What the Online Safety Act changed, and what it did not
Ofcom fined a suicide forum £950,000, then reported that it had exhausted every legal route to collect it. Three years of Online Safety Act enforcement.
Cybersecurity
Almost every organisation in Britain now has a supplier whose bad week becomes its bad month. This section reports the incidents, the regulation and the supply chain underneath both.
The compromise that stops a British organisation trading is now more likely to begin in somebody else's login than in its own. That is not a prediction. It is the pattern in the caseload.
In the twelve months to 31 August 2025 the National Cyber Security Centre received 1,727 incident tips and triaged them into 429 incidents needing support. Of those, 204 were rated nationally significant and 18 highly significant. The categories are the NCSC's own, and the ratio is what should hold a chief executive's attention: nearly half of everything the national authority handled last year landed in its more serious bracket.
Set against that, the Cyber Security Breaches Survey published on 10 April 2025 found 43% of businesses had identified a breach or attack in the preceding year, and that phishing featured in 85% of those cases. Read that figure carefully. It counts breaches organisations noticed, so it measures detection capability as much as attacker activity, and the apparent fall among the smallest firms is at least partly a fall in noticing.
The Network and Information Systems Regulations 2018 were written for a market in which the important systems belonged to the organisation running them. The Cyber Security and Resilience Bill, introduced to Parliament on 12 November 2025, is the attempt to close that gap, and its central move is to pull managed service providers into scope. The government's policy statement of 9 April 2025 estimated that between 900 and 1,100 managed service providers would be caught.
If you buy managed services, that changes your position twice over. Your provider acquires duties it did not have, which will appear in your renewal pricing. And the regulator gains a route to ask you why you did not know what your provider was doing on your estate.
British organisations trading into the European Union have been through a version of this already, without a domestic statute obliging them to. Obligations reach UK-headquartered companies through European customers, contracts and group structures rather than through Parliament, which is a route into scope that a compliance function organised by jurisdiction tends to miss. That is the subject of NIS2 reaches British companies that never opted in.
The phishing figure above deserves one further note, because the defence most organisations bought no longer matches the attack. Awareness training built around spotting clumsy grammar and implausible urgency was calibrated for messages written by people who did not speak the language of the target. That tell has gone. What replaces it is procedural rather than perceptual: out-of-band confirmation for payment changes, and an internal culture in which challenging a plausible request from a senior name carries no cost. Phishing got fluent and training did not works through what survives the change.
Ask a UK board which of its suppliers could halt operations for a fortnight and you will usually get a procurement list ranked by spend. Those are different questions with different answers. The payroll bureau, the pathology laboratory, the print house that produces statutory letters and the single integration partner holding privileged access to four systems rarely sit near the top of a spend table, and any one of them can stop a service.
Public bodies have been learning this in the most public way available, which is covered in councils are being breached through their vendors.
When a British organisation publishes an honest account of its own worst month, naming what failed and in what order, it does more for national resilience than any quantity of threat reporting. Those documents exist. They arrive as regulators' notices, committee sessions, court filings and lessons-learned reviews commissioned by the victim, and they are read by a few hundred specialists and almost nobody in a position to act on them.
They are also the only account of an incident that carries a stated impact alongside a named organisation. Attribution claims resting on a vendor's private telemetry cannot be checked by anybody outside the vendor, and breach counts scraped from criminal groups' own leak sites are advertising, with the reliability of advertising.
The practical position this section takes is that resilience is now mostly a procurement and architecture discipline rather than a security one. The controls that decide whether an incident is a fortnight or an afternoon are chosen years earlier, when somebody agrees a support model, a network design or an identity boundary. Those choices are made in the pages covered under cloud and infrastructure, usually by people who were not in the room when the risk was discussed.
Ofcom fined a suicide forum £950,000, then reported that it had exhausted every legal route to collect it. Three years of Online Safety Act enforcement.
Training taught staff to spot bad grammar. That tell was an artefact of the attacker's budget and it has gone. What still works is procedural, not perceptual.
A dormant wallet moved 8.2 bitcoin and the Met made an arrest. The chain worked perfectly. Five categories of failure that sit around it, and what each one costs.
NIS2 is not UK law and never will be. Three separate routes still pull British organisations into it, and only one of them involves a regulator writing to you.
One council's cyber lead put it exactly: every time we have been compromised it was through a third party. The regulator's fine list now reads like a supplier list.
Britain tried four things against pandemic misinformation. One survived into statute, and it is not the takedown power everybody spent three years arguing over.
The national technical authority now publishes a page whose job is telling you what zero trust is not. That is what the end of a hype cycle looks like in writing.