AuraTracer智迹闻
中文

EVENT DOSSIER

Peers ask why UK cyber bill leaves execs off the personal liability hook

2026-09-07 17:15 Policy & Governance 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
5mentions
SummaryAI generated

On September 7, 2026, the UK’s “Cybersecurity and Resilience Act” sparked criticism from peers, primarily because it did not allow regulators to impose personal responsibility on executives. MPs Kidron and Ludford supported amendments to impose personal civil liability on executives and board-level security responsibilities, aiming to change organizational culture and refer to the management accountability measures in the EU NIS2 directive. The government argued that existing high fines (up to 17 million pounds or 4% of annual revenue) and security governance requirements implemented through secondary legislation were sufficient, and no consultations had been held on details. Additionally, peers questioned that strict reporting requirements in the act might impose administrative burdens on regulators, suggesting changing “may cause” to “likely cause,” and criticizing the overly broad definition of data breaches.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
Baroness KidronBaroness Lloyd of EffraBaroness LudfordLord Clement-JonesUK Cyber Security and Resilience Bill

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Baroness Kidron × Baron…1Baroness Kidron × Baron…1Baroness Kidron × Lord …1Baroness Kidron × UK Cy…1Baroness Lloyd of Effra…1Baroness Lloyd of Effra…1

SignalsSIGNALS

Keyword heat
  • UK Cyber Security and Resilience Bill1
  • Baroness Kidron1
  • Baroness Ludford1
  • Lord Clement-Jones1
  • Baroness Lloyd of Effra1

All reports (1)SOURCES

T The Register en 2026-09-07 17:15

Peers ask why UK cyber bill leaves execs off the personal liability hook

The UK’s `Network Security and Resilience Act` does not allow regulators to impose personal responsibility on executives, which has sparked criticism from peers. Members of Parliament Kidron and Ludford support amendments to impose personal civil liability on executives and board-level security responsibilities, aiming to change organizational culture and draw upon the management accountability measures in the EU’s NIS2 directive. The government argues that existing high fines (up to 17 million pounds or 4% of annual revenue) and security governance requirements implemented through secondary legislation are sufficient, and no consultations have yet been held on details. Additionally, peers question that the strict reporting requirements of the act may impose an administrative burden on regulators, suggesting changing “may cause” to “likely cause” and criticizing the overly broad definition of data breaches.