A moment of recognition in Parliament
The U.K.’s Cyber Security and Resilience Bill entered a critical stage when members of the House of Lords debated its principles at second reading on 14 July. For ISC2 and the cybersecurity profession, the debate marked an important moment: the organization’s expertise and member feedback were reflected in the House of Lords Library’s official briefing.
The Bill updates the U.K.’s 2018 Network and Information Systems Regulations by expanding cyber regulation, strengthening incident reporting and giving regulators and government new powers to respond to evolving threats. It reflects the U.K.’s dependence on digital infrastructure and the risks facing operators of essential services, managed service providers, data centers and other organizations that underpin everyday life.
During the parliamentary debate, workforce and skills emerged as a central theme, with peers questioning whether the U.K. has the cyber talent, leadership awareness and regulatory capacity to make the regime effective. Those themes align with ISC2’s view that resilience depends on qualified professionals, accountable leaders and clear standards.
The latest ISC2 Cybersecurity Workforce Study found that 52% of U.K. respondents cited skills shortage as the main obstacle to complying with cyber legislation and regulations, underscoring ISC2’s call for a skilled workforce to support the CSR Bill.
ISC2 Member Insight Reflected in the Official Briefing
ISC2’s participation began before the Lords debate. In April, ISC2 partnered with the (former) Department for Science, Innovation and Technology (DSIT) to host a roundtable with U.K. members on the Bill’s implementation and impact. The discussion focused on senior-level competence, regulated entities, enforcement and alignment with other regimes.
That engagement was highlighted when the House of Lords Library included ISC2 feedback in its research briefing for peers ahead of second reading. The briefing stated:
"At a round table discussion, members of ISC2, a cyber security professional association, raised several concerns about the potential effectiveness of the bill. First, they emphasised a need to improve board-level cyber security competence and awareness to ensure the regulations are implemented successfully. Second, they noted that only medium and large RMSPs would be in scope, potentially excluding smaller RSMPs with large impacts. Third, members argued that fines issued under the 2018 NIS regulations were too low and suggested that the new regime should also reward good practice. Finally, they called for regulatory alignment, particularly with the EU’s NIS2 directive, to reduce regulatory duplication."
Why This Representation Matters to ISC2 Members and the Cybersecurity Profession
For ISC2 members, this reference shows cybersecurity professionals’ experience is informing parliamentary understanding of major cyber legislation and whether organizations will have the workforce and skills needed to meet new obligations.
From Compliance to Competence
Board-level awareness is critical. The Bill will place new expectations on organizations that provide or support essential services, but compliance cannot be treated as a narrow technical exercise. Senior leaders must understand cyber risk, resource security programs and ensure qualified cybersecurity professionals have authority to act.
Getting the Scope Right
The Bill’s scope is another critical question. By bringing more digital and third-party service providers into regulation, it recognizes that cyber risk often sits deep in supply chains. ISC2 members’ concern about excluding smaller providers shows cyber risk is not determined solely by company size.
Enforcement, Incentives and Alignment
Enforcement and incentives will shape the Bill’s success. Concern that fines under the 2018 NIS Regulations were too infrequent reflects the need for penalties that drive action. ISC2 also called for the regime to reward good practice and encourage investment in resilience.
Regulatory alignment is equally important. Organizations operating across borders already face complex cyber, privacy and resilience requirements in other jurisdictions. Alignment where appropriate with frameworks such as the EU’s NIS2 Directive can reduce duplication and help professionals focus on security.
A Credible Voice in the Debate
ISC2 was also referenced during the Lords debate, reinforcing its position as a credible voice in U.K. cyber policy. Lord Arbuthnot cited ISC2’s briefing as “very helpful,” and peers raised issues tied to ISC2’s advocacy, including workforce capacity, skilled person definitions, regulator cooperation and public administration.
In fact, 13 of the 24 contributions mentioned workforce and skills. Lords Taylor, Clement-Jones and Arbuthnot specifically called for a definition of a skilled person, which ISC2 advocated for.
What Comes Next for the Cyber Security and Resilience Bill
The Bill will now move to Committee stage, where peers will examine its provisions line by line and table amendments. This next phase presents an opportunity to embed workforce considerations more clearly in implementation.
There will be a public consultation on the Bill later this year, focused on the Bill’s implementation. ISC2 will be submitting a detailed response to the consultation, building on member feedback.
For the U.K., the Bill represents a significant step toward modernizing cyber regulation for an increasingly connected economy. For ISC2, its presence in the House of Lords briefing and debate demonstrates the value of bringing member voices directly into policymaking.
As the Bill continues through Parliament, ISC2 will remain focused on helping policymakers connect ambition with implementation. Stronger cyber resilience will require clear regulation, capable regulators, informed boards and a skilled, trusted workforce. The House of Lords’ recognition of ISC2’s contribution shows the cybersecurity profession’s voice is being heard.
