What the UK Cyber Security and Resilience Bill’s New Standard of Proof Means for OT Organisations

   Sep 01, 2026 | Adam Fearn, Senior OT Architect, Radiflow

The UK Cyber Security and Resilience Bill is working its way through Parliament. As currently drafted, it introduces a new standard for how organisations must show they manage the cyber risk in their plants. The new standard asks for ongoing proof rather than reasonable periodic effort.

Most OT-heavy organisations, if asked today, would probably say they manage this well. Perhaps there’s a policy, and there’s been an audit within the last year or two. Someone in engineering may have a risk assessment filed away somewhere. Under the standard that’s applied until now, that’s a reasonable answer.

Under the new standard the Bill introduces, it isn’t enough.

From periodic effort to continuous demonstration

The bar organisations have been held to until now has, in practice, been evidence of intent. This has previously meant the creation of the policy, the point-in-time audit, or having the named risk owner documented somewhere in the structure. Regulators and boards alike have generally treated these as adequate proxies for showing that things are under control.

The standard introduced by the Bill is different in kind, not just degree. It asks for continuous demonstration. Ideally a live, current, defensible picture of the OT environment, kept up to date as the environment changes. A folder of policies and a penetration test report from eighteen months ago will no longer satisfy a regulator asking what’s connected to the network today, what’s changed since the last review, or what the organisation’s risk looks like this quarter.

Why this is a harder standard for OT than for IT

IT environments tend to meet a continuous standard by default. Asset management, patch cadence, and centralised visibility are built into how IT already operates. OT environments generally aren’t built the same way, for structural reasons rather than through any failure of the teams involved.

OT estates accumulate over decades. Equipment gets added during a maintenance window and is never formally logged. A vendor installs machinery with its own embedded remote access that silently slips through the formal approval process. Segmentation designed years ago gets worked around, piece by piece, by engineers solving real operational problems in the moment, with no obligation to record the change. It might sound negligent to someone in IT, but this is a realistic reflection of OT environments where uptime has been the only metric that mattered for years, and cyber visibility was never genuinely part of the brief.

The practical result is that most OT organisations do not have a current, confident answer to the question of what’s on their network right now. No one has been asked to maintain that picture continuously, until now.

What a demonstrable answer actually requires

A defensible response tends to rest on four things.

  1. An asset inventory that reflects the network as it stands today. Continuous or near-continuous visibility will be enough, but a periodic manual exercise generally won’t be.
  2. Risk scoring tied to what an asset actually does operationally (not a generic severity rating). A compromised historian and a compromised safety controller are not the same operational risk, even where a vulnerability scanner would flag them identically.
  3. A structure that maps to a recognised methodology. IEC 62443’s zone and conduit model is the most widely applied in OT, which means a risk rating can be justified against a known, credible framework.
  4. Clear ownership and a defined review cadence. Someone accountable for the risk, and a set process for updating and reviewing i Without this, even a good inventory drifts back into being a snapshot within a few months.
The gap most boards haven’t tested yet

Organisations that already treat OT visibility as a live, ongoing discipline rather than a periodic exercise will find this transition manageable. For the majority that don’t yet, there’s a gap between believing the risk is managed and being able to show it, and that gap is generally wider than leadership teams assume, because nothing has forced them to test it before now.

The Bill isn’t in force yet, and the formal designation process is still concluding. But the direction of travel is clear enough that closing this gap ahead of a regulatory conversation is a considerably stronger position than closing it during one.

Building that continuous, defensible picture, and the ownership and cadence that keep it current, is the everyday work of OT security. It’s the problem Radiflow spends its time helping customers solve, well before a regulator forces the question.

Three questions worth asking to your team

  1. Do we have a current, defensible picture of our OT environment?
  2. Has this actually been seen and understood by the board, rather than held informally by someone in OT or Engineering?
  3. If a regulator asked, could we prove we’re actively and continuously managing the cyber risk in our plant?

The answer to these questions will tell you more about your readiness than any compliance checklist. And it’s a better question to answer in a boardroom now, than in the aftermath of an incident later.

Building OT visibility and cyber risk management capability is the work Radiflow helps manufacturers and critical infrastructure operators do.

Additional Resources

Request Demo Contact Us