Cybersecurity 2026

UK Trends and Developments Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

Enhanced incident reporting obligations Under the current UK NIS, reportable incidents are limited to those “having an actual adverse effect” on the security of network and information systems. The CS&R Bill lowers this threshold to incidents “having or capable of having an adverse effect”. It also intro - duces a two-stage reporting requirement: an initial notification within 24 hours of an entity becoming “first aware” of an incident, followed by a full report within 72 hours. Strengthened investigatory powers The CS&R Bill proposes to strengthen investigatory powers under the UK NIS regime by expanding “infor - mation gathering” powers. In particular, competent authorities would be able to require an organisation to provide information or documents, including by requiring them to obtain or generate information, or to collect or retain information that they would not otherwise maintain. These measures are intended to support more effective investigation and enforcement. Online Safety Act 2023 The UK Online Safety Act 2023 (“OSA”) aims to strengthen online protections for both children and adults and received Royal Assent on 26 October 2023. Under the OSA’s “illegal content” regime (which requires in-scope online service providers to protect users from illegal content and activities), Ofcom (the UK communications regulator) finalised its first illegal content Codes of Practice (the “CoPs”) on 24 Febru - ary 2025. The CoPs, which are non-binding, set out recom - mended measures for risk assessment, the proac - tive moderation of terrorism and child sexual abuse material (“CSAM”), user reporting mechanisms, and governance arrangements. They take full effect from March 2025. Ofcom is expected to publish advice to the Secretary of State and final guidance on the use of Technology Notices by April 2026. Where necessary and propor - tionate, such notices may require providers to deploy accredited technology to tackle CSAM and/or terror - ism content. Ofcom has also announced a number of other OSA-related cyber guidelines and reports antici - pated in 2026, including a report on age assurance,

“FCA”) to develop “interface rules” supporting open finance, including requirements to use prescribed dig - ital interfaces and comply with technical standards. As a result, UK financial firms may need to update their systems to ensure compliance with any new FCA rules. This will be particularly relevant when engaging third-party vendors or data analytics providers. Taken together, the reforms introduced by the DUA Act signal a more pragmatic and risk-based approach to data protection in the UK, but one that may require organisations to review and adapt their compliance strategies and closely monitor regulatory guidance as the new regime takes effect. Cyber Security and Resilience (Network and Information Systems) Bill The most significant cyber-related development is the UK Cyber Security and Resilience (Network and Information Systems) Bill (the “ CS&R Bill ”). The Gov - ernment introduced the CS&R Bill to Parliament in November 2025, with its second reading taking place in January 2026. The CS&R Bill is due to enter the committee stage in February 2026. The CS&R Bill aims to strengthen the UK’s cyber resilience by intro - ducing a number of key reforms, as follows. Expanding the scope of regulated entities The existing Network and Information Systems Reg - ulations (“UK NIS”) apply to “operators of essential services” (such as those in the energy, transport and health sectors), and “relevant digital service provid - ers” (including, for example, search engines and cloud computing services). The CS&R Bill extends the regime to additional sectors, notably data centres and managed service providers. Closer alignment with the EU framework The CS&R Bill aligns more closely with the EU’s Net - work and Information Security Directive 2 (“NIS 2”). For example, NIS 2 designates data centre service providers as operating in “sectors of high criticality,” and the CS&R Bill similarly brings data centres within scope as providers of “essential services.” The inci - dent reporting deadlines under the CS&R Bill also mir - ror those in NIS 2 ( see below).

458 CHAMBERS.COM

Powered by