House of Lords peers proposed amendments to the UK Cyber Security and Resilience Bill that would make senior executives personally civilly liable for serious cybersecurity failures. The government rejected the measure, citing proposed penalties of up to £17 million or 4% of annual turnover and forthcoming board-governance requirements. Peers also warned that the bill's 24-hour incident-notification and 72-hour detailed-reporting deadlines could drive defensive over-reporting, while the government said the measures are needed to modernize the NIS Regulations 2018 and enable NCSC response.
Liberal Democrat peer Lord Tim Clement-Jones also sought emergency powers for the government to deactivate dangerous AI systems and, in national-security emergencies, shut down data centers. He framed the AI “kill switch” as a last-resort control against autonomous systems compromising critical national infrastructure, including misuse by state-backed actors or ransomware groups. Industry voices supported emergency controls in principle but cautioned that the UK's dependence on foreign technology suppliers would limit their practical effectiveness without greater sovereign technology capacity and procurement reform.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
At CyberUK in Glasgow, the Security Minister announced a voluntary Cyber Resilience Pledge for organizations. Signatories must implement the Cyber Governance Code of Practice and commit to board cyber training, NCSC Early Warning registration, and Cyber Essentials coverage across their supply chains; the formal launch is planned for summer 2026.
The UK government issued a Cyber Governance Code of Practice to support boards and directors of medium and large public- and private-sector organisations in governing cyber risk. The framework covers risk management, strategy, people, incident response and recovery, and assurance and oversight, alongside government-provided board training and a cybersecurity toolkit.
The UK government proposed amendments to the Cyber Security and Resilience Bill that would let ministers restrict high-risk suppliers serving essential-service organisations, including by blocking new deployments or requiring existing technology to be removed, disabled, or modified. The amendments would also permit a mandatory referral scheme requiring government clearance for specified critical-technology purchases, subject to parliamentary approval.
Lord Tim Clement-Jones proposed amendments to give the UK government emergency authority to deactivate dangerous AI systems and shut down data centers during national-security threats. The proposal was presented as a safeguard against autonomous AI compromising critical national infrastructure.
Peers challenged the bill's requirement for initial incident notifications within 24 hours and detailed reports within 72 hours, warning that its threshold could generate defensive reporting. The government defended the two-stage process as necessary for the NCSC to assess wider exposure and coordinate an actionable response.
House of Lords peers backed amendments to the Cyber Security and Resilience Bill that would impose personal civil liability on senior executives whose consent, connivance, or neglect contributes to serious organizational noncompliance. The UK government opposed the proposal, citing organizational fines of up to £17 million or 4% of annual turnover and planned board-governance requirements.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
isms.online
Open sourceteiss.co.uk
Open sourcetheregister.com
Open sourceitpro.com
Open sourcegov.uk
Open sourcegov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.