General News
Cyber Security and Resilience Bill: What SMEs in Essential-Service Supply Chains Should Do Now
- Nicky Whitson
- 22 September, 2026

The Cyber Security and Resilience Bill has entered committee stage in the House of Lords, but it is not yet law. For smaller businesses, the practical question is not simply whether the bill will apply directly, but whether customers and larger partners will expect stronger cyber controls throughout their supply chains.
What is happening with the bill?
Line-by-line scrutiny began on 1 September 2026, with further amendments scheduled for 3 September. The bill is intended to strengthen cyber security and resilience for organisations providing essential services and to update the way serious incidents are reported.
The final scope and requirements may change as the bill moves through Parliament. Many small transport, courier and service businesses will not automatically fall within its direct scope. Whether an organisation is covered will depend on the final legislation, the sectors included and any relevant thresholds or designations.
That does not make the development irrelevant to smaller firms. A business may support an organisation that is directly regulated, provide a critical service to a larger customer or handle systems and data that customers consider operationally important.
Prepare for questions from customers
Large organisations are increasingly asking suppliers how they manage cyber risk. The questions may cover access controls, backups, incident reporting, staff training and the use of third-party software.
A small business does not need a large compliance department to make useful progress. Start by identifying:
- The systems needed to take orders, schedule work, invoice customers and communicate.
- The people who can access those systems and whether access is still required.
- The suppliers that host email, files, payment services, fleet systems or customer portals.
- The information that would cause harm if it was lost, altered or disclosed.
- The first people to contact if systems become unavailable.
This simple map can show where a business is dependent on one provider, one administrator or one shared password.
Test the response, not just the backup
A backup is valuable only if the business can restore what it needs. Test whether key data can be recovered and whether staff know how to work safely while systems are unavailable.
The incident plan should cover practical decisions such as:
- Who can isolate an account or system.
- How customers and suppliers will be contacted.
- How urgent deliveries or services will be managed if digital systems fail.
- When the insurer, broker, IT provider, legal adviser or law enforcement should be notified.
- How evidence will be preserved for investigation.
Staff should also understand the most likely routes into the business, including phishing, stolen credentials and payment diversion. Controls such as multi-factor authentication, software updates and restricted administrator access remain useful whether or not the bill ultimately applies to the organisation.
Check the cyber policy against the real risk
The National Cyber Security Centre describes cyber insurance as one possible part of a wider approach. It is not a substitute for preventative security measures.
A review should consider whether the policy is designed for the incidents the business could actually face. Questions may include:
- Is business interruption cover available, and are there waiting periods or time limits?
- Does the policy address dependence on a key supplier or platform?
- What support is available for incident response, legal advice and customer notification?
- Are social-engineering or payment-diversion losses treated separately?
- Are regulatory costs covered only where legally insurable?
- What notification requirements apply after a suspected incident?
Ratcliffes’ Cyber Liability Insurance page outlines areas that may be relevant, including breach response, data and website damage, loss of revenue and certain third-party liabilities. The precise protection depends on the policy terms, exclusions, limits and circumstances of the incident.
Use the committee stage as a planning prompt
There is no need to wait for the bill to become law before improving basic cyber resilience. Map the systems that keep the business moving, test recovery, clarify who responds and make sure customer commitments can be explained.
If a major customer has already sent a cyber questionnaire, treat it as a useful indication of the controls and evidence that may be expected commercially.
If you would like to review whether your cyber policy matches your systems, suppliers and contractual responsibilities, contact Ratcliffes on 01242 544544.
Sources
Back to Insights page...