Recording script
NIS2 and UK cyber resilience law: what your business has to do
- 3modules
- 1369words
- 9minutes when read
- 2voices
How to record this
Emma is the host. Curious, a little sceptical, asks the question the learner is actually thinking, and pushes back when something sounds unrealistic on a short staffed shift.
George is the practice educator. Warm, direct, never condescending. Answers the awkward question rather than deflecting it.
Leave a beat of silence between speakers rather than overlapping. Timestamps assume 150 words per minute, which is a natural teaching pace. Cue numbers mark where each on screen graphic should land.
Wording that must not be upgraded
planned The CPD Certification Service
Application scheduled.
aligned Directive (EU) 2022/2555 (NIS2)
Written against the published Directive. Our own summary, which is not legal advice and carries no endorsement from any EU body. National laws implementing the Directive differ in detail.
aligned Cyber Security and Resilience (Network and Information Systems) Bill
Written against the Bill and the government's published factsheets as at October 2026, when the Bill had not received Royal Assent. Our own summary, with no endorsement from the government implied.
Do not promote any of these words in a video title, description or thumbnail. Aligned is not accredited, and planned is not approved.
1. NIS2: who it catches, and what it asks of managers
About 3 minutes, 490 words. Starts at 00:00 in the full course recording.
Outcomes to state on camera
- Explain why NIS2 is not UK law and how it still reaches UK firms
- Say which sectors and sizes of organisation are covered
- Distinguish essential from important entities and the fines for each
- State what Article 20 asks of management bodies
- List the ten measures in Article 21
Script
Cue 1 A map with the EU shaded and the UK outside it, with two arrows reaching a UK firm: a service sold into the EU and a customer's contract
EMMA 00:00 George, I keep being told NIS2 has landed and we all have to comply. We're a UK business. Do we?
GEORGE 00:08 Not as UK law, and that's the first thing to get straight before anyone spends money. NIS2 is an EU Directive. The UK left before it was made. So it doesn't apply here the way it applies in Germany.
EMMA 00:23 So I can ignore it.
GEORGE 00:25 No, and here's why. It reaches UK firms in two ways. Directly, if you provide a covered service inside the EU or have an establishment there. And indirectly, which is far more common, because a covered customer has to manage the security of its supply chain. They write that into your contract.
Cue 2 Eighteen sectors in two groups with a size threshold marker at fifty staff or ten million euros
EMMA 00:46 That'll be the questionnaire we got from our Dutch customer.
GEORGE 00:50 Exactly that. So two questions first. Do we provide a covered service in the EU? And do any customers have to comply and pass it down?
EMMA 01:00 Who does it cover over there?
GEORGE 01:03 Eighteen sectors. The high criticality ones include energy, transport, banking, health, water, digital infrastructure and managed IT services. The others include post and couriers, waste, chemicals, food, and manufacturing of things like medical devices, electronics, machinery and vehicles.
Cue 3 Essential and important entities side by side with their maximum fines
EMMA 01:18 Every business in those sectors?
GEORGE 01:20 Generally medium and large ones. Broadly, fifty or more staff or more than ten million euros of turnover. Some kinds of provider are covered whatever their size. And because it's a Directive, each country's version differs in detail.
EMMA 01:35 I've heard essential and important. What's the difference?
GEORGE 01:38 Two classes. Similar duties, closer supervision for essential. And different maximum fines. At least ten million euros or two per cent of worldwide turnover for essential entities. At least seven million or 1.4 per cent for important ones. Whichever is higher.
Cue 4 A boardroom table with three labels: approve, oversee, answer for it, and a training record
EMMA 01:55 Those are data protection sized numbers.
GEORGE 01:57 They are, and that's deliberate. But the part that really changes things is Article 20. Management bodies must approve the security measures, oversee them, and can be held liable for infringements.
EMMA 02:10 So the board can't just say that's an IT matter.
GEORGE 02:14 Not any more. And the same Article says members of management bodies are required to follow training. Staff should be offered similar training regularly.
Cue 5 Ten numbered measures as a checklist, each with policy, owner, in place and last checked boxes
EMMA 02:23 Required. For directors.
GEORGE 02:24 Required. So keep a record of who was trained, in what, and when. A training duty you can't evidence is treated as one you didn't meet.
