UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

The UK government has taken a significant step towards bolstering its national resilience against cyber threats by proposing amendments to the Cyber Security and Resilience Bill (CSRB). The bill, which is poised to become an Act of Parliament, aims to prevent high-risk technology suppliers from being used by critical infrastructure organizations. This move comes on the heels of a recent cyber attack that forced a small-scale UK energy facility offline for four days.

The proposed amendments are a direct response to the growing concern over supply chain attacks. These types of attacks exploit vulnerabilities in third-party vendors or suppliers, which can have devastating consequences for critical infrastructure organizations. According to Darren Guccione, CEO and co-founder at Keeper Security, “Attackers rarely go through the front door of a well-defended organization. The majority go through a vendor with lighter security, a managed service provider with standing access, or a supplier nobody has audited in years.” Research by Keeper shows that 34% of UK organizations report incidents involving third-party vendors or suppliers.

The CSRB already contains stringent requirements for incident reporting and penalties for failure. However, the proposed amendments take it to a new level by allowing ministers to block critical-sector organizations from using technology suppliers deemed high risk. This approach is being seen as a way to improve the security of critical infrastructure not by demanding better in-house security, but by disconnecting them from third-party suppliers that are considered inadequately secure.

Jamie Akhtar, CEO and co-founder at CyberSmart, notes that many small and medium-sized enterprises (SMEs) may not consider themselves part of the UK’s critical infrastructure, but if they provide technology or services to organizations in critical sectors, their cyber resilience matters greatly. The proposed measures reflect a wider shift towards greater accountability for third-party risk.

The supply chain threat is not new, but it continues to grow in sophistication and impact. The UK’s Cyber Security and Resilience Act will have teeth to force weak points in the supply chain to improve their security. However, the target is the supply chain, but the bullseye is the SME origin of these attacks. As Akhtar concludes, “The message to SMEs serving the UK critical infrastructure is simple: improve your own cybersecurity lest your future profitability be affected by it.”


Source: SecurityWeek — 2026-09-02