Peers press for a fourteen day and a one month cyber incident report, and are refused

Technology and AI

Peers press for a fourteen day and a one month cyber incident report, and are refused

By Staff Writer  |  4 September 2026

The Victoria Tower and the river front of the Palace of Westminster in London under a bank of cloud

The Lords Grand Committee spent its second day on the Cyber Security and Resilience Bill arguing over how many times a breached operator should have to report. The bill requires an early alert within 24 hours and a full notification within 72 hours. A peer who has led a company through an attack wanted two more stages. The minister said no.

The Cyber Security and Resilience (Network and Information Systems) Bill passed the Commons on 16 June 2026 and had its second reading in the Lords on 14 July. Committee stage in Grand Committee began on 1 September and continued on 3 September, when the committee worked from clause 15, on the reporting of incidents by regulated persons, to clause 36, before adjourning at 4.55 pm. Further sittings are listed for 7 and 9 September.

The regulated groups are operators of essential services, data centres, relevant digital service providers and relevant managed service providers. As drafted, the bill requires each of them to make an initial report within 24 hours of an incident and a full notification within 72 hours.

Two more stages

Baroness Harding of Winscombe moved amendments, supported by Baroness Kidron and Lord Holmes of Richmond, to add an intermediate report capped at 14 days after first notification, or sooner if the regulator requires, and a final report within one month, in each case without undue delay. Because the bill deals with the four groups separately, each change had to be repeated four times. She said the staging follows the European Union's NIS2 directive, and she spoke from having led a telecommunications company through an attack ten years ago: in the first hours nobody knows what has happened, after 72 hours the real data begins to arrive, and only after a couple of weeks is there a proper sense of the scale. Every incentive in that period, she said, is to say nothing, which is why the later stages need to be in the legislation.

Baroness Lloyd of Effra, the minister, said the staged approach in the bill had been developed in consultation with industry and had been quantified in the impact assessment. The 24 hour alert gives regulators and the National Cyber Security Centre early awareness and lets them see whether more than one entity is affected; the 72 hour report gives them actionable detail. Regulators can also request further information about a reported incident under the information gathering powers in clause 15. By her calculation the amendments could produce up to five stages of reporting.

The model set out in the Bill strikes the right balance. It will provide clarity to potential affected regulated organisations.

Baroness Lloyd of Effra, Parliamentary Under-Secretary of State (Minister for Space, Cyber and Regulatory Reform)

She also resisted, as a precaution, amendments in the name of Lord Ashcombe that would have moved the full notification from 72 hours to 30 days, saying that would leave regulators with nothing after the initial alert.

The door and the report stage

Lord Clement-Jones said the minister's account of industry consultation was at odds with the experience of organisations that had lived through a major attack, and asked her to publish which sectors had been consulted and which had agreed the reporting model. Baroness Harding said the reliance on regulators' discretion to ask for more added uncertainty rather than removing it, and that a company under attack wants clear guardrails.

I had hoped that we could have follow-up discussions between now and Report, but I feel like the door has been rather slammed in my face.

Baroness Harding of Winscombe, Conservative peer

She withdrew the amendment, noting the support it had drawn from across the committee and saying she expected to return to it. Three government amendments to clause 15 were then agreed, including one requiring an operator of an essential service to consider whether any data relating to the service has been compromised, not only data relating to its users, when deciding whether an incident is reportable. Clause 15 was agreed as amended, and clauses 16 to 36, with schedules 1 and 2, were agreed.

Data centres are a regulated group in their own right under the bill. Anyone building, operating or contracting for one in the United Kingdom should read clause 15 as it stands, because the reporting clock it sets is the one the government intends to keep.

Committee stage is where a bill is tested rather than changed. The test on 3 September was whether the government would move on incident reporting. It did not, and the peers who pressed it have said they will bring the question back on report.