The UK government has proposed amendments to its Cyber Security and Resilience Bill that would give ministers new powers to restrict, condition, phase out, or ban technology suppliers used by operators of essential and critical services on national security grounds. The measures would apply beyond telecoms to sectors including energy, water, transport, healthcare, managed service providers, data centers, and digital infrastructure, and are intended to reduce the risk of hostile-state-linked vendors being used for spying, sabotage, or disruption.
Under the proposed vendor-related direction regime, the government could intervene when organizations seek to buy from suppliers judged to pose critical risks, require extra security controls, or order withdrawal of existing technology. The framework would also allow ministers to act without publicly naming the vendor and, in some cases, without directly notifying the supplier, while restricting recipients and consulted parties from disclosing the order. The package also includes cyber-safe procurement guidance, a voluntary referral process for uncertain buyers, public notice that a direction was issued, and annual reporting to Parliament ahead of House of Lords scrutiny.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The UK government laid amendments to the Cyber Security and Resilience Bill before Parliament, proposing new powers to restrict, direct, or ban procurement from technology suppliers deemed national security risks in critical sectors. The measures include binding directions, cyber-safe procurement guidance, and a vendor-risk assessment process for essential service providers.
The proposed amendments are set to be considered during House of Lords committee stage scrutiny in September. This marks the next formal legislative step for the proposed vendor-restriction powers.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourceitpro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.