Members of the UK's House of Lords have challenged the government's decision to exclude personal liability provisions for senior executives from the Cyber Security and Resilience Bill, arguing that regulators should be able to penalize top managers when an organization's non-compliance involves their approval, complicity, or intentional or reckless failure to act. Baronesses Kidron and Ludford introduced amendments that would establish individual civil accountability for C-suite leaders and require cybersecurity oversight to become a board-level duty. The government defended its approach, pointing to maximum penalties of £17 million or 4 percent of annual revenue, whichever is larger, and promised that forthcoming regulations would mandate board-level governance aligned with the NCSC's Cyber Assessment Framework.
The bill requires regulated entities to file an initial alert within 24 hours of an incident and a more comprehensive account within 72 hours, defining an incident as any event that has or could have a harmful impact on operations. Peers supporting the personal liability amendments referenced financial sector regulations from the past decade that can place regulatory or criminal responsibility on executives for major failures, and they noted that the amendments would align the bill more closely with the EU's NIS2 directive, which contains senior management accountability mechanisms. Former security minister Baroness Neville-Jones proposed softening the reporting threshold from incidents "capable of" causing harm to those "likely to" do so, warning that the current language would trigger what Lord Clement-Jones called an "administrative tsunami of defensive reporting."
"If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it," Lord Clement-Jones stated in support of personal liability. Baroness Kidron argued that "culture change starts at the top," emphasizing that the goal of the amendment is to shift organizational behavior and encourage preventative measures to avoid fines. Baroness Harding, drawing on her tenure as TalkTalk CEO during a cyberattack, proposed adding a 14-day intermediate report and a final assessment one month after an incident, explaining that real understanding emerges only after the initial fog clears and that sharing information with regulators during an attack helps law enforcement track perpetrators and warn other potential targets.
Cybersecurity minister Baroness Lloyd of Effra rejected the personal liability amendment, defending the bill's existing two-stage reporting process as carefully designed in consultation with industry to deliver the right notifications at the appropriate moments, with the 24-hour alert enabling the NCSC to assess whether other organizations face risk and the 72-hour report providing detail for actionable responses. The minister said that board-level governance requirements in secondary legislation would address senior responsibility and accountability for security and resilience, connecting expectations with the enforcement regime through substantial fines rather than individual penalties. While personal liability isn't mandatory under NIS2 and member states have adopted it inconsistently, supporters argued that without direct consequences for executives, organizational culture won't shift and preventative action will remain secondary to other business priorities. The debate reflects a broader tension between holding institutions accountable through financial penalties versus placing responsibility directly on the individuals making decisions about cybersecurity investment and risk management.

