MSPs and the Cyber Security and Resilience Bill

Published on
September 9, 2026
Read time
5 mins

MSPs and the Cyber Security and Resilience Bill

Published on
September 9, 2026
Read time
5 mins
Category
5 min read

MSPs and the Cyber Security and Resilience Bill

Published on
09 Sep 26

Table of contents

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

The UK's Cyber Security and Resilience Bill would bring medium and large managed service providers into its regulatory scope for the first time. Once the relevant provisions take effect, any MSP that qualifies as a Relevant Managed Service Provider (RMSP) must identify and manage the cyber risks in its own environment, take proportionate measures to prevent incidents and minimize their impact, report significant incidents to the relevant authority, and formally register once the regime takes effect. Noncompliance carries fines running into the tens of millions of pounds. Regulators settled on MSPs for a specific reason: attackers already know that one compromised service desk can open a door into every client network behind it.

What the Cyber Security and Resilience Bill Actually Does

The Cyber Security and Resilience (Network and Information Systems) Bill is the UK government's update to the 2018 NIS Regulations, the law that already governs cyber obligations for sectors like energy, transport, water, and digital infrastructure. It was introduced to the House of Commons on November 12, 2025, passed the House of Commons, and is currently at report stage in the House of Lords, with final stages and Royal Assent expected before the end of 2026 (UK Parliament, 2026). The regime may not be fully implemented until 2028.

The Bill expands the scope of entities and services regulated under NIS in four ways. It brings data centers into scope as essential services. It brings large load controllers into scope, meaning organizations that manage significant flows of electricity to smart appliances and electric vehicle chargers. It gives regulators a new power to designate any supplier, regardless of size, as a critical supplier if that supplier's disruption could cause serious downstream harm. And, most relevant here, it brings medium and large managed service providers into scope for the first time, as a new category called Relevant Managed Service Providers (RMSPs).

Why Managed Service Providers Specifically



MSPs were not swept into this Bill because of one dramatic incident. The government's own stated reasoning for the new rule, set out in debates in Commons and Lords, is based as much on market concentration as on security risk. Large and medium MSPs make up fewer than one in ten of the roughly 11,000 MSPs operating in the UK, yet they account for around 97.6% of the sector's revenue, suggesting a similar concentration of client relationships and network access (Hansard, House of Lords, July 2026). Compromise one of these firms and an attacker gains a foothold across every client that firm serves, a genuine one-to-many problem no individual customer can fix on their own.

Separately, and not cited in the Bill's own debate, the specific tactic behind that risk is well documented by threat researchers elsewhere: attackers impersonating internal IT staff, calling into outsourced service desks, and persuading staff to reset a privileged account’s password.

  • The New York State Department of Financial Services issued an advisory on exactly this tactic in February 2026.
  • Microsoft's incident response team separately traced a November 2025 intrusion to attackers who kept calling support lines, posing as staff, until an employee handed over remote access to their device (NY DFS, 2026; Microsoft, 2025).
  • ConnectWise's 2026 MSP Threat Report, built on real-world incident response data across its own customer base, summed up the shift bluntly. "The defining theme of 2025 was the abuse of trust," said Patrick Beggs, ConnectWise's chief information security officer (ConnectWise, 2026).

Attackers are no longer trying to break in through the front door. They are calling ahead and asking to be let in through the back door.

Which MSPs Are In Scope, and Which Are Not



The Bill defines a RMSP by reference to four cumulative conditions. The service has to be provided to another organization under contract. It has to involve the ongoing management, support, maintenance, monitoring, or administration of that organization's IT systems. It must rely on a connection to, or access to, the customer’s network and information systems. And it must not already be captured separately as a data center or a public electronic communications service.

The size threshold also matters. The obligations fall on medium and large providers only. Small and micro MSPs sit outside the regime by default, on the logic that they represent a small share of total MSP revenue and client reach, though a regulator can still designate a smaller provider as a critical supplier if its disruption would carry outsized consequences for the organizations it serves.

The Five Duties of a Relevant Managed Service Provider (RMSP)

Once in scope, an RMSP takes on a set of duties that mirror duties similar to those that have applied since 2018. Clause 9 of the Bill defines who counts as an RMSP in the first place, and the actual duties are set out across clauses 10, 14, and 15.

The penalties behind these duties carry real financial weight. The Bill introduces a two-tier structure, with fines of up to 10 million pounds or 2% of global turnover for standard breaches, rising to 17 million pounds or 4% for serious ones, plus penalties of up to 100,000 pounds per day for ongoing noncompliance (DigitalXRAID, 2026). These penalties could be financially material for a mid-sized MSP.

