed Service Providers could be caught in the scope of a more challenging regulatory environment under the requirements of the Cyber Security and Resilience (Network and Information Systems) Bill.
The bill puts MSPs in focus, as larger players now feature in a new “Relevant Managed Service Provider” category with increased reporting requirements – including a 24-hour window for some types of incident.
Roy Shelton, Group CEO of managed services provider Connectus Business Solutions, commented: “This Bill formalises what has been best practice for us for years – the difference now is that a supply-chain breach at one provider can no longer be treated as somebody else’s problem.
“We hold the keys to hundreds of client networks, and regulation catching up with that responsibility is overdue.
“A 24-hour reporting window sounds demanding if you haven’t already built the incident response playbook to meet it, which is exactly where Connectus clients sit today.”
The bill is expected to complete its path through Parliament in late 2026 and many provisions will not come into play until 2028, as they require secondary legislation.
The new RMSP designation will apply to medium and large MSPs and, while small and micro-enterprise MSPs are exempted, they still could be individually designated as a “critical supplier” if disruption to their activities carries a significant knock-on risk.
It is estimated that 900 to 1,100 MSPs could be classed as supporting critical business sectors, in health, energy, finance and others.
An in-scope MSP will need to register with the Information Commission and implement “appropriate and proportionate” security measures reflecting state-of-the-art practice, with compliance required within three months of registration.
It will introduce a two-stage reporting duty, where a significant incident will require an initial notification within 24 hours, followed by a fuller report within 72 hours.
Also, the current focus on service disruption is being widened to cover confidentiality and integrity incidents which bring data breaches and unauthorised-access events into the reporting net alongside network outages.
The critical supplier designation is a before-the-fact mechanism rather than something triggered after an incident, and it means even a small MSP could still be pulled into a version of the regime if it is deep enough in a critical supply chain.
It is worth noting that data centres are being regulated for the first time as critical national infrastructure; though most MSPs do not operate data centres, many re-sell or broker colocation and hosting.
Penalties under the bill fall into two bands: the higher band stipulates a penalty of up to £17 million or 4% of global turnover, whichever is higher, while the standard band is up to £10 million or 2% of worldwide turnover.
Mr Shelton observed: “We’re not scrambling to react to this legislation; we’re already operating to the standard it’s about to make law. Those who’ll struggle are the ones who’ve treated cyber security as a checkbox exercise rather than a discipline.
“Connectus clients are covered by Cyber Essentials Plus and ISO 27001 certification, so for them this bill isn’t a compliance deadline to fear.”
For more information, see connectus.org.uk.