The UK government has tabled late amendments to its Cyber Security and Resilience Bill that would give ministers new powers to block critical-sector organizations from using technology suppliers considered a national security risk, as concern grows over supply-chain vulnerabilities feeding attacks on critical infrastructure.
A Response to a Recent Energy Sector Attack
The government tabled the amendments on August 24, 2026, underscoring what officials describe as an urgent need to give ministers explicit authority to prevent critical infrastructure operators from engaging technology suppliers deemed high risk. The move follows a cyberattack, reportedly linked to a nation-state actor, that took a UK energy generator offline for four days, an incident that industry commentators say sharpened political attention on supply-chain exposure across the country’s critical infrastructure. Once passed, the legislation is expected to be referred to as the Cyber Security and Resilience Act.
Targeting the Supply Chain, With SMEs in the Middle
The Cyber Security and Resilience Bill is designed to give the UK stronger enforcement tools against the weak points that enable supply-chain attacks, extending obligations further down the vendor chain than earlier UK cybersecurity legislation. Security industry commentators have noted that while the bill’s blocking power targets specific high-risk suppliers, the practical burden falls heavily on smaller technology vendors serving critical infrastructure operators, who will need to demonstrate stronger security practices or risk being excluded from the market entirely once the provisions take effect.
Scrutiny Alone Is Not a Complete Fix, Critics Say
Industry reaction has been mixed: while cybersecurity professionals broadly welcomed greater scrutiny of high-risk suppliers, some cautioned that blocking individual vendors cannot substitute for broader supply-chain security improvements across the sector. Commentators pointed to the energy sector incident as evidence that nation-state-linked attacks on critical infrastructure increasingly exploit third-party and supply-chain relationships rather than targeting operators directly, a pattern the new ministerial powers are intended to address but cannot fully eliminate on their own.








