MSPs face scrutiny in Cyber Security and Resilience Bill
Renewed emphasis on supply chain security sees the channel called out in UK cyber security bill


The UK government has called out managed services providers (MSPs) as critical to the UK’s cyber defenses in its proposed Cyber Security and Resilience Bill.
A policy statement released on 1 April contains a section dedicated to the role and regulation of MSPs, stating that as they “play a critical role in the UK economy by offering core IT services to businesses” they’re a particularly attractive target for cyber criminals.
It lists two cases where this has already happened, the 2018 Cloud Hopper attack on MSPs and a 2024 attack on the personnel system of the Ministry of Defence (MoD). “These highlight the vulnerabilities of MSPs and by extension, the critical services they support,” the report says.
Therefore, the proposed Bill will bring an estimated 900-1100 MSPs into the scope of the rules laid out in the Network and Information Systems Regulation (NIS) 2018.
The government does acknowledge that MSPs will likely incur additional costs as a result of the regulation; it claims “these investments will position MSPs as trusted and reliable partners in the cyber security landscape”.
Commenting on the contents of the proposed Bill Colette Kitterhing, vice president of Netskope UK and Ireland, said bringing suppliers including MSPs into the scope of this regulation will "doubtless help the country to face down current and future threats through a general upleveling of the entire supply chain of public data”.
Supply chain attacks are a growing threat
Supply chain attacks have been a continuing threat to businesses since the late 2010s, and a common way cyber criminals gain access to organizations’ systems.
Stay up to date with the latest Channel industry news and analysis with our twice-weekly newsletter
In March 2025, researchers at StepSecurity discovered a supply chain attack on GitHub Action put more than 20,000 organizations at risk. Meanwhile, research from SecurityScorecard found almost all of the companies in the UK’s FTSE 100 were exposed to supply chain breaches between March 2023 and March 2024.
When it comes to MSPs in particular, Kaseya’s 2025 State of the MSP Industry report found that 29% of companies in this sector were themselves targeted in a supply chain attack. Similarly, Acronis’ Cyberthreats Report, H2 2024 – published in February 2025 – showed that MSPs were increasingly targeted by malicious actors, including through phishing and supply chain attacks.
“The increase in the sophistication and number of attacks highlights the critical role MSPs play in protecting organizations by offering advanced security measures and incident response strategies,” said Acronis – something it seems the UK government is keenly aware of with this new cyber security legislation.
MORE FROM ITPRO
- MSP security confidence remains high despite facing a torrent of cyber threats
- Elevating compliance standards for MSPs in 2025
- UK Public sector at risk from supply chain attacks, new report warns

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Using DeepSeek at work is like ‘printing out and handing over your confidential information’
News Thinking of using DeepSeek at work? Think again. Cybersecurity experts have warned you're putting your enterprise at huge risk.
-
Can cyber group takedowns last?
ITPro Podcast Threat groups can recover from website takeovers or rebrand for new activity – but each successful sting provides researchers with valuable data
-
LevelBlue and Akamai are teaming up to launch a managed web application and API protection service
News The new Managed WAAP offering aims to help organizations secure their rapidly expanding web app and API ecosystems
-
SonicWall launches new firewalls as part of Generation 8 refresh
News The vendor’s latest update includes unified management and integrated ZTNA, backed by embedded warranty and co-managed services
-
MSPs beware – these two ransomware groups are ramping up attacks and have claimed hundreds of victims
News The Akira and Lynx ransomware groups are focusing on small businesses and MSPs using stolen or purchased admin credentials
-
Cybersecurity complexity and the channel
Industry Insights Channel partners must tackle cybersecurity complexity to drive outcomes and build trust
-
Nearly half of MSPs admit to having a ransomware kitty
News The firm’s annual MSP report highlights the mounting pressure on MSPs as attackers increasingly leverage the latest AI advancements
-
MSPs emerge as key security partners for mid-market enterprises
News The MSP Customer Insight Report reveals 85% of mid-sized organizations now rely on MSPs for security support
-
Pressure mounts on MSPs as enterprises flock to managed cybersecurity services
News Expected to handle security for clients as well as themselves, MSPs feel they're battling on the front line
-
IT management and security in the modern age: Moving away from fragmentation towards seamless success
Sponsored Content Proper endpoint, user, and business management demands a unified approach