Jersey Cyber Security Law Passed: What Organisations Need to Know and How to Prepare
March 15, 2026
Jersey’s new Cyber Security Law has now been approved by the States Assembly, introducing new legal obligations for organisations providing essential services across the island.
The legislation is designed to strengthen Jersey’s cyber resilience and improve the reporting and management of cyber security incidents. With the law expected to come into force later this year, affected organisations should begin preparing now.
This article outlines who the law applies to, what it requires, and how we support organisations in taking practical steps towards compliance.
The Cyber Security Law establishes a formal framework for managing cyber risk in Jersey. It makes the Jersey Cyber Security Centre (JCSC) the national authority responsible for issuing cyber security guidance, standards, and oversight.
Under the law, organisations deemed critical to the island’s infrastructure must implement proportionate cyber security measures and report significant incidents within a defined timeframe.
The law applies to organisations classified as Operators of Essential Services (OES). These are organisations that deliver services critical to the functioning of the island, including:
If your organisation operates in one of these sectors, the Cyber Security Law is likely to apply to you.
While not all businesses fall directly within scope, the law sets a clear benchmark for cyber security best practice across Jersey and is relevant to organisations of all sizes.
Organisations must take steps that are appropriate and proportionate to their size, risk profile, and the services they provide.
In practical terms, this includes:
This is not about adopting the most complex tools, but about demonstrating a clear, documented, and risk-based approach to cyber security.
Under the law, organisations must report any significant cyber security incident to the JCSC within 24 hours of becoming aware of it.
Having a defined incident response plan in place is essential to meeting this requirement. Without clear roles, processes, and escalation paths, organisations may struggle to respond effectively during an incident.
Cyber threats continue to increase in frequency and sophistication. As highlighted during the States debate, a single vulnerability can lead to serious operational disruption, financial loss, and reputational damage.
Once in force, organisations that fail to comply with the law may face financial penalties of up to £10,000. However, the greater risk is often the impact of an unmanaged or poorly handled cyber incident.
Preparing early allows organisations to reduce risk, improve resilience, and avoid reactive decision-making under pressure.
At OneCollab, we support organisations in understanding and applying cyber security in a practical, business-focused way.
Our cyber security services include:
Our approach focuses on building cyber resilience that works in day-to-day operations — not just compliance on paper.
With the Cyber Security Law expected to come into force later this year, now is the right time to assess your organisation’s readiness.
Whether you are directly impacted as an Operator of Essential Services or want to align with Jersey cyber security best practice, early preparation will put you in a stronger position.
If you would like to sense-check your current approach or discuss how the law applies to your organisation, please contact OneCollab today.
Cyber security shouldn’t be a headache. Get clear and actionable insights delivered straight to your inbox. We make complex threats understandable, empowering you to make informed decisions and protect your business.
Call us +44 20 8126 8620
Email us [email protected]