For years, managed service providers (MSPs) have occupied a slightly unusual position in the cyber resilience ecosystem.
MSPs can have privileged access to hundreds or even thousands of customer environments. They manage infrastructure, cloud services, security systems, identities and backups. Yet, in the UK, the cyber resilience of the MSP itself has largely remained outside direct regulation.
That is now set to change.
The UK Government’s proposed Cyber Security and Resilience (Network and Information Systems) Bill would bring qualifying MSPs within the scope of the Network and Information Systems Regulations 2018.
If enacted, this would make cyber resilience a direct regulatory responsibility for a significant part of the MSP market.
And the consequences for MSP business models, operating costs, technology choices and customer relationships could be profound.
Which MSPs would be covered?
The legislation is intended to apply to medium and large providers that meet the definition of a “Relevant Managed Service Provider”, or RMSP.
In broad terms, this means an organisation that:
Provides ongoing management of a customer’s IT systems under contract
Connects to, or otherwise accesses, systems used by that customer
Provides those managed services within the UK
Is not classed as a small or micro enterprise
The definition potentially captures a wide range of services, including:
Remote IT support and helpdesks
Infrastructure and application management
Managed cloud services
Managed security and SOC services
Firewall and network management
Critically, the backup and recovery of customer data
Small and micro MSPs are generally outside the automatic scope, although smaller providers could still be designated as critical suppliers where their services are considered sufficiently important.
One of the most significant details is that this is not limited to British-headquartered MSPs.
A provider could be based in the United States, India, continental Europe or anywhere else and still fall within scope if it provides qualifying managed services in the UK. Overseas providers would also be required to appoint a UK representative.
The Government’s research identified 12,867 active MSPs in the UK and estimated that around 1,214 could potentially fall within scope, although the final number will depend on the legislation and its secondary regulations.
What would MSPs actually have to do?
The Bill would require RMSPs to register with the Information Commission within three months of the relevant provisions taking effect.
They would then need to identify and implement “appropriate and proportionate” measures to manage risks to the networks and information systems supporting their managed services.
That language matters.
This is not simply about owning a few security products or producing an annual compliance certificate. An MSP would need to demonstrate that it understands its risks and has taken proportionate steps to:
Secure the systems used to deliver its services
Protect data stored or processed within those systems
Prevent incidents where reasonably possible
Minimise the impact when incidents occur
Maintain the continuity and recoverability of its services
The Government says the assessment should consider the current state of the art, including the security measures available and the techniques being used by attackers.
In other words, “we have always done it this way” will not be much of a defence.
The exact technical requirements will be set through secondary legislation and regulator guidance, so nobody can yet produce a definitive compliance checklist. But MSPs should expect scrutiny across areas such as privileged access, identity security, segmentation, vulnerability management, monitoring, supply-chain risk, incident response, backup security and recovery readiness.
Incident reporting will become a serious operational requirement
The Bill proposes a two-stage reporting process for significant incidents.
An MSP would need to provide an initial notification to the Information Commission, with the National Cyber Security Centre informed at the same time, within 24 hours of becoming aware of a reportable incident.
A fuller report would then be required within 72 hours.
Importantly, reporting would not necessarily be limited to attacks that have already disrupted services. Ransomware, spyware or an attacker successfully establishing a position inside an environment could become reportable where the likely impact is significant, even before the attacker has caused an outage.
The MSP may need to determine:
Which services and systems are affected
When the incident began
Whether it is still active
Whether customer data has been compromised
The actual or likely operational impact
How many customers or users could be affected
Whether the incident originated with another regulated supplier
Following the fuller notification, the MSP would also need to identify customers likely to have been adversely affected and notify them.
That is a demanding timetable.
An organisation cannot begin working out where its data is, whether its backups are clean, who its affected customers are and how its recovery process works after the clock has already started.
Twenty-four hours is a very short time when production systems are down, attackers may still be present, and customers are demanding answers.
What will compliance cost?
The honest answer is that nobody yet knows precisely.
The Government estimates that the Bill as a whole will cost affected businesses and other stakeholders less than £150 million per year. That is an economy-wide figure, not a reliable estimate of what an individual MSP will spend.
For MSPs, the costs are likely to fall into several categories.
1. Governance and compliance
MSPs will need legal interpretation, regulatory scoping, documented risk assessments, compliance ownership, policies, evidence and board-level oversight.
For some larger providers, these capabilities already exist. For a fast-growing regional MSP without a dedicated risk and compliance function, this could require new people or external consultancy.
2. Security remediation
A gap assessment may identify underinvestment in identity security, network segregation, privileged-access controls, monitoring, vulnerability management or backup protection.
The real cost will not be the assessment. It will be fixing what the assessment discovers.
3. Incident readiness
Meeting a 24-hour reporting window requires rehearsed processes, clear decision rights, retained evidence, forensic capability and accurate service and customer mapping.
MSPs may need new tooling, external incident-response retainers, legal support and regular exercises.
4. Resilience and recovery
MSPs will need to demonstrate not merely that backups exist, but that those backups remain protected if production credentials, identities or administrative systems are compromised.
That means reviewing immutability, isolation, recovery access, clean recovery-point identification and the frequency with which recovery is tested.
5. Regulatory charges
The Bill would allow regulators to recover the full cost of carrying out their NIS functions through charges and fees.
The eventual charging scheme must be consulted upon and published, and regulators would not be permitted to make a profit. Nevertheless, regulated MSPs should expect supervision itself to become a direct operating cost.
