top of page

What the Cyber Security and Resilience Bill means for Scottish law firms

  • Writer: Innovec
    Innovec
  • 6 days ago
  • 3 min read

The UK's cyber security rulebook is about to get a significant rewrite, and it's one that will reach further into the supply chain than most businesses realise. As of this summer, the Cyber Security and Resilience (Network and Information Systems) Bill has cleared all its stages in the House of Commons and moved to the House of Lords, putting it on track for Royal Assent later this year.


For law firms, who handle some of the most sensitive client data of any profession, from conveyancing to client funds, this isn't a distant policy debate. It's a change that's likely to arrive through your next contract renewal.


Why the ICO is involved. And how the cyber security resilience bill effects law firms.

The Information Commissioner's Office published its formal response to the Bill in December 2025, broadly welcoming the reforms while flagging areas that still need clarity. The headline change: the ICO's regulatory remit would expand well beyond the digital service providers currently covered under the 2018 NIS Regulations, to bring managed service providers and critical suppliers within digital supply chains into scope for the first time. cyber security resilience bill law firms


That matters for law firms specifically. Most solicitors' practices rely on an outside IT provider for infrastructure, cybersecurity and day-to-day support. Under the new regime, that provider will face direct regulatory obligations, meaning the standard of security your firm operates under is no longer just a matter of your own policy, it's tied to whether your provider is genuinely equipped to meet a statutory bar.


What's actually changing

The Bill shifts the ICO from a largely reactive regulator to one with proactive, risk-based oversight, backed by stronger powers:


  • Wider information-gathering powers, letting the ICO request data from regulated entities and third parties

  • Better information-sharing with other regulators and public bodies

  • New enforcement tools, including penalties for registration failures and cost-recovery powers


According to the House of Commons Library's briefing on the Bill, the Bill had its committee stage in February 2026 and is now progressing through the Lords. Other sources tracking that progress report a tightening of incident reporting timelines too, with an initial notification expected within 24 hours of a significant incident and a full report following at 72 hours. For law firms already bound by strict client confidentiality and professional conduct rules, that's a tight window that needs a provider who can actually deliver on it.


The bit still to be worked out

The ICO has been clear that a lot of the practical detail, what counts as a "significant impact," the specific security requirements, and the criteria for identifying a "critical supplier", will be set out in secondary legislation rather than the Bill itself. That's still to come, and it's worth watching closely rather than waiting for it to land.


Infographic titled Bill passage showing UK bill stages; Commons complete, Lords committee stage in progress, final stages not reached.
Cyber Security and Resilience (Network and Information Systems) Bill 30th July 2026

What this means for you

If your firm's IT is provided or co-managed by a third party (which for most SME-sized practices, it is) this is worth raising with them now, not after Royal Assent. The questions worth asking: does your provider already work to a recognised framework like the NCSC Cyber Assessment Framework, could they meet a 24-hour reporting requirement if something went wrong, and do they understand the specific data sensitivities that come with legal work.


We'll be tracking the secondary legislation as it's published and will share what it means in practice. In the meantime, if you want a straight conversation about where your current setup stands, get in touch.


 
 
 

Comments


bottom of page