UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
UK bill amended to block high-risk tech suppliers from critical infrastructure.
Summary
The UK's Cyber Security and Resilience Bill (CSRB) has been amended to grant ministers powers to block high-risk technology suppliers from critical infrastructure. This move comes in response to an incident where an Iran-linked adversary took a UK energy facility offline, highlighting the growing threat of supply chain attacks. The amendments aim to bolster national resilience by ensuring that even smaller suppliers connected to critical sectors meet cybersecurity standards.
Full text
The UK Cyber Security and Resilience Bill (CSRB) has been given late amendments specifically targeting the supply chain threat against the nation’s critical infrastructure. The UK CSRB – not to be confused with the US Cyber Safety Review Board (CSRB) – was introduced to Parliament in November 2025. It has successfully completed all necessary steps through the House of Commons, has moved to the House of Lords (as HL Bill 32) and is now close to receiving Royal Assent. Royal Assent is the point at which the Bill becomes an Act of Parliament and part of UK legislation, where it transitions into the Cyber Security and Resilience (Network and Information Systems) Act. At any time, both a bill and an act can be amended. An example has occurred recently. On August 22, 2026, The Telegraph newspaper reported that Iran-linked adversaries had targeted and forced a small-scale UK energy facility offline for four days. In itself, the attack had no serious effect but did raise questions over the potential effect of wider supply chain attacks on critical industry. The government reacted rapidly, and on August 24, 2026, tabled amendments to the CSRB underscoring an urgent need to give ministers powers to prevent (block) critical-sector organizations from using technology suppliers deemed high risk. “The confirmation that a UK energy generator was taken offline for four days following a cyber-attack, alongside government moves to widen the Cyber Security and Resilience Bill’s supply chain provisions, brings a long running policy debate into sharp focus. The incident involving the energy generator and the purported involvement of a nation state, has clearly sharpened appetite for the bill’s power to designate critical suppliers, regardless of sector or size,” comments Darren Guccione, CEO and co-founder at Keeper Security. “This Bill makes a critical distinction – that a hacker who can take a hospital offline, or compromise a water supply isn’t an IT problem, they’re a public safety threat,” adds Shankar Haridas, UK business head at ManageEngine.Advertisement. Scroll to continue reading. Jamie Akhtar, CEO and co-founder at CyberSmart, explains, “The proposed measures are another clear sign that supply chain security is becoming a national resilience issue, as well as a concern for individual businesses. Critical infrastructure organizations may have sophisticated security controls of their own, but their defenses can quickly be undermined if attackers are able to exploit a smaller, less well-protected supplier further down the chain.” The CSRB already contains stringent requirements, with very strict incident reporting timelines and heavy penalties for failure. Blocking individual companies takes it to a different level. “Attackers rarely go through the front door of a well-defended organization. The majority go through a vendor with lighter security, a managed service provider with standing access, or a supplier nobody has audited in years,” comments Guccione. Keeper’s own research shows that 34% of UK organizations report incidents involving third-party vendors or suppliers. It’s an interesting approach. Improve the security of the critical infrastructure not by demanding it implements better in-house security, but by disconnecting them from the third-party suppliers they consider to be inadequately secure. “Many SMEs won’t necessarily think of themselves as part of the UK’s critical infrastructure,” continues Akhtar, “but if they provide technology, services or access to organizations operating in critical sectors, their cyber resilience matters massively. Attackers understand this and will naturally look for the easiest route into their ultimate target.” He continues, “The Cyber Security and Resilience Bill reflects a wider shift towards greater accountability for third-party risk. Ultimately, the UK’s critical infrastructure is only as resilient as the organizations connected to it, and that means raising the baseline of cybersecurity across the entire supply chain,” concludes Akhtar. The supply chain threat is not new, but it continues to grow. The UK’s Cyber Security and Resilience Act will have teeth to force the weak point origin of supply chain attacks to make greater effort to ensure their own security. The target is the supply chain, but the bullseye is the SME origin. So, the message to SMEs serving the UK critical infrastructure is simple: improve your own cybersecurity lest your future profitability be affected by the UK government when the CSRB becomes the CSRA. Related: Rust Supply Chain Attack Linked to North Korean Hackers Related: Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Related: Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Sevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseThink You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco SaysCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteIran-Linked Hackers Shut Down UK Power Plant for Four DaysEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiNew Phishing Toolkit Uses Passkeys to Maintain Access After Password ResetsSurveillance – Everything You Wanted to Know, But Were Afraid to AskCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW Latest News Rockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsExploit Published for Fresh Cleo Harmony VulnerabilityAnthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsMalicious Virtualizor Update Served via BGP HijackingOpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-DaysChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet DisruptedSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates