On 17 June, the Cyber Security and Resilience Bill (CSRB) started its journey through the House of Lords. The Bill updates the Network and Information Systems Regulations, which lean directly on the National Cyber Security Centre's Cyber Assessment Framework, the standard built for operators of essential services. Principle A3 of that framework, Asset Management, is worth reading twice. Organisations need "a clear understanding of what needs to be protected," and that understanding "might include physical assets, software, data, essential staff and utilities," with dependencies across "elements of the supply chain."

I did not expect a cyber security framework to hand me the argument this newsletter exists to make, but there it is, almost word for word. A caveat before anyone gets carried away: most of what the security world calls "asset visibility" is genuinely digital, IP addresses, domains, certificates, software versions. That is a real discipline and it is not mine. Physical asset condition, ownership, and lineage are a different trade. What matters is that the NCSC's framework refuses to stop at the digital layer. It names physical assets and supply chain dependencies as part of the same understanding, reaching into territory that compliance conversations tend to narrow back down to servers and endpoints.

What the Bill actually asks

The CSRB widens the net considerably, pulling in data centres above certain capacity thresholds, managed service providers, and critical suppliers whose failure could cause major disruption further up the chain. That last category stopped being abstract in August. Jaguar Land Rover's cyber incident halted production for five weeks, caused a modelled UK economic loss of £1.9 billion, materially affected more than 5,000 UK organisations, and required a £1.5 billion government loan guarantee to keep the supplier base solvent. Months into a forensic investigation, the precise entry point remains unresolved, and a parliamentary committee has formally questioned the role of third-party IT provision. An organisation of that scale is still establishing which door the attackers came through. Who was behind it is a question I will come back to, because the answer reframes the incident.

I have sat in rooms when that kind of news arrives. The quiet interruption, the phone call taken outside, the department head returning with an excuse and a look nobody around the table quite believes, then the meeting ending early for no stated reason, a decision parked, an opportunity gone. Understanding dawns later, when the dots align and the issue finally has a name. Sometimes there is relief, it was not internal after all. It is not always that kind of ending.

The enforcement detail, 24-hour incident reporting, penalties up to £17 million or 4% of worldwide turnover, will get the headlines, but the diagnostic underneath it deserves more attention than it will receive. Regulators assessing compliance will be asking, in effect, whether an organisation can demonstrate it knows what assets it operates, who owns them, and what state they are in. After 26 years of walking estates in this sector, I can tell you that is not a cyber security question dressed up in new language. It is the oldest question in asset management, and cyber security has finally been forced to ask it out loud. The NCSC's own post-implementation reviews found that just over half of essential service operators had strengthened their practices since 2018. Read that the other way round. Just under half had not, seven years into a regime that already asked them to know their own estate.

If your organisation cannot answer cleanly what you operate, who owns each asset, and what condition it is in, the CSRB does not care whether the gap originated in IT, in facilities, or in engineering. The regulator's penalty does not read your organisational chart. And if that sounds theoretical, it already has case law. In October 2024, Sellafield Ltd was fined £332,500 after prosecution by the Office for Nuclear Regulation for four years of failing to follow its own approved security plan, including missed annual health checks on its operational technology (OT). No vulnerability was ever exploited. The company was fined for the unexploited gap itself, known about for years and left unfixed. UK regulators have already shown they will not wait for an incident before treating the gap as the offence.

Nor is the threat driving all this adequately described as cyber crime any more. On the same day the Bill entered the Lords, the NCSC's chief executive told the RUSI Annual Security Lecture that his teams had managed more than 200 incidents affecting critical national infrastructure and its supporting ecosystem in the year to May 2026, around three-quarters of them believed to be the work of hostile states. This is grey zone activity, deniable and persistent, aimed less at immediate disruption than at prepositioning. The NCSC's warning was blunt: kinetic targeting in any future conflict will be based on intelligence gathered today. The week this issue went to press, reporting emerged that a GRU-attributed campaign had stolen British government login credentials by hijacking thousands of poorly secured routers. And a New York Times investigation has now attributed the Jaguar Land Rover attack itself to a Russian group, prompting the Defence Secretary to warn that hostile states have concluded the most effective way to attack is by quietly hollowing out the economy. The adversary is not probing for a payday. It is mapping the estate.

The estates being mapped are the ones this newsletter serves, and the gaps are familiar to anyone who has worked in them. A Defence estate can usually name every classified system on its network. Ask instead which maintenance contractor holds keys and access rights to the building those systems sit in, and how current that record is, and the answer gets slower, which matters rather a lot when the NCSC is warning that state-sponsored actors are living off the land inside compromised infrastructure networks, staying resident and undetected. NHS Trust estates teams carry a version of the same gap on spreadsheets and institutional memory, one retirement away from losing it entirely. Water and energy operators often have the inverse problem, an OT network mapped thoroughly once, at commissioning, then left to drift from reality for a decade.

The NCSC's prescription for boards, delivered in the same lecture, could have been lifted from this newsletter's masthead: understand your exposure, build on proven fundamentals, and be able to operate and recover through an attack. The distance between that advice and the state of most asset registers is the grey zone's favourite terrain.

The same question, asked from Brussels

The EU AI Act asks a version of the same question from a completely different direction. The obvious comparison would have been NIS2, the EU's own update to the same security regime the CSRB amends, but two security laws agreeing with each other proves very little. What makes the AI Act the more telling comparison is that it was built for a different purpose entirely, in a different legal tradition, and still arrives at the same assumption. For a UK-only operator it does not apply, unless your organisation has EU market exposure or sits inside a group with EU-regulated entities, in which case it applies in full. That caveat matters, so I will not pretend otherwise.

Where it does apply, Annex III classifies AI systems used as safety components in managing critical digital infrastructure, water, gas, heating, or electricity supply as high-risk by definition. That classification triggers named obligations: documented data governance for the datasets the system is trained and run on (Article 10), record-keeping capable of reconstructing what the system did and why (Article 12), and human oversight designed in rather than bolted on (Article 14).

A note on timing, because it cuts both ways. None of those high-risk obligations is in force yet. They were due to apply from August 2026, and the EU's Digital Omnibus, endorsed by the Parliament on 16 June and approved by the Council on 29 June, has deferred them to December 2027, with AI embedded in regulated products pushed to August 2028. The stated reason matters: the standards and organisational readiness needed to comply did not materialise on schedule. Brussels has formally acknowledged that the gap between what the regulation assumes and what organisations can demonstrate is real enough to move a statutory deadline for. A deferral granted because nobody was ready is not an invitation to stay unready. It is the readiness gap, written into the Official Journal.

Notice, too, what the AI Act never does. It does not treat the physical asset as a regulated object at all. The turbine, the pipe network, the substation appear only as context, the thing that makes an AI system high-risk, and as the source of the data the system reasons over. So the CSRB starts from the asset and asks whether you can see it, while the AI Act starts from the algorithm and asks whether you govern its data. Two regulators arriving at the same requirement from opposite directions: you cannot run this safely unless you know what you have, where the data about it came from, and who is accountable for both.

Neither framework asks the question sitting in between. Neither requires you to prove your asset register is complete, that your condition data has a defined owner, or that the lineage from sensor to record to decision is documented. Both assume that foundation exists, and both impose serious consequences when the assumption turns out to be wrong.

Why this converges rather than coincides

I do not think this is coincidence, and I doubt it stays confined to two pieces of legislation. When regimes built by different governments, for different purposes, independently conclude that foundational data discipline is the thing worth legislating around, that tells you where the underlying problem sits. Neither Whitehall nor Brussels set out to write an asset management standard. Both ended up writing one anyway, because you cannot regulate AI safety or infrastructure resilience without arriving at the same locked door: does this organisation know and control the data its critical systems depend on.

Watch the UK's own AI policy next. The government's approach remains principles-based rather than statutory, but the CSRB's policy statement already signals closer alignment with the Cyber Assessment Framework and the EU's NIS2 direction. A framework that asks "do you know what you operate" is a short step from asking "do you know what your AI system is operating on," and the second question is the first one wearing a different badge.

For Defence, NHS, and critical infrastructure operators, the practical implication is not to wait for guidance. Secondary legislation for the CSRB is still being consulted on, with full force not expected until 2028, and the AI Act's high-risk obligations now arrive in December 2027. Both timelines look generous, and both are the same trap. Remember what Sellafield was actually fined for: not an incident, but a gap it had known about for years and failed to close, prosecuted under regulations that have existed since 2003. The CSRB hands every sector regulator a sharper version of that same power, with penalties two orders of magnitude larger. The hard part of readiness, building the inventory and the ownership behind it, is the part no deferral makes easier, and it is the part a regulator can already see.

The question for your board

Ask two things, whichever regulator eventually knocks. Could you demonstrate, without convening a working group, what critical assets you operate, who owns each one, and what condition they are in. And if you are running AI against that same infrastructure, could you show where the data behind it came from, whether it is governed, and who intervenes when it gets something wrong.

If either answer takes more than a meeting to construct, you are not behind on compliance. You are behind on the thing compliance was always going to ask you to prove.


If your organisation sits inside the CSRB's expanded scope, or has EU exposure under the AI Act, reply and tell me which question is harder to answer. I read every response.

Alex Brain Founder and Managing Director, Brainwave Asset Intelligence

Foundations First publishes monthly. Next issue: first Wednesday of August.