The new Bill is mandatory for specific sectors and services, and it expands on the UK Network Information Security 2018 regulations, so who is directly impacted by CSRB?
Operators of Essential Services (OES) that were originally in scope remain as:
– Energy: Electricity, oil, and gas.
– Transport: Air, rail, water, and road.
– Health: Healthcare settings (including hospitals, private clinics, and online settings).
– Water: Drinking water supply and distribution.
– Digital infrastructure: TLD (top-level domain) name registries, DNS (domain name systems) service providers, and IXP (Internet exchange point) operators.
Thresholds for each sector are specific to several factors, such as their services, the size of the customer base, the impact on customers, and geography (Great Britain and Northern Ireland).
Relevant Digital Service Providers (RDSPs) that were in the original scope also remain:
– Online search engines
– Online marketplaces
Cloud computing services
New sectors in scope are:
– Data centres: For example, those that hold patient records, emails, and financial data.
– Managed service providers: Outsourced IT services that are essential to OESs and RDSPs.
– Large load controllers: Organisations managing electrical loads for smart appliances, e.g., to support electric vehicle (EV) charging during peak times.
– Designated critical suppliers: Regulators will be able to designate critical suppliers, ensuring the most important suppliers to essential and digital services are subject to the regulatory regime.
Micro and small enterprises are exempt from the Bill, pointing to the EU NIS for reference to define these:
– Enterprises: Employ fewer than 250 persons, annual turnover not exceeding EUR 50 million, and/or an annual balance sheet total not exceeding EUR 43 million.
– SMEs: Small enterprises employing fewer than 50 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 10 million.
– Micro-enterprises: Employing fewer than 10 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 2 million.
Whilst the exemptions are clear, our recommendation to smaller suppliers is that your customers will need to be certain that their supply chain is secure and resilient, so it can only be a benefit to all parties if you can demonstrate that you have the same measures in place as your larger counterparts. It will certainly set you apart from other businesses that chose not to put measures in place.
To learn more about CSRB, contact us or register for our webinar, where expert advice and insights will be shared. You will also have access to a free cyber security and business resilience assessment.
The registration page is here: https://lnkd.in/e2B6_W76







