• insights-banner

    In the Press

How retailers should prepare for upcoming cyber legislation

min read

Recent weeks have seen cybersecurity thrown into sharp focus. Continuous cyber-attacks at key times of the year for businesses providing online services disrupts their own business as well as the wider economy.

For tech companies, which are often both targets and service providers to these affected sectors, this evolving threat carries not just operational risk but also growing legal responsibility.

The new Cyber Security and Resilience (CS&R) Bill aims to address this challenge. Announced in the King’s Speech in July 2024 and set for introduction in Parliament later in 2025, it represents a significant strengthening of the UK’s cybersecurity framework.

The Bill’s purpose is to close critical gaps in national cyber defenses, impose new obligations on a broader array of digital infrastructure to protect the wider UK economy, and establish the UK as a global leader in cyber regulation.

Rebecca Steer, Partner in our Commercial team, writes on the Bill for Infosecurity Magazine. She explains that while "we are still awaiting the introduction of the Bill to Parliament, for some in the technology sector, this is more than just another compliance hurdle. It is a legislative reset that directly affects how tech businesses operate their services."

Rebecca then provides a number of key takeaways for tech companies, explaining that "careful preparation and monitoring will be key":

  • Understand your responsibility: Understand which parts of your organization – and which of your vendors – might fall within the Bill’s scope. Even if you fall outside, you may find that obligations are passed down from vendors or customers who’s business does fall within scope of the Bill.
  • Map your exposure: Map what technology infrastructure, processes and software could be an exposure risk to your business.
  • Invest in resilience: The Bill emphasises outcomes, not box-ticking. A robust incident response plan (including insurance cover), regular risk assessments, training staff on key cyber threats and board-level oversight will be essential. Invest in experience professionals and integrate best practice for cyber security throughout all business decision making.
  • Track regulatory guidance and best practice: With the National Cyber Security Centre (NCSC) playing an influential role, align your practices with their evolving recommendations will serve both security and compliance ends.
  • Engage with policymakers: The Bill is still in formation. For companies operating at scale, this is a crucial time to engage constructively and help shape realistic, effective standards and processes.

Read the full article in Infosecurity Magazine here.

Our thinking

  • IBA Annual Conference 2026

    Jean-Baptiste Beauvoir-Planson

    Events

  • Surveyors' Refresher Seminar

    Hope Barton

    Events

    min read
  • Building Safety Update Seminar

    David Savage

    Events

    min read
  • Why the UK-India Trade Deal Matters for Private Capital

    Kim Lalli

    Quick Reads

    min read
  • What Wadworth Tells Us About the Next Phase of PISCES

    Greg Stonefield

    Insights

    min read
  • Supply chain social audits: what they are, their limitations, and why they matter for human rights due diligence

    Kerry Stares

    Insights

    min read
  • Building Safety Levy: What Do the Proposed 2026 Amendments Mean?

    Mark Barley

    Insights

    min read
  • Autumn Budget 2026: possible CGT changes and pre-budget planning

    Julia Cox

    Insights

    min read
  • Family team successfully represent high-profile businessman in High Court jurisdiction dispute case

    Matt Foster

    Quick Reads

    min read
  • Can you terminate an “indefinite” trade mark licence even if there’s no express right to do so?

    Isabella Ross-Skinner

    Insights

    min read
  • Shaping the Future of AIM: What the New AIM Rules Mean for Growth Companies, Founders and Advisers

    Paul Arathoon

    Insights

    min read
  • Charles Russell Speechlys named a ‘Firm to Watch’ by India Business Law Journal

    News

    min read
  • Kerry Stares, Rory Partridge, and Lyla Gilbert write in Packaging Europe about landmark reforms on packaging sustainability regulations in the UK and Europe

    Kerry Stares

    In the Press

    min read
  • Rebecca Morjaria and Steven Carey write in Building about liability for defective construction products

    Rebecca Morjaria

    In the Press

    min read
  • Arbitrating Construction Disputes – Comparing the ICC, LCIA, SIAC and SCCA Rules

    Christopher O'Brien

    Insights

    min read
  • Simon Ridpath discusses Charles Russell Speechlys' strategic US expansion with Legal Business

    In the Press

    min read
  • What last week’s Bank of England decision means for private capital stakeholders

    Philip Withey

    Insights

    min read
  • Corporate Deal Highlights - A spotlight on H1 2026

    Sarah Wigington

    Insights

    min read
  • Anna Sowerby writes in City AM about the implications for sponsorship agreements when sporting events are cancelled

    Anna Sowerby

    In the Press

    min read
  • European Supervisory Authorities publish first Joint Report on Major ICT incidents under DORA: Key lessons and practical recommendations for ICT contracting

    Courtney Benard

    Quick Reads

    min read
Back to top