APPG hears from parliamentary roundtable on digital sovereignty in the UK

As the UK navigates an increasingly complex geopolitical and technological landscape, questions of digital sovereignty, control over our data, infrastructure and standards have never been more pressing.

Last week, members of the APPG for Cyber Innovation convened a roundtable discussion with industry, academics, and parliamentarians to test working definitions, compare the UK’s position with the EU and other international partners, and identify where policy or governance gaps most need addressing.

The discussion was chaired by Lord Clement-Jones who opened by noting that ‘digital sovereignty’ is a term widely used but without a universal definition, and framed it as the ability of the state to maintain strategic leverage over critical inputs.

The group consensus was that there is no shared UK definition of digital sovereignty. Participants discussed how sovereignty is fundamentally a characteristic of state activity, but the UK by design is deeply enmeshed in a globalised system, making a single coherent definition and policy very hard to reach.  It was discussed how there can be three layers to digital sovereignty: technological sovereignty (owning the technology), operational sovereignty (the ability to switch providers) and governance (a UK-specific trustworthy framework).

Open source software was also discussed, where the case was made that open source’s portability and reliance on open standards make it a natural building block for genuinely sovereign and resilient infrastructure, but only if the UK also owns the institutions around it – others cautioned that ‘open’ governance is not a guarantee of neutrality.

Views diverged on EU policy alignment, after the announcement of the EU’s digital sovereignty package in June, with a spectrum of perspectives from the belief that the UK should align closely with the EU’s emerging sovereignty framework, to avoiding over-alignment with the EU. There was a general consensus that EU alignment matters commercially, since international manufacturers have to build to common standards across both UK and EU markets and there is therefore market demand. However, there was disagreement on the extent to which the UK should align with the EU’s digital sovereignty package.

Sovereignty was seen by many delegates as a potential opportunity for economic growth, with the UK having a real strength in governance, even outside of arguments around EU regulatory alignment, with some critical of the tendency to discuss sovereignty only in defensive and resilience terms. 

Finally, it was found that no single government department owns the issue. With that in mind, the APPG heard how greater consistency across government departments, potentially through a formalised digital sovereignty strategy/framework, would be beneficial. This is important especially now as the Department of Science, Innovation and Technology’s functions are shared across government. 

Lord Clement-Jones, said:
“It was great to hear such a wide range of perspectives on digital sovereignty from industry, academia and think tanks alike. One consensus reached in the room was the need for greater consistency and coherence in the UK’s approach to sovereignty across government departments, whether that takes form as a dedicated digital sovereignty strategy or simply more comprehensive guidance from the government. There is also the broader conversation about where the UK should, and shouldn’t, align with existing frameworks from our international partners, particularly those emerging from the EU. But perhaps most encouragingly was the recognition that digital sovereignty isn’t purely a risk to be managed, but rather a potential future growth sector for UK tech in its own right.” 

Committee Stage Insights on the Cyber Security and Resilience Bill

17 February 2026

The committee stage hearings on the Cyber Security and Resilience Bill have brought together voices across from the industry, including regulators, public bodies and academia, to scrutinise the government’s flagship cyber resilience legislation and expand on the existing framework of the Network and Information Systems (NIS) regulations. 

Although there seems to be a general consensus that the Cyber Security and Resilience Bill acts as a positive step to strengthen resilience in some of the UK’s more vulnerable sectors, the committee stage hearings saw a number of critiques raised against the current version of the Bill.

There was notable tension between the Government’s push for regulatory agility against systemic threats and industry demands for definitional clarity and legal certainty. The Bill dramatically expands the NIS regulatory perimeter to encompass data centres, large load controllers, and Managed Service Providers (MSPs), introducing powers to designate critical suppliers based on a cumulative five-step test. 

One central issue lies in the government’s reliance on secondary legislation to define key thresholds, argued as necessary to keep pace with threats like AI, but which critics fear creates a disproportionate, costly, and legally ambiguous compliance burden, especially for small and medium-sized enterprises (SMEs).

Other key takeaways from the committee stage include:

The Bill Committee will now digest the evidence presented to them and produce a report scheduled to be published on 3rd March, that will outline recommendations and amendments for the Bill prior to its third reading in the House of Commons.

If you have any questions about the Cyber Security and Resilience Bill, committee stage scrutiny, or how this new legislation may affect your business, please get in touch at secretariat@cb-network.org.

Cybersecurity Business Network submits evidence on Cyber Security and Resilience Bill

2 February 2026

Image credit: House of Commons

The Cybersecurity Business Network (CBN) has submitted written evidence to the Public Bill Committee on the Cyber Security and Resilience (Network and Information Systems) Bill, welcoming the Government’s ambition to strengthen the UK’s cyber resilience while recommending them to go further in several key areas.

Our written evidence has been developed through close engagement with our members and additional voices from across the cyber sector, from startups to established multinational providers, working to shape the policy to support a more secure and resilient digital economy.

Calling for a broader approach

CBN backs the Bill’s wider overall objectives, including expanding the scope of the NIS Regulations to reflect modern digital infrastructure, enhancing regulators’ powers to implement and enforce cyber resilience requirements and allowing the Secretary of State to update regulations via secondary legislation.

However, CBN warns that the Bill, as drafted, risks falling short of its potential impact if several issues are not addressed.

1. Expanding the scope to reflect real economic risk

CBN argues that the Bill’s scope remains too narrow, potentially leaving out major parts of the economy whose operations are critical to everyday life and national prosperity.

Our position calls for the adoption of a risk-based approach to determining which organisations fall in scope, based on factors such as:

This should include key sectors like retail, manufacturing and financial services.

2. Aligning with existing resilience standards

Many organisations already rely on established frameworks and accreditations, such as the NCSC’s Cyber Essentials scheme, ISO 27001, and other international frameworks.

CBN recommends that the Bill explicitly reference and leverage an existing resilience standard, both to:

This would also help avoid regulatory duplication, particularly where organisations are already subject to other regimes.

3. Making reporting requirements proportionate and practical

The current ‘one‑size‑fits‑all’ reporting model risks over‑burdening SMEs, especially those dealing with limited resources or major system outages during an incident.

CBN calls for:

4. Encouraging board‑level accountability

Finally, there is a need to move cyber resilience from being seen as a purely IT issue to a core element of enterprise risk management.

CBN recommends:

You can read CBN’s full written evidence to the Public Bill Committee below for a detailed breakdown of our recommendations and rationale.

Written Evidence for Public Bill Committee – Cyber Security and Resilience Bill from Cybersecurity Business NetworkDownload

If you have any questions around the Cyber Security and Resilience Bill, or are interested in our work and would like to get involved, please email secretariat@cb-network.org.

Security minister Dan Jarvis doubles-down on government vision for UK’s cyber resilience and security at Parliament & Cyber conference

London, UK – 25th November 2025: The future plans surrounding UK cybersecurity resilience took centre stage yesterday at the inaugural Parliament & Cyber Conference 2025, hosted by the Cybersecurity Business Network (CBN), a UK coalition of cybersecurity organisations. This conference comes at a critical time as the risk landscape is worsening across the UK and just days after the announcement of the Cyber Security and Resilience (CSR) Bill that will bring data centres and Managed Service Providers into the scope of existing cyber regulations.

Keynote speaker and Security Minister, Home Office & Cabinet Office, Dan Jarvis MP, set the tone for the day by highlighting the government’s all-of-society approach to strengthening our national cyber resilience:

“Parliament and tech are now becoming inseparable. The pace of change is only accelerating and the speed in which new technology is introduced and adopted is becoming shorter and shorter.

“Technology enhances everything we do. It keeps our democracy transparent, it keeps our businesses successful, it keeps people connected and safe. 

“But this interconnection between technology and society can be exploited by those who seek to cause us harm. 

“Many of you in this room lead by example. I hope that, through Government support and their own initiative, that the rest of our business leaders follow in your footsteps.”

