UK Government Moves to Cut High-Risk Tech Suppliers Out of Critical Infrastructure
Late additions to a new cybersecurity law would give ministers the power to remove or restrict technology providers judged to pose a national security risk, as attacks on supply chains grow more frequent.

Key points
- The UK government is adding new powers to the Cyber Security and Resilience Bill that would let ministers block or restrict high-risk technology suppliers.
- The changes target supply chain risk, where an attacker breaks into a major software or hardware provider to reach dozens of its customers at once.
- Critical infrastructure, meaning services like power grids, water systems, hospitals, and financial networks, is the focus of the new rules.
- The amendments were introduced late in the Bill's progress, suggesting urgency on the government's part.
- No specific supplier has been named publicly under the new powers.
The UK government is tightening its grip on who can sell technology to the country's most sensitive sectors. Late amendments added to the Cyber Security and Resilience Bill would hand ministers direct authority to bar or limit technology providers deemed too risky to be trusted inside critical infrastructure. SecurityWeek first reported the changes.
Why does a software supplier matter to national security?
Supply chain attacks are the reason. When criminals or state-backed hackers want to reach hundreds of targets at once, they often go after a shared supplier first. Break into the software company, and you quietly inherit access to every organisation running that software.
The 2020 SolarWinds attack showed exactly how damaging this can be. Hackers, later attributed with high confidence to a Russian state-linked group tracked as APT29 (also called Cozy Bear, in Mandiant's naming convention), slipped malicious code into a routine software update. Thousands of organisations, including US government departments, downloaded it without knowing. The UK recorded its own affected organisations. That single breach through one supplier created a cascading compromise across government and industry.
What does the Bill actually do?
The Cyber Security and Resilience Bill is the UK's main vehicle for updating national cyber rules, the first significant overhaul in years. The new amendments go further than the original draft by giving ministers a specific mechanism to act against suppliers, not just set standards for the organisations buying from them.
In plain terms: if a technology company is judged to carry unacceptable risk, whether because of where it is based, who owns it, or how it has behaved, ministers could order critical infrastructure operators to stop using it or put strict conditions on how they do.
No supplier has been named publicly yet. But the direction of travel is clear. Governments in the UK, US, and European Union have already moved against specific vendors in recent years on security grounds, so a formal legal power to act faster is a logical next step.
Should businesses or members of the public be concerned?
For most people, the direct impact will be invisible. Critical infrastructure operators will bear the burden of checking their supply chains and, where required, switching suppliers. That is expensive and slow work.
What does matter to ordinary people is the underlying problem the law is trying to fix. A successful attack on a hospital's software supplier, or on the systems running an energy network, can knock out services that everyone depends on. These rules are an attempt to reduce that risk before an incident happens rather than after.
Organisations operating in regulated sectors should start mapping which of their technology suppliers could fall under the new rules, and what alternatives exist. Waiting for a minister's order is the harder path.



