UK plans tougher laws to protect public services from cyberattacks
Published by Global Banking and Finance Review
Posted on November 12, 2025
2 min readLast updated: January 21, 2026
Published by Global Banking and Finance Review
Posted on November 12, 2025
2 min readLast updated: January 21, 2026
The UK plans to implement stricter cybersecurity laws to protect public services, requiring companies to meet high security standards and report incidents.
LONDON (Reuters) -Britain plans to strengthen its public services' defences against cyberattacks, requiring companies that provide services to private and public sector organisations such as the National Health Service to meet strict security standards.
In 2024, hackers breached the Ministry of Defence's payroll system and other recent attacks included one that disrupted over 11,000 NHS medical appointments and procedures.
The proposals also follow a series of cyberattacks in recent months that disrupted some of Britain's biggest brands, including Marks & Spencer, the Co-op, and Jaguar Land Rover.
Under the proposed laws, medium and large companies providing services such as IT management, help desk support, and cybersecurity to both private and public sector organisations would be regulated, the government said in a statement on Wednesday .
"Because they hold trusted access across government, critical national infrastructure and business networks, they will need to meet clear security duties," the Department for Science, Innovation and Technology (DSIT) said.
If approved, the proposals would require companies to promptly report significant or potentially significant cyber incidents to both the government and their customers, and to have robust plans in place to manage the consequences.
Regulators would gain new powers to designate critical suppliers to essential services, and there would be tougher penalties for serious breaches, the DSIT said.
The government has also set out plans to ban public sector bodies and operators of critical national infrastructure, including the NHS, local councils and schools, from paying ransom demands to cybercriminals.
(Reporting by Catarina Demony; Editing by Frances Kerry)
Cybersecurity refers to the practice of protecting systems, networks, and programs from digital attacks, which can lead to unauthorized access, data breaches, and damage to systems.
A cybersecurity incident is any event that compromises the confidentiality, integrity, or availability of information, such as data breaches or malware attacks.
Regulatory changes are modifications to laws or guidelines that govern how organizations operate, often aimed at improving compliance, safety, or security.
A ransom payment is money paid to cybercriminals to regain access to data or systems that have been compromised or held hostage.
Explore more articles in the Headlines category



