The CSR Bill is a national security issue

Cyber resilience is now a national security issue. Is your organisation ready for the threats operating in the grey zone?

There’s a phrase that keeps appearing in official language when governments discuss the current cyber threat landscape. The National Cyber Security Centre has described hostile actors as conducting daily operations in the “grey zone”, by which they mean the ambiguous space that lies somewhere between war and peace.

The cyber security grey zone is the permanent, ambiguous, undeclared state in which adversarial nations probe, map, and quietly compromise the digital systems that keep our country functioning, long before any formal hostilities begin.

If you’re responsible for technology or security in an organisation that touches critical services in the UK, then that framing should change the way you think about what you’re actually defending and why.

The Cyber Security and Resilience Bill, introduced to Parliament in November 2025, is often billed as a regulatory update, a compliance framework, or an expansion of the NIS Regulations. And all of those things are accurate.

But they don’t capture what the Bill actually represents at the political level, which is the UK government's acknowledgement that securing critical digital infrastructure is no longer just a technical or commercial consideration. It’s now a matter of national security, and it should be treated as one.

The evidence underpinning that conclusion has been accumulating for quite some time. The NCSC's 2024 Annual Review recorded 89 nationally significant cyber incidents in a single twelve-month period, including 12 classified as critical. To put it into perspective, that’s three times the number of severe attacks recorded the year before.

By mid-2025, the NCSC was managing twice as many nationally significant incidents compared to the equivalent period in the previous year. And these aren’t abstract statistics: each one represents a system that stopped working, data that was exfiltrated, a service that couldn’t be delivered, or an organisation that spent weeks piecing together the scale of what had happened to it and how.

The adversaries behind the most serious of these incidents aren’t criminal enterprises motivated by ransom payments (although those threats are real and growing). They’re state-sponsored actors operating with strategic patience and long-term objectives that have very little to do with money.

Russia, China, Iran, and North Korea have remained the dominant nation-state threat actors against Western interests for over a decade, and their methods have become more sophisticated and more difficult to detect with each passing year.

As an example, the discovery of Volt Typhoon, the China-affiliated group that the NCSC co-signed an international advisory about in 2024, illustrates the nature of this threat with unusual clarity.

Volt Typhoon wasn’t conducting smash-and-grab operations; it was embedding itself inside critical infrastructure networks across communications, energy, transport, and water sectors, using legitimate system tools to avoid triggering detection. Once embedded, it sat patiently waiting.

The assessment from intelligence agencies makes it clear that these actors were pre-positioning themselves for potential disruptive attacks in the event of geopolitical conflict or military crisis.

They weren’t exploiting vulnerabilities to steal data there and then. Instead, they were building the capability to switch the lights off later.

That distinction matters enormously for how you think about your own risk exposure. The conventional cyber security posture (detect intrusions, respond to incidents, patch vulnerabilities) was designed for a threat environment in which the attacker's goal was immediate. They wanted your data, your money, or access to your systems, and they wanted it right here, right now.

Nation-state actors operating in the grey zone have an entirely different objective. They want persistent, undetected access to the systems that underpin critical services, so that they can act when it’s geopolitically prudent for them to do so, not when it’s convenient for your incident response team to notice.

That’s why the CSR Bill's approach to detection capability is as significant as its compliance requirements. The Bill's demand for 24-hour incident notification and 72-hour investigative response isn’t primarily about keeping regulators informed (although that’s obviously part of it). It’s about forcing organisations to develop the continuous visibility and automated detection capability that nation-state-level threats require.

A rogue actor using living-off-the-land (LOTL) techniques, blending malicious activity into the normal behaviour patterns of legitimate tools and user accounts, likely won’t be caught by periodic security reviews or manual log analysis. For that, you need real-time, AI-powered behavioural analytics running continuously across your entire environment.

The regulatory clock is, in effect, a proxy for a deeper question: do you actually have the capability to see what’s happening in your network, at all times, across every edge?

