On September 7, 2026, the UK’s “Cybersecurity and Resilience Act” sparked criticism from peers, primarily because it did not allow regulators to impose personal responsibility on executives. MPs Kidron and Ludford supported amendments to impose personal civil liability on executives and board-level security responsibilities, aiming to change organizational culture and refer to the management accountability measures in the EU NIS2 directive. The government argued that existing high fines (up to 17 million pounds or 4% of annual revenue) and security governance requirements implemented through secondary legislation were sufficient, and no consultations had been held on details. Additionally, peers questioned that strict reporting requirements in the act might impose administrative burdens on regulators, suggesting changing “may cause” to “likely cause,” and criticizing the overly broad definition of data breaches.
The UK’s `Network Security and Resilience Act` does not allow regulators to impose personal responsibility on executives, which has sparked criticism from peers. Members of Parliament Kidron and Ludford support amendments to impose personal civil liability on executives and board-level security responsibilities, aiming to change organizational culture and draw upon the management accountability measures in the EU’s NIS2 directive. The government argues that existing high fines (up to 17 million pounds or 4% of annual revenue) and security governance requirements implemented through secondary legislation are sufficient, and no consultations have yet been held on details. Additionally, peers question that the strict reporting requirements of the act may impose an administrative burden on regulators, suggesting changing “may cause” to “likely cause” and criticizing the overly broad definition of data breaches.