Business

New UK cyber law could make bosses personally liable

Ryan Brothwell 2 min read
New UK cyber law could make bosses personally liable

Key Points

  • Lords committee stage on the Cyber Security and Resilience Bill starts Tuesday 1 September
  • Day one amendments cover executive liability, AI and software firms, and data centre incidents
  • The bill as drafted does not impose personal liability on senior managers, unlike the EU's NIS2
  • Four committee days are scheduled, running to 9 September, with more possible
  • Royal Assent is expected late in 2026, with full implementation running to 2028

Peers will begin their line-by-line examination of the Cyber Security and Resilience (Network and Information Systems) Bill on Tuesday (1 September), with the personal liability of senior executives among the first amendments up for debate.

The bill sets tougher cyber security duties on organisations that run essential services in the UK, including healthcare, drinking water, and energy.

It also brings additional sectors into the regime, updates incident reporting duties, and hands the government powers to direct organisations in the interests of national security.

The bill as drafted stops short of making directors and senior managers personally answerable for a cyber failure at their organisation.

Legal firm Norton Rose Fulbright flagged that gap against the EU’s NIS2 directive, which does introduce personal liability for senior management. The firm said the two regimes also diverge on scope, penalties and the UK’s critical supplier designation.

Peers made the same point at second reading in July. “Unlike the EU’s NIS2, the Bill fails to mandate executive responsibility,” said Lord Clement-Jones, Liberal Democrat peer, who pointed to Jaguar Land Rover losing around £500 million in a single attack while sitting outside the bill’s scope entirely.

Members speaking on day one of committee stage will consider amendments on subjects including:

  • Inclusion of service providers under the new regulations, covering artificial intelligence, software manufacturers and platforms
  • Service providers that fall below megawatt size thresholds
  • The definition of a data centre incident
  • The liability of senior executives.

The bill entered the Lords on 25 June and cleared second reading on 14 July, having already passed every Commons stage after its introduction in November 2025.

Royal Assent is expected late this year, though most operational obligations will arrive through secondary legislation, with full implementation running to 2028.

Tuesday’s session starts at 15h45 on Parliament TV, and the Lords Hansard transcript follows around three hours after the debate.

Now read: MI5 and GCHQ open 2027 summer internship applications: Pay, dates, and who can apply