
The UK Cyber Security and Resilience Bill is working its way through Parliament. As currently drafted, it introduces a new standard for how organisations must show they manage the cyber risk in their plants. The new standard asks for ongoing proof rather than reasonable periodic effort.
Most OT-heavy organisations, if asked today, would probably say they manage this well. Perhaps there’s a policy, and there’s been an audit within the last year or two. Someone in engineering may have a risk assessment filed away somewhere. Under the standard that’s applied until now, that’s a reasonable answer.
Under the new standard the Bill introduces, it isn’t enough.

The bar organisations have been held to until now has, in practice, been evidence of intent. This has previously meant the creation of the policy, the point-in-time audit, or having the named risk owner documented somewhere in the structure. Regulators and boards alike have generally treated these as adequate proxies for showing that things are under control.
The standard introduced by the Bill is different in kind, not just degree. It asks for continuous demonstration. Ideally a live, current, defensible picture of the OT environment, kept up to date as the environment changes. A folder of policies and a penetration test report from eighteen months ago will no longer satisfy a regulator asking what’s connected to the network today, what’s changed since the last review, or what the organisation’s risk looks like this quarter.
IT environments tend to meet a continuous standard by default. Asset management, patch cadence, and centralised visibility are built into how IT already operates. OT environments generally aren’t built the same way, for structural reasons rather than through any failure of the teams involved.
OT estates accumulate over decades. Equipment gets added during a maintenance window and is never formally logged. A vendor installs machinery with its own embedded remote access that silently slips through the formal approval process. Segmentation designed years ago gets worked around, piece by piece, by engineers solving real operational problems in the moment, with no obligation to record the change. It might sound negligent to someone in IT, but this is a realistic reflection of OT environments where uptime has been the only metric that mattered for years, and cyber visibility was never genuinely part of the brief.
The practical result is that most OT organisations do not have a current, confident answer to the question of what’s on their network right now. No one has been asked to maintain that picture continuously, until now.

A defensible response tends to rest on four things.
Organisations that already treat OT visibility as a live, ongoing discipline rather than a periodic exercise will find this transition manageable. For the majority that don’t yet, there’s a gap between believing the risk is managed and being able to show it, and that gap is generally wider than leadership teams assume, because nothing has forced them to test it before now.
The Bill isn’t in force yet, and the formal designation process is still concluding. But the direction of travel is clear enough that closing this gap ahead of a regulatory conversation is a considerably stronger position than closing it during one.
Building that continuous, defensible picture, and the ownership and cadence that keep it current, is the everyday work of OT security. It’s the problem Radiflow spends its time helping customers solve, well before a regulator forces the question.
Three questions worth asking to your team
The answer to these questions will tell you more about your readiness than any compliance checklist. And it’s a better question to answer in a boardroom now, than in the aftermath of an incident later.
Building OT visibility and cyber risk management capability is the work Radiflow helps manufacturers and critical infrastructure operators do.
What the UK Cyber Security and Resilience Bill’s New Standard of Proof Means for OT Organisations
Fleet-Wide Maritime OT Cybersecurity for a Leading European Dredging Operator
Who Owns OT Cyber Risk Under New UK Bill?