Peers ask why UK cyber bill leaves execs off the personal liability hook
The UK's Cyber Security and Resilience Bill is facing scrutiny from peers who argue it doesn't adequately hold senior executives accountable for cybersecurity failures. While the bill includes substantial fines and governance requirements, amendments to introduce personal liability for executives are being debated. Concerns are also being raised about the reporting requirements, with some arguing the current wording creates an excessive administrative burden and potentially hinders effective response efforts. The government maintains that the existing reporting structure provides sufficient information at the critical times needed by regulators and law enforcement.
The UK's Cyber Security and Resilience Bill is facing significant debate in Parliament, with peers questioning the extent to which it holds senior executives responsible for cybersecurity failures. Several amendments are being proposed to introduce personal liability for executives, arguing that this would incentivize a shift in organizational culture towards proactive cybersecurity measures. Currently, the bill focuses on imposing substantial maximum fines and establishing security, resilience, and governance requirements through secondary legislation.
However, concerns remain about the bill's reporting requirements. Peers have voiced worries that the current wording, requiring organizations to issue initial notifications within 24 hours and a fuller report within 72 hours, creates an excessive administrative burden and could potentially hinder effective response efforts. Former security minister Baroness Neville-Jones suggested revising the language from "capable of" to "likely to have" to reduce the reporting burden.
Baroness Harding, drawing on her experience as a former TalkTalk CEO, proposed a 14-day intermediate report and a final report due one month after an attack, arguing that this would provide more meaningful data for regulators and law enforcement. The government, however, defended its existing two-stage reporting process, asserting that it provides sufficient information at the appropriate times.
Furthermore, the bill includes provisions for reporting data breaches to downstream customers within 24 hours, a change that has also been debated. The government has dismissed concerns that cybersecurity data collected under the reporting rules could contribute to unfair overseas proceedings, assessing the risk as low. The Grand Committee spent the second day scrutinizing the bill, fleshing out datacenters’ responsibilities, and examining the reporting requirements in detail. The debate highlights a broader tension between ensuring robust cybersecurity governance and avoiding an overly burdensome regulatory framework.