Tuesday afternoon, and a client rings me in a bit of a panic.
He runs a managed service provider out of Leeds, forty-odd staff, the kind of business that quietly keeps other people's networks running without anyone outside IT ever thinking about it. He'd just come off a call with his insurer about renewing cyber cover, and the broker had mentioned, almost in passing, that new UK legislation was about to pull firms exactly like his into a formal regulatory regime. Fines. Reporting deadlines. The lot. He wanted to know if I'd heard about it and, more to the point, whether he needed to hire someone to deal with it.
What's actually changing, and why it matters to employers
He was talking about the Cyber Security and Resilience Bill, and yes, I'd heard about it. It had its second reading in the House of Lords in mid-July and amendments were still being tabled as of late July, so this is very much live legislation rather than settled law. What it does is expand the old 2018 network and information systems rules to cover a much wider set of organisations, including medium and large managed service providers, data centres above a set size threshold, and what the Bill calls designated critical suppliers, meaning firms whose systems are important enough that disrupting them could seriously damage the wider economy. And according to techUK's own briefing on the Bill, data centres are being formally brought into scope with thresholds set around 1MW of IT load for commercial sites and 10MW for larger enterprise operators. MSPs offering things like helpdesk, cloud support, or managed security services are now squarely inside the regulatory net too. That's a very different position from where most of these businesses sat a year ago.
Then there's the reporting side, which is where most business owners actually flinch.
Organisations in scope have to notify regulators within 24 hours of an incident that could have a real effect on their systems, then follow up with a full report inside 72 hours. Miss that, or fall short on the underlying security obligations, and the penalties are not trivial. Serious breaches carry fines of up to £17 million or 4% of worldwide turnover, whichever is larger, and continuing non-compliance can add daily fines of up to £100,000 on top of that.
What does the Cyber Security and Resilience Bill actually change for IT hiring?
It brings a much wider range of businesses, particularly MSPs and larger data centres, under formal cyber regulation for the first time, with strict 24-hour and 72-hour incident reporting duties. For employers, that turns cybersecurity leadership from a nice-to-have into a role someone has to be formally accountable for, whether that's a CISO, a security-literate IT director, or a senior architect who understands both the technical and compliance sides of the job. My client's business is a textbook example. Forty staff. No dedicated security lead. But a managing director who, until that phone call with his broker, honestly had no idea his firm was about to be swept into the same regulatory bracket as businesses five times its size.
Which UK businesses need to act on this first?
Medium and large MSPs, data centre operators above the size thresholds, and anyone supplying critical services to a regulated operator should be looking at this now, not waiting for Royal Assent. Implementation is expected to be phased, but the obligations around governance and incident response will land well before every detail of secondary legislation is finalised.
And hiring a security-capable leader takes months, not weeks, not the other way round. I've had three separate conversations like the Leeds one in the past fortnight, different sectors, different sizes, same underlying question every time. Who's actually going to own this once the Bill lands?
Passing a bill and finding the person to implement it are two completely different problems. The second one is much harder to solve on a deadline, and it's the bit the legal briefings tend to skip over entirely. Right now, more IT leaders are trying to hire cybersecurity manager UK talent than the market can supply. That mismatch gets worse, not better, the closer this legislation gets to enforcement.
Waiting until Royal Assent to start the search is, frankly, leaving it too late.
What tends to happen instead is a scramble. A generalist recruiter gets handed a brief they don't fully understand, three unsuitable CVs come back, and three months later the role is still open while the compliance clock keeps ticking.
We've watched it happen more than once. It's avoidable, and the businesses that avoid it tend to share one habit: they start early. One client, a regional data centre operator, began scoping a head of information security role back in the spring, well before most of their peers had even read the Bill properly. They had someone in post by midsummer. No panic, no compressed timeline, no settling for whoever happened to be available that month.
Same legislation, same deadline, completely different outcome, purely down to when the search started.
Yet the skills gap here isn't evenly spread. Generalist IT managers who've picked up security as one responsibility among several are relatively easy to find. Properly senior security leaders, people who can sit across the table from a board and explain risk in commercial terms while still understanding the technical detail underneath, are a much smaller pool. So a specialist search tends to earn its keep over a generic job board post, mostly because a recruiter who only works this market already knows who's actually good. If you're weighing up whether to run this search yourself or bring in outside help, that's a fair question, and I'd rather answer it honestly than sell you on it. Internal HR teams do a solid job with most IT hiring. Where they tend to struggle is on roles this specific, where the gap between a candidate who sounds right and one who actually understands NIS-style obligations only becomes obvious three months into the job.
But we run this kind of search every week, across MSPs, data centre operators, and firms newly caught by regulation like this one, and we already know which candidates in the market have the compliance literacy this role now demands. So if your business is going to fall inside the new scope, and you're ready to get ahead of it rather than scramble later, send our IT recruitment team the brief. We'll tell you honestly whether the market can move as fast as you need it to, and if it can't, we'll say that too.
My Leeds client, incidentally, has started the search. Smart move.
Better to be the business with a security lead already in place than the one explaining to a regulator why the seat's still empty.















