I read both days of Lords committee on the UK Cyber Security and Resilience Bill. Eight times the answer to a gap was "secondary legislation", "a voluntary code", or "we'll write to you"
I read both days of Lords committee on the UK Cyber Security and Resilience Bill. Eight times the answer to a gap was "secondary legislation", "a voluntary code", or "we'll write to you" Source: http://pk-sharma.com
I read both days of Lords committee on the UK Cyber Security and Resilience Bill. Eight times the answer to a gap was "secondary legislation", "a voluntary code", or "we'll write to you"
Description
I read both days of Lords committee on the UK Cyber Security and Resilience Bill. Eight times the answer to a gap was "secondary legislation", "a voluntary code", or "we'll write to you" Source: http://pk-sharma.com
Reddit Discussion
The Bill is halfway through Grand Committee in the Lords. Days one and two were 1 and 3 September, days three and four are the 7th and 9th. Both transcripts are on Hansard, about 67,000 words between them. I read them in full because the news coverage is thin and mostly recycles the press notice.
The thing that struck me only appears if you read both back to back. Eight separate times, on eight unrelated subjects, a peer identifies something the Bill does not do, the Minister agrees the concern is real, and the answer turns out to be something that has not been written yet.
- Reporting thresholds and what counts as a "significant impact": secondary legislation, after a consultation that has not started
- The factors that trigger a data centre incident report: absent, although they are in the Bill for every other entity
- Board and senior executive accountability: the Cyber Governance Code of Practice, which is voluntary
- Staged reporting at 14 days and one month, matching NIS2: refused
- Near misses and sub-threshold incidents: voluntary trust groups
- Whether AI models are in scope: unnamed, possibly caught by a vendor direction power
- Statutory powers for AISI: refused
- Limits on sharing data with jurisdictions that cannot guarantee a fair trial: regulator discretion
The one requirement that is fully drafted today is the penalty. £17m or 4% of turnover, whichever is higher, on the organisation.
I want to be fair about this: framework legislation with the detail in secondary instruments is completely normal, and the Minister committed to consulting on most of it. It is not a scandal. But if you are trying to budget compliance work, the duties you will actually be measured against do not exist in readable form, and the consultation that produces them has not started.
Three things that ARE decided and worth acting on:
1. Government Amendments 19, 36 and 44 were agreed. They delete "users of" from the significance test, so you now have to consider whether any data relating to the service was compromised, not just data about users. The Minister said explicitly this pulls in commercially sensitive info and exposed usernames or access details. If your incident playbook triggers on customer data, that is stale.
2. Data centres get a broader threshold than everyone else, on purpose. Theirs covers incidents that "could have had" a significant effect, and the significance factors that exist for every other entity are omitted for them. The stated reasoning is colocation: one incident can reach multiple customers across multiple sectors. If you buy colo, worth asking your provider how they plan to read Regulation 11A.
3. Plan for 24 and 72 hours. Baroness Harding moved a big block of amendments adding a 14-day interim and a one-month final report, aligned to NIS2, on the basis of having run TalkTalk through its breach. Refused. Her line about being told regulators can just ask for more is worth quoting: "that is a company's worst nightmare. What you want is really clear black and white guardrails."
The stat that framed the accountability debate, from the Government's own Cyber Security Breaches Survey: board-level ownership of cyber risk in the UK has fallen from 38% to 27% over three years. The proposed answer is a voluntary code.
One correction, because it went the other way and I think it matters: it was argued in the debate that senior manager liability would "align the UK with NIS2". It would not. Individual board liability is not mandatory under NIS2 and member states implemented it differently. The Minister was right on that point and the amendment's supporters were not.
And in a Bill with "Cyber" in the title, AI is named nowhere. Amendments to define AI products as relevant digital services, and to give AISI statutory pre-deployment testing powers, were both resisted. The AISI one was refused on the ground that a regulatory role "would undermine the voluntary collaboration on which AISI operates". Meanwhile AISI's own August incident report found 19 distinct unsanctioned actions on the live internet across 10 of 122 evaluation runs on seven frontier models.
Everything contested was withdrawn rather than defeated, which in Committee usually means it comes back. Report stage is where this gets decided.
Disclosure: I write at pk-sharma.com and there is a longer version there with the amendment-by-amendment table, but the above is the finding.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a9abb70acd9273b4995c02a
Added to database: 09/04/2026, 12:37:04 UTC
Last updated: 09/05/2026, 00:22:22 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.