The UK government advanced its Cyber Security and Resilience Bill after publishing policy materials in 2024 and formally introducing the legislation to Parliament in November 2025, later adding an impact assessment, factsheets, supporting research, and notice that the Regulatory Policy Committee rated the assessment fit for purpose. The bill is part of a broader push to strengthen cyber resilience obligations as the government also signaled tougher online safety enforcement and wider expectations that critical services and digital platforms improve security governance.
Government survey data published in 2026 showed why the pressure is increasing: 43% of UK businesses and 28% of charities reported a cyber breach or attack in the previous year, with phishing remaining the most common and disruptive threat. While ransomware among businesses fell to 1%, the survey found repeat victimisation drove an estimated 5.19 million cyber crimes against UK businesses, and more advanced controls such as two-factor authentication, formal incident response plans, VPN use, and supplier risk reviews remained uneven, especially among smaller organisations. Industry reporting said the findings are sharpening focus on resilience measures including Cyber Essentials Plus, phishing-resistant MFA, network segmentation, tested backups, dependency mapping, and board-level reporting on recovery and operational survivability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The UK government published the Cyber Security Breaches Survey 2025/2026, reporting that 43% of businesses and 28% of charities identified a cyber security breach or attack in the previous 12 months, with phishing remaining the most common and disruptive attack type.
Fieldwork for the UK Cyber Security Breaches Survey 2025/2026 was conducted between August and December 2025 to assess cyber resilience among UK businesses and charities.
The UK government published a news announcement stating it was taking action to keep children safe online, framed by the Prime Minister's statement that no platform would get a free pass.
The GOV.UK bill page was updated to note that the Regulatory Policy Committee had rated the Cyber Security and Resilience Bill's impact assessment as fit for purpose, with a green rating.
The UK government's Cyber Security and Resilience Bill was introduced to Parliament, and the related GOV.UK page was updated with links to the Parliament bill page, impact assessment, factsheets, and supporting research.
The UK government first published its Cyber Security and Resilience Bill collection page, establishing a central location for policy and supporting materials related to the proposed legislation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcegov.uk
Open sourcegov.uk
Open sourcegov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.