OpusBUSINESS EXPERT

Your IT provider is about to be regulated. Here is what to ask them

Andy Shepherd5 min read

A bill working through the House of Lords right now will do something that has never been done in the UK: regulate the firms that run other firms' IT. The Cyber Security and Resilience Bill entered committee stage on 1 September, Royal Assent is expected late this year, and when its duties switch on, managed service providers of any size beyond small will be answerable to a regulator for their security.

Your business will not be regulated by it. Your IT provider might be. And there is a useful thing to do about that this month, which is not to read the bill. It is to ask your provider four questions and pay attention to how the answers arrive.

Why the law is aimed at them

An IT provider is a strange kind of supplier. The firm that delivers your stationery can lose its own systems without touching yours. The firm that manages your IT holds administrator access to your network, your mailboxes and your data as a basic condition of doing the job, so a breach of their systems is a breach of everyone's.

The government's fact sheet for the bill cites the May 2024 attack in which hackers reached the Ministry of Defence's payroll through a managed service provider, putting the personal data of around 270,000 serving personnel, reservists and veterans at risk. One provider, one compromise, many victims. That is the pattern the bill exists to break.

So providers in scope will have to register with the Information Commission, put appropriate and proportionate security measures around their own systems, and report significant incidents on a clock:

24 hrs
Initial notification to the regulator
72 hrs
Full incident report

Buried in the same measure is the part that matters most to you as a customer. After that full report, a regulated provider must work out which of its customers were likely affected and tell them. That obligation does not exist today. A provider can currently be breached, clean up quietly, and never mention it; you would learn about it from the consequences.

The exemption that changes the question

Small and micro providers are exempt. The law is aimed at medium and large firms; the one-person IT support company and the four-person outfit on the industrial estate are outside it, and around Knutsford, Warrington and South Manchester, that describes a good share of the firms actually holding the keys to local businesses.

We should declare an interest here, because the exemption describes us too. We are a two-person consultancy. No regulator will ever ask us these questions.

Which is exactly why you should. For a provider outside the regime, your questions are the only scrutiny their security will ever get, and the standard the bill sets for the big firms is a perfectly good measuring stick for the small ones. The risk never depended on headcount: the access did.

The four questions

Send these by email, so the answers arrive in writing.

  1. 01What access do you hold into our systems, and where is it recorded? You want a list: which admin accounts, which remote-access tools, which passwords or keys, and where that list lives
  2. 02If your systems were breached, when and how would we hear from you? The law will oblige regulated providers to notify affected customers. Ask yours to commit to the same in writing, whatever their size
  3. 03What protects the accounts you use to reach us? Multi-factor authentication on every one of them is the floor, and a current Cyber Essentials certificate is reasonable to expect
  4. 04Would the new law apply to you? They should know. A medium or large provider should be preparing now; a small one should be able to say so plainly and point back at their answers to the first three

What a confident answer sounds like is specific and prompt: named tools, a real list, a certificate with a date on it. Nobody security-competent is offended by the request. We answer versions of these for clients and for their larger customers' supplier questionnaires, and the honest experience is that writing the answers down is the work; a provider who has done it once can answer in a day.

A worrying answer is fog. "All covered, nothing to worry about" is not an answer, it is a request to stop asking.

Why now, when the duties are years off

The bill's obligations arrive through secondary legislation after Royal Assent, with consultation first, so the regulator will not knock on anyone's door for a while. The pressure arrives earlier by a different route: supplier questionnaires. If you sell to larger companies, councils or the NHS, their security questions about your suppliers are already getting longer, and your IT provider's answers become your answers when you fill one in.

A provider who can respond to the four questions above without a fortnight's scramble is one who will not cost you a contract when a questionnaire lands. That test is available now, costs one email, and does not need to wait for Parliament. Cyber Essentials got stricter in April, and the same logic applied then: the certificate matters less than the habits it forces.

We run Microsoft 365 estates for our clients, so we are the party these questions get put to, and we would rather they were asked. If you want help reading a provider's answers, or a second opinion on what access into your systems actually exists, ask us. The awkward version of this conversation is the one that happens after an incident.


We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.

If any of this sounds like your business, we will tell you plainly whether we can help.

We would like to use analytics cookies to understand how this site is used, advertising cookies to measure our ads, and to load our office map from Google. None of them loads on its own unless you accept — though Google Tag Manager itself loads either way, with every category switched off. The map also has a button of its own. Read our cookie policy