Home › Blog

💀 Who Actually Writes a Cyber Resilience Bill?

💀 Who Actually Writes a Cyber Resilience Bill?

Not the ministers with their “vision.”
Not the think-tank interns quoting ChatGPT like it’s Cicero.
Not even the cyber folk in hoodies who actually know how TLS works.

No — the real authors sit quietly in Whitehall basements, members of the Office of the Parliamentary Counsel, armed with fountain pens and 200 years of precedent.
They don’t “ideate.” They legislate.
Their job: turn policy hand-waving into something that can be prosecuted in court.

Upstairs, DSIT holds the PowerPoint.
NCSC whispers, “maybe make it actually secure.”
Regulators nod sagely and add more acronyms.
Then someone mutters “AI,” “quantum,” or “supply chain,” and another 30 pages appear.

By the time it reaches Parliament, the bill reads like a Victorian séance transcript — half-spirit, half-Latin, all unenforceable.
A “duty of care,” a “reasonable step,” a “resilient framework.”
In practice: an obligation to have an obligation.

So who writes a Cyber Resilience Bill?
Nobody you’ll ever see at Infosec.
Just the quiet lawyers who convert ambition into clauses…
and clauses into plausible deniability.

Somewhere deep in the annex, beneath the layers of “guidance” and “definitions,” you’ll find the truth:

The bill doesn’t create resilience. It regulates the illusion of it.

Have fun 🤩

Scott G

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing