Cyber Security & Resilience Bill: How Healthcare Organisations Can Prepare

In the UK, the government is considering a major new framework called the Cyber Security & Resilience Bill. The new Bill is intended to build upon the Network and Information Systems (NIS) Regulations 2018, as the government continues to revise its approach to national cyber security (1).

In 2024, a third-party provider for the NHS, called Synnovis, experienced a devastating cyber-attack which affected over 11,000 appointments and resulted in a £32.7 million financial loss. One government paper suggests that part of the reason for this new framework is that NIS does not sufficiently manage risks across the digital services and supply chains that healthcare services depend on (2).

Whilst the Cyber Security & Resilience Bill is not expected to receive Royal Assent until late 2026, the Bill will focus heavily on essential services to minimise the impact of cyber-attacks and, subsequently, the impact on patient care.

With Royal Assent expected in late 2026, the Government is likely to begin implementing new regulations throughout 2027. This article is intended to inform healthcare organisations on how best to prepare for the Bill.

law and authority lawyer concept, judgment gavel hammer in court courtroom for crime judgement legislation and judicial decision, judge having justice of punishment guilt and criminal verdict legal

What are the anticipated changes?

Whilst the changes will not be confirmed until Royal Assent is granted, the government has released information about what essential services and healthcare organisations can expect.

  • 24-hour early reporting of incidents, followed by a full report to the National Cyber Security Centre (NCSC) within 72 hours.
  • Mandatory notification to affected parties in selected breach circumstances.
  • Changes to penalties depending on the seriousness of the breach. Penalties could reach up to 4% of global turnover for serious breaches, and up to £100,000 per day where an incident remains ongoing.
  • Additional sectors operating within essential services will fall within the scope of the Bill, including relevant digital service providers, critical suppliers, and data centres (3).

What does this mean for healthcare organisations?

Both private and NHS-run healthcare organisations are likely to feel the effects of these UK-wide legislative changes.

The best way for private and NHS-run healthcare organisations to prepare for the Bill is to begin implementing stronger security measures and protocols to help minimise the risk and impact of a breach.

Healthcare organisations may wish to consider:

  • Referring to Information Commissioner’s Office (ICO) and NCSC checklists.
  • Auditing third-party providers and supply chains.
  • Implementing two-factor authentication.
  • Building an incident response plan and toolkit.
  • Exploring Cyber Liability Insurance options.
  • Creating an ongoing employee cyber security training programme.

A woman using a computer in a dark room. PC, dark, crime, crime prevention, security, risk, hacker, darkness, internet.


Cyber Liability Insurance for healthcare organisations

As both NHS and private healthcare organisations move away from analogue tools, Cyber Liability Insurance is becoming an essential policy for protecting patient data and financial assets. MIAB’s Cyber Liability Insurance is designed with healthcare organisations and their unique requirements in mind, as non-specialised Cyber Insurance may not provide sufficient protection for your organisation.

When purchasing Cyber Liability Insurance, healthcare organisation directors, owners, and managers should ensure their policy provides cover for patient data breaches, incidents arising from third-party suppliers that impact their business, network failure or system downtime, and regulatory or legal costs.

Not only can a Cyber Liability policy help reimburse financial losses incurred following a cyber incident, but it can also play a proactive role in safeguarding your organisation if your policy provides complementary risk management services.

 

 

Prepare Your Healthcare Organisation for the Anticipated Changes

Receive your no-obligation Cyber Liability Insurance quotation today from one of our specialist healthcare insurance advisers.

Get a Quote

 

Have an enquiry about our Cyber Liability Insurance?

T: 01438 730210

E: info@miab.co.uk

 

 

References

  1. https://www.gov.uk/government/collections/nis-directive-and-nis-regulations-2018
  2. https://www.gov.uk/government/collections/cyber-security-and-resilience-bill
  3. https://www.digitalxraid.com/blog/cyber-security-and-resilience-bill-guide/

 

Related pages