Peers have questioned why the UK's Cyber Security and Resilience Bill does not allow regulators to penalise senior executives when an organisation's failure to comply involves their consent, connivance, or deliberate or careless neglect. Baroness Kidron and Baroness Ludford backed probing amendments that would introduce personal civil liability for senior executives and make cybersecurity a board-level responsibility.
"The intention behind the amendment is to change the culture of an organisation, to ensure preventative action is taken, to avoid penalties," said Baroness Kidron. "As I said at the outset, culture change starts at the top."
Peers supporting the amendments pointed to financial sector rules introduced over the past decade that can impose regulatory or criminal liability on the C-suite for serious failings. They argued that the amendments would bring the bill closer to the EU's NIS2 directive, which includes senior management accountability measures, though personal liability is not mandatory under NIS2 and member states have implemented it differently.
Supporting the personal liability proposal, Lord Clement-Jones said: "If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it."
Despite support from several peers, the government defended its existing plan to impose substantial maximum fines and introduce security, resilience, and governance requirements through secondary legislation. Cybersecurity minister Baroness Lloyd of Effra said: "It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities." She cited the maximum fines of £17 million or 4 percent of the offending organisation's annual turnover, whichever is higher, calling it "a meaningful enforcement regime."
Baroness Lloyd said the forthcoming security and resilience requirements would mandate board-level governance in line with the NCSC's Cyber Assessment Framework. The government has yet to consult on the details. "That will cover issues such as organisational capability, senior responsibility, and accountability for security and resilience and effective risk escalation, and it is in that way that we will connect the clarity on what is expected of boards with the accountability through the enforcement regime."
Separately, peers quizzed the government on the structure of the bill's strict reporting requirements, warning that the current wording threatens to overwhelm regulators with an administrative burden. The bill requires regulated organisations to issue an initial notification within 24 hours and a fuller report within 72 hours. It defines an incident as an event that has, or is capable of having, an adverse effect on an operation. Former security minister Baroness Neville-Jones suggested changing the wording from "capable of" to "likely to have" to reduce the reporting burden, while Lord Clement-Jones warned of "an administrative tsunami of defensive reporting."