EMMA 02:35 And what do they actually have to have in place?
GEORGE 02:39 Article 21 lists ten measures as a minimum. Risk and security policies. Incident handling. Business continuity with backups. Supply chain security. Secure development and vulnerability handling. Checking the measures work. Cyber hygiene and training. Cryptography. Access control and asset management. And multi-factor authentication with secure communications.
EMMA 02:57 That's a lot to hold.
GEORGE 02:59 So don't hold it, check it. For each of the ten ask four things. Is there a written policy? A named owner? Something actually in place? And a date it was last checked? Four yeses per line is a defensible position.
Sources for the on screen credit
- Directive (EU) 2022/2555 (NIS2), Articles 20, 21 and 34, EUR-Lex
- NIS2 Directive: securing network and information systems, European Commission
- Cyber Assessment Framework, National Cyber Security Centre (UK)
2. Incidents, suppliers and the 24 hour clock
About 3 minutes, 448 words. Starts at 03:16 in the full course recording.
Outcomes to state on camera
- State the three stages of NIS2 incident reporting and their deadlines
- Explain what makes an incident significant
- Describe what a first hour looks like when something goes wrong
- Explain why NIS2 customers send security questionnaires to suppliers
- Answer a supplier questionnaire honestly and usefully
Script
Cue 1 A timeline with three markers at 24 hours, 72 hours and one month, starting from the moment of becoming aware
EMMA 03:16 George, the bit that worries people is the 24 hours. Report an incident in a day? We'd still be working out what happened.
GEORGE 03:25 And nobody expects you to have worked it out. NIS2 Article 23 has three stages. An early warning within 24 hours of becoming aware. A fuller incident notification within 72 hours. And a final report within one month.
EMMA 03:40 What goes in the early warning?
GEORGE 03:42 Very little. That it happened, whether it looks malicious, and whether it could affect other countries. It's deliberately light. They don't want the full story in a day. They want to be told.
Cue 2 An incident that was contained, with the words capable of causing highlighted
EMMA 03:56 And when does the clock start?
GEORGE 03:58 When the organisation becomes aware. Not when the investigation finishes. That's the point people miss.
EMMA 04:04 Does every little thing count?
GEORGE 04:06 No, it has to be significant. Severe operational disruption or financial loss, or considerable damage to other people. But the wording is caused or capable of causing. Something you contained can still be reportable.
Cue 3 A first hour checklist: note the time, contain, tell the decision owner, tell customers, keep a log
EMMA 04:20 So if in doubt?
GEORGE 04:21 Make the early warning and correct it later. That's the safer course.
EMMA 04:26 Realistically, who notices first? It's not going to be me.
GEORGE 04:30 No, and it's almost never the security lead. It's whoever is at the screen. So they need one thing. Who to tell, at any hour, without fear of blame.
Cue 4 A covered customer passing requirements down a chain of suppliers
EMMA 04:42 And then?
GEORGE 04:42 In order. Write down the time you became aware, because every deadline runs from it. Contain what you can without destroying evidence. Tell the person who owns the decision to report. Tell affected customers. And keep a log of what was known and decided, and when.
EMMA 05:01 Why customers so early?
GEORGE 05:02 Because your contract probably requires it, and their own clock may have started. Which brings us to the questionnaire you got.
Cue 5 A questionnaire with honest answers: a no with a date, and three boxes customers check first
EMMA 05:11 Yes. Why are they asking me forty questions?
GEORGE 05:14 Supply chain security is one of the ten measures. A covered organisation has to consider each direct supplier's vulnerabilities and practices. So they ask, and they write it into the contract. Security measures, a right to audit, and a duty to tell them about incidents fast.
EMMA 05:32 I'm tempted to tick yes to everything.
GEORGE 05:35 Don't. A no with a date beside it is more useful to them than a yes that turns out to be untrue. And an untrue answer in a contract is a liability of a different kind.
EMMA 05:50 What do they check first?
GEORGE 05:52 Three things. Multi-factor authentication. Backups you've actually tested. And staff training. Only tick those if you can show them.
EMMA 05:59 And one practical test?
GEORGE 06:01 Ask a member of staff at random. If your screen showed a ransom note at two in the morning on a Sunday, who would you ring? If they can't answer, the deadline is already lost.
Sources for the on screen credit
- Directive (EU) 2022/2555 (NIS2), Articles 21 and 23, EUR-Lex
- NIS2 Directive: securing network and information systems, European Commission
- Incident management guidance, National Cyber Security Centre (UK)
3. The UK Cyber Security and Resilience Bill, and what to do now
About 3 minutes, 431 words. Starts at 06:15 in the full course recording.
Outcomes to state on camera
- State the Bill's status and why it is not yet law
- Say who the Bill would bring into scope
- State the Bill's incident reporting timeline and who is told
- Explain what will be decided later in secondary legislation
- Set out five steps worth taking now under either regime
Script
Cue 1 A parliamentary timeline from November 2025 to report stage on 26 October 2026, with Royal Assent still ahead
EMMA 06:15 George, so NIS2 is the EU's. What has the UK actually done?
GEORGE 06:20 It has a Bill, and it isn't law yet. That's the headline. The UK already has the Network and Information Systems Regulations from 2018. The Cyber Security and Resilience Bill amends and widens them.
EMMA 06:33 How far has it got?
GEORGE 06:35 Introduced in November 2025. Through the Commons in June 2026. Lords second reading in July, committee stage finished in September, report stage scheduled for 26 October 2026. Royal Assent has been expected late in 2026 or in spring 2027.
Cue 2 Four groups joining the regime: managed service providers, data centres, load controllers, designated critical suppliers
EMMA 06:51 So today, what applies?
GEORGE 06:52 The 2018 Regulations as they stand. Until the Bill passes and the regulations under it are made. Check the current position before you rely on anything I'm about to say.
EMMA 07:04 Fair. Who would it bring in?
GEORGE 07:07 Four groups, according to the government's factsheets. Medium and large managed service providers, the firms that run IT for other organisations. Data centres above set thresholds. Large load controllers, which manage power for things like vehicle chargers. And designated critical suppliers.
Cue 3 A supplier outside regulation failing and a hospital's appointments being postponed
EMMA 07:23 Designated by whom?
GEORGE 07:24 By regulators. If a supplier's failure would disrupt an essential service, they could be designated and brought under duties.
EMMA 07:32 Why that power?
GEORGE 07:33 June 2024. An attack on a pathology supplier to the NHS led to more than eleven thousand postponed appointments and procedures. The supplier wasn't itself regulated. That's the gap.
Cue 4 A 24 hour and 72 hour clock with the regulator and the National Cyber Security Centre both receiving the report
EMMA 07:45 And reporting? Is it the same 24 hours as Europe?
GEORGE 07:49 Similar shape. An initial notification within 24 hours and a full report within 72, to the regulator, with the National Cyber Security Centre told at the same time. More incidents become reportable, including ones capable of significant impact, like ransomware.
EMMA 08:05 What about customers?
GEORGE 08:06 Managed service providers, digital service providers and data centres would have to tell customers likely to be affected.
Cue 5 Five numbered steps on a single card headed do this now
EMMA 08:13 And the fines?
GEORGE 08:14 Maximum penalties go up, to align with things like data protection law. Regulators can recover their costs. And the Secretary of State can set priorities and give directions for national security. I won't quote figures, because a lot is left to secondary legislation, including what counts as significant.
EMMA 08:34 So what do I do while Parliament finishes?
GEORGE 08:37 Five things, and none needs the Bill to pass. Work out where you stand. Brief the people who run the business and record it. Check your critical suppliers and your incident clauses. Write down who decides and who reports, and test it out of hours.
EMMA 08:55 And the fifth?
GEORGE 08:56 Fix the three basics. Multi-factor authentication, backups you've tested, and staff training. They've been the advice for years, and they're what every one of these regimes checks first.
Sources for the on screen credit
- Cyber Security and Resilience (Network and Information Systems) Bill factsheets: summary of the Bill, GOV.UK
- Cyber Security and Resilience (Network and Information Systems) Bill factsheets: incident reporting, GOV.UK
- Cyber Security and Resilience (Network and Information Systems) Bill: stages, UK Parliament
- The Network and Information Systems Regulations 2018, legislation.gov.uk