Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Burnham beware, the bond markets will demand proper answers in the budget | Nils Pratley

    September 2, 2026

    Range Rover’s new EV looks just like a regular Range Rover — that’s refreshing

    September 2, 2026

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    September 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Burnham beware, the bond markets will demand proper answers in the budget | Nils Pratley
    • Range Rover’s new EV looks just like a regular Range Rover — that’s refreshing
    • UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
    • SEC wants stocks onchain, but your crypto wallet still isn’t enough
    • NASA Rocket Takes First Multi-Point Look Inside Radio-Disrupting Clouds
    • At the Grand Canyon, Flooding and Wildfire Underscore Compounding Extreme Weather Risks
    • WATCH: $12.5B gas project closing in on first LNG cargo as 10-storey module comes to Australia
    • Illinois, Midwest saw large reduction in conservation staff in 2025, study shows 
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 2, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The UK Cyber Security and Resilience Bill (CSRB) has been given late amendments specifically targeting the supply chain threat against the nation’s critical infrastructure.

    The UK CSRB – not to be confused with the US Cyber Safety Review Board (CSRB) – was introduced to Parliament in November 2025. It has successfully completed all necessary steps through the House of Commons, has moved to the House of Lords (as HL Bill 32) and is now close to receiving Royal Assent. Royal Assent is the point at which the Bill becomes an Act of Parliament and part of UK legislation, where it transitions into the Cyber Security and Resilience (Network and Information Systems) Act.

    At any time, both a bill and an act can be amended. An example has occurred recently. On August 22, 2026, The Telegraph newspaper reported that Iran-linked adversaries had targeted and forced a small-scale UK energy facility offline for four days. In itself, the attack had no serious effect but did raise questions over the potential effect of wider supply chain attacks on critical industry. 

    The government reacted rapidly, and on August 24, 2026, tabled amendments to the CSRB underscoring an urgent need to give ministers powers to prevent (block) critical-sector organizations from using technology suppliers deemed high risk. 

    “The confirmation that a UK energy generator was taken offline for four days following a cyber-attack, alongside government moves to widen the Cyber Security and Resilience Bill’s supply chain provisions, brings a long running policy debate into sharp focus. The incident involving the energy generator and the purported involvement of a nation state, has clearly sharpened appetite for the bill’s power to designate critical suppliers, regardless of sector or size,” comments Darren Guccione, CEO and co-founder at Keeper Security.

    “This Bill makes a critical distinction – that a hacker who can take a hospital offline, or compromise a water supply isn’t an IT problem, they’re a public safety threat,” adds Shankar Haridas, UK business head at ManageEngine.

    Advertisement. Scroll to continue reading.

    Jamie Akhtar, CEO and co-founder at CyberSmart, explains, “The proposed measures are another clear sign that supply chain security is becoming a national resilience issue, as well as a concern for individual businesses. Critical infrastructure organizations may have sophisticated security controls of their own, but their defenses can quickly be undermined if attackers are able to exploit a smaller, less well-protected supplier further down the chain.”

    The CSRB already contains stringent requirements, with very strict incident reporting timelines and heavy penalties for failure. Blocking individual companies takes it to a different level. “Attackers rarely go through the front door of a well-defended organization. The majority go through a vendor with lighter security, a managed service provider with standing access, or a supplier nobody has audited in years,” comments Guccione. Keeper’s own research shows that 34% of UK organizations report incidents involving third-party vendors or suppliers.

    It’s an interesting approach. Improve the security of the critical infrastructure not by demanding it implements better in-house security, but by disconnecting them from the third-party suppliers they consider to be inadequately secure.

    “Many SMEs won’t necessarily think of themselves as part of the UK’s critical infrastructure,” continues Akhtar, “but if they provide technology, services or access to organizations operating in critical sectors, their cyber resilience matters massively. Attackers understand this and will naturally look for the easiest route into their ultimate target.”

    He continues, “The Cyber Security and Resilience Bill reflects a wider shift towards greater accountability for third-party risk. Ultimately, the UK’s critical infrastructure is only as resilient as the organizations connected to it, and that means raising the baseline of cybersecurity across the entire supply chain,” concludes Akhtar. 

    The supply chain threat is not new, but it continues to grow. The UK’s Cyber Security and Resilience Act will have teeth to force the weak point origin of supply chain attacks to make greater effort to ensure their own security. The target is the supply chain, but the bullseye is the SME origin. So, the message to SMEs serving the UK critical infrastructure is simple: improve your own cybersecurity lest your future profitability be affected by the UK government when the CSRB becomes the CSRA.

    Related: Rust Supply Chain Attack Linked to North Korean Hackers

    Related: Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

    Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    Related: Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

    block critical HighRisk infrastructure Moves Suppliers tech
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Ransomware protection for MSPs: A 6-point checklist for faster recovery

    Microsoft Defender flags legitimate Google search links as malicious

    Dropbox accounts breached through Lenovo email verification flaw

    Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards

    The AI vulnerability surge is breaking the OT patch cycle

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Burnham beware, the bond markets will demand proper answers in the budget | Nils Pratley

    September 2, 2026

    Range Rover’s new EV looks just like a regular Range Rover — that’s refreshing

    September 2, 2026

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    September 2, 2026

    SEC wants stocks onchain, but your crypto wallet still isn’t enough

    September 2, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Burnham beware, the bond markets will demand proper answers in the budget | Nils Pratley

    September 2, 2026

    Range Rover’s new EV looks just like a regular Range Rover — that’s refreshing

    September 2, 2026

    UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

    September 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.