Regulatory Watch: Three Developments Risk Leaders Should Be Preparing For

Protective security, cyber resilience and data governance are moving at different speeds, but each requires the same early disciplines: establish scope, name an owner and connect legal interpretation to operational reality.

Regulatory watch Three developments For risk leaders

1. Martyn’s Law: move from awareness to preparation

The Terrorism (Protection of Premises) Act 2025, widely known as Martyn’s Law, establishes a new protective-security framework for qualifying premises and events. The Security Industry Authority will regulate the regime.

Implementation is not immediate. Current government information indicates that the Act is expected to come into force in spring 2027, with final regulator guidance expected in autumn 2026. That period should be used carefully. Organisations that wait for commencement may find that decisions about responsibilities, procedures, training, physical measures and evidence cannot be completed well.

Preparation should begin with a defensible view of scope. Consider each premises and event separately, including expected capacity, use and access arrangements. Where a site is likely to qualify, compare current emergency and security arrangements with the developing framework.

Priority actions:

  • Nominate a senior owner and a competent operational lead.
  • Build an inventory of potentially qualifying premises and events.
  • Review evacuation, invacuation, lockdown and communication procedures.
  • Identify how front-line employees, contractors and volunteers will be briefed.
  • Test how security decisions connect with fire safety, accessibility and crowd management.
  • Retain an assumptions log so the assessment can be updated when final guidance is issued.

The purpose is not to predict every possible attack. It is to make proportionate arrangements, give people usable procedures and build organisational preparedness.

2. Cyber Security and Resilience Bill: prepare for broader operational resilience duties

The Cyber Security and Resilience Bill was introduced in November 2025 and is intended to update the UK’s framework for essential and digital services. Government material describes reforms to the Network and Information Systems regime, including broader scope and stronger expectations around supply-chain and incident resilience.

The precise obligations will depend on the Bill’s progress and final form. The management signal is already clear: cyber risk can no longer be treated solely as an information-technology control. Operational services, outsourced providers, physical systems and executive decision-making all sit within the resilience picture.

Organisations that may be directly regulated, or that supply regulated entities, should use the legislative period to answer four questions:

  • Which services are essential to our customers and operations?
  • Which suppliers, platforms and connected systems could interrupt those services?
  • How quickly would we detect, escalate and report a significant incident?
  • What evidence shows that continuity and recovery arrangements work?

Procurement teams should review contractual notification, assurance and cooperation provisions. Risk teams should make sure cyber scenarios are represented in business-continuity exercises. Boards should receive information that connects technical vulnerabilities with service and customer consequences.

3. Data (Use and Access) Act 2025: implementation is now an operating issue

The Data (Use and Access) Act 2025 changes aspects of the UK data-protection and privacy framework. The majority of the Act’s Part 5 data-protection and privacy provisions came into force on 5 February 2026.

For many organisations, the compliance risk is assuming that a legal update is complete once a privacy notice has been reviewed. Changes may affect policies, records, complaint handling, automated decision processes, recognised legitimate interests and the way teams explain and evidence decisions.

Practical implementation should include:

  • Mapping relevant provisions to existing UK GDPR and Data Protection Act controls.
  • Updating policies, templates and guidance only where required.
  • Briefing privacy, HR, marketing, customer-service, security and technology teams.
  • Checking that data-subject request and complaint workflows reflect current requirements.
  • Reviewing the governance of automated decision-making where it is used.
  • Retaining a clear record of legal interpretation and implementation decisions.

Risk leaders should also look for unintended gaps between functions. A change may be legally owned by a data-protection specialist but operationally delivered through many teams and systems.

The shared assurance question

These three developments differ in subject, maturity and enforcement route. What joins them is the need to translate a changing external requirement into owned, tested and evidenced controls.

A useful regulatory-change record should show:

  • The source and current status of the change.
  • Why it is or is not relevant.
  • Affected entities, sites, services and processes.
  • Accountable and responsible owners.
  • Actions, dependencies and target dates.
  • Decisions awaiting final guidance.
  • The evidence that will demonstrate implementation.

This prevents regulatory watch from becoming a passive list of headlines. The objective is not merely to know that change is coming, but to be ready to manage it.

Technical source note

SIA, Understanding Martyn’s Law and the SIA’s role as regulator: View the SIA guidance

Home Office, Martyn’s Law factsheet: View the Home Office factsheet

UK Government, Cyber Security and Resilience Bill collection: View the Bill collection

UK Government, Data (Use and Access) Act 2025 commencement: View the commencement guidance

UK Government, data protection and privacy changes: View the data protection guidance

Speak to one
of our experts
today