<img alt="" src="https://secure.inventive52intuitive.com/789747.png" style="display:none;">
What the Cyber Security and Resilience Bill means for business leaders

What the Cyber Security and Resilience Bill means for business leaders

Posted by Kevin Howell

The Cyber Security and Resilience Bill moved into detailed scrutiny in the House of Lords yesterday. For business leaders, there's a bigger message here than just another piece of cyber legislation.

Cyber security is becoming a supply-chain issue.

The proposed legislation doesn't only look at the organisations that deliver the UK's essential services. It puts far more weight on the technology businesses and suppliers they depend on, including managed service providers.

That's the part worth paying attention to.

Most organisations don't run their technology in isolation. They rely on MSPs, Microsoft 365, cloud platforms, software providers and a digital supply chain that gets more interconnected every year.

Attackers know this. Compromise one supplier with privileged access and you've got a potential route into every organisation that supplier touches.

It's one reason I'm glad we spent years building HTG around a security-first approach, rather than bolting cyber security onto a traditional IT support service.

But here's the other point for business leaders. You don't need to wait for legislation to tell you to improve your cyber resilience.

Here are the questions I'd be asking today:

  • Does our IT provider follow recognised security standards themselves?

  • Do we have MFA and proper identity controls everywhere they should be?

  • Are devices properly managed and patched?

  • Do we know who has privileged access to our environment?

  • Can we detect and respond to an attack, not just try to prevent one?

  • Could we keep operating if one of our critical technology suppliers was compromised?

  • And is someone regularly explaining these risks to the board in language we actually understand?

These aren't IT questions anymore. They're business resilience questions.

The Bill is still making its way through Parliament, and the wording may change. But the direction is clear. Cyber resilience is moving up the boardroom agenda and down through the supply chain.

For MSPs like HTG, that's a good thing. Businesses should expect a lot more from the people they trust with the keys to their technology.

Contact

Want to partner with us?

Get in touch to learn more about our services or arrange a free 30-minute consultation with one of our Secure Cloud Experts.

Get in touch
HTG - Contact CTA