6. Customer and contractual costs
Customers are likely to ask harder questions about resilience, notification commitments, audit rights and liability.
Cyber insurance, contract negotiation, customer assurance and supplier due diligence may all become more expensive, particularly for MSPs unable to demonstrate mature controls.
The highest hidden cost, however, could be architectural complexity.
Every backup server, management console, storage platform and manually maintained component creates another asset that must be secured, patched, monitored, evidenced and recovered.
The penalties are potentially substantial
The proposed enforcement regime introduces two principal penalty bands.
For more serious breaches, including failures relating to security duties or incident notification, the maximum would be the higher of:
£17 million; or
4% of the regulated entity’s worldwide turnover.
For less serious breaches, such as certain registration failures, the maximum would be the higher of:
£10 million; or
2% of worldwide turnover.
The precise definition of turnover will follow in secondary legislation. The Government has indicated that it intends the calculation to remain proportionate to UK-regulated services, although the turnover of other group companies may sometimes be considered.
These are maximum penalties, not automatic fines.
Regulators would need to act proportionately and consider factors such as the seriousness of the failure, efforts to mitigate the impact and any previous pattern of non-compliance.
But the regulatory risk is only part of the story.
An MSP suffering a major incident could simultaneously face:
Regulatory investigation and remediation orders
Contractual claims from customers
Reputational damage
Customer attrition
Increased insurance costs
Emergency recovery expenditure
Lost revenue while services are unavailable
The Bill would also give the Government powers to direct regulated organisations to take action against imminent or live national-security threats. Non-compliance with such a direction could, in the most serious circumstances, lead to penalties of up to 10% of turnover or £17 million, whichever is higher, plus potential daily penalties for continuing breaches.
This is no longer a risk that can sit solely with the IT team.
How Druva can help MSPs reduce the risk
No technology platform can, by itself, make an MSP compliant with this legislation.
The MSP will remain responsible for its governance, broader security controls, risk decisions, incident reporting and customer communications.
But the architecture used to protect and recover customer data can either reduce that compliance burden or add significantly to it.
Druva can help in several important ways.
Reduce the infrastructure that must be secured
Druva is delivered as a fully managed SaaS platform.
MSPs do not need to deploy and maintain additional backup servers, storage systems, databases or management infrastructure for every customer.
That removes assets that would otherwise need to be patched, hardened, monitored, upgraded and included in the MSP’s own resilience plan.
Isolate backups from production compromise
Druva provides air-gapped and immutable data protection across cloud, SaaS, data-centre, and endpoint environments.
Separating protected data from the customer’s production environment helps prevent compromised production credentials or ransomware from destroying the recovery copy at the same time as the live systems.
This is fundamental to minimising the impact of an incident.
Provide better visibility into recovery risk
Druva’s security capabilities can help identify backup risks, anomalous behaviour and indicators of compromise.
Threat Watch continuously examines backup snapshots for known and emerging indicators of compromise, helping teams identify potentially infected recovery points before they are restored.
This can support the critical questions an MSP will face during the proposed 24- and 72-hour reporting windows: What was affected? How far back does the compromise go? Which recovery points can be trusted?
It does not automate the MSP’s regulatory decision, but it can provide faster and better evidence for that decision.
Accelerate clean recovery
Immutability is valuable, but resilience ultimately depends on recovery.
Druva allows MSPs to centralise protection, identify clean restore points and recover affected data without first rebuilding a compromised backup infrastructure.
That can reduce downtime, limit customer impact and provide evidence that the MSP took meaningful steps to minimise the consequences of the incident.
Improve consistency across customers
One of the hardest challenges for an MSP is maintaining consistent controls across a large and varied customer base.
A common SaaS platform can standardise protection policies, access controls, monitoring and reporting across multiple workloads and customers. That is considerably easier to govern than dozens of separately built backup environments using inconsistent hardware, software and operating procedures.
What should MSP leaders do now?
The Bill has passed through the House of Commons and, at the time of writing, is progressing through the House of Lords. It has not yet received Royal Assent, and important details will follow through secondary legislation.
But waiting for every final technical requirement would be a mistake.
MSP leaders should already be asking:
Are we likely to meet the definition of an RMSP?
Which UK services, systems and legal entities would be in scope?
Can we identify and escalate a potentially reportable incident within 24 hours?
Do we know which customers are affected by any given system or security event?
Are our customer backups isolated from our own administrative and production environments?
Can we prove that recovery points are clean?
Have we recently tested recovery at the scale required during a major incident?
How much infrastructure are we maintaining that could instead be consumed as a secure SaaS service?
The MSP market has spent years telling customers that cyber resilience matters.
The Government is now preparing to require qualifying MSPs to prove that they practise it themselves.
For the strongest providers, this should not simply be viewed as another compliance cost. It is an opportunity to differentiate, build customer trust and turn demonstrable cyber recovery into a strategic managed service.
But the dividing line will be increasingly clear: It will no longer be enough to say that customer data is backed up. MSPs will need to know that it is secure, understand when it has been compromised, and prove that it can be recovered when everything else has gone wrong.
Sources
The principal sources are the Government’s RMSP factsheet, incident-reporting factsheet, enforcement factsheet, cost-recovery factsheet and the UK Parliament Bill page. Druva capability claims are supported by its MSP cyber-resilience overview, Threat Watch announcement and Trust Center.