Who Owns OT Cyber Risk Under New UK Bill?

   Aug 17, 2026 | Adam Fearn, Senior OT Architect, Radiflow

What the UK Cyber Security and Resilience Bill Changes for Boards

The UK Cyber Security and Resilience Bill is working through its final parliamentary stages, and most of the attention has focused on incident reporting timelines, penalty structures, and which sectors fall into scope. Those are important questions, particularly for organisations that rely heavily on operational technology.

Someone in your organisation is about to become accountable for OT cyber risk in a way they probably aren’t today. The question is whether your leadership team has worked out who that is.

What the Bill does and doesn’t do on accountability

As currently drafted, the Bill doesn’t name a person. It doesn’t create direct individual liability for senior managers or directors in the way that NIS2’s equivalent provisions do in some EU member states. The obligations sit at the organisational level. It’s the organisation itself that bears the statutory duty and the financial exposure.

But that distinction matters less than it might appear. The penalty structure goes up to £10 million or 2% of global turnover at the standard level, rising to £17 million or 4% for more serious breaches. This means that OT cyber security can no longer credibly be treated as a departmental concern. At those numbers, it belongs on a board agenda, with named ownership and active oversight.

And there is a separate accountability mechanism that already exists, entirely independent of the Bill itself. Under the UK Companies Act 2006, directors have a fiduciary duty to act with care and in good faith. Neglecting a known, material risk (which OT cyber risk increasingly is) can constitute a breach of that duty, creating personal liability exposure through company law even without a specific Bill provision naming individuals. The Bill doesn’t need to name a person. The existing legal framework already can.

Who the Bill applies to

The Bill organises obligations around three categories of organisation. Understanding which one you are (or whether you’re more than one) is the starting point for working out what’s expected of you.

Operators of Essential ServicesThe organisation whose operational environment needs protecting
Manufacturers, water companies, energy producers, and port operators whose plant or infrastructure is the thing being protected. This is the organisation the Bill is primarily aimed at. Large-scale industrial operators, utilities, grid operators, and port authorities across the sectors most critical to how the country functions. The Bill’s formal designation process is still concluding, but if you operate critical infrastructure at scale, this category is likely to include you.

Relevant Digital Service ProvidersThe cloud or platform partner
The technology layer sitting above the OT customer. Cloud infrastructure, managed services, large-scale digital platforms. Less commonly your direct manufacturing or operational audience, but relevant to the IT ecosystem around them.

Designated Critical SuppliersThe vendors supplying into the above
The OT software vendor, systems integrator, or specialist component supplier whose product sits inside an operational environment. This is the category that might catch organisations off guard, and the one that puts OT technology vendors and systems integrators into scope, even if they don’t run essential services themselves. If your product or service sits inside a designated critical operation, the Bill may already be relevant to you, whether or not you expected it to be.

Why OT organisations face a specific challenge here

For most OT-heavy organisations, the cyber accountability gap is rarely anyone’s fault. It’s a product of how organisations in these sectors have always worked.

OT cyber risk has historically lived in the plant, with engineering teams, managed in a technical language that most boards were never expected to speak. The assumption, often reasonable at the time, was that air gaps and legacy obscurity provided adequate protection, and that the cyber risk relevant to the boardroom was primarily an IT concern, because at the time, IT was the part of the business connected to the internet.

That assumption has been eroding for years as IT and OT environments have converged. The Bill, as currently set out, effectively closes it. It doesn’t ask whether your engineering team did their best. It asks whether your organisation can demonstrate it is actively managing the risk. That’s a fundamentally different standard, and it requires a fundamentally different kind of ownership.

What genuine board-level ownership actually requires

Owning OT cyber risk at board level isn’t the same as understanding the technical detail. It means being able to answer a small number of questions with confidence, and knowing where to go if you can’t.

What are our most critical OT assets, and what would happen to operations if they were compromised? Do we have continuous visibility into our OT network, or are we relying on periodic assessments that may already be out of date? Do we understand our exposure well enough to prioritise what to fix first? And if something went wrong tomorrow, could we demonstrate to a regulator that we knew about the risk and were actively managing it?

Most boards of OT-heavy organisations can’t answer all of these questions today. That’s not so much a criticism as a reflection on how the expectation is shifting. But the window for treating this as someone else’s problem is closing.

Three questions worth asking to your team

Who in our organisation owns OT cyber risk?

What visibility do we have into your actual exposure?

What would we show to a regulator if we were asked about this?

The answer to these questions will tell you more about your readiness than any compliance checklist. And it’s a better question to answer in a boardroom now, than in the aftermath of an incident later.

Building OT visibility and cyber risk management capability is the work Radiflow helps manufacturers and critical infrastructure operators do.

Additional Resources

Request Demo Contact Us