NewsGator+
All NewsTechnologyScienceSportsBusinessLifestyleShowbizWorld
Weekly Brief
NewsGator+
All NewsTechnologyScienceSportsBusinessLifestyleShowbizWorld
Weekly Brief
  1. Home
  2. /
  3. Technology
  4. /
  5. Peers ask why UK cyber bill leaves execs off the p...
Technology

Peers ask why UK cyber bill leaves execs off the personal liability hook

Peers have questioned why the UK's Cyber Security and Resilience Bill does not allow regulators to penalize senior executives when an organization's failure to…

6 min read
Peers ask why UK cyber bill leaves execs off the personal liability hook
Executive DigestOriginal Reporting by The Register

This is a curated overview of the story reported by The Register. Full text remains copyright of the publisher.

Read Full Story on The Register →
Peers have questioned why the UK's Cyber Security and Resilience Bill does not allow regulators to penalize senior executives when an organization's failure to comply involves their consent, connivance, or deliberate or careless neglect. Echoing arguments heard across the industry for years, Baronesses Kidron and Ludford backed probing amendments that would introduce personal civil liability for senior execs and make cybersecurity a board-level responsibility. "The intention behind the amendment is to change the culture of an organization, to ensure preventative action is taken, to avoid penalties," said Baroness Kidron. "As I said at the outset, culture change starts at the top." The Register has previously reported on calls for NHS organizations, some of which would be covered by the bill's reforms, to treat cybersecurity as a board-level priority. More recently, 60 organizations committed to the aims of the UK government's Cyber Resilience Pledge, promising to ensure their boards take responsibility for their organization's cybersecurity. Peers supporting the amendments pointed to financial sector rules introduced over the past decade that can impose regulatory or criminal liability on the C-suite for serious failings. They argued that the amendments would bring the bill closer to the EU's NIS2 directive, which includes senior management accountability measures. Personal liability is not mandatory under NIS2, however, and member states have implemented it differently. Supporting the personal liability proposal, Lord Clement-Jones said: "If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it." Despite support from several peers, the government defended its existing plan to impose substantial maximum fines and introduce security, resilience, and governance requirements through secondary legislation. "It is absolutely right that organizations, especially those delivering our essential services, are held properly accountable for their activities," said cybersecurity minister Baroness Lloyd of Effra, who did not support the personal liability amendment. She cited the maximum fines of £17 million or 4 percent of the offending organization's annual turnover, whichever is higher, calling it "a meaningful enforcement regime." Baroness Lloyd said the forthcoming security and resilience requirements would mandate board-level governance in line with the NCSC's Cyber Assessment Framework. The government has yet to consult on the details. "That will cover issues such as organisational capability, senior responsibility, and accountability for security and resilience and effective risk escalation, and it is in that way that we will connect the clarity on what is expected of boards with the accountability through the enforcement regime." Reporting requirements and other matters Separately, peers quizzed the government on the structure of the bill's strict reporting requirements, warning that the current wording threatens to overwhelm regulators with an administrative burden. One of the CSR bill's primary objectives is to collect more data about the threats facing UK organizations by imposing stricter reporting requirements on in-scope entities. The bill requires regulated organizations to issue an initial notification within 24 hours and a fuller report within 72 hours. It defines an incident as an event that has, or is capable of having, an adverse effect on an operation. Former security minister Baroness Neville-Jones suggested changing the wording from "capable of" to "likely to have," to reduce the reporting burden on regulated organizations. Lord Clement-Jones agreed, warning that the current wording would "unleash an administrative tsunami of defensive reporting." He also argued that the government's definition of a data compromise was overly broad and "dramatically expanding the notification net to include technical data anomalies that cause zero disruption or loss to actual customers." He said the reporting rules and broad definition of compromise could leave responsible operators of essential services spending more time on paperwork than improving their defenses. The government was unmoved, and Baroness Lloyd said that the more stringent reports were crucial in achieving the aims of the bill, which seeks to update the existing NIS Regulations 2018. While some peers were looking to ease the burden of reporting, others sought to increase it in other areas. Baroness Harding, who is uniquely placed to weigh in on cyberattack response, proposed a 14-day intermediate report and a final report due one month after the attack first occurred. Drawing on her experience as the former TalkTalk CEO, she said that after 72 hours, attacked organizations start to get "real data," but "it's really only after a couple of weeks that you've got a proper sense of what has happened." The final report comes at the one-month mark, when "the fog is starting to clear and you have a proper sense of the real scale of the problem," she said. Harding said that senior executives are typically told from all sides not to say anything about a cyberattack, but this only serves the criminals, who meanwhile may be attacking other victims. "If you share this information in the fog with regulators and with law enforcement agencies, that's how the law can prevail," she said. "It's how regulators can work out what's happening, it's how they can warn others who might be affected, and it's how the law enforcement agencies can do their work to actually try and find the bad guys." Baroness Lloyd defended the bill's existing two-stage process, arguing that it already provides information at the points when regulators need it. She reaffirmed that the initial 24-hour report alerts the NCSC and allows it to determine whether other organizations are affected, while the 72-hour report will contain the necessary details to enable a more actionable response. "We believe that the stages we set out meet that. They have been carefully developed to provide the right notification at the appropriate time," she told peers. "They have been developed in consultation with industry, as many noble Lords exhorted in the previous group. "Crucially, under the information-gathering powers in Clause 15, regulators can also request further information about an incident that has been reported to them if they consider this necessary to understanding the incident and how it is being managed. "Obviously, that may be appropriate in some incidents and not in others. That kind of practical balance is enabled by the bill." Separately, the Grand Committee spent the second day scrutinizing the bill, fleshing out datacenters' responsibilities, as well as examining requirements to notify affected downstream customers within 24 hours of a breach instead of 72 hours. The government also rejected concerns that cybersecurity data collected under the reporting rules could contribute to unfair overseas proceedings. Baroness Lloyd said ministers had considered the issue and assessed the risk as very low. ®
#security
0 views0 shares
The Register
September 7, 2026
9:15 AM
0 comments
Join the discussion
Category
Technology
Original source
Read at source →
0
0

Related Articles

Salesforce has built the TSA a new AI agent to make travelling less awful for everyone
TechRadar·16h ago·Technology

Salesforce has built the TSA a new AI agent to make travelling less awful for everyone

Salesforce has revealed Ace, a new AI agent for the TSAAce should take the pressure of answering basic questions off human agentsAce has already resolved 96% of basic inquiries so farSalesforce has built the Transportation Security Administration (TSA) a new AI agent to try and help streamline trave…

Considering a Level 2 EV charger? How to know if you need one
Engadget·16h ago·Technology

Considering a Level 2 EV charger? How to know if you need one

Charging your EV from home is cheap and convenient, but knowing which type of charger will get the most out of your electric car can often be confusing.

Nvidia RTX 5090 GPU prices skyrocket to $9,000 — as fresh RTX 6000 rumor suggests a 2027 launch that fills me with dread
TechRadar·16h ago·Technology

Nvidia RTX 5090 GPU prices skyrocket to $9,000 — as fresh RTX 6000 rumor suggests a 2027 launch that fills me with dread

Nvidia's RTX 5090 is now over $9,000 in the USA new rumor suggests that RTX 6000 gaming GPUs are coming in 2027, maybe in the first half of the yearIf true, the price tag that's attached to the RTX 6090 will likely be colossal, and lower-tier GPUs could be pricey tooNvidia's RTX 5090 flagship has hi…

India escalates Apple probe over alleged iOS 18 issues that incurred repair costs
9to5Mac·16h ago·Technology

India escalates Apple probe over alleged iOS 18 issues that incurred repair costs

India’s Central Consumer Protection Authority (CCPA) has reportedly escalated its probe into whether Apple should be held responsible for an iOS 18 update that allegedly caused display and microphone issues on some iPhones. Here are the details. more…

Stay Informed.

The day's biggest stories, curated and trusted.

Browse CategoriesSearch Articles
NewsGator .
Privacy PolicyTerms of ServiceContactAbout Us
© 2026 NewsGator. Aggregating news from trusted sources.