For many organisations, the honest answer to that question is “no”. Security architectures that grew organically rather than strategically, fragmented tooling accumulated over years of point-solution purchasing, visibility gaps where hybrid and cloud environments meet legacy on-premises infrastructure… these are more than mere compliance problems. In the context of a nation-state threat environment, they’re strategic vulnerabilities, the places that sophisticated actors, given enough time and patience, will eventually find and exploit.

The CSR Bill also draws a direct connection between national security and supply chain integrity that has significant implications for any organisation in or adjacent to regulated sectors. The Bill extends regulatory coverage to managed service providers, data centres, and infrastructure vendors, precisely because intelligence assessments have shown that supply chains are among the most productive attack vectors for state-sponsored actors.

Compromising a single managed service provider with access to multiple critical organisations is more efficient than attacking each one individually. It’s the geopolitical equivalent of turning one key to open many locks.

The NCSC and its allies identified a China-linked network called Flax Typhoon in 2024 that had quietly compromised over 260,000 devices globally, building a covert infrastructure that could be leveraged for further operations at scale. These aren’t random intrusions. They represent the kind of deliberate, long-term infrastructure building that state-sponsored actors invest in specifically because the payoff, when geopolitical conditions require it, is disproportionately large. If any of those 260,000 compromised devices belonged to an organisation in your supply chain, you had a problem that your existing processes were almost certainly not equipped to detect.

The architecture question that follows on from all of this isn’t simply whether your own systems meet the new regulatory baseline. It’s whether your security model is built for this new threat environment rather than a simpler one that no longer exists.

Traditional perimeter security, broad-access VPNs, and on-premises firewalls were designed for a world in which users sat inside a defined network boundary and threats came from outside it. That model was always a simplification. In the current threat environment, it’s a liability.

The shift towards unified, cloud-delivered security architectures, and specifically towards Secure Access Service Edge (SASE) as a strategic framework, is significant precisely because it addresses the structural weaknesses that nation-state actors exploit.

SASE integrates SD-WAN, Zero Trust Network Access, Firewall-as-a-Service, Secure Web Gateway, and Cloud Access Security Broker capabilities into a single, continuously enforced policy layer.

It provides identity-driven access controls that verify every user and every device on a per-session basis, rather than granting broad network access that a compromised account can abuse for months without detection. It enables micro-segmentation that limits lateral movement, so that an actor who does gain a foothold in one part of your environment cannot freely traverse to the systems they are actually looking for.

Critically, SASE provides the unified visibility across internal systems, cloud environments, and third-party connections that the nation-state threat environment demands. The living-off-the-land techniques used by groups like Volt Typhoon are specifically designed to evade detection in siloed, fragmented environments where visibility is inconsistent. A unified platform that correlates activity across every edge, applies behavioural analytics continuously, and can identify anomalies in the way legitimate tools are being used is the architecture best suited to detecting the kind of patient, methodical intrusion that state-sponsored actors specialise in.

At Nasstar, our partnership with Fortinet shapes how we think about this challenge in practical terms. Fortinet's approach to building a broad, integrated, and extensible security platform is directly relevant to the threat environment described here.

The CSR Bill grants the government the power to direct regulated organisations and regulators to take specified actions in the interests of national security. That’s an unusually direct provision for a piece of cyber security legislation. It signals that the government reserves the right to treat critical infrastructure security not as an operational matter for individual organisations to manage in their own time, but as a sovereign concern to be directed from the centre when circumstances require it.

That’s not the language of regulatory compliance, it’s the language of national security.

The grey zone isn’t going away. The actors operating within that grey area are becoming more capable, more patient, and more sophisticated in their ability to evade detection. The CSR Bill sets a baseline. Whether you meet it and stop there, or use it as the starting point for building a security posture genuinely suited to the threat environment you are operating in, is a choice that will have consequences well beyond your next regulatory audit.