Peers have questioned why the UK's Cyber Security and Resilience Bill does not allow regulators to penalize senior executives when an organization's failure to comply involves their consent, connivance, or deliberate or careless neglect.Echoing arguments heard across the industry for years, Baronesses Kidron and Ludford backed probing amendments that would introduce personal civil liability for senior execs and make cybersecurity a board-level responsibility."The intention behind the amendment is to change the culture of an organization, to ensure preventative action is taken, to avoid penalties," said Baroness Kidron. "As I said at the outset, culture change starts at the top."
The Register has previously reported on calls for NHS organizations, some of which would be covered by the bill's reforms, to treat cybersecurity as a board-level priority.
More recently, 60 organizations committed to the aims of the UK government's Cyber Resilience Pledge, promising to ensure their boards take responsibility for their organization's cybersecurity.Peers supporting the amendments pointed to financial sector rules introduced over the past decade that can impose regulatory or criminal liability on the C-suite for serious failings.They argued that the amendments would bring the bill closer to the EU's NIS2 directive, which includes senior management accountability measures. Personal liability is not mandatory under NIS2, however, and member states have implemented it differently.Supporting the personal liability proposal, Lord Clement-Jones said: "If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it."Despite support from several peers, the government defended its existing plan to impose substantial maximum fines and introduce security, resilience, and governance requirements through secondary legