In the same week the Cyber Security and Resilience Bill (CSRB) received its First Reading in the House of Lords as HL Bill 32, two major intelligence signals arrived that make its passage through the Upper House a matter of considerable urgency for organisations across the UK's critical economy.
On 17th June 2026 - the same day the Bill was laid before the Lords - NCSC Chief Executive Officer Richard Horne addressed the RUSI Annual Security Lecture and delivered some of the starkest threat statistics in the Centre's history. Less than a week later, on 22nd June 2026, the leaders of the Five Eyes cyber security agencies published a joint statement entitled The AI shift in cyber risk: why leaders must act now - a rare, unified call to action framing artificial intelligence as a threat accelerant operating on a timeline of months, not years.
Together, these two signals provide the clearest official articulation yet of the threat environment that the Cyber Security and Resilience Bill is designed to address. For every organisation that falls within the Bill's scope - from managed service providers and data centres to operators of essential services across energy, transport, health and telecommunications - they carry an urgent message about what is at stake while the Bill works through the Lords.
Richard Horne at RUSI: 75% of UK CNI Attacks Linked to Hostile States
The RUSI Annual Security Lecture is one of the most prominent public platforms available to the NCSC's leadership. Horne used it on 17th June 2026 to frame the current cyber threat in language that goes well beyond standard risk communications.
In the year to May 2026, the NCSC managed more than 200 cyber incidents affecting organisations within the UK's critical national infrastructure and its broader supporting ecosystem. Around 75% of those incidents are believed to be linked to state actors - principally Russia, China and Iran.
That figure matters directly for the CSRB. The Bill introduces, for the first time in UK law, a mandatory reporting framework for ransomware and significant cyber incidents designed to give the NCSC and Government the visibility of attacks that currently go under-reported or unreported. If three-quarters of the incidents that do reach the NCSC are already state-linked, the true scale of hostile state activity against UK CNI is very likely higher. The Bill's 24/72-hour reporting obligations are designed to close that intelligence gap, and the NCSC's own data illustrates exactly why.
Horne also warned that adversaries are engaged in pre-positioning activity - establishing persistent footholds within the technology underpinning critical services, not to disrupt now, but to enable rapid exploitation in a future crisis or conflict. He cited the Volt Typhoon campaign - a People's Republic of China state-sponsored group that has burrowed into critical infrastructure operators in the United States and allied nations - as a prominent example of this strategy. The implication for the UK is clear: the threat is not hypothetical and it is not future-tense.
On artificial intelligence, Horne's assessment was direct: the NCSC has concluded that by 2028 it is highly likely that AI-enabled cyber capabilities will be used by attackers to exploit known vulnerabilities in legacy technology at scale across UK critical national infrastructure. Frontier AI models are already effective at discovering long-standing vulnerabilities in code. The combination of state-actor motivation and AI-enabled automation represents a qualitative escalation in the threat to UK CNI.
Horne called on "every board member and every executive, in every organisation" to strengthen cyber resilience as a matter of urgency, and he was explicit that "initiatives such as the Cyber Security and Resilience Bill will help drive action, using regulation to strengthen the defence and resilience of the most essential and national services."
Five Days Later: Five Eyes Agencies Issue a Unified AI Warning
On 22nd June 2026, the leaders of the cyber security agencies of all Five Eyes nations - the UK's NCSC, the US Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA), Australia's Australian Signals Directorate (ASD), the Canadian Centre for Cyber Security (CCCS), and New Zealand's National Cyber Security Centre - issued a joint statement on the transforming cyber threat landscape.
The statement, "The AI shift in cyber risk: why leaders must act now," is notable both for the breadth of consensus it represents and for the sharpness of its framing. The Five Eyes agencies conclude that frontier AI models are anticipated to exceed current industry expectations within months, not years, fundamentally transforming both offensive and defensive cyber capabilities.
Their core message is stark: AI will help defenders over time, but in the near term the speed, scale and sophistication of threats will accelerate faster than most organisations are currently equipped to respond. Key findings include:
- AI is already discovering long-standing code vulnerabilities at speed and scale that human attackers could not previously achieve alone, compressing the window between vulnerability discovery and active exploitation.
- Patching delays are increasingly dangerous: as AI shortens the exploitation window, organisations that tolerate extended patching cycles are taking on risk that would previously have been acceptable but no longer is.
- Legacy systems are strategic liabilities, not just technical debt: unsupported and end-of-life systems are the easiest entry points for AI-assisted attacks and require urgent prioritisation.
- Supply chain risk is amplified: a single compromised managed service provider or cloud platform can provide AI-driven attackers with propagation paths into many dependent organisations simultaneously.
The Five Eyes agencies set out five practical recommendations for boards and senior leaders:
- Reduce attack surface: challenge which systems genuinely need to be internet-facing and remove unnecessary connectivity.
- Accelerate patching: make vulnerability remediation a continuous, prioritised process, not a scheduled maintenance task.
- Address legacy systems as a strategic priority: build and fund a plan to remove unsupported software and hardware from critical environments.
- Strengthen identity and access controls: limit who can access critical systems, enforce strong authentication, and review permissions regularly.
- Prepare for incidents: test and rehearse incident response plans; assume breaches will occur and prepare to continue operating through them.
Accompanying all five recommendations is a leadership imperative: cyber risk can no longer be treated as a purely technical issue - it is a core business risk and leadership responsibility, with boards and executives accountable for ensuring cyber resilience is in place and functional under pressure.
What the CSRB's Provisions Are Designed to Address
The timing of these intelligence signals is not coincidental. The threat picture that Horne described at RUSI, and that the Five Eyes statement elaborates, is precisely the environment that the CSRB's architects sought to address. The alignment between the NCSC's threat data and the Bill's specific duties is direct.
Mandatory 24/72-hour incident reporting exists because the NCSC's current visibility is incomplete. With 75% of what it does see being state-linked, the reporting regime is designed to give the Centre the full picture it needs to detect coordinated campaigns and pre-positioning activity. For a detailed explanation of how the thresholds will work, see our guide to incident and near-miss reporting under the CSRB.
Expanded scope to cover managed service providers - designated as Relevant Managed Service Providers (RMSPs) - directly reflects the supply chain risk the Five Eyes statement highlights. AI-assisted compromise of a single RMSP can cascade to the managed organisations across its client base. The MSP compliance obligations under the CSRB require registered RMSPs to meet security duties and report incidents within the same 24/72-hour window as their clients.
Data centre regulation under Ofcom as sole regulator ensures that the UK's digital infrastructure - including the cloud platforms that underpin essential services - is within the regulatory perimeter. Data centres and cloud operators processing essential services are exactly the kind of high-value target the Five Eyes statement identifies. See data centre compliance under the CSRB for a full summary.
Critical supplier designation - the Bill's power to designate critical suppliers and impose security requirements on them - addresses the pre-positioning risk Horne identified. An adversary establishing a foothold in a critical supplier can potentially move laterally into the essential services that depend on it.
Enhanced oversight powers and executive accountability - the CSRB's strengthened regulator tools, codes of practice, and statements of strategic priorities - provide the regulatory basis for the board-level accountability that both Horne and the Five Eyes agencies are calling for.
For a full breakdown of which sectors are in scope and what each must do, see who is affected by the CSRB, including sector-specific pages for energy and utilities, transport infrastructure, NHS and health organisations and telecommunications operators.
What Comes Next in the Lords
Update (22 July 2026): the Lords Second Reading took place on 14 July 2026 and Committee Stage is scheduled for 1 September 2026. See our report on the Second Reading. The passage below reflects the position when this article was published on 23 June 2026.
HL Bill 32 is now awaiting its Second Reading in the House of Lords, which has not yet been scheduled. When it is set, the Second Reading will be the first opportunity for peers to debate the general principles of the Bill, and analysis such as Horne's RUSI speech and the Five Eyes statement will inform those debates.
Lords Committee Stage, Report Stage and Third Reading will follow, with any amendments then exchanged between the two Houses before Royal Assent - still widely expected in late 2026. The current text and progress of the Bill can be followed at View the Bill. For a summary of where the Bill stands and what it does, see What is the Cyber Security and Resilience Bill?
What Organisations Should Do Now
The Five Eyes agencies and the NCSC CEO have both said: act now, and do not wait for Royal Assent. For organisations that are, or may be, in scope of the CSRB, these are the most pressing immediate priorities:
- Understand your exposure to state-sponsored threats. The 75% state-actor figure is not a government concern only - it applies directly to operators of essential services, MSPs, data centres and critical suppliers.
- Address legacy systems as a strategic priority. The NCSC's 2028 AI assessment targets known vulnerabilities in legacy technology. Patching backlogs and unsupported systems are the most likely near-term attack vectors.
- Build and test your incident reporting capability. The CSRB's 24/72-hour reporting duty requires a workflow that can function during an active incident, under pressure. Tabletop-test it before you need it.
- Elevate cyber to board level. Both the Five Eyes statement and the NCSC CEO were unequivocal: this is a leadership accountability issue, not a technical function to be delegated.
- Engage with the forthcoming DSIT implementation consultation. The secondary legislation and consultation following Royal Assent will define the detailed obligations organisations must meet. Engaging at that stage is the best way to understand and influence the requirements.
For a full analysis of who the Bill covers and what it requires, read our complete guide to the Cyber Security and Resilience Bill, or see the changes the Bill introduces.
Conclusion
The week of 17th June 2026 produced a striking convergence. The Cyber Security and Resilience Bill received its Lords First Reading on the same day the NCSC CEO told the UK's leading security think-tank that three-quarters of incidents on UK critical infrastructure are state-linked and that AI-enabled mass exploitation of legacy systems is highly likely by 2028. Five days later, all Five Eyes agencies issued a joint statement confirming that AI is compressing the timeline for exactly those threats.
This is the threat environment the CSRB is being enacted to address. For organisations in scope, the message from this week's intelligence signals is unambiguous: preparation cannot wait for Royal Assent, and board-level engagement with the Bill's implications is no longer optional.
This article reflects information published as of 23rd June 2026. For the current version of the Bill and the latest parliamentary progress, see the UK Parliament Bill page for the Cyber Security and Resilience (NIS) Bill.