On a warm Tuesday morning in early June 2024, clinicians at King's College Hospital in London arrived at work to find that a critical part of their diagnostic infrastructure had simply stopped functioning overnight. Blood test results weren't coming through, transfusion requests couldn't be processed, and surgical lists that depended on pathology results had to be ripped up and rewritten.
Within hours, it became clear that the problem wasn't a localised one. It had originated somewhere else entirely, and it was spreading.
The ransomware attack on Synnovis, a pathology services provider working across multiple major NHS trusts in London, would go on to become one of the most consequential cyber incidents in the history of the UK's public health services. In the wake of that attack, more than 10,000 appointments were cancelled, and over 1,700 operations had to be delayed. Hospital staff had to rely on pen-and-paper for the first time in years, creating backlogs that persisted for months.
Ultimately, roughly 400 gigabytes of patient data was exfiltrated by the Qilin group behind the attack, data that was later published on Qilin’s leak site after ransom demands were refused.
If you work in cyber security, or if you're responsible for broader technology decisions in any organisation that’s closely connected to critical services, then you will probably have followed those events very closely. And if you were honest with yourself at the time, you would probably have recognised that the Synnovis attack wasn’t an outlier.
The UK government clearly thought so too. The Cyber Security and Resilience Bill, introduced to Parliament with a first reading in the House of Commons on the 12th November 2025, is in many respects a direct legislative response to what happened at Synnovis, and to the broader pattern of supply chain attacks that the incident so starkly illustrated. Understanding why that attack was so significant tells you almost everything you need to know about why the new regulatory framework is structured the way it is, and what it is going to demand of you.
The first thing to understand about the Synnovis breach is that it wasn’t a direct attack on the NHS.
Synnovis is a private pathology provider, a joint venture operating under contract to deliver diagnostic services to NHS trusts across south-east London. When the Qilin group targeted it, they weren’t trying to break into an NHS hospital directly. They were going through the back door, via a supplier with deep operational connections to multiple healthcare organisations, handling data and processes that those organisations could not function without.
That’s a defining characteristic of many modern critical infrastructure attacks, and it’s one that legacy regulatory frameworks simply weren’t designed to handle.
The original Network and Information Systems Regulations, enacted in 2018, were built around the concept of protecting operators of essential services directly. So the NHS trusts themselves were within the scope of those NIS Regulations, but as a supplier, Synnovis wasn’t. That gap between where the regulation ended and where the operational dependency began turned out to be exactly the gap that attackers exploited.
It’s worth sitting with that fact for a moment, because it has profound implications for how you think about your own risk exposure. The Synnovis incident forces a harder question than whether your own systems are secure: can you genuinely account for every supplier, every third-party dependency, every organisation that has access to your data or whose own failure would cascade into your operations?
For most organisations, if you answer that question honestly, the answer is likely to be a fairly resounding “no”.
What made the fallout from Synnovis so severe was not just the initial compromise. It was the absence of segmentation. Because Synnovis was deeply embedded in the clinical workflows of multiple trusts, a single point of failure became a multi-site operational crisis almost instantly. By targeting Synnovis, the attackers didn’t need to breach each hospital individually, and there wasn’t any meaningful boundary that prevented the disruption from spreading.
This is the problem that the CSR Bill is attempting to solve at a systemic level. By extending regulatory coverage to managed service providers, data centres, SOC and SIEM operators, and infrastructure vendors, the government is publicly acknowledging a fact that cyber security practitioners have known for years: the attack surface does not respect the boundaries of any single organisation.
The CSR Bill introduces mandatory supply chain assurance requirements, meaning that regulated entities will be expected to ensure that their suppliers are meeting the same resilience standards that they themselves are held to. For many organisations, implementing that in practice is going to require a fundamental rethink of how supplier oversight works.
You’re probably already familiar with the gap between how supplier risk management is supposed to work and how it tends to work in practice. The annual security questionnaire, the checkbox audit, the contractual clause that nobody ever enforces: these processes were designed for a world in which your suppliers were peripheral to your operations. They’re really not fit for purpose in a world where a pathology provider can take down surgical lists at multiple hospitals simultaneously.
The CSR Bill is, among other things, a legislative acknowledgement that periodic assurance isn’t assurance at all.
The Bill's 24-hour incident notification requirement and 72-hour investigative response window are also, in part, a consequence of what happened at Synnovis. One of the most damaging aspects of that incident was the length of time over which its effects persisted. The investigation stretched across months, complicated by the volume of exfiltrated data and the complexity of piecing together what had happened across a fragmented environment.
By the time a full picture emerged, the harm had long since been done.
Faster reporting requirements are not simply about keeping regulators informed. They’re about forcing organisations to have the detection capability, the visibility, and the response processes in place to be able to act quickly in the first place. If you can’t identify an incident, triage it, and notify the relevant authority within 24 hours, that’s telling you something important about the gaps in your current security posture. The new obligations don’t create those gaps; they just reveal them.
This is where the architecture question becomes unavoidable. Many organisations are still running security models that were designed for a perimeter that no longer exists. VPNs, on-premises firewalls, periodic access reviews: these tools were built for an environment in which users sat inside a defined network boundary, data lived in a specific location, and suppliers operated at arm's length. For many organisations, that environment hasn’t existed for years, and the Synnovis incident illustrates what happens when you try to defend a modern, distributed, deeply interconnected operational environment with tools designed for something much simpler.
Meeting these new obligations cannot be achieved through policy alone; it requires architectural change. The shift that organisations need to make, and that the CSR Bill is forcing them to make by raising the baseline of what good looks like, is towards unified, cloud-delivered security architectures. Secure Access Service Edge (SASE) has emerged as the most coherent strategic response to this challenge, precisely because it was designed for the environment that actually exists rather than the one that legacy tools assumed. By integrating SD-WAN, Zero Trust Network Access, Firewall-as-a-Service, Secure Web Gateway, and Cloud Access Security Broker capabilities into a single platform, SASE provides the kind of unified visibility and policy enforcement that the Synnovis-style attack exploits the absence of.
Critically, SASE enables micro-segmentation and per-session access controls that would have fundamentally changed the geometry of the Synnovis incident. When access is granted on a per-session, identity-verified basis rather than through broad network access, the lateral movement that allowed an attack on a single supplier to cascade across multiple NHS trusts becomes dramatically harder to execute. Attackers who find a way in are contained rather than free to move.
That’s not a complete solution on its own, of course, but it’s the structural change that makes everything else more manageable.
It’s also worth understanding that the CSR Bill's alignment with CAF 4.0 makes the direction of travel clear in a way that leaves little room for interpretation. The Cyber Assessment Framework's 108 indicators embed zero trust principles, mandatory segmentation, and continuous detection capability throughout. If you map your current security architecture against those indicators, the gaps will tell you where you need to go. SASE addresses a significant number of those gaps directly, particularly around identity-driven access, supplier oversight, and automated detection and response.
What the Synnovis attack made viscerally clear is that resilience isn’t an IT problem; it’s an operational and societal one. The CSR Bill is a recognition, long overdue, that the digital infrastructure underpinning essential services in the UK needs a regulatory framework commensurate with its importance. The organisations that will navigate the new landscape most effectively are not the ones that treat the Bill as a compliance exercise to be managed. They’re the ones that recognise it as an opportunity to reassess their architecture, take supply chain risk seriously as a continuous rather than periodic obligation, and invest in the unified visibility and automated response capabilities that modern threats actually require.
At Nasstar, we’ve been watching the trajectory of UK cyber regulation very closely, and in our view, the CSR Bill is the right response to what the threat landscape has become.
If the Synnovis attack taught us anything, it’s that the question is not whether an incident will occur, but rather when one does occur, will you be able to contain it, respond to it, and demonstrate to regulators, patients, customers, and the public that you had the right foundations in place? The CSR Bill sets the floor. What you build above it is still yours to decide.






