Peers ask why UK cyber bill leaves execs off the personal liability hook
Ministers say £17M corporate fines and forthcoming board-level governance rules provide sufficient accountability
Members of the UK Parliament have raised concerns about the Cyber Security and Resilience Bill, questioning the lack of provisions for senior executives to face personal liability when their organization's non-compliance is due to their negligence or deliberate actions. Baronesses Kidron and Ludford advocated for amendments to introduce personal civil liability for top executives and to embed cybersecurity as a board-level responsibility.
Baroness Kidron emphasized the importance of altering organizational culture to encourage proactive measures and prevent penalties.
The UK government has defended its plan to impose significant fines and introduce security measures through secondary legislation, stating that the maximum penalties of £17 million or 4% of the offending organization's annual revenue are sufficient. The forthcoming security and resilience requirements would require board-level governance aligned with the National Cyber Security Centre's Cyber Assessment Framework. However, the government has not yet consulted on the details.
Peers also examined the bill's reporting requirements, expressing worries that the current language might overwhelm regulators with administrative tasks. They suggested simplifying the reporting process by changing the wording "capable of" to "likely to have" to lessen the reporting load. Additionally, some peers proposed extending the reporting period to 14 days for intermediate reports and one month for final reports, arguing that this would allow organizations to gather more comprehensive data after a cyberattack.
Baroness Harding, a former TalkTalk CEO, emphasized the importance of timely reporting to assist regulators, law enforcement agencies, and other organizations facing similar threats.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.