The Human Layer Hiding Inside Every MSP Breach

Read the small print of nearly every major MSP-related incident over the past 18 months and the pattern repeats. Technical controls may remain intact while an attacker exploits weaknesses in human verification processes because the attacker was never really trying to beat the technology in the first place.

Verizon's 2026 Data Breach Investigations Report, drawing on more than 22,000 confirmed breaches, found a human element present in 62% of them, a figure that remains high despite continued investment in security awareness. The same report found that breaches involving third-parties increased sharply year over year, now present in close to half of all breaches it analyzed, and that mobile-focused social engineering, the kind used to trick a service desk agent on a phone call, rose by roughly 40%. IBM's 2025 Cost of a Data Breach Report adds the financial angle: breaches that started with a supply-chain or third-party compromise averaged 4.91 million dollars and took the longest of any category to resolve, at 267 days, compared with a global average of 4.44 million dollars and 241 days.

This is not any single company's story. It is a documented pattern. Palo Alto Networks' Unit 42 found that social engineering was the entry point in 36% of the incidents its responders investigated in 2025, and that more than a third of those cases involved social engineering targeting service-desk staff rather than a traditional phishing email (Unit 42, 2025). None of it requires beating a firewall. It requires convincing one person, once, that the caller on the other end of a support line is exactly who they say they are.

For an MSP, every one of these weaknesses multiplies rather than adds. A service desk process that is too trusting is a risk to every client whose account that service desk can touch. A dormant privileged account may create risk across every client environment that the associated credentials can access. That is why the fix cannot live in a single spreadsheet or one client's ticketing system. It requires exactly the kind of consolidated, continuously updated view of human risk, across every account, every client, and every credential an MSP holds, that the new regulatory requirements effectively demand. Call it what it is: human risk intelligence applied at the scale an MSP actually operates at, not the scale of one company at a time.

When Individual Risk Factors Combine Into a Breach



None of these individual weaknesses look dramatic on their own. A service desk without a stronger verification step for privileged resets is a manageable gap. An account without multifactor authentication is a manageable gap. A password that has been sitting in a breach database for months is a manageable gap. The trouble starts when several of these ordinary weaknesses land on the same account at the same time, because each one removes a barrier the others were relying on.

Security teams sometimes call this a toxic combination: a set of individually modest risk factors that, taken together, create a single high-probability path into the network. A dormant account with an old, reused password and standing administrative access is not five separate risks. It is one very short route from a stolen credential to the deployment of ransomware, and it is exactly the kind of route that a compromised service desk reset can open in minutes.

What This Means If You Are an MSP Customer

The Bill does not put every MSP customer into a regulated category, and it would be a stretch to claim otherwise. The duties fall on the MSP itself, not automatically on the businesses it serves. But the secondary effect is real. As larger MSPs are pushed to formalize risk management, register with a regulator, and prove their own resilience, customers are likely to face greater pressure to conduct rigorous supplier due diligence, both because insurers and auditors will expect it and because a customer relying on an unregulated small provider cannot assume that provider is being held to any external standard at all.

Getting Ahead of the Requirement

For an MSP working out where to start, a useful starting point is to recognise that most of what regulators, insurers, and the Bill itself are really asking for is visibility. Not a single new tool, but a genuine, current answer to a small set of questions:

  • who has access to what;  
  • whether that access still needs to exist;
  • whether it is protected the way it should be, and
  • whether the people holding it understand the ways they personally could be targeted.

In practice, that tends to mean a shift away from point-in-time compliance checks and toward continuous, human-focused risk management. Instead of an annual training module that proves attendance, it means tracking whether staff actually recognize and report the kind of impersonation attempt documented across these service desk campaigns. Instead of a one-off access review, it means an ongoing view of dormant accounts, standing privileges, and exposed credentials, correlated together rather than sitting in five different systems that nobody has time to compare by hand. This is, in essence, what a human risk intelligence approach is built for: pulling training records, identity hygiene, dark web exposure, and phishing performance into one place so that a toxic combination shows up as a single alert rather than five disconnected data points nobody happened to cross-reference.

Concretely, that looks like requiring a second verification step for any privileged credential reset that comes in over the phone, regardless of how convincing the caller sounds. It looks like phishing-resistant multifactor authentication on every account with administrative reach, not just the accounts an auditor is likely to check. It looks like monitoring for detecting exposed staff and executive credentials before attackers can exploit them. And it looks like being able to demonstrate to a regulator or insurer, in specific terms, how in specific terms, how human risk across the organization has changed over the past quarter, rather than pointing at a certificate from a training platform and hoping that is enough.

Frequently Asked Questions

Does the Cyber Security and Resilience Bill apply to every MSP?
No. The obligations apply to medium and large managed service providers, defined in the Bill as RMSPs. Small and micro MSPs are generally excluded, unless a regulator separately designates one as a critical supplier because of the organizations it serves.

When will the Bill become law?
As of September 2026, the Bill has cleared the House of Commons and is at report stage in the House of Lords. It must complete its remaining parliamentary stages and receive Royal Assent after which enforcement is expected to be phased in gradually, potentially running through 2028.

What counts as a managed service provider under the Bill?
An organization contracted to manage, support, maintain, monitor, or administer another organization's IT systems on an ongoing basis, where doing so requires an active connection into that customer's network. Data centers and public electronic communications services are covered under separate provisions.

What happens if a Relevant Managed Service Provider does not comply?
The Bill sets out a two-tier penalty structure: up to 10 million pounds or 2% of global turnover for standard breaches, rising to 17 million pounds or 4% for serious ones, plus daily penalties for ongoing noncompliance.

Does this mean MSP customers need to do anything right now?
Not directly, since the legal duties sit with the MSP. In practice, though, customers are likely to see more scrutiny from insurers and auditors, well ahead of the regime formally taking effect.

The Real Test the Bill Is Setting

The Cyber Security and Resilience Bill treats MSPs as what they actually are: a concentrated point of trust that, if compromised, does not fail quietly. Compliance with the new regime will not be achieved merely by adding another annual audit, with an extra audit bolted onto the calendar. It will be won by MSPs that can already answer, in real time and across every client they manage, who holds the keys, whether those keys are still needed, and whether the person holding them is as protected as the systems those keys unlock. That is the real test the Bill is setting, and for an MSP, it is a human risk question before it is ever a technology one. Book a demo to learn how we can help MSPs manage human cyber risk under the proposed regime.

Subscribe to newsletter

BOOK A DEMO

See usecure in action

A 30-minute walkthrough of how to cut human risk across your users, tailored to MSPs and IT teams.

Get a Demo

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

The UK's Cyber Security and Resilience Bill would bring medium and large managed service providers into its regulatory scope for the first time. Once the relevant provisions take effect, any MSP that qualifies as a Relevant Managed Service Provider (RMSP) must identify and manage the cyber risks in its own environment, take proportionate measures to prevent incidents and minimize their impact, report significant incidents to the relevant authority, and formally register once the regime takes effect. Noncompliance carries fines running into the tens of millions of pounds. Regulators settled on MSPs for a specific reason: attackers already know that one compromised service desk can open a door into every client network behind it.

What the Cyber Security and Resilience Bill Actually Does

The Cyber Security and Resilience (Network and Information Systems) Bill is the UK government's update to the 2018 NIS Regulations, the law that already governs cyber obligations for sectors like energy, transport, water, and digital infrastructure. It was introduced to the House of Commons on November 12, 2025, passed the House of Commons, and is currently at report stage in the House of Lords, with final stages and Royal Assent expected before the end of 2026 (UK Parliament, 2026). The regime may not be fully implemented until 2028.

The Bill expands the scope of entities and services regulated under NIS in four ways. It brings data centers into scope as essential services. It brings large load controllers into scope, meaning organizations that manage significant flows of electricity to smart appliances and electric vehicle chargers. It gives regulators a new power to designate any supplier, regardless of size, as a critical supplier if that supplier's disruption could cause serious downstream harm. And, most relevant here, it brings medium and large managed service providers into scope for the first time, as a new category called Relevant Managed Service Providers (RMSPs).

Why Managed Service Providers Specifically



MSPs were not swept into this Bill because of one dramatic incident. The government's own stated reasoning for the new rule, set out in debates in Commons and Lords, is based as much on market concentration as on security risk. Large and medium MSPs make up fewer than one in ten of the roughly 11,000 MSPs operating in the UK, yet they account for around 97.6% of the sector's revenue, suggesting a similar concentration of client relationships and network access (Hansard, House of Lords, July 2026). Compromise one of these firms and an attacker gains a foothold across every client that firm serves, a genuine one-to-many problem no individual customer can fix on their own.

Separately, and not cited in the Bill's own debate, the specific tactic behind that risk is well documented by threat researchers elsewhere: attackers impersonating internal IT staff, calling into outsourced service desks, and persuading staff to reset a privileged account’s password.

  • The New York State Department of Financial Services issued an advisory on exactly this tactic in February 2026.
  • Microsoft's incident response team separately traced a November 2025 intrusion to attackers who kept calling support lines, posing as staff, until an employee handed over remote access to their device (NY DFS, 2026; Microsoft, 2025).
  • ConnectWise's 2026 MSP Threat Report, built on real-world incident response data across its own customer base, summed up the shift bluntly. "The defining theme of 2025 was the abuse of trust," said Patrick Beggs, ConnectWise's chief information security officer (ConnectWise, 2026).

Attackers are no longer trying to break in through the front door. They are calling ahead and asking to be let in through the back door.

Which MSPs Are In Scope, and Which Are Not



The Bill defines a RMSP by reference to four cumulative conditions. The service has to be provided to another organization under contract. It has to involve the ongoing management, support, maintenance, monitoring, or administration of that organization's IT systems. It must rely on a connection to, or access to, the customer’s network and information systems. And it must not already be captured separately as a data center or a public electronic communications service.

The size threshold also matters. The obligations fall on medium and large providers only. Small and micro MSPs sit outside the regime by default, on the logic that they represent a small share of total MSP revenue and client reach, though a regulator can still designate a smaller provider as a critical supplier if its disruption would carry outsized consequences for the organizations it serves.

The Five Duties of a Relevant Managed Service Provider (RMSP)

Once in scope, an RMSP takes on a set of duties that mirror duties similar to those that have applied since 2018. Clause 9 of the Bill defines who counts as an RMSP in the first place, and the actual duties are set out across clauses 10, 14, and 15.

The penalties behind these duties carry real financial weight. The Bill introduces a two-tier structure, with fines of up to 10 million pounds or 2% of global turnover for standard breaches, rising to 17 million pounds or 4% for serious ones, plus penalties of up to 100,000 pounds per day for ongoing noncompliance (DigitalXRAID, 2026). These penalties could be financially material for a mid-sized MSP.

The Human Layer Hiding Inside Every MSP Breach

Read the small print of nearly every major MSP-related incident over the past 18 months and the pattern repeats. Technical controls may remain intact while an attacker exploits weaknesses in human verification processes because the attacker was never really trying to beat the technology in the first place.

Verizon's 2026 Data Breach Investigations Report, drawing on more than 22,000 confirmed breaches, found a human element present in 62% of them, a figure that remains high despite continued investment in security awareness. The same report found that breaches involving third-parties increased sharply year over year, now present in close to half of all breaches it analyzed, and that mobile-focused social engineering, the kind used to trick a service desk agent on a phone call, rose by roughly 40%. IBM's 2025 Cost of a Data Breach Report adds the financial angle: breaches that started with a supply-chain or third-party compromise averaged 4.91 million dollars and took the longest of any category to resolve, at 267 days, compared with a global average of 4.44 million dollars and 241 days.

This is not any single company's story. It is a documented pattern. Palo Alto Networks' Unit 42 found that social engineering was the entry point in 36% of the incidents its responders investigated in 2025, and that more than a third of those cases involved social engineering targeting service-desk staff rather than a traditional phishing email (Unit 42, 2025). None of it requires beating a firewall. It requires convincing one person, once, that the caller on the other end of a support line is exactly who they say they are.

For an MSP, every one of these weaknesses multiplies rather than adds. A service desk process that is too trusting is a risk to every client whose account that service desk can touch. A dormant privileged account may create risk across every client environment that the associated credentials can access. That is why the fix cannot live in a single spreadsheet or one client's ticketing system. It requires exactly the kind of consolidated, continuously updated view of human risk, across every account, every client, and every credential an MSP holds, that the new regulatory requirements effectively demand. Call it what it is: human risk intelligence applied at the scale an MSP actually operates at, not the scale of one company at a time.

When Individual Risk Factors Combine Into a Breach



None of these individual weaknesses look dramatic on their own. A service desk without a stronger verification step for privileged resets is a manageable gap. An account without multifactor authentication is a manageable gap. A password that has been sitting in a breach database for months is a manageable gap. The trouble starts when several of these ordinary weaknesses land on the same account at the same time, because each one removes a barrier the others were relying on.

Security teams sometimes call this a toxic combination: a set of individually modest risk factors that, taken together, create a single high-probability path into the network. A dormant account with an old, reused password and standing administrative access is not five separate risks. It is one very short route from a stolen credential to the deployment of ransomware, and it is exactly the kind of route that a compromised service desk reset can open in minutes.

What This Means If You Are an MSP Customer

The Bill does not put every MSP customer into a regulated category, and it would be a stretch to claim otherwise. The duties fall on the MSP itself, not automatically on the businesses it serves. But the secondary effect is real. As larger MSPs are pushed to formalize risk management, register with a regulator, and prove their own resilience, customers are likely to face greater pressure to conduct rigorous supplier due diligence, both because insurers and auditors will expect it and because a customer relying on an unregulated small provider cannot assume that provider is being held to any external standard at all.

Getting Ahead of the Requirement

For an MSP working out where to start, a useful starting point is to recognise that most of what regulators, insurers, and the Bill itself are really asking for is visibility. Not a single new tool, but a genuine, current answer to a small set of questions:

  • who has access to what;  
  • whether that access still needs to exist;
  • whether it is protected the way it should be, and
  • whether the people holding it understand the ways they personally could be targeted.

In practice, that tends to mean a shift away from point-in-time compliance checks and toward continuous, human-focused risk management. Instead of an annual training module that proves attendance, it means tracking whether staff actually recognize and report the kind of impersonation attempt documented across these service desk campaigns. Instead of a one-off access review, it means an ongoing view of dormant accounts, standing privileges, and exposed credentials, correlated together rather than sitting in five different systems that nobody has time to compare by hand. This is, in essence, what a human risk intelligence approach is built for: pulling training records, identity hygiene, dark web exposure, and phishing performance into one place so that a toxic combination shows up as a single alert rather than five disconnected data points nobody happened to cross-reference.

Concretely, that looks like requiring a second verification step for any privileged credential reset that comes in over the phone, regardless of how convincing the caller sounds. It looks like phishing-resistant multifactor authentication on every account with administrative reach, not just the accounts an auditor is likely to check. It looks like monitoring for detecting exposed staff and executive credentials before attackers can exploit them. And it looks like being able to demonstrate to a regulator or insurer, in specific terms, how in specific terms, how human risk across the organization has changed over the past quarter, rather than pointing at a certificate from a training platform and hoping that is enough.

Frequently Asked Questions

Does the Cyber Security and Resilience Bill apply to every MSP?
No. The obligations apply to medium and large managed service providers, defined in the Bill as RMSPs. Small and micro MSPs are generally excluded, unless a regulator separately designates one as a critical supplier because of the organizations it serves.

When will the Bill become law?
As of September 2026, the Bill has cleared the House of Commons and is at report stage in the House of Lords. It must complete its remaining parliamentary stages and receive Royal Assent after which enforcement is expected to be phased in gradually, potentially running through 2028.

What counts as a managed service provider under the Bill?
An organization contracted to manage, support, maintain, monitor, or administer another organization's IT systems on an ongoing basis, where doing so requires an active connection into that customer's network. Data centers and public electronic communications services are covered under separate provisions.

What happens if a Relevant Managed Service Provider does not comply?
The Bill sets out a two-tier penalty structure: up to 10 million pounds or 2% of global turnover for standard breaches, rising to 17 million pounds or 4% for serious ones, plus daily penalties for ongoing noncompliance.

Does this mean MSP customers need to do anything right now?
Not directly, since the legal duties sit with the MSP. In practice, though, customers are likely to see more scrutiny from insurers and auditors, well ahead of the regime formally taking effect.

The Real Test the Bill Is Setting

The Cyber Security and Resilience Bill treats MSPs as what they actually are: a concentrated point of trust that, if compromised, does not fail quietly. Compliance with the new regime will not be achieved merely by adding another annual audit, with an extra audit bolted onto the calendar. It will be won by MSPs that can already answer, in real time and across every client they manage, who holds the keys, whether those keys are still needed, and whether the person holding them is as protected as the systems those keys unlock. That is the real test the Bill is setting, and for an MSP, it is a human risk question before it is ever a technology one. Book a demo to learn how we can help MSPs manage human cyber risk under the proposed regime.

Subscribe to newsletter

Subscribe to newsletter

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Discover how professional services firms reduce human risk with usecure

See how IT teams in professional services use usecure to protect sensitive client data, maintain compliance, and safeguard reputation — without disrupting billable work.

Related posts

Explore more insights, updates, and resources from usecure.