The conference hosted by Matt Warman, Chair of CBN and former UK Minister for Digital and Broadband brought together over 150 leaders from government, industry, and academia and some insightful panel discussions. The speakers include Jonathon Ellison OBE, Director of National Resilience for the National Cyber Security Centre (NCSC); Shona Lester, Head of the Cyber Security and Resilience Bill Team at DSIT; Daniel Aldridge MP, Chair of the APPG for Cyber Innovation; Alison Griffiths MP, Chris Francis, Director Government Relations at SAP, Zeki Turedi, Field CTO, Europe at Crowdstrike amongst others.

The panel discussion on the CSR Bill highlighted that there is no single solution for cyber resilience. Instead, panellists stressed that building maturity and a multi-layered approach across organisations is essential to reducing risk at scale. Outdated practices among many businesses, such as neglecting software updates, are no longer acceptable, underscoring the need for clear, harmonised legislation to push organisations to a place of protection. 

“The Cyber Security and Resilience Bill is an important step in fortifying the UK’s cyber defences in today’s evolving and complex cyber landscape. However, it’s crucial to work closely with industry, academia, and the public sector to ensure organisations build the agility and resilience they need to withstand and recover from attacks” explained the Director for Cyber Security and Digital Identity at DSIT.

“The Cyber Security and Resilience Bill’s stricter incident reporting requirements, now set at 24 hours, and the broadening of reportable incidents, are positive steps towards public transparency. However, it will be vital to consult widely with industry, especially around definitions and future regulatory direction” said Matt Warman, Chair of CBN. 

As quantum and AI threats emerge, the second panel discussion emphasised the urgent need to improve cyber awareness and education at every level. Many individuals and businesses remain unprepared for these evolving risks, and current initiatives are falling behind. Increasing investment in cyber education and skills, ensuring everyone understands their role in resilience, should be a top priority for both government and industry, to keep the UK at the forefront of global security.”CBN is committed to championing the vital role of the UK’s cyber sector by providing an important conduit for the industry to collaborate with policymakers to strengthen economic growth, innovation and public trust in this flourishing sector. Today’s conference showcased the power of bringing together expertise from across the ecosystem. As we look to 2026 and beyond, the UK must stay ahead of the curve, ensuring our policy, investment, and innovation strategies keep pace with the evolving threat landscape.” Matt added.


Former Minister for Digital and Broadband Matt Warman announced as Chair of Cybersecurity Business Network

This appointment signifies ambitious growth, impact and value of the network as it seeks to create a platform for collaboration across UK cyber

This appointment signifies ambitious growth, impact and value of the network as it seeks to create a platform for collaboration across UK cyber

The Cybersecurity Business Network (CBN), is delighted to announce the appointment of former UK Minister for Digital and Broadband, Matt Warman, as Chair of the CBN. Matt’s appointment comes at a critical time for the UK’s cybersecurity sector, as recent high-profile cyberattacks across sectors have underscored the urgent need for enhanced industry collaboration, resilience and the right regulatory approach.

As Chair, Matt will spearhead the continued growth of the network, engaging various stakeholders from the private and public sectors, and championing the UK cyber sector as CBN aims to become a single unifying voice for UK based cyber organisations.

I am delighted to be joining the Cybersecurity Business Network as Chair. The UK’s dynamic and innovative cybersecurity industry is in need of a strong voice as it becomes an increasingly important sector both for economic growth and strengthening resilience…

As we have seen in recent months, malicious cyber attacks and geopolitical threats have presented UK businesses and consumers with a clear warning about how destructive cyber attacks can be, and we need to stay ahead of the curve. CBN is leading the industry collaboration by linking government, industry, and the media to strengthen defences and promote growth.

Matt Warman, Chair of CBN and Former Minster for Digital & Broadband

During his tenure as Minister for Digital, Matt developed the Government Cyber Security Strategy alongside the NCSC to improve cyber resilience in the public sector. He stimulated growth of the UK’s cyber sector with a 21% increase in start-up and scale up UK organisations, created an environment that enabled approx £2.6 billion of public and private investment to strengthen resilience and lay the foundation for the UK to become a leading global cyber innovator. Prior to government, Matt was a renowned technology journalist and worked as the Technology Editor for the Daily Telegraph.

