Peers ask why UK cyber bill leaves execs off the personal liability hook

The UK's Cyber Security and Resilience Bill is facing scrutiny from peers who argue it lacks sufficient personal accountability for senior executives in cases of organizational cybersecurity failures. Amendments proposed to introduce personal civil liability for executives, drawing parallels with financial sector regulations and the EU's NIS2 directive, were debated. Proponents, including Baronesses Kidron and Ludford, contend that individual responsibility is crucial for driving a top-down cultural shift in cybersecurity practices. The government, however, maintains that substantial corporate fines of up to £17 million or 4% of turnover, combined with forthcoming mandatory board-level governance rules, provide adequate accountability. Peers also raised concerns about the bill's reporting requirements, fearing an "administrative tsunami" due to broad definitions of incidents and data compromises, potentially diverting resources from defense to compliance. Conversely, others argued for more stringent reporting timelines to facilitate better threat intelligence sharing and law enforcement action. The government defended its phased reporting structure as balanced and responsive to regulator needs.

AI Signal Decode

Peers are advocating for amendments to the UK's Cyber Security and Resilience Bill that would introduce personal civil liability for senior executives whose consent, connivance, or neglect contributes to an organization's cybersecurity failures. This push aims to foster a culture of preventative action and ensure cybersecurity is treated as a board-level responsibility, aligning with practices in the financial sector and the EU's NIS2 directive. The argument is that executives drawing high salaries should bear personal responsibility for securing critical national infrastructure and services. The government, however, prefers to rely on significant corporate fines and upcoming secondary legislation mandating board-level governance as sufficient deterrents and accountability measures.

The bill's proposed reporting requirements are a point of contention, with some peers expressing concern that overly broad definitions of cyber incidents and data compromises could lead to an "administrative tsunami." This could burden regulated organizations with excessive reporting obligations, diverting resources away from actual security enhancements. Baroness Neville-Jones suggested refining the definition of an incident from "capable of" to "likely to have" an adverse effect to mitigate this. Conversely, Baroness Harding proposed extending reporting timelines to allow for more comprehensive data collection and analysis, emphasizing the importance of sharing information with regulators and law enforcement to track attackers and warn potential victims.

The government has defended the bill's existing two-stage reporting mechanism, asserting that the initial 24-hour notification allows regulators to assess broader impacts, while the 72-hour report provides necessary detail for actionable responses. Cybersecurity minister Baroness Lloyd highlighted that regulators can also request further information under Clause 15, offering a degree of flexibility. The government also rejected concerns about cybersecurity data collected being used in overseas proceedings, deeming the risk very low. The debate underscores a fundamental tension between promoting proactive security culture through personal accountability and balancing regulatory burdens with operational realities.