decrypted · 2 september 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law

The UK just gave ministers a veto over your suppliers

The Cyber Security and Resilience Bill, now in the House of Lords and close to Royal Assent, has just been amended to hand ministers a power UK industry has not seen before: the right to order an energy, healthcare or telecoms operator to stop buying from a named technology supplier, or to phase an existing one out, before anything has gone wrong. The trigger was almost mundane by critical infrastructure standards. The Telegraph reported in August that an Iran linked attacker had forced a small UK power generator offline for four days. Officials said it posed no risk to the wider grid. The amendment, tabled on 24 August, is a bet that the next one might.

A veto before the damage, not an inquiry after it

The new clause, dubbed "vendor related directions", lets ministers intervene wherever they judge that a supplier to essential services poses a national security risk, up to and including a phased removal or an outright ban on new purchases. Cyber Security Minister Baroness Liz Lloyd put the intent plainly: the power exists to act "before a threat materialises, not just after the damage is done." The bill separately tightens incident reporting, requiring operators to notify the NCSC of a significant incident within 24 hours and file a full report within 72.

The mechanism is worth translating out of Westminster language. Today, a critical sector operator can buy from any vendor it likes and only faces scrutiny once something breaks. This clause moves the checkpoint earlier, closer to a landlord vetting a subcontractor before handing over keys, rather than launching an inquiry once the locks have already been changed by someone else.

The lesson is procurement, not just patching

Secure by Design is usually discussed as a coding discipline: safe defaults, memory safe languages, authentication that cannot be switched off by accident. This amendment applies the same logic one layer up, to the supply chain decisions that put software in place at all. A UK organisation in scope should already be able to answer, today, which of its critical suppliers it could not quickly replace, and why. Most cannot.

The trade-off is real, not rhetorical. Green energy operators leaning on Chinese solar panels, batteries and inverters would face materially higher costs and longer deployment timelines if directed to diversify. That is the honest price of resilience, and it is worth UK boards budgeting for it now rather than discovering it mid-direction. Organisations outside the named sectors should treat this as a preview rather than someone else's problem: UK regulation has a habit of widening its scope once the first version proves workable.

Also this week

A JFrog Artifactory flaw is being exploited days after the fix shipped. CVE-2026-82329, a 9.8 severity authentication bypass in JFrog Artifactory, lets an unauthenticated attacker exploit a "phantom" join key issued to instances that never configured their own, forging admin tokens with no login required. JFrog patched it on 28 August; by 1 September, researchers at watchTowr had already observed attackers minting admin tokens, enumerating users and credentials, and in some cases planting backdoor accounts. This is a different bug to the Artifactory zero-day used in July's Hugging Face breach, JFrog's CTO has confirmed, which makes it worse rather than better: the same product has now been hit twice in two months. Any UK team running self-hosted Artifactory in its CI/CD pipeline should check its version against JFrog's advisory today, since a compromised build server is a compromised supply chain for every customer downstream.

A ransomware claim against a UK financial advisory firm, unconfirmed. The Anubis group listed Marlborough Partners, a London capital solutions advisory, on its leak site on 2 September, alleging a "major data breach" with no supporting files, screenshots or ransom figure attached. Anubis has a track record of posting claims that do not hold up. That is not a reason to ignore it, since Marlborough Partners will still need to investigate properly, but it is a reason for anyone reporting on leak site activity, including us, to say "claimed" and mean it until evidence appears.

Sources

Questions on vendor risk, patch triage or making sense of a leak site claim? get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.