Since the start of 2025, CBN has grown its presence in the UK cybersecurity landscape by expanding its membership and strengthening its partnerships. A key milestone was helping to establish the All Party Parliamentary Group (APPG) for Cyber Innovation (CBN runs the Secretariat) alongside parliamentarians, including Dan Aldridge MP, which has enabled a forum for MPs to connect with industry on cybersecurity’s most critical challenges. This announcement comes on the back of the latest report by the APPG for Cyber Innovation which explored and provided feedback on the development of the UK’s first ever dedicated Cyber Security and Resilience (CSR) Bill expected later this year.

“We’re very pleased to welcome Matt as our new Chair. His leadership comes at a crucial time for our organisation as we continue to grow and work to ensure the cybersecurity sector is properly represented. The recent high-profile cyber-attacks are a stark reminder of the need for a strong and unified cybersecurity industry – not only for protecting people and businesses, but also for supporting the UK’s economy and overall resilience. With Matt at the helm, we’re looking forward to championing the sector’s value, driving innovation, and helping to secure both economic growth and public confidence.

Nick Lansman, Founder of CBN

In addition to acting as a spokesman for CBN, he will also play a central role at the network’s events, chairing and supporting members as CBN looks to bring together industry, politics and media to drive collaborative and productive outcomes.

“As Chair, I will look to build on the initial success of the network, helping its growth, unifying our member community and championing our cyber security sector, enabling greater growth and public confidence. As part of this, I am most looking forward to hosting our inaugural Parliament & Cyber Conference in November, which will be a landmark event for the sector and Government as we collaborate on the path to growth and resilience.”

Matt Warman, Chair of CBN

Discover new opportunities by becoming a member of CBN today!

Through proactive engagement, deep collaboration, and expert consultation, we convene leaders from across the cybersecurity industry.

Media contacts:

For any media queries, please contact secretariat@cb-network.org

APPG for Cyber Innovation publishes feedback on the CSR Bill

The Cyber Innovation APPG publishes feedback on the upcoming Cyber Security & Resilience Bill. In this document, the All-Party Group provides an initial view on the upcoming Cyber Security and Resilience (CSR) Bill. It has been informed through a survey with 89 respondents from across the cyber sector and beyond, as well as input from a parliamentary roundtable discussion held under the Chatham House rule that brought together 17 representatives from Managed Service Providers (MSPs), cyber companies, academics and other organisations. 

This document is aimed at supporting the development of the CSR Bill, and the Cyber Innovation APPG would be happy to facilitate further engagement between the Department for Science, Innovation and Technology (DSIT), Parliament, and the wider sector. The Bill provides a unique opportunity to improve cyber security and resilience in the UK.

The report collated the feedback from the APPG’s initial call for input and made clear some clear asks – notably the need for the Bill to widen its scope. As the first Act of Parliament to include “cyber” in the title, representing a fundamental step forward in how the UK approaches digital security. However, there is concern that this historic opportunity is too narrowly focused on compliance and prevention and not sufficiently ambitious in tackling some of the wider challenges that the UK faces.

This bill is a historic opportunity to strengthen the UK’s cyber resilience, but we risk falling short if we don’t listen to those on the frontline.

“We’re calling on DSIT to open up the conversation, coordinate across government, to provide a timeline and process for tackling the urgent issues that are deemed out of scope. By future-proofing regulations and giving parliament a clear role in oversight, we can make sure the UK remains secure and competitive in a rapidly changing digital world.”

Dan Aldridge MP, Chair of the APPG for Cyber Innovation

Become a Full Member of the Cybersecurity Business Network

Connect. Collaborate. Shape the Future of Cybersecurity in the UK.

We’re excited to share that CBN’s refreshed Membership Programme is now live – and we’ve already welcomed several new companies into the network.

Our Full Membership offer is open to all UK-based organisations with a vested interest in cybersecurity and provides access to a growing community of like-minded businesses working to promote innovation, share insights, and shape the future of cyber in the UK.

For all those that have previously signed up to our network, we would ask you to fill out the registration form on our website via the link below to remain as full members of the association.

Full Membership
Fee: £750 + VAT per annum

Membership includes:


We’re looking forward to bringing more organisations into the community and continuing to support the growth of the UK’s cyber ecosystem.

For any queries, please contact: secretariat@cb-network.org