News and updates from Maple

The Cyber Security and Resilience Bill - what it means if someone else manages your IT image

The Cyber Security and Resilience Bill - what it means if someone else manages your IT

There's a new piece of UK legislation working its way through Parliament that's worth knowing about, even if it hasn't made many headlines outside specialist press. The Cyber Security and Resilience Bill is the biggest update to UK cyber law in almost a decade, and for the first time, it brings managed IT providers directly into scope.

This matters most if you're in a regulated sector already, and it matters more than most people realise if you're a hedge fund, family office or insurer relying on a third party to run your IT. Here's what's actually changing, why it's different for financial services firms specifically, and what's worth asking your provider now rather than waiting for the Bill to pass.

What's actually happening

The Bill updates the UK's existing NIS Regulations, in place since 2018, to reflect a threat landscape that's moved on considerably since they were written. It had its Second Reading in the House of Lords in mid-July, and Royal Assent is expected later this year, with the detailed rules likely phased in over the following couple of years. It won't land overnight, but the direction of travel is clear and worth planning around now.

The headline change for our world: the Bill creates a new regulated category called a Relevant Managed Service Provider. In plain terms, that's a business that manages another business's IT systems on an ongoing basis, exactly what Maple does, and exactly what many of our clients rely on us for. Until now, MSPs sat largely outside formal cyber regulation even though they hold the keys to the systems that matter. This closes that gap.

What the Bill will actually require

Once in force, Relevant Managed Service Providers will need to meet a set of obligations that go well beyond "have some antivirus and a firewall":

  • Mandatory incident reporting: an early warning within 24 hours of a significant incident, and a full report within 72 hours. No more discovering weeks later that your provider had a problem.
  • Formal risk management obligations: documented, ongoing assessment of the risks to the systems being managed, not a one-off exercise.
  • Security by design expectations: providers will need to demonstrate that security is built into how systems are managed, not bolted on afterwards.
  • Regulatory oversight and enforcement: a designated authority will have the power to inspect, request evidence, and issue real financial penalties for serious non-compliance.

Why this lands differently for finance sector clients
If you're an FCA authorised firm, a family office managing significant private wealth, or an insurer, you're not just watching this Bill from a distance. A few things compound for you specifically:

  • You already carry obligations around operational resilience, and outsourcing arrangements under things like the FCA's SYSC rules and, for larger firms, formal outsourcing and operational resilience requirements. A regulated MSP tightens up one link in that chain, but it doesn't remove your own responsibility for it. Your regulator will still expect you to be able to answer for your provider's security, not just point at them.
  • Incident reporting timelines are converging. Your own regulatory reporting obligations, and increasingly your cyber insurance policy wording, often run on similarly tight windows. A provider who can only tell you about a problem after they've quietly fixed it is a genuine gap in your own compliance picture, not just theirs.
  • Due diligence questions from investors, auditors and insurers about your IT arrangements are only going to get more specific. "Do you use a managed IT provider, and are they regulated or independently certified" is becoming a standard line in due diligence questionnaires, not a niche one.

Why this is good news for us, and should be reassuring for you
Everything this Bill will eventually require is already how we operate at Maple, because it's what ISO 27001 and Cyber Essentials Plus already ask of us. Structured risk management, documented incident response, independent third party verification, that's not new territory for us, it's the standard we're already held to and audited against annually.

What we'd suggest if you outsource your IT

  • Ask your provider directly whether they're aware of the Bill and already preparing for it, not whether they've "heard of it"
  • Ask how they currently handle and report security incidents to you, and how quickly, in writing, not as a verbal assurance
  • Ask whether they hold ISO 27001 or Cyber Essentials Plus. If they do, they're likely most of the way to compliance already. If they don't, it's a reasonable moment to ask why not
  • If you're a regulated firm, check that your own outsourcing and third party risk register reflects your IT provider accurately, this is an easy thing for due diligence to catch out

What happens next
The Bill still needs to complete its passage through the Lords and Commons before Royal Assent, and the detailed secondary legislation that will set exact thresholds and timelines typically follows months after. We'll keep tracking it and update this post, and our clients directly, as anything concrete changes. If you want to talk through what this means for your specific setup, that's exactly the kind of conversation worth having before it's mandatory rather than after.