• insights-banner

    In the Press

How retailers should prepare for upcoming cyber legislation

Recent weeks have seen cybersecurity thrown into sharp focus. Continuous cyber-attacks at key times of the year for businesses providing online services disrupts their own business as well as the wider economy.

For tech companies, which are often both targets and service providers to these affected sectors, this evolving threat carries not just operational risk but also growing legal responsibility.

The new Cyber Security and Resilience (CS&R) Bill aims to address this challenge. Announced in the King’s Speech in July 2024 and set for introduction in Parliament later in 2025, it represents a significant strengthening of the UK’s cybersecurity framework.

The Bill’s purpose is to close critical gaps in national cyber defenses, impose new obligations on a broader array of digital infrastructure to protect the wider UK economy, and establish the UK as a global leader in cyber regulation.

Rebecca Steer, Partner in our Commercial team, writes on the Bill for Infosecurity Magazine. She explains that while "we are still awaiting the introduction of the Bill to Parliament, for some in the technology sector, this is more than just another compliance hurdle. It is a legislative reset that directly affects how tech businesses operate their services."

Rebecca then provides a number of key takeaways for tech companies, explaining that "careful preparation and monitoring will be key":

  • Understand your responsibility: Understand which parts of your organization – and which of your vendors – might fall within the Bill’s scope. Even if you fall outside, you may find that obligations are passed down from vendors or customers who’s business does fall within scope of the Bill.
  • Map your exposure: Map what technology infrastructure, processes and software could be an exposure risk to your business.
  • Invest in resilience: The Bill emphasises outcomes, not box-ticking. A robust incident response plan (including insurance cover), regular risk assessments, training staff on key cyber threats and board-level oversight will be essential. Invest in experience professionals and integrate best practice for cyber security throughout all business decision making.
  • Track regulatory guidance and best practice: With the National Cyber Security Centre (NCSC) playing an influential role, align your practices with their evolving recommendations will serve both security and compliance ends.
  • Engage with policymakers: The Bill is still in formation. For companies operating at scale, this is a crucial time to engage constructively and help shape realistic, effective standards and processes.

Read the full article in Infosecurity Magazine here.

Our thinking

  • Key Developments in International Arbitration for 2026

    Dalal Alhouti

    Quick Reads

  • Agricultural policy review 2025: Key changes and what to expect in 2026

    Maddie Dunn

    Insights

  • Leasehold and Freehold Reform Act 2024: Government launches consultation to switch on provisions relating to estate management charges

    Laura Bushaway

    Quick Reads

  • M&A in UK financial services - will mega-deals in 2025 lead to more mid-market activity in 2026?

    Mike Barrington

    Quick Reads

  • A new prospectus regime and other developments impacting UK Equity Capital Markets in 2026

    Andrew Collins

    Insights

  • The Introduction of Aquis Support Services – 19 January 2026

    Emily Dobson

    Insights

  • POATR - What type of securities does the new regime apply to?

    Emily Dobson

    Quick Reads

  • Infosecurity Magazine quotes Mark Bailey on the Cyber Security and Resilience Bill

    Mark Bailey

    In the Press

  • Hannah Catt writes for Tax Adviser on the implications of the newly introduced high value council tax surcharge in the UK

    Hannah Catt

    In the Press

  • eprivateclient quotes Dominic Lawrance on rumours surrounding potential UK government plans to attract HNW investors

    Dominic Lawrance

    In the Press

  • UK Living Sector 2026: Regulatory pressures, new trading platforms and more accessible public markets

    Sarah Wigington

    Insights

  • A Family Lawyer’s guide to five of the top most Googled Family Law questions in England and Wales relating to children

    Hannah Owen

    Quick Reads

  • Drip Pricing and Enforcement: How the DMCC Act is Changing the Rules

    Mark Dewar

    Insights

  • The Standard quotes William Marriott on the impact of the newly introduced 'mansion tax' in the UK

    William Marriott

    In the Press

  • Amenity Space in UK Office Buildings: Why It Matters and What Tenants Need to Consider

    Lynsey Inglis

    Insights

  • UK Hotels Sector 2026: Renovations, AI and Experience‑Led Stays

    James Broadhurst

    Insights

  • Charles Russell Speechlys grows Real Estate team with the appointment of UK and Italian market expert Chiara Del Frate

    Robin Grove MIoL

    News

  • Investment Week quotes Greg Stonefield on whether 2026 will be the year of London IPOs

    Greg Stonefield

    In the Press

  • Compliance Week quotes Abigail Rushton on the UK’s anti-corruption strategy and compliance lessons for companies and advisors

    Abigail Rushton

    In the Press

  • When Saying “No” to Mediation Is Reasonable: Guidance from Grijns v Grijns

    Bella Preece

    Quick Reads

Back to top