A Guide to Cybersecurity Laws and Regulations in the UK
The UK's compliance environment is shifting fast as organisations move to the cloud and accelerate digital transformation. This guide breaks down the core cybersecurity laws and regulations UK organisations need to know, from data protection statutes to sector-specific frameworks, and what recent government data reveals about the threat landscape driving them.

Key takeaways
- UK cybersecurity law spans criminal law (Computer Misuse Act 1990), data protection (UK GDPR, DPA 2018, PECR, DUAA 2025), and sector frameworks (NIS Regulations, Operational Resilience Framework, Telecommunications Security Act).
- Approximately 43% of UK businesses and 30% of charities reported a breach or attack in 2025/2026, with ransomware incidents doubling year-on-year.
- Board-level ownership of cyber security has fallen to 27%. This is down from 38% in 2021, even as regulatory obligations increase.
- The Cyber Security and Resilience Bill will expand compliance scope for supply chains and digital service providers.
Why UK Cybersecurity Regulation Matters Now
The compliance environment in the UK is evolving quickly as more organisations adopt cloud-based services and accelerate digitalisation. Regulators are responding in kind, tightening data protection rules and introducing new resilience obligations for critical sectors.
The scale of the problem explains the pace of reform. According to the Department for Science, Innovation and Technology's Cyber Security Breaches Survey 2025/2026, 43% of UK businesses and 30% of charities reported a breach or attack in the past 12 months. Ransomware crime doubled year-on-year, from under 0.5% to 1% of all businesses, and has affected an estimated 19,000 organisations. Board-level accountability is also slipping, with only 27% of UK businesses having a board member responsible for cyber security. This is down from 38% in 2021.
Key UK Cybersecurity Laws and Regulations
Computer Misuse Act 1990 Criminalises unauthorised access to computer systems and cyber-enabled crimes. It remains the primary criminal law used to prosecute hacking offences in the UK. View the Act.
UK GDPR and Data Protection Act 2018 UK GDPR governs the processing of personal data belonging to UK citizens. The Data Protection Act 2018 sets out the UK's domestic data protection regime, applying to organisations handling personal data within the UK.
Privacy and Electronic Communications Regulations (PECR) PECR sits alongside UK GDPR and applies to organisations handling personal data for marketing and electronic communications activities.
Data (Use and Access) Act 2025 (DUAA) The DUAA amends UK GDPR, the DPA 2018, and PECR, marking the most significant update to the UK's data protection framework since Brexit.
Network and Information Security Regulations 2018 (SI 2018/506) The NIS Regulations set security and incident-reporting requirements for operators of essential services and digital service providers.
Telecommunications (Security) Act 2021 Introduces a security framework for providers of public electronic communications in the UK. It is backed by the Communications Act 2003.
Product Security and Telecommunications Infrastructure Act 2022 Sets baseline security requirements for connectable consumer products sold in the UK. View the Act.
UK Operational Resilience Framework Applies to financial institutions. It requires firms to identify important business services and remain within impact tolerances during disruption, as set out in the FCA Handbook and PRA Rulebook.
What's Next: The Cyber Security and Resilience Bill
The forthcoming Cyber Security and Resilience Bill is expected to widen the scope of the NIS Regulations, bringing more supply chain providers and digital services into scope and strengthening incident reporting obligations across critical sectors. For a deeper look at what the Bill covers and why threat intelligence is central to meeting it, read CYJAX's guide to the Cyber Security and Resilience Bill.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.



