Peers ask why UK cyber bill leaves execs off the personal liability hook
AI Signal Decode
Peers are advocating for amendments to the UK's Cyber Security and Resilience Bill that would introduce personal civil liability for senior executives whose consent, connivance, or neglect contributes to an organization's cybersecurity failures. This push aims to foster a culture of preventative action and ensure cybersecurity is treated as a board-level responsibility, aligning with practices in the financial sector and the EU's NIS2 directive. The argument is that executives drawing high salaries should bear personal responsibility for securing critical national infrastructure and services. The government, however, prefers to rely on significant corporate fines and upcoming secondary legislation mandating board-level governance as sufficient deterrents and accountability measures.
The bill's proposed reporting requirements are a point of contention, with some peers expressing concern that overly broad definitions of cyber incidents and data compromises could lead to an "administrative tsunami." This could burden regulated organizations with excessive reporting obligations, diverting resources away from actual security enhancements. Baroness Neville-Jones suggested refining the definition of an incident from "capable of" to "likely to have" an adverse effect to mitigate this. Conversely, Baroness Harding proposed extending reporting timelines to allow for more comprehensive data collection and analysis, emphasizing the importance of sharing information with regulators and law enforcement to track attackers and warn potential victims.
The government has defended the bill's existing two-stage reporting mechanism, asserting that the initial 24-hour notification allows regulators to assess broader impacts, while the 72-hour report provides necessary detail for actionable responses. Cybersecurity minister Baroness Lloyd highlighted that regulators can also request further information under Clause 15, offering a degree of flexibility. The government also rejected concerns about cybersecurity data collected being used in overseas proceedings, deeming the risk very low. The debate underscores a fundamental tension between promoting proactive security culture through personal accountability and balancing regulatory burdens with operational realities.