UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

A landmark piece of legislation aimed at safeguarding the UK’s critical infrastructure has taken a significant step forward in Parliament. The UK Cyber Security and Resilience Bill (CSRB) has been amended to give ministers powers to block high-risk technology suppliers from serving critical sector organizations, following a recent cyberattack that left a small-scale energy facility offline for four days.

The attack, which was attributed to Iran-linked adversaries, raised concerns about the potential impact of supply chain attacks on critical industry. The government moved swiftly to table amendments to the CSRB, which has already completed all necessary steps through the House of Commons and is now close to receiving Royal Assent. Once passed into law, the Cyber Security and Resilience (Network and Information Systems) Act will give ministers powers to designate high-risk suppliers and prevent critical sector organizations from using their services.

Experts warn that supply chain attacks are becoming increasingly common, with attackers often exploiting vulnerabilities in third-party vendors or suppliers to gain access to well-defended organizations. According to research by Keeper Security, 34% of UK organizations report incidents involving third-party vendors or suppliers. The CSRB’s proposed measures aim to address this issue by targeting the weakest link in the supply chain – small and medium-sized enterprises (SMEs) that provide technology, services, or access to critical sector organizations.

“This Bill makes a critical distinction – that a hacker who can take a hospital offline, or compromise a water supply isn’t an IT problem, they’re a public safety threat,” says Shankar Haridas, UK business head at ManageEngine. The proposed measures are seen as a significant step forward in addressing the growing concern of supply chain security, which is becoming increasingly recognized as a national resilience issue.

The CSRB already contains stringent requirements for incident reporting and penalties for failure, but blocking individual companies takes it to a different level. Experts warn that attackers rarely target well-defended organizations directly, instead exploiting vulnerabilities in third-party suppliers or vendors with standing access.

“The proposed measures are another clear sign that supply chain security is becoming a national resilience issue, as well as a concern for individual businesses,” says Jamie Akhtar, CEO and co-founder at CyberSmart. “Critical infrastructure organizations may have sophisticated security controls of their own, but their defenses can quickly be undermined if attackers are able to exploit a smaller, less well-protected supplier further down the chain.”

In conclusion, the UK’s Cyber Security and Resilience Bill reflects a growing recognition of the importance of supply chain security in protecting critical infrastructure. As Akhtar notes, “The UK’s critical infrastructure is only as resilient as the organizations connected to it, and that means raising the baseline of cybersecurity across the entire supply chain.” SMEs serving the critical infrastructure are advised to take immediate action to improve their own cybersecurity, lest their future profitability be affected by unforeseen consequences.


Source: SecurityWeek — 2026-09-02