Summary
- Qualifying UK data centres will enter the Network and Information Systems regime, with Ofcom as operational regulator.
- CSBR warns that skills shortages could move technical staff from active defence into assurance work.
- Compliance will need to connect cybersecurity with power, cooling, controls, physical security, and incident response.
Britain’s proposed cyber resilience regime could expand compliance work faster than the workforce available to deliver practical security improvements, according to a report published as data centres prepare to enter statutory Network and Information Systems regulation.
The UK Cyber Skills Gap: Building Capability and Resilience, produced by the not-for-profit CSBR, argues that recruitment has become concentrated around experienced specialists while entry routes remain too narrow. New reporting and assurance duties could consequently draw technical staff away from engineering, monitoring, and incident response.
The government’s data centre factsheet says qualifying facilities will be designated as essential services, with Ofcom acting as their operational regulator.
The regulated system includes the building
The proposed threshold covers commercial data centres with a rated IT load of at least 1MW and enterprise facilities of at least 10MW operated solely for their owner’s internal use. Organisations brought into scope will have to notify the regulator, provide information, apply proportionate security and resilience measures, and report significant incidents.
The government’s definition extends beyond servers and networks to the building and its supporting infrastructure, including electricity, HVAC, environmental controls, physical security, and resilience systems. Cyber teams will therefore need to work alongside facilities engineering, operations, legal, risk, and senior management.
Incidents can move quickly across those boundaries. Compromised building-management credentials may affect cooling controls, while ransomware can interrupt monitoring, maintenance, or access systems. A power failure can expose weaknesses in communications and coordination even when the original fault was electrical rather than malicious.
Significant near misses are also expected to enter the reporting regime, acknowledging that a fault can reveal systemic weakness without causing an outage. Operators will need a common method for classifying events across electrical, mechanical, network, security, and supplier systems.
Evidence must lead back to engineering
Regulators need asset records, risk assessments, incident data, governance evidence, and clear responsibilities to assess whether essential services are protected. Problems arise when producing that evidence absorbs the same specialists responsible for fixing insecure systems and testing recovery plans.
Smaller operators and suppliers may face the greatest strain because cyber, operational technology, facilities, and compliance responsibilities are often concentrated among a few people. Hiring additional specialists remains difficult when the wider market is competing for the same experienced staff.
An effective compliance programme will have to connect documentation with operational work. Backup systems need credible tests, remote access must be controlled, firmware and software require disciplined management, and supplier accounts should be reviewed against their actual maintenance role.
Recovery exercises must also cross departmental boundaries. A response plan that restores corporate IT but leaves cooling controls, access systems, generator telemetry, or network management unavailable will not return the facility to normal operation.
The government plans to give Ofcom powers to request information, inspect premises, interview staff, and assess infrastructure. Detailed duties and reporting thresholds will follow through secondary legislation and consultation, giving operators an opportunity to map their assets and capability gaps before the final regime takes effect.
Workforce development cannot be confined to recruiting more people with cybersecurity titles. Facilities engineers, commissioning teams, maintenance contractors, and operational managers need enough knowledge to recognise insecure configurations and preserve evidence, while cyber specialists need to understand industrial controls and the safety consequences of isolating them.
Data centres currently lack sector-wide minimum requirements for cybersecurity and operational resilience despite their critical national infrastructure status. The legislation can close that gap, provided assurance work remains tied to maintenance, testing, remediation, and recovery rather than becoming a separate administrative system.

