The UK’s Cyber Security and Resilience Bill (CSRB) received late amendments specifically targeting the supply chain threat against the nation’s critical infrastructure.
The UK CSRB – not to be confused with the US Cyber Security Review Board (CSRB) – was introduced to Parliament in November 2025. It has successfully completed all the necessary steps through the House of Commons, moved to the House of Lords (as HL Bill 32) and is now close to receiving Royal Assent. Royal Assent is the point at which the Bill becomes an Act of Parliament and part of UK law, where it passes into the Cyber Security and Resilience (Network and Information Systems) Act.
Both a bill and an act can be changed at any time. One example happened recently. On August 22, 2026, The Telegraph newspaper reported that Iran-linked adversaries had attacked and forced a small power facility in the United Kingdom to go offline for four days. The attack itself had no major effect, but it raised questions about the potential effect of broader supply chain attacks on the critical industry.
The Government reacted quickly and on 24 August 2026 introduced amendments to the CSRB, highlighting the urgent need to give Ministers powers to prevent (block) critical sector organizations from using technology providers deemed high risk.
“Confirmation that a UK power generator was knocked out for four days following a cyber-attack, alongside the Government’s move to extend the Bill’s cyber security and supply chain resilience provisions, brings a long-running policy debate into sharp focus. The incident involving the power generator and the alleged involvement of a nation state has clearly sharpened appetite for the Bill’s powers to designate critical suppliers, regardless of sector or size,” commented Darren Guccione, Chief CEO and co-founder of Keeper Security.
“This bill makes a critical distinction – that a hacker who can shut down a hospital or compromise a water supply is not an IT problem, it’s a threat to public safety,” added Shankar Haridas, UK business leader ManageEngine.
Jamie Akhtar, CEO and Co-Founder of CyberSmartexplains: “The proposed measures are another clear sign that supply chain security is becoming a national sustainability issue as well as an issue for individual businesses. Critical infrastructure organizations may have their own advanced security controls, but their defenses can be quickly undermined if attackers manage to exploit a smaller, less secure supplier further down the chain.”
The CSRB already contains strict requirements, with very strict deadlines for reporting incidents and severe penalties for failure. Blocking individual companies takes it to a different level. “Attackers rarely walk through the front door of a well-protected organization. Most go through a provider with lighter security, a managed service provider with persistent access, or a provider that no one has checked in years,” Guccione commented. Keeper’s own research shows that 34% of UK organizations report incidents involving suppliers or third party suppliers.
This is an interesting approach. Improve the security of critical infrastructure not by requiring it to implement better internal security, but by excluding them from third-party vendors it deems insufficiently secure.
“Many SMEs would not necessarily consider themselves part of the UK’s critical infrastructure,” continues Akhtar, “but if they provide technology, services or access to organizations operating in critical sectors, their cyber resilience is of huge importance. Attackers understand this and will naturally look for the easiest route to their end goal.”
He continues: “The Cyber Security and Resilience Bill reflects a wider shift towards greater accountability for third-party risk. Ultimately, the UK’s critical infrastructure is only as resilient as the organizations connected to it, and this means raising the cyber security baseline across the entire supply chain,” concludes Akhtar.
The supply chain threat is not new, but it continues to grow. The UK’s Cyber Security and Resilience Act will have the power to force weak points of origin of supply chain attacks to do more to ensure their own security. The target is the supply chain, but the main target is the origin of the SME. So the message to SMEs serving the UK’s critical infrastructure is simple: improve your own cyber security so that your future profitability is not affected by the UK Government when the CSRB becomes the CSRA.
Connected: Rust Supply Chain Attack Linked to North Korean Hackers
Connected: Over 2,500 organizations affected by LiteLLM supply chain attack
Connected: Over 400 NPM packages infected in ChainDrop supply chain attack
Connected: Trump orders defense contractors to map software, suppliers in critical supply chains