Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Politics

Peers push for personal liability for executives in UK cyber security bill

Members of the House of Lords urged the government to let regulators hold senior executives personally liable under the Cyber Security and Resilience Bill.

During a Lords debate, Baroness Kidron and Baroness Ludford advocated for amendments to the Cyber Security and Resilience Bill that would create personal civil liability for senior executives whose consent, collusion, or careless neglect leads to cyber-security breaches. They said such measures would shift organisational culture and ensure preventative action starts at the top. The government, through cybersecurity minister Baroness Lloyd of Effra, opposed the amendment, emphasizing the bill’s existing enforcement tools, including fines up to £17 million or 4 percent of turnover and board-level governance requirements drawn from the NCSC’s Cyber Assessment Framework.

Lords also raised concerns about the bill’s reporting obligations, with former security minister Baroness Neville-Jones and Lord Clement-Jones warning that one outlet wording could generate an “administrative tsunami” of defensive reporting. Baroness Harding suggested a longer reporting timeline, proposing a 14-day intermediate report and a final report after one month to capture a clearer picture of attacks. The government maintained that the two-stage reporting system is sufficient and that the risk of overseas misuse of collected data is low.

Why it matters

The debate could reshape how UK companies hold executives accountable for cyber failures, affecting board practices and regulatory penalties.

In this story

cyber security billpersonal liabilityboard responsibilityincident reportingfinesNIS2cyber resilience pledge
Get the beta ↗