Westminster eForum

For booking-related queries or information on speaking please email us at info@forumsupport.co.uk, or contact us: +44 (0)1344 864796.

Next steps for cyber security policy and regulation in the UK

Morning, Tuesday, 15th December 2026

Online


This conference will assess next steps for cyber security in the UK. It will bring stakeholders and policymakers together to examine priorities as the Government Cyber Action Plan moves through the first phase of its delivery timetable to April 2027, and as the Cyber Security and Resilience (Network and Information Systems) Bill continues its passage and attention turns to commencement, codes of practice and regulator readiness.


Policy, investment & threat management
Attendees will consider implications of an evolving threat environment, including the increasing use of AI in cyber attacks, for policy, regulation and organisational preparedness. Areas for discussion include the effectiveness of the Cyber Resilience Pledge in changing board-level behaviour and priorities for improving uptake, the role of public-private collaboration in strengthening resilience across national infrastructure, public services and supply chains, and how far funding and support are reaching the public-sector bodies and SMEs that need them most.


The agenda will examine investment, research and development, and policy coordination, including how cyber priorities sit alongside wider security, infrastructure and economic objectives under the National Security Strategy 2025. Planned sessions will explore practical steps for implementing the Government Cyber Action Plan, how the Government Cyber Unit exercises its accountability and assurance role across departments and arm's-length bodies, and priorities for improving public-sector resilience under the revised delivery timetable, together with the application of National Cyber Security Centre guidance and assurance frameworks in preparing for emerging threats.


Regulation, organisational responsibility & skills
The proposed extension of the Network and Information Systems regulatory framework to managed service providers and data centres will be considered, including transition arrangements, incident-reporting requirements and regulatory consistency. Sessions will also assess the capacity and respective roles of regulators, including Ofcom, as the framework develops.


Discussion is expected on secure-by-design approaches, leadership and organisational responsibility, cross-sector collaboration, international alignment, supply-chain and third-party risk, and the management of risks associated with increasingly autonomous and generative technologies. This also includes implications for interoperability, international cooperation and the competitiveness of the UK cyber security sector.


Further discussion will consider skills needs for supporting resilience, looking at ways forward for strengthening cyber capability in public services and addressing regional disparities in skills and sector development.


Overview of areas for discussion

  • policy & regulation:
    • the Cyber Security and Resilience Bill - expanding the regulatory perimeter to MSPs, data centres, large load controllers and designated critical suppliers
    • split of oversight between the Information Commission for managed and digital service providers and Ofcom for data centres - regulator capacity, consistency and statement of strategic priorities
    • legal and logistical risks for regulated entities under new reporting obligations - readiness for 24-hour initial notification and 72-hour full reporting
    • coordination of cyber priorities with wider security, infrastructure and economic objectives under the National Security Strategy 2025
  • investment & sector growth: maximising the impact of the £90m investment for SMEs announced in April 2026 - commercial incentives for adopting the Cyber Resilience Pledge
  • critical national infrastructure:
    • implementation of the NCSC’s 2026 severe cyber threat planning guidance by critical national infrastructure organisations
    • the expansion of Ofcom’s role as an essential services regulator
  • public sector resilience, supply chain & third-party risk: priorities for meeting 2030 public sector resilience targets - addressing vulnerabilities within commercial supply chains
  • growth:
    • UK Cyber Growth Action Plan 2025 recommendations and awaited government response
    • role of anchor institutions and private investors - regional capability and commercial scale‑up
  • design standards: integration of security into digital infrastructure - sector‑specific expectations for default protections - support for legacy system transitions
  • organisational practice: leadership responsibilities for cyber risk - organisational culture frameworks for improving risk management - governance pressures on exposed sectors
  • incident response & recovery: continuity planning under the NCSC's severe cyber threat guidance - decision-making on ransom demands and disclosure - lessons from recent nationally significant incidents
  • workforce readiness:
    • priorities for skills pipelines - regional and demographic disparities in access to careers
    • planning for future requirements for specialist and cross‑disciplinary expertise - recruitment and retention
  • technology risk:
    • interaction between AI capability and cyber threats - responsible deployment
    • monitoring and addressing the potential for automated systems to both defend and escalate attacks
  • international positioning:
    • UK alignment with frameworks such as NIS2 and DORA - competitiveness and interoperability
    • issues and opportunities for UK firms exporting cyber products and services