
Cyber Insurance After NIS Reform:
A UK Catalyst for More Cyber Evolution?
The UK’s Cyber Security and Resilience (Network and Information Systems) Bill (the “Cyber Bill”) represents the most significant recalibration of cyber risk regulation since the original Network and Information Systems (NIS) Regulations came into force in 2018.
Originally introduced in the 2024-25 session of Parliament, the Cyber Bill was reintroduced on 14th May and is set to have its third reading about the time this Newsletter will be appearing - on 16th June. It’s very possible it could be enacted as soon as Summer 2026, with certain provisions taking effect on day one or shortly thereafter, and other provisions requiring secondary legislation to come into force. Unlike some bills we have speculated may not make it into law, we are confident this one will, although it remains to be seen if it changes much as it goes through the lawmaking process.
The NIS Regulations apply to operators of essential services (“OES”): energy, water, digital infrastructure, transport, and health. If an organisation meets the criteria the regulations automatically apply with no designation needed.
The Cyber Bill updates and substantially expands the NIS Regulations. While framed as a response to escalating cyber threats and systemic vulnerabilities, the Cyber Bill also serves a more practical function: it creates a clearer, more structured environment in which cyber risk must be managed on an ongoing basis. That, in turn, provides a useful platform for the insurance market to continue developing in step with regulatory expectations.
The proposed reforms are likely to accelerate trends already underway — tighter articulation of risk, more deliberate underwriting, and a gradual expansion in how cyber insurance supports policyholders.
From NIS to “Resilience”: An Expanding Opportunity Set
At first glance, the Cyber Bill looks like a natural evolution of an ageing NIS framework. In reality, it meaningfully broadens both the scope and specificity of the regulations.
The Cyber Bill takes the NIS Regulations further by:
-
Expanding the categories of regulated entities, including data centres, managed service providers (MSPs), and designated “critical suppliers”;
-
Extending obligations through supply chains, recognising the systemic nature of cyber risk;
-
Enhancing regulator powers, including proactive supervision and cost recovery; and
-
Introducing a more comprehensive incident reporting regime.
A notable feature is the number of commercial organisations now brought within scope that would not previously have viewed cyber risk as a regulatory issue. That shift is likely to drive more disciplined risk assessment and, in turn, more informed use of insurance.
Cyber insurance has historically focused on incident-driven loss. The broader regulatory perimeter provides a natural prompt to extend that conversation – not by replacing core cover – incident response will always be key – but by providing opportunities to build around it.
Regulatory Exposure and Insurance: Refining the Fit
The question of how regulatory exposure maps to insurable cyber risk is not at all new. What the Cyber Bill does is bring greater clarity — and, with it, a practical opportunity to refine how that interface is managed.
The Cyber Bill introduces:
-
Ongoing expectations around systems and controls;
-
Wider and more rapid reporting of incidents, embracing ransomware attacks regardless of disruption, and system compromise, not just outages;
-
Much more purposeful cost recovery by regulators for supervision and enforcement; and
-
Stronger sanctions linked to issues such as reporting failures.
As some of the requirements do not have to be linked to cyber incidents, but are ongoing, they will not always sit comfortably within traditional policy structures which as stated above are primarily incident driven. Investigations cover under D&O policies is not typically event driven, so there is a precedent here, although the greater challenge may be to avoid an overlap with D&O (see below). Governance related failure (albeit about cyber risk) may still be deemed more the domain of the D&O policy.
Enforcement will be by the existing UK data privacy regulator, the Information Commissioner’s Office (“ICO”), and all other competent authorities so focus in policies on the ICO alone will not be enough.
The costs recovery for supervision reminds me a bit of the “Fee For Intervention” payable by entities under the Health & Safety (Fees) Regulations 2012 in respect of a written notice of a material breach of health and safety law (without there having been any incident) issued by the Health & Safety Executive – which is routinely covered under CLL policies. So, cover for this kind of thing is already being given by the market.
The fines for non-compliance are going up and will be more flexible, with a “two tier” approach for lesser and greater infringements such as a failure to report. The maximum fine will be GBP17m or 4% of global turnover, whichever is higher, and there will also be daily penalties for ongoing infringement.
Non-criminal fines and penalties (such as these) are frequently covered under cyber policies where insurable. Insurability will depend on the conduct involved with inadvertent mistakes probably being insurable, and deliberate wrongdoing, recklessness or gross negligence being very unlikely to be insurable. Like other cyber related UK legislation, the Cyber Bill currently does not place any prohibition on taking out insurance for such fines.
The main takeaway here is that the insurance market already has the tools to respond given what is already typically covered under Cyber policies. As regulatory expectations settle, it is likely that coverage will continue to adjust incrementally rather than through any step-change redesign.
Incident Reporting: A Point of Coordination
The Cyber Bill’s focus on timely incident reporting is likely to be one of its more operationally significant aspects.
For insureds and insurers, this is less a point of tension and more one of coordination. In particular:
-
Regulatory notification timelines will need to sit alongside policy notification provisions;
-
Early-stage engagement between insureds, insurers and vendors will become more important; and
-
Communication — including with regulators — will increasingly form part of the insured service offering.
Many policies already include PR and crisis management support. There is a clear pathway for those features to be used more deliberately in a regulatory context, particularly where messaging and timing are sensitive. And a failure to report something under the regulations may also give rise to a failure to notify something under the Cyber policy. Could a Cyber policy then cover the consequences of a failure to notify a regulator? Typically, “failure to notify” is already covered but what if this also amounts to a breach of a policy condition? If the failure is inadvertent as opposed to deliberate this will likely make a big difference to the eventual outcome.
In D&O, “self-reporting” related cover has been baked in for years, usually as part of a “Pre-Investigation”. So maybe there’s an opportunity to give affirmative cover for the consequences of notifications under the regulations in Cyber policies.
Supply Chains and Systemic Risk: Familiar Territory, Continuing Evolution
The Cyber Bill’s emphasis on supply chain resilience and expansion of the types of entity that are caught by its provisions reflects a position the market has long recognised: cyber risk is rarely isolated and is often systemic.
Under the Cyber Bill, Managed Service Providers (“MSPs”) and large data centres will automatically be covered by the NIS Regulations as OES’s, without being designated. In addition, the Regulations will apply to “critical suppliers”. A supplier is a “critical supplier” if all of the following apply:
-
It supplies goods/services to an entity already subject to NIS regulations (e.g. NHS, energy operators, major MSPs); and
-
It relies on network and information systems to deliver that service; and
-
A cyber incident affecting it could disrupt essential or digital services (or have wider systemic impact).
And crucially:
-
It must be explicitly designated by the regulator (ie. It is NOT automatically included).
The inclusion of MSPs and the definition of “critical supplier” remind me of the “Contingent Business Interruption” cover in most Cyber policies these days – where the Insured is covered when its business is disrupted due to a cyber incident involving a “critical service provider” which is usually (but not always) an IT-related vendor. We could we see a harmonisation of these definitions to reflect the specifics of this likely new regulatory designation.
Interestingly, a non-UK based entity can be designated a critical service provider if it meets the above criteria. I immediately thought of CrowdStrike and how it occupies a critical link in the IT chain, so its troubles were quickly magnified across the world.
From a wider insurance perspective, systemic exposure has been a central consideration for some time. The response has been gradual but tangible — improved modelling, more deliberate aggregation management, and closer scrutiny of common dependencies. Insurers need to know who the critical service providers are and consider if they are covering them as well as the entities they serve. The recent lengthy debate about the “Cyber War Exclusion” demonstrates how hot this issue is. While people have a legitimate need for the cover, the market still has to be sustainable.
The discussion around potential mechanisms such as a “Cyber Re”–type backstop is part of that broader evolution. Whether or not such solutions materialise in the near term, they point to a market that is actively engaging with the more complex end of the risk spectrum.
At the same time, a wider regulatory perimeter is likely to support increased take-up of cyber cover among organisations that have not historically prioritised it.
Ransomware and Public Policy: Reinforcing The Existing Direction of Travel?
As mentioned above, ransomware incidents will have to be reported sooner, when they occur, and before there is any disruption (see earlier comments on incident reporting).
Whilst the Cyber Bill is silent about the legality of making ransom payments, it sits alongside an increasingly clear UK governmental stance on ransomware, particularly the discouragement of making payments. Where a payment is in breach of a sanction it will be illegal. Bans on payments by public bodies and critical national infrastructure seem to be on their way. For private companies the advice has been: making a payment is not illegal per se but is legally risky in view of the potential application of anti-money laundering and criminal financing laws among other reasons.
So, the future of insurance coverage for ransom payments will continue to remain uncertain: watch this space.
Boards, Governance and the Expanding Role of D&O
Although not primarily aimed at the directors’ liability regime, as mentioned above, the Cyber Bill continues the trend of positioning cyber risk as a governance issue.
That has predictable implications for D&O exposure, particularly in relation to:
-
Oversight of cyber preparedness;
-
Compliance with regulatory obligations; and
-
The adequacy of disclosure and reporting.
For insurers and brokers, this is less about new risk than about clearer articulation — ensuring that the interaction between cyber and D&O cover is properly understood and, where necessary, aligned. Insofar as Cyber is an ongoing governance issue without an incident why wouldn’t the D&O policy respond to investigations and pre-investigations for instance? Of the two policies I think it is the more likely policy to respond as most products are currently drafted, but will Cyber invade that space?
Market Response: Measured Evolution
The cyber market’s response to a changing risk landscape has not simply been a question of appetite or pricing. More interestingly, it has been reflected in the steady evolution of coverage itself. That trend seems likely to continue with the advent of the Cyber Bill.
Policies have become more structured and deliberate in how they address cyber risk, with future developments likely to show further continuation of trends such as:
-
The clearer delineation between first-party, third-party and regulatory-related loss, reducing ambiguity around triggering events and scope of cover;
-
More sophisticated incident response frameworks, with predefined access to legal, forensic and communications support forming an increasingly central part of the insured offering;
-
Targeted extensions and sub-limited covers addressing areas such as non-incident regulatory investigation costs, crisis management and system restoration; and
-
Greater integration of conditions and operational requirements (for example, around incident response planning and security controls), aligning cover more closely with the insured’s risk profile.
Seen in that light, the market has been moving towards a more mature position in which coverage is better defined, more transparent and more closely aligned to how cyber risk actually manifests in practice for the firms facing the threats.
Against that backdrop, the Cyber Bill is likely to reinforce — rather than disrupt — this direction of travel. As regulatory expectations become clearer, there is a natural pathway for further refinement, whether through incremental wording development or more targeted solutions addressing specific regulatory exposures.
Conclusion: A Constructive Step in Market Maturity
The Cyber Bill is best seen as part of the continued maturation of both cyber regulation and the cyber products.
It provides a clearer framework for how organisations should approach cyber risk, while reinforcing trends already visible in underwriting, coverage design and incident response.
For insurance and risk practitioners, the implications are relatively straightforward:
-
greater clarity around risk and incident response;
-
more structured engagement between all the parties to an insurance contract; and
-
the need for continued, incremental development of products and coverage.
Viewed in that light, the Cyber Bill is less a step into the unknown and more a continuation of cyber risk finding its natural level. In short, it is a Bill that will help the insurance market to do what it does best – innovate to meet evolving financial risks. But could we be heading for yet another overlap for Cyber coverage – this time with D&O?
