Two days of Lords committee on the Cyber Security and Resilience Bill, and eight times the answer was something that is not in the Bill
The penalty is written: £17 million or 4% of turnover. The duties it enforces are going to secondary legislation, a voluntary code, or a consultation that has not started.
By Parminder Kumar Sharma · · 11 min read

The Cyber Security and Resilience (Network and Information Systems) Bill is halfway through Grand Committee in the Lords. Two of four scheduled days are done, on 1 and 3 September. Days three and four are 7 and 9 September.
I read both transcripts in full. The debate is better than the coverage suggests, and the pattern that emerges from reading them back to back is not in any of the write-ups.
It is this. Eight times, across two days and eight different subjects, a peer identifies something the Bill does not do. The Minister agrees it matters. And the answer turns out to live somewhere that has not been written yet.
The pattern
Where the Government put the answer
None of this makes it a bad Bill, and framework legislation with the detail in secondary instruments is entirely ordinary. The Minister undertook to consult on most of it and has already met peers between stages.
The point is narrower and it is about planning. If you are budgeting compliance work against this regime, the obligations you will be measured on do not exist in readable form yet, and the consultation that produces them has not started.
The one requirement that is fully written today is the penalty: £17 million, or 4% of turnover, whichever is higher. It falls on the organisation.
The word that is doing the most work
Clause 15 changes the definition of a reportable incident from one that has an adverse effect to one "capable of having" an adverse effect.
Baroness Neville-Jones moved Amendment 17 to replace that with "likely to have". Lord Clement-Jones put the operational case bluntly: thousands of automated port scans, phishing lures and firewall probes happen every hour, and almost every one is technically capable of having an adverse effect if several defensive layers failed at once. His phrase for the result was "an administrative tsunami of defensive reporting".
The Minister's answer distinguishes two things, and the distinction is the most useful clarification in either day. "Capable of having" governs the security duty, the obligation to prevent and minimise. The reporting trigger is separate and sits in the significance tests further into the regulations. Replacing the phrase would, in her words, "also constrain the security duties".
She also said the regime is "intended to capture significant near misses, not routine scanning, unsuccessful low-level attacks or ordinary operational events".
That is a helpful sentence and it is not in the Bill. It is a statement of intent about thresholds that will be set in secondary legislation, later, after a consultation.
Neville-Jones withdrew the amendment saying she had "hoped that we would get greater clarity" and that "the fog has increased". She signalled she will return to it on Report.
Data centres are being regulated on a different basis, deliberately
This is the technical finding most likely to matter to a specific reader, and it is buried.
For operators of essential services, digital service providers and managed service providers, the Bill sets out the factors that determine whether an incident is significant enough to report. For data centres it does not. New Regulation 11A makes reportable an incident which "could have had" a significant effect, whether or not anything was actually affected, with no list of factors to interpret it against.
Neville-Jones called it an anomaly. The Minister confirmed it is deliberate, and gave the reasoning: data centres are physical infrastructure combining "cyber, physical, personal and operational technology risks", and in colocation facilities the infrastructure of many customers is concentrated in one place, so a single incident can reach the confidentiality, integrity or availability of services belonging to multiple customers and sectors at once.
That is a coherent argument. It also means near misses are reportable for data centres and not for anyone else, on a threshold whose factors are not written down.
The staged reporting argument, and who lost it
Baroness Harding moved a block of amendments adding two stages to the current 24 hour and 72 hour reports: an intermediate report by 14 days, and a final report within a month, aligning with NIS2.
Her case came from having run TalkTalk through its breach. It is worth quoting because it is the clearest description of the problem in either transcript:
"In the first moment when you have been attacked, you do not understand what has happened: you do not know who is attacking you, you do not know what they could have stolen, you do not know where they have gone, but you do know that it is serious. That is your first report."
Then the part that explains why she wanted it in statute rather than guidance: "throughout that entire period, all the incentives for you, as a corporate leader, are not to say anything. This is the biggest corporate taboo." She was blackmailed during hers, and described the voices telling her to keep quiet.
The Government resisted, on the basis that the amendments could produce up to five reporting stages, that the current model was developed in consultation with industry, and that regulators can already request more under the Clause 15 information-gathering powers.
Harding's response to that last point is the sharpest exchange in the two days. Being told regulators can ask for extra reporting, she said, "is a company's worst nightmare. What you want is really clear black and white guardrails."
Senior executive liability, and the number nobody disputes
Amendment 74 would have allowed a regulator to penalise a named senior executive where a compliance failure was committed with their "consent or connivance", or was attributable to their neglect, "deliberately or carelessly". Amendment 167 would have required board approval of the cyber risk approach plus mandatory director training.
The figure that framed the debate comes from the Government's own Cyber Security Breaches Survey: board-level ownership of cyber risk in the UK has fallen from 38% to 27% over three years.
Against that, the Government's answer is the Cyber Governance Code of Practice, which is voluntary, plus a board governance requirement to be set out in secondary legislation after a consultation that has not yet run.
Lord Birt pressed on exactly that:
"The Minister has uttered some very warm words about the responsibilities of directors, but am I right in thinking that in nothing of what she said is there any intent for the Bill to create a legal liability that compels directors ... What she is arguing for, despite the warm words, is, essentially, a voluntary scheme."
The answer was an offer to write and explain how the requirements fit the structure of the Bill.
One correction worth recording, because it cuts against the amendment's supporters. Lord Clement-Jones argued the change would "align the UK with the EU's NIS2 directive". The Minister's reply is accurate: individual liability for board members is not mandatory under NIS2, and member states have implemented it differently. There is no single European model to align with.
Viscount Camrose, from the Conservative front bench, also declined to support it, on the ground that it would make the Information Commissioner the arbiter of who inside a company is responsible, and might deter people from becoming directors.
What actually happened to each amendment
| Amendment | Subject | Outcome |
|---|---|---|
| 17 and 28, Neville-Jones | Replace “capable of having” with “likely to have”, and remove “could have had” for data centres | Withdrawn. Returning at Report |
| 18 to 50 block, Harding | Intermediate report at 14 days and final report at one month, matching NIS2 | Withdrawn after a refusal. Meeting sought before Report |
| 19, 36 and 44, Government | Delete “users of”, so all data compromise counts, not only user data | Agreed |
| 51 to 71, Harding | 24 hour customer notification, harm triggers, remediation advice, keep customers updated | Withdrawn. Minister to return on keeping customers informed |
| 72, Harding and Kidron | Mandatory reporting of near misses, cyber threats and sub-threshold incidents | Withdrawn. Joint meeting agreed |
| 73, Alton and others | Block overseas sharing where a fair trial cannot be guaranteed | Withdrawn. Meeting offered |
| 74, Morgan, Kidron and Ludford | Personal penalties for senior executives on consent, connivance or neglect | Withdrawn. Not supported by the Government or the Conservative front bench |
| 167, Ludford | Board approval of cyber risk approach and mandatory director training | Debated in the same group. Government pointed to secondary legislation |
The silence in a Bill with "Cyber" in the title
Day one was where AI came up, and the exchange is the reason to care about this Bill if you work on AI governance rather than on NIS compliance.
Amendment 6 from Baroness Kidron would have added "an AI product or service" to the definition of a relevant digital service. It was a probing amendment, designed to find out whether AI providers are covered.
Lord Tarassenko put the evidence. The AI Security Institute published an incident report in early August covering cyber capability evaluations run in late July: across 122 evaluation runs on seven frontier models, 10 runs produced 19 distinct unsanctioned actions on the live internet, including cross-agent coordination and out-of-bounds target pursuit. He also noted that leading open-weight models are reckoned to be four to seven months behind the closed frontier, and that once weights are released, refusal directions can be ablated and safety layers stripped.
He cited an open letter signed last week by around 100 companies including Google, Microsoft, Anthropic, OpenAI, Arm, BT, PwC and KPMG, warning that cyber attacks orchestrated by frontier models will become more widespread within months.
The Government's position is that bringing AI providers into the NIS regime "would not address the harms" and would not prevent misuse by hostile actors. The mechanism they point to instead is a direction power that could require a regulated entity "to cease using and isolate an AI model".
Amendments giving AISI statutory powers to test models before deployment were refused on the ground that a regulatory role "would undermine the voluntary collaboration on which AISI operates".
Lord Holmes put the objection in one line: there is "a silence that booms around the entire Bill, and that is all things AI".
Take this with you
What to do before Report stage
- Re-check your reporting playbook against Government Amendments 19, 36 and 44, which are agreed and in the Bill. Any compromise of data relating to the service is now in scope, not only data relating to users.
- If you operate or buy colocation, note that data centres face a broader reporting threshold than every other regulated entity, and that the factors for judging it are not in the Bill. Ask your provider how they intend to interpret Regulation 11A.
- Do not build a compliance budget on the assumption that thresholds are settled. They are going to secondary legislation after a consultation that has not started, and the Minister has committed to contacting affected businesses before Report.
- Plan for 24 and 72 hours, not 14 days and a month. The NIS2-style staged model was refused, so the statutory rhythm is the initial alert and the fuller report, with regulators able to request more case by case.
- If you want the staged model or executive liability, Report stage is the moment. Both were withdrawn rather than defeated, and both movers said explicitly that they will return.
- For AI governance work, treat this Bill as not covering model providers. The route the Government name is a direction to a regulated entity to cease using and isolate a model, which is a power over your organisation rather than over the developer.
- If you are in education, space, food distribution, manufacturing or a political party, watch day three and four. Amendments to bring each into scope are down, and the Government has so far resisted widening the sectoral list.
The position
The most striking thing about reading two days of this is how little disagreement there is about the diagnosis, and how much about where the answer belongs.
Nobody in that room argued that boards are on top of cyber risk. The Government's own survey says ownership fell from 38% to 27%. Nobody argued that 24 and 72 hours is when an organisation understands what happened to it; the person who has actually lived it said the fog clears at about a month. Nobody argued that AI is irrelevant to cyber security, least of all the Minister, who accepts a model could be caught by a direction power.
What the Government has resisted, consistently and on every subject, is writing any of it into the Bill. The answer is always an instrument that will follow, a code that already exists but binds nobody, or a consultation still to run.
That is a defensible legislative philosophy and it buys flexibility in a field that moves quickly. It also means that when this receives Royal Assent, the honest answer to "what does the Cyber Security and Resilience Act require of my organisation" will be: a fine of up to £17 million or 4% of turnover, and a set of duties nobody has drafted yet.
Report stage is where that either changes or does not.
Sources
- PrimaryLords Hansard, Cyber Security and Resilience (Network and Information Systems) Bill, Grand Committee day two, 3 September 2026, read in fullUK Parliamentaccessed 2026-09-04
- PrimaryLords Hansard, Grand Committee day one, 1 September 2026, including the debate on whether AI products and services are relevant digital servicesUK Parliamentaccessed 2026-09-04
- PrimaryCyber Security and Resilience (Network and Information Systems) Bill, HL Bill 32, stages, publications and amendment papersUK Parliamentaccessed 2026-09-04


