Zero Day Room
Live
Vulnerabilities

UK Cybersecurity Bill Gains Supplier Blocking Powers

Amendments to the UK's Cyber Security and Resilience Bill grant ministers new powers to prevent critical infrastructure organizations from using technology suppliers considered a security risk.

Amendments to the UK's Cyber Security and Resilience Bill grant ministers new powers to prevent critical infrastructure...

The UK government has amended pending cybersecurity legislation to give ministers the power to block critical infrastructure operators from using high-risk technology suppliers. This move follows a reported cyber-attack in August 2026 that took a small UK energy generator offline for four days, an incident The Telegraph newspaper linked to Iran-aligned actors.

Amendments Target Supply Chain Weakness

The changes were tabled on August 24, 2026, as amendments to the Cyber Security and Resilience Bill (CSRB). The bill, introduced in November 2025, is nearing final approval, having moved to the House of Lords as HL Bill 32 and being close to receiving Royal Assent. The amendments specifically aim to widen the bill's provisions to address supply chain threats. They underscore an urgent need for ministerial authority to prevent critical-sector organizations from contracting with suppliers considered a security risk.

Darren Guccione, CEO of Keeper Security, commented that the confirmation of the attack and the government's moves bring a long-running policy debate into sharp focus.

Shifting Accountability to Third Parties

The approach marks a strategic shift. Instead of solely demanding better internal security from large critical infrastructure entities, the legislation seeks to disconnect them from less secure third-party suppliers. Jamie Akhtar, CEO of CyberSmart, explained that critical infrastructure organizations may have sophisticated security controls, but their defenses can be undermined if attackers exploit a smaller, less well-protected supplier further down the chain.

Guccione highlighted that attackers rarely go through the front door of a well-defended organization. Keeper's own research indicates 34% of UK organizations have reported incidents involving third-party vendors or suppliers.

Implications for Small and Medium Enterprises

The new focus places significant responsibility on small and medium-sized enterprises (SMEs) within supply chains. Akhtar noted that many SMEs won't necessarily think of themselves as part of the UK's critical infrastructure, but if they provide technology, services or access to organizations operating in critical sectors, their cyber resilience matters massively.

Shankar Haridas of ManageEngine framed the stakes in stark terms, stating that the bill makes a critical distinction that a hacker who can take a hospital offline, or compromise a water supply isn't an IT problem, but a public safety threat.

The bill already carries stringent incident reporting requirements and heavy penalties for non-compliance. The new blocking powers take its potential impact to a different level. The ultimate message to SMEs serving critical infrastructure is to improve their cybersecurity or risk having their contracts blocked by the government once the bill becomes law.

Related coverage

More from Vulnerabilities