Cyber Security and Resilience Bill

The Cyber Security and Resilience (Network and Information Systems) Bill proposes new laws to improve UK cyber defences and protect our essential public services.

The UK government introduced the Cyber Security and Resilience Bill to Parliament for its first reading on 12 November 2025. The Bill builds on the existing Network and Information Systems (NIS) Regulations 2018, strengthening the UK's defences against cyber attacks and better protecting the essential services people rely on daily — from the power grid and water supply to the NHS.

The reforms represent a significant step in the UK's approach to national security, aiming to make essential and digital services more resilient against both cybercriminals and state-sponsored actors. The government has framed the changes as supporting economic stability by reducing the cost and disruption businesses face from cyber incidents, while encouraging continued investment.

Read the full government collection here: [gov.uk link]

For organisations working across connected AV, security and building management systems, this legislation reinforces something CMC has been saying for some time — that cyber resilience can no longer be treated as separate from the physical infrastructure it protects. Our Known Systems. Hidden Risks. series explores exactly this, examining the cyber exposure hidden within everyday connected technology across a range of industries.

Read the series below.

Professional Audio over IP Security

The Risk Most Organisations Still Underestimate

Digital Signage, Cyber Security and Protective Security

Why the Industry Needs to Move Beyond “Screens on Walls”

CCTV Isn’t Just Watching Anymore

It’s Talking, Sharing, and Sometimes Exposing You

Modern Building Control Protocols

Understanding BACnet, KNX and MODBUS - and the Cybersecurity Risks Emerging Behind Them

Cyber Frameworks

The Rules That Already Apply to Your Network