UK peers push for personal liability for executives in Cyber Security Bill

Amendments to hold senior leaders accountable for cybersecurity failures fail to gain government support

edit
By LineZotpaper
Published
Read Time3 min
Crossbench peers in the House of Lords have proposed amendments to the UK's Cyber Security and Resilience Bill that would introduce personal civil liability for senior executives whose organisations fail to comply with cybersecurity requirements, but the government has resisted the changes, arguing that existing maximum fines of £17 million or 4% of turnover are sufficient to drive change.

Peers have questioned why the UK's Cyber Security and Resilience Bill does not allow regulators to penalise senior executives when an organisation's failure to comply involves their consent, connivance, or deliberate or careless neglect. Baroness Kidron and Baroness Ludford backed probing amendments that would introduce personal civil liability for senior executives and make cybersecurity a board-level responsibility.

"The intention behind the amendment is to change the culture of an organisation, to ensure preventative action is taken, to avoid penalties," said Baroness Kidron. "As I said at the outset, culture change starts at the top."

Peers supporting the amendments pointed to financial sector rules introduced over the past decade that can impose regulatory or criminal liability on the C-suite for serious failings. They argued that the amendments would bring the bill closer to the EU's NIS2 directive, which includes senior management accountability measures, though personal liability is not mandatory under NIS2 and member states have implemented it differently.

Supporting the personal liability proposal, Lord Clement-Jones said: "If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it."

Despite support from several peers, the government defended its existing plan to impose substantial maximum fines and introduce security, resilience, and governance requirements through secondary legislation. Cybersecurity minister Baroness Lloyd of Effra said: "It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities." She cited the maximum fines of £17 million or 4 percent of the offending organisation's annual turnover, whichever is higher, calling it "a meaningful enforcement regime."

Baroness Lloyd said the forthcoming security and resilience requirements would mandate board-level governance in line with the NCSC's Cyber Assessment Framework. The government has yet to consult on the details. "That will cover issues such as organisational capability, senior responsibility, and accountability for security and resilience and effective risk escalation, and it is in that way that we will connect the clarity on what is expected of boards with the accountability through the enforcement regime."

Separately, peers quizzed the government on the structure of the bill's strict reporting requirements, warning that the current wording threatens to overwhelm regulators with an administrative burden. The bill requires regulated organisations to issue an initial notification within 24 hours and a fuller report within 72 hours. It defines an incident as an event that has, or is capable of having, an adverse effect on an operation. Former security minister Baroness Neville-Jones suggested changing the wording from "capable of" to "likely to have" to reduce the reporting burden, while Lord Clement-Jones warned of "an administrative tsunami of defensive reporting."

§

Analysis

Why This Matters

  • The Cyber Security and Resilience Bill will impose stricter cybersecurity obligations on critical national infrastructure and other regulated entities; how enforcement is structured will directly affect corporate behaviour and accountability.
  • Personal liability for executives could drive a cultural shift in boardrooms, making cybersecurity a genuine board-level priority rather than a compliance checkbox.
  • The outcome will influence how the UK balances deterrence against regulatory burden, especially given the bill's extensive reporting requirements.

Background

The Cyber Security and Resilience Bill is a UK government proposal to strengthen cybersecurity across critical sectors, building on the existing Network and Information Systems (NIS) Regulations. It introduces mandatory incident reporting, enhanced security requirements, and a new enforcement regime with fines up to £17 million or 4% of turnover. The bill is currently progressing through Parliament, where amendments can be debated and voted on. Similar debates have occurred in the EU with NIS2, which includes provisions on senior management accountability but leaves implementation to member states. The UK government has previously encouraged organisations through initiatives like the Cyber Resilience Pledge to make cybersecurity a board-level responsibility.

Key Perspectives

Supporters of personal liability (Baroness Kidron, Lord Clement-Jones): Argue that holding senior executives personally accountable is essential to change organisational culture. They point to existing financial sector rules and the EU's NIS2 directive as precedents. Government (Baroness Lloyd of Effra): Maintains that the existing enforcement regime of significant fines plus forthcoming secondary legislation on board-level governance is sufficient. They prefer to mandate responsibility through requirements rather than personal liability. Critics of the bill's reporting regime (Baroness Neville-Jones, Lord Clement-Jones): Warn that the current 24-hour notification requirement with a broad definition of “incident” could produce excessive defensive reporting, overwhelming both companies and regulators.

What to Watch

  • The outcome of the amendment debate as the bill moves through the Lords—whether personal liability provisions are reintroduced or the government stands firm.
  • The publication of the government's consultation on the security and resilience requirements, which will detail exactly what is expected of boards.
  • How the final reporting threshold is defined ("capable of" vs. "likely to have"), which will significantly affect the administrative burden on regulated entities.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.