The UK government intends to give itself new powers to step in if essential service providers, such as electricity and water suppliers or NHS bodies, propose to buy technology from suppliers with ties to hostile states that the authorities believe could seek to use them for cyber espionage or other forms of malicious activity, including sabotage.
In amendments introduced to the Cyber Security and Resilience Bill this week by Tony Blair-era policy adviser and life peer Elizbeth Lloyd, Baroness Lloyd of Effra, Westminster proposed the introduction of the so-called “vendor-related directions” clause.
This clause would give ministers the ability to intervene should they consider “risks to national security could arise from the use of goods, services or facilities in connection with network and information systems linked to essential activities or the provision of essential goods or services”.
The government declared that with cyber attacks and sabotage on essential services a fast-growing reality – as demonstrated by a July 2026 attack on a small UK-based ‘peaker’ power plant attributed to Iran – tech suppliers with connections to hostile states pose a “serious and growing threat” to the security of millions.
Citing its own figures, it said the economic scale of what may be at stake was clear, suggesting that a hypothetical cyber attack on electricity networks in London and southeast England could cost the economy as much as £442bn in the ensuing five-year period.
“These new powers mean we can act before a threat materialises, not just after the damage is done. By working together with industry, we’re putting national security at the heart of how essential services choose their suppliers,” said cyber security minister Liz Jones.
“This is about staying ahead of a growing threat, and giving the public confidence that the everyday services we depend on like water and energy supplies, our transport network and hospitals, are protected.”
Baroness Jones’ proposals also seek to establish “cyber safe” procurement guidance for essential service providers, and such bodies will also be able to refer themselves for a risk assessment if they have any qualms about a potential supplier.
The package also grants the government legal powers to issue binding directions to essential service providers, which could force them to implement extra cyber security measures, or phase out use of potentially dangerous technology.
Opaque powers?
The proposed amendments extend, and put a new slant, on powers that were used a few years ago to block and remove telecoms and networking hardware and software made by China’s Huawei from the UK’s then under-construction 5G mobile networks.
Under the new legal regime the government would have no obligation to publicly name a risky supplier before taking action, nor disclose any orders to an affected supplier.
However it would be required to disclose higher-level data on any directions imposed in an annual report, leading to a situation in which it would be publicly known that a service provider had had a purchase blocked, but not from whom.
While Baroness Lloyd’s amendments do not specifically name any hostile states, given the use of similar powers against Huawei, tech suppliers hailing from China would almost certainly be subject to scrutiny.
However, looking beyond China, the proposals may serve to reignite debate over the UK’s general reliance on a small number of technology providers, many of them US-based.
In June, the crossbench Science, Innovation and Technology Committee warned that the public sector in particular was overly dependent on the likes of Amazon Web Services, Microsoft, and Palantir, the latter of which has been a source of particular controversy.
The MPs spoke of clear vulnerabilities that could leave Britain’s public services “at the mercy” of foreign actors.

