A New Cyber Law Is About To Land On IT Leaders' Desks

A new UK cyber law is about to pull MSPs and data centres into a strict compliance regime, and the businesses starting the search for security leadership now will be well ahead of the ones scrambling later.

By
Charles Trivett
,
Head of IT Recruitment
of Coburg Banks
LinkedIn Profile
July 29, 2026

Tuesday afternoon, and a client rings me in a bit of a panic.

He runs a managed service provider out of Leeds, forty-odd staff, the kind of business that quietly keeps other people's networks running without anyone outside IT ever thinking about it.

He'd just come off a call with his insurer about renewing cyber cover, and the broker had mentioned, almost in passing, that new UK legislation was about to pull firms exactly like his into a formal regulatory regime.

Fines. Reporting deadlines. The lot.

He wanted to know if I'd heard about it and, more to the point, whether he needed to hire someone to deal with it.

What's actually changing, and why it matters to employers

He was talking about the Cyber Security and Resilience Bill, and yes, I'd heard about it.

It had its second reading in the House of Lords in mid-July and amendments were still being tabled as of late July, so this is very much live legislation rather than settled law.

What it does is expand the old 2018 network and information systems rules to cover a much wider set of organisations, including medium and large managed service providers, data centres above a set size threshold, and what the Bill calls designated critical suppliers, meaning firms whose systems are important enough that disrupting them could seriously damage the wider economy.

And according to techUK's own briefing on the Bill, data centres are being formally brought into scope with thresholds set around 1MW of IT load for commercial sites and 10MW for larger enterprise operators. MSPs offering things like helpdesk, cloud support, or managed security services are now squarely inside the regulatory net too. That's a very different position from where most of these businesses sat a year ago.

Then there's the reporting side, which is where most business owners actually flinch.

Organisations in scope have to notify regulators within 24 hours of an incident that could have a real effect on their systems, then follow up with a full report inside 72 hours.

Miss that, or fall short on the underlying security obligations, and the penalties are not trivial. Serious breaches carry fines of up to £17 million or 4% of worldwide turnover, whichever is larger, and continuing non-compliance can add daily fines of up to £100,000 on top of that.

What does the Cyber Security and Resilience Bill actually change for IT hiring?

It brings a much wider range of businesses, particularly MSPs and larger data centres, under formal cyber regulation for the first time, with strict 24-hour and 72-hour incident reporting duties.

For employers, that turns cybersecurity leadership from a nice-to-have into a role someone has to be formally accountable for, whether that's a CISO, a security-literate IT director, or a senior architect who understands both the technical and compliance sides of the job. My client's business is a textbook example.

Forty staff. No dedicated security lead.

But a managing director who, until that phone call with his broker, honestly had no idea his firm was about to be swept into the same regulatory bracket as businesses five times its size.

Which UK businesses need to act on this first?

Medium and large MSPs, data centre operators above the size thresholds, and anyone supplying critical services to a regulated operator should be looking at this now, not waiting for Royal Assent. Implementation is expected to be phased, but the obligations around governance and incident response will land well before every detail of secondary legislation is finalised.

And hiring a security-capable leader takes months, not weeks, not the other way round. I've had three separate conversations like the Leeds one in the past fortnight, different sectors, different sizes, same underlying question every time. Who's actually going to own this once the Bill lands?

Passing a bill and finding the person to implement it are two completely different problems. The second one is much harder to solve on a deadline, and it's the bit the legal briefings tend to skip over entirely. Right now, more IT leaders are trying to hire cybersecurity manager UK talent than the market can supply. That mismatch gets worse, not better, the closer this legislation gets to enforcement.

Waiting until Royal Assent to start the search is, frankly, leaving it too late.

What tends to happen instead is a scramble. A generalist recruiter gets handed a brief they don't fully understand, three unsuitable CVs come back, and three months later the role is still open while the compliance clock keeps ticking.

We've watched it happen more than once. It's avoidable, and the businesses that avoid it tend to share one habit: they start early. One client, a regional data centre operator, began scoping a head of information security role back in the spring, well before most of their peers had even read the Bill properly. They had someone in post by midsummer. No panic, no compressed timeline, no settling for whoever happened to be available that month.

Same legislation, same deadline, completely different outcome, purely down to when the search started.

Yet the skills gap here isn't evenly spread. Generalist IT managers who've picked up security as one responsibility among several are relatively easy to find.

Properly senior security leaders, people who can sit across the table from a board and explain risk in commercial terms while still understanding the technical detail underneath, are a much smaller pool. So a specialist search tends to earn its keep over a generic job board post, mostly because a recruiter who only works this market already knows who's actually good.

If you're weighing up whether to run this search yourself or bring in outside help, that's a fair question, and I'd rather answer it honestly than sell you on it. Internal HR teams do a solid job with most IT hiring.

Where they tend to struggle is on roles this specific, where the gap between a candidate who sounds right and one who actually understands NIS-style obligations only becomes obvious three months into the job.

But we run this kind of search every week, across MSPs, data centre operators, and firms newly caught by regulation like this one, and we already know which candidates in the market have the compliance literacy this role now demands.

So if your business is going to fall inside the new scope, and you're ready to get ahead of it rather than scramble later, send our IT recruitment team the brief. We'll tell you honestly whether the market can move as fast as you need it to, and if it can't, we'll say that too.

My Leeds client, incidentally, has started the search. Smart move.

Better to be the business with a security lead already in place than the one explaining to a regulator why the seat's still empty.

Coburg Banks IT Recruitment
We help outstanding IT professionals get brilliant jobs in top companies.

Continue reading

Coburg Banks IT Recruitment Agency

The Dangerous Myth of the Rockstar Developer

The "rockstar developer"myth hinders collaboration and team growth. Learn why focusing on balanced, cohesive teams leads to long-term IT success.
Coburg Banks IT Recruitment Agency

Your Best IT Leader Might Be About to Do Paperwork

Why the Cyber Security and Resilience Bill could quietly pull your best IT people off technical work and onto compliance paperwork instead.
Coburg Banks IT Recruitment Agency

What Football Can Teach You About Tech Hiring

Building a tech team is like creating a winning football squad—strategy, role clarity, and teamwork are essential. Learn how football-inspired hiring principles can transform your recruitment success.
Coburg Banks IT Recruitment Agency

10 Factors Behind the Shortage of Skilled IT Professionals

Struggling to find skilled IT professionals? You're not alone. Uncover the causes of the IT talent shortage and learn how to overcome recruitment challenges.
Coburg Banks IT Recruitment Agency

Is Your IT Team Understaffed? Signs You Need More Support

Understaffed IT teams lead to missed deadlines, errors, and high turnover. Discover the signs and solutions to keep your business running smoothly.
Coburg Banks IT Recruitment Agency

Your IT Team Just Got 24 Hours to Make the Right Call

A new bill gives some UK firms just 24 hours to report a serious cyber incident, and most haven't worked out who actually makes that call.
Coburg Banks IT Recruitment Agency

Permanent IT Hiring Is Recovering. Contract Got There First

The data shows why contract IT roles picked up before permanent hires did, and what that gap actually means for you right now.
Coburg Banks IT Recruitment Agency

8 Skills Every Modern IT Team Should Have

Equip your IT team with essential modern IT skills to stay ahead. Discover the top eight capabilities crucial for navigating today’s competitive tech landscape.
Coburg Banks IT Recruitment Agency

There Are Now Two Very Different UK Tech Job Markets

One developer on our books turned down three job offers in a week, because that's the new normal in senior tech hiring right now.
Coburg Banks IT Recruitment Agency

How Our Hiring Tools Make Interviews Easier for You

January 1, 2026
Struggling to manage time-consuming IT interviews effectively? Discover simple strategies to streamline your process and hire top tech talent faster.
Coburg Banks IT Recruitment Agency

Why Our Onboarding Process Helps Clients Hire Faster

December 25, 2025
Struggling to hire IT talent quickly? Discover how a streamlined, specialised process can cut delays, attract top candidates, and keep your projects on track.
Coburg Banks IT Recruitment Agency

Why Our Clients Trust Us With Senior Dev Roles

December 18, 2025
Struggling to hire senior developers? Discover why traditional methods fall short and how tailored IT recruitment can help you secure top talent effortlessly.
Coburg Banks IT Recruitment Agency

Why Our Clients Recommend Us Internally

January 2, 2026
Internal referrals for IT recruiters prove exceptional results and trust. Learn how consistent value and tailored solutions can transform your hiring success.
Coburg Banks IT Recruitment Agency

How We Work With Fast-Growth Tech Teams

December 26, 2025
Struggling to scale your tech team as your business grows? Discover smarter hiring strategies to keep pace with demand and drive success.
Coburg Banks IT Recruitment Agency

What Sets Our Dev Shortlists Apart

December 19, 2025
Struggling with shortlists full of mismatched candidates? Learn how high-quality IT shortlists save time, cut costs, and deliver the perfect fit for your team.
Coburg Banks IT Recruitment Agency

What Makes Our Candidate Briefings So Effective

Unprepared candidates can derail your interviews and hiring process. Learn how effective IT candidate briefing ensures confident, aligned, and successful interviews.
Coburg Banks IT Recruitment Agency

Why Our Clients Recommend Us Internally

Internal referrals for IT recruiters prove exceptional results and trust. Learn how consistent value and tailored solutions can transform your hiring success.
Coburg Banks IT Recruitment Agency

How We Work With Fast-Growth Tech Teams

Struggling to scale your tech team as your business grows? Discover smarter hiring strategies to keep pace with demand and drive success.