UK cybersecurity policy

The Lords Are Right to Test the Cyber Bill's Gaps, but Part 4 Needs Tighter Limits Than Director Liability Does

Lords committee stage on the UK Cyber Security and Resilience Bill ended with 65 amendments. Researcher protection and limits on national security directions matter most.

UK Cyber Bill at Lords Committee People of Internet Research · UK 65 Amendments tabled by peers Covering director liability, AI, r… £17m Maximum fine cited Or 4% of turnover, as cited by gov… 26 Oct Report stage date Committee stage completed 7 Septem… peopleofinternet.com
UK Cyber Bill at Lords Committee People of Internet Research · UK 65 Amendments tabled by peers £17m Maximum fine cited 26 Oct Report stage date peopleofinternet.com

Key Takeaways

The House of Lords finished committee stage of the Cyber Security and Resilience (Network and Information Systems) Bill on 7 September 2026, with report stage scheduled for 26 October. Peers tabled 65 amendments, according to a tracker of the debates. They ranged from personal liability for directors to an AI shutdown power. The bill is meant to strengthen the UK's cyber defences, and the amendments show which of its gaps matter in practice.

What the bill does

The government describes the bill as a reform of, and addition to, the Network and Information Systems Regulations 2018, aimed at raising defences for essential services such as utilities, water and the NHS. It was introduced on 12 November 2025. According to the government's factsheets, it extends the regime to data centres and managed service providers. It also adds provisions on critical supplier designation, incident reporting and enforcement.

The case for the tougher amendments

The strongest argument for the peers' proposals is that deterrence has to reach the people who make security decisions. Baronesses Kidron and Ludford proposed civil liability for senior executives. Lord Clement-Jones argued that anyone fit to draw a multimillion-pound salary running a critical national provider must accept personal responsibility for securing it. Corporate fines are paid by shareholders, and boards can treat them as a cost of doing business. The government's answer, per the same tracker, was that existing penalties already reach £17 million or 4% of annual turnover. There is a serious case that this leaves accountability diffuse.

I still think the personal-liability route is the weaker one. Civil liability for individual directors, written into a statute that regulators will apply to thousands of organisations, risks defensive over-compliance. Boards may respond by buying paper assurance rather than fixing systems, and capable people may avoid serving on the boards of critical providers. Evidence from other regimes suggests that clear governance duties and regulator supervision change behaviour without personal-liability tail risk. The government's existing structure already lets regulators act on board-level failures. The better fix is to require named board-level responsibility for cyber risk and to let regulators publish how they will enforce it.

Good-faith researchers are the clearest gap

The amendment with the strongest innovation and security case is protection for good-faith researchers. The Computer Misuse Act 1990 criminalises unauthorised access regardless of intent. In February 2026, Public Bill Committee witnesses said this creates a chilling effect. Professor John Child said the blanket model undermines collaboration and structured reporting between industry and public bodies. Chris Anley of NCC Group called the bill a golden opportunity to add a tightly safeguarded statutory defence. Child also noted that Portugal has already shielded public-interest researchers when it updated its law during NIS2 implementation.

The objection is that a defence could be abused as cover for intrusion, and that the criminal law is a blunt instrument to reopen in a resilience bill. That is a fair worry about drafting. It is an argument for a narrow defence with conditions such as proportionality, prompt disclosure and no data exfiltration. It is not an argument for leaving defenders exposed. A bill whose purpose is to make UK systems harder to attack should not leave the people who find the flaws under a threat of prosecution. Ministers withdrew the earlier committee amendments after assurances about their direction of travel. Report stage is the point to turn those assurances into text.

Part 4 needs the most scrutiny

The provision that most deserves peers' attention is the national security direction power in Part 4. It lets the Secretary of State direct regulated persons to act where a threat to network and information systems creates a risk to national security. As summarised by Osborne Clarke, directions can include:

Governments need such powers. Telecoms security law has long included comparable ones, and speed matters in a real emergency. But a power to require a private company to disable or modify a service is a large one. Its safeguards should be specified now rather than left to guidance: a defined trigger, proportionality and necessity tests, time limits with review, a route to challenge directions, and compensation or cost recovery. Without them, businesses face regulatory risk that is hard to price, and that risk falls hardest on the smaller firms and open-source and software suppliers that peers also asked about.

AI, software and SMEs

Peers also probed whether AI, software and platform providers should fall in scope, and proposed an AI shutdown power for national security emergencies. Extending the bill to every software supplier would turn a resilience law into a general product-regulation regime. A more proportionate route is to use the bill's critical supplier designation and to designate on evidence of systemic dependence. Amendments on a national cyber support service for SMEs, on the UK Cyber Security Council's statutory functions and on minimising data retention are more useful. Each addresses resilience without adding open-ended obligations. Retention limits reduce what an attacker can steal, and SME support helps the firms least able to buy expertise.

What to watch on 26 October

Three things will show whether report stage improves the bill. First, whether the government brings forward its own narrow researcher defence or a firm commitment to one. Second, whether Part 4 gains hard procedural limits. Third, whether board accountability is handled through duties and supervision rather than personal civil liability. The government has the votes, so its own amendments will decide the outcome. A resilience law works best when it is precise about what it demands and protective of the people doing the defending.

Sources & Citations

  1. GOV.UK: Cyber Security and Resilience Bill
  2. GOV.UK: Bill factsheets
  3. Osborne Clarke: UK Regulatory Outlook, September 2026
  4. ComplianceHub: Lords amendments tracker
  5. CyberUp: Public Bill Committee evidence on the Computer Misuse Act