Desk live·
ForensicPost
Breaches/Regulation/File 25-1124

Managed Service Providers, Data Centres, and Designated Critical Suppliers

The draft Bill extends regulatory scope to the organisations other organisations depend on. It is the central argument of this database, written into a statute.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUK supplier population
ActorRegulator
D. Kennedy & S. Rosler12 min readConfidence: high3 sources reviewed

The draft Bill expands regulatory scope to cover managed service providers, data centres, and suppliers that may be designated as critical.

This Corpus Has Been Making This Argument For 280 Files

The concentration theme is the largest in this database. The largest healthcare breach of 2025 happened at a company with no patients, at 25-0801. Seventy-four banks were exposed through one analytics vendor at 25-0814. Nineteen organisations’ staff directories sat in a procurement platform at 25-0613. Thousands of retailers lost deliveries because a distributor could not invoice, at 25-0606.

In every one, the regulated, notifying, publicly accountable entity was not the entity that failed. Extending scope to the dependency is the only structural answer, and this is the first time this corpus has recorded a general regime attempting it.

Designation Is Where The Difficulty Sits

"Managed service provider" and "data centre" are definable categories. "Critical supplier" is a designation somebody has to make, about a specific company, in advance of the incident that would demonstrate criticality.

Nothing in this corpus suggests that is easy. Marquis was a data analytics vendor. Chain IQ handled procurement. Neither would appear on any prospective list of critical national suppliers, and both are exactly the kind of organisation whose failure this provision is meant to reach.

Criticality in this database is emergent — it comes from how many organisations happen to depend on you, which is not a property visible from the outside and frequently not known to the supplier itself.

What Would Make It Work

A designation regime that depends on a regulator guessing correctly will always trail the market. One that requires regulated entities to declare their dependencies would produce the map from the other direction — from the parties who actually know.

That is a heavier obligation and, on this desk’s reading of the corpus, the only version likely to catch the next Marquis before rather than after. Whether the Bill does that is a detail of the regime this desk cannot assess from a draft.

How we reported this

Built on published legal analysis of the draft Bill, listed below. The designation critique is this desk’s argument from the incident record, not a finding about the Bill’s mechanics. Corrections: corrections@forensicpost.com.

Sources
  1. Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience BillGlobal Policy Watch
  2. UK Bill would increase cybersecurity standards for critical infrastructure operatorsSkadden
  3. Cyber Security and Resilience (network and information systems) Bill issued by UK governmentClifford Chance
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary