Lincoln 01522 740818 Hull 01482 520818
Shop certified radios

Wireless Communications Blog

How the UK Cyber Security and Resilience Bill Affects Industrial Radio | Yesway Communications

Most of the commentary on the UK Cyber Security and Resilience Bill focuses on IT systems, supply chain software security, and incident reporting obligations. Very little of it addresses what the Bill means for organisations running industrial radio and wireless communications infrastructure. That gap in the commentary does not reflect a gap in the legislation. The Bill’s extended scope, its reference to IEC 62443 as the OT security framework, and its application to critical national infrastructure sectors that are heavy users of industrial radio — utilities, energy, transport, manufacturing — means that radio and wireless communications systems are directly in scope. Organisations that have not assessed their radio infrastructure against IEC 62443 are building a compliance gap that is going to become visible and consequential. This post explains what the Bill requires, which sectors and organisations are affected, and what industrial radio operators need to do about it. What the Cyber Security and Resilience Bill is The UK Cyber Security and Resilience Bill was announced in the King’s Speech in July 2024 and detailed further in November 2025. It is the UK’s legislative response to the gap left by the end of NIS1 applicability post-Brexit, and it is modelled substantially on NIS2 — the EU Network and Information Security Directive that came into force across EU member states in October 2024. The Bill does three things that are directly relevant to industrial radio operators: It significantly extends the scope of mandatory cybersecurity requirements. NIS1 covered a relatively narrow set of operators of essential services. The Bill extends this to a much broader range of organisations — including managed service providers, digital infrastructure operators, and a wider range of CNI sectors. The detail of exactly which organisations will be in scope is still being developed in secondary legislation, but the direction is clear: more organisations, in more sectors, will face mandatory OT cybersecurity requirements. It references IEC 62443 as the OT security framework. Rather than creating a bespoke UK standard, the Bill works with established international frameworks including IEC 62443 for industrial control system security. This means that compliance with the Bill, for OT environments, will be demonstrated through IEC 62443 assessment and certification — not through a separate UK-specific process. It introduces incident reporting obligations and supply chain security requirements. Organisations in scope will be required to report significant cyber incidents within defined timeframes and to demonstrate that their supply chains — including technology suppliers and service providers — meet appropriate security standards. Which sectors are most affected — and why radio matters for them The sectors most directly affected by the Bill are also the sectors that are the heaviest users of industrial radio and wireless communications. This is not coincidental — they are critical infrastructure sectors where radio is a core operational technology, not a peripheral convenience. Water and wastewater utilities Water utilities run wide-area radio networks connecting remote pump stations, treatment works, and reservoirs to central control rooms. Many of these links carry SCADA telemetry — process data that directly controls pumping, treatment dosing, and distribution. A significant proportion run on legacy analogue radio or early-generation digital systems without encryption. Under the Bill, water utilities are critical national infrastructure. Their radio networks are OT assets. IEC 62443 applies. Energy generation and distribution Power generation sites — from conventional plant to wind farms and solar installations — use radio for operational communications, site safety, and increasingly for connecting remote assets to SCADA systems. Grid operators use radio for substation communications and switching operations. These are high-consequence environments. The Bill will apply mandatory cybersecurity requirements. Radio conduits will be in scope. Transport infrastructure Rail operators use GSM-R for train control communications and TETRA for operational radio. Port operators use VHF, UHF, and TETRA across cargo handling, vessel traffic management, and port security. Road operators and highways authorities use radio for traffic management and incident response. All of these are transport CNI operators. All run significant radio infrastructure. All will face the Bill’s requirements. Manufacturing — Tier 1 supply chain pressure Manufacturing organisations may not all be directly in scope of the Bill as CNI operators, but they face the supply chain security requirements from a different direction: Tier 1 customers in automotive, aerospace, defence, and food manufacturing are increasingly requiring IEC 62443 compliance as a supply chain condition. If your factory radio network has not been assessed, and a Tier 1 customer conducts a supply chain cybersecurity audit, the finding will not be comfortable. The NIS2 dimension — relevant for UK organisations with EU operations The UK Cyber Security and Resilience Bill is the domestic legislation. For UK organisations with operations, customers, or supply chains in EU member states, NIS2 — which came into force in October 2024 — creates parallel obligations that apply regardless of Brexit. NIS2 is broadly similar to the Bill in its approach: extended scope, IEC 62443 alignment for OT environments, incident reporting, and supply chain security requirements. The practical implication for UK organisations operating in EU markets is that IEC 62443 compliance — including radio conduit assessment — is not just a future UK regulatory requirement. It is a current EU obligation for in-scope organisations. What the Bill means specifically for industrial radio operators For an organisation that runs industrial radio as part of its OT infrastructure and is in scope of the Bill, four specific obligations follow from the IEC 62443 alignment: Radio conduits must appear in your zone-and-conduit model. IEC 62443-3-2 requires that all conduits be identified and assessed. A zone diagram that shows only wired network connections is not a complete IEC 62443 zone diagram — and will not demonstrate compliance with the Bill’s requirements. Radio conduits must have Security Level targets assigned. Every conduit in the zone model must have a Security Level target based on the consequence of compromise. For radio conduits carrying operational or safety-critical communications, SL2 is typically the minimum appropriate target. Technical controls must meet the assigned Security Level. For SL2, this means encryption of radio transmissions, authentication of radio users, controlled access to talkgroups, and a radio asset register. Unencrypted radio conduits — analogue or unencrypted DMR — do not meet SL2 requirements and represent a compliance gap under the Bill. Significant incidents involving radio systems must be reportable. If an industrial radio system is compromised — whether through interception, signal injection, or denial of service — and that compromise has a material impact on operations, it will likely meet the Bill’s incident reporting threshold. Having a radio network that has never been assessed, with no baseline documentation, makes incident detection and reporting significantly more difficult. The timeline and the window The Bill is currently progressing through Parliament. Secondary legislation defining the specific scope of organisations covered is expected through 2026. Enforcement is likely to become active in 2027 for the initial tranche of in-scope organisations, with the scope potentially widening further in subsequent tranches. That timeline creates a window — and it is worth using it. Organisations that begin IEC 62443 programmes now, including radio conduit assessment, will be in a significantly stronger position when enforcement arrives than those who wait for the secondary legislation to be finalised before acting. The radio infrastructure gap, in particular, takes time to remediate: migrating from analogue to encrypted DMR, implementing key management processes, and updating zone-and-conduit documentation are not tasks that can be completed in weeks. The organisations that will find the Bill most disruptive are those that have done nothing. The organisations that will find it manageable are those that have already begun — and have documentation to show for it. What to do now For industrial radio operators assessing their position ahead of the Bill, three immediate actions are worth taking: First, determine whether your organisation is likely to be in scope — either as a CNI operator under the Bill directly, or through Tier 1 supply chain requirements from customers already in scope. If you operate in water, energy, transport, health, or digital infrastructure, assume you are in scope until secondary legislation clarifies otherwise. Second, check whether your existing IEC 62443 programme — if you have one — includes your radio network. Ask specifically: does the zone-and-conduit diagram include wireless conduits? Was an RF survey conducted? Are your radio encryption status and licence compliance documented? If the answer to any of these is no, you have a radio assessment gap. Third, if you do not have an IEC 62443 programme, begin scoping one now. The radio infrastructure assessment is a natural starting point — it is a bounded, deliverable engagement that produces documentation immediately useful for a wider IEC 62443 programme, and it addresses the gap most likely to be missed if you bring in a cybersecurity firm to conduct the broader assessment. Yesway Communications provides IEC 62443 industrial radio conduit gap analysis — the specific assessment that addresses the wireless gap in most existing IEC 62443 programmes. We also provide IEC 62443 wireless security awareness training for OT security teams who need to understand how the standard applies to their radio infrastructure. Contact us to arrange a free 30-minute scoping call. Craig Miles is the founder of Yesway Communications and a wireless communications engineer with 30 years of experience across RF, industrial radio and satellite systems — including ILS engineering at Airbus Defence and Space on NATO satellite programmes. BSc · PGCE · QTS · Ofcom Licensed. IEC 62443 industrial radio security services ?

Need a standalone IEC 62443 wireless conduit assessment? Yesway is the only organisation offering a dedicated wireless conduit audit in the UK — covering SCADA telemetry, DMR, TETRA and unlicensed bands as a standalone service. Find out how the assessment works →

Author

  • craig miles

    TEDx Conversation

    Wireless communications engineer, technical educator and founder with 30 years of experience spanning aerospace, LEO satellite systems and RF engineering.

    Former ILS engineer at Airbus Defence and Space on NATO satellite and classified UK defence radio programmes.

    Founder of Yesway Communications — a Lincoln-based wireless communications specialist established in 2010, and ReachED, a new charitable initiative using LEO direct-to-device satellite connectivity to deliver education to the 273 million children globally without school access.

    TEDx Brayford Pool 2023 speaker. BSc · PGCE · QTS · Level 4 DSA Specialist Mentor · Ofcom Licensed · DBS Checked.