The UK government is introducing a new mandatory reporting obligation on managed service providers (MSPs) to disclose cyber incidents, alongside minimum security requirements, which could see MSPs fined up to £17 million ($20 million) for non-compliance. Quoting The Record:
The government said on Wednesday that MSPs “play a central role in supporting the UK economy” and warned they are “an attractive and high-value target for malicious threat actors, and can be used as staging points through which threat actors can compromise the clients of those managed services.” MSPs are paid to manage IT infrastructure and provide support, often to smaller businesses that don’t have a designated IT department.
The new obligations on these providers will be introduced through an update to the Network and Information Systems (NIS) Regulations which in their current form require essential services such as water, energy, and transport to uphold security standards and notify national authorities about incidents.
The existing reporting requirements are also going to be updated. Their effectiveness has been criticized following reporting, which revealed that, despite numerous security breaches affecting the energy and transport sectors, no incidents have ever met the actual thresholds for being disclosed to the government.
The existing notification thresholds are based on whether the incidents impact the actual service the organizations provide; for instance, whether at least 50,000 customers went without electricity supply for more than three minutes. However, they do not account for the risks that activities exploiting a network can pose before they become attacks.
Essential services will now need to notify regulators “of a wider range of incidents that disrupt service or which could have a high risk or impact to their service, even if they don’t immediately cause disruption,” the government announced Wednesday. The new thresholds have not yet been disclosed — they will be set by the sector-specific regulators in collaboration with the NCSC.
If you’re a UK-based MSP – and I know from my data that some of you are –this directly impacts your business and is primarily focused on specific industries.
The takeaway for those in the US is that this is a model of how I would expect regulation to look here. Reporting and disclosure requirements, particularly around specific industries, with minimum standards and fines for non-compliance. Let’s note that this level of penalty is significant – with most providers under $10M in revenue, this has teeth.

