UK to ban high-risk tech suppliers from critical infrastructure

Ministers table amendments to the Cyber Security and Resilience Bill after a cyber-attack linked to Iran took a small UK energy generator offline for four days.

The UK government has introduced late amendments to the Cyber Security and Resilience Bill to give ministers new powers to block technology suppliers judged to be high risk from critical infrastructure. The changes were tabled on Aug. 24, 2026, two days after a cyber-attack linked to Iran forced a small energy generator offline for four days. The bill was first introduced to Parliament in November 2025, cleared the House of Commons and is now progressing in the House of Lords as HL Bill 32; once it receives Royal Assent it will become the Cyber Security and Resilience (Network and Information Systems) Act.

The proposed amendments would allow ministers to designate specific suppliers and restrict their use by organisations in regulated critical sectors, regardless of a supplier’s size or industry. The bill already sets strict incident-reporting deadlines and provides for penalties for non-compliance. The new language would give regulators powers to sever or prevent links between critical infrastructure and third parties assessed to present supply-chain risk.

Industry representatives highlighted the supply-chain pathway for many attacks. Darren Guccione, CEO and co-founder of Keeper Security, said the power to designate critical suppliers gained urgency after the recent incident and noted attackers often exploit vendors with weaker security. Shankar Haridas, UK business head at ManageEngine, described attacks that take hospitals or water supplies offline as public safety threats rather than solely IT problems. Jamie Akhtar, CEO and co-founder of CyberSmart, called the measures a recognition that supplier security affects national resilience and urged suppliers to raise their security standards.

Critics warned the designation power could affect small and medium-sized enterprises that provide software, services or access to large infrastructure operators. They said the government will need clear criteria for designations and defined appeal routes to limit unnecessary disruption. Research cited by industry groups indicates 34% of UK organisations reported incidents involving third-party vendors or suppliers, a statistic supporters of the amendments have used to justify stronger supply-chain controls.

Supporters of the amendments say regulators will be able to require weaker links in the supply chain to improve or face the risk of losing access to critical-sector contracts. Opponents emphasise the need for transparent processes and safeguards for businesses affected by any designation. The bill’s amendments set out a framework for how critical infrastructure operators will be required to manage third-party relationships once the legislation becomes law.

Articles by this author