UK Cyber Security Bill Proposes Stricter Reporting and Wider Scope
At a glance
- The Cyber Security and Resilience Bill was introduced in November 2025.
- Only 10% of surveyed UK IT professionals said they could meet the proposed 24-hour reporting rule.
- The Bill would extend requirements to managed service providers and data centres.
The UK government has proposed new cyber security legislation that would require faster incident reporting and expand the range of organisations covered by the rules. The development comes as survey data indicates limited readiness among industry professionals to comply with the proposed requirements.
The Cyber Security and Resilience Bill was introduced to Parliament in November 2025. According to government documents, the Bill would reform the existing Network and Information Systems Regulations 2018 by broadening its scope, shortening reporting timelines, and strengthening enforcement measures.
If enacted, the Bill would require organisations in scope to notify their regulator within 24 hours of becoming aware of a reportable cyber incident. A full incident report would then need to be submitted within 72 hours, as outlined in official guidance.
The proposed legislation would also include managed service providers, data centres, and certain critical suppliers within its regulatory framework. These changes are intended to help regulators and the National Cyber Security Centre provide support more quickly and improve the UK’s understanding of cyber threats.
What the numbers show
- Only 10% of 156 surveyed UK IT, compliance, and security professionals said they were confident their organisations could meet the proposed 24-hour notification rule.
- The Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses experienced a cyber security breach or attack in the previous year.
- Among medium-sized businesses, 65% reported a breach or attack, while 69% of large businesses did so.
Survey results published by VinciWorks in September 2026 showed that 38% of respondents believed they could meet the 24-hour reporting deadline in theory, but had not tested their procedures. Another 26% were unsure about their ability to comply, 17% said they were working toward readiness, and 9% stated they could not currently meet the deadline.
The Bill would give regulators the authority to impose financial penalties for non-compliance. According to official information, fines could reach up to £10 million or 2% of worldwide turnover for certain breaches, and up to £17 million or 4% of worldwide turnover for more serious failures, whichever is higher. Ongoing non-compliance could result in daily penalties of up to £100,000.
Government sources stated that the incident reporting requirements are designed to enable faster regulatory support and contribute to a better national understanding of cyber threats. The Bill’s measures reflect an effort to address the high frequency of cyber incidents reported across UK businesses.
By expanding the scope of regulated entities and introducing stricter reporting deadlines, the Bill aims to update and strengthen the UK’s cyber security regulatory framework. The proposed changes would place new obligations on a broader range of organisations operating in the UK’s digital infrastructure.
* This article is based on publicly available information at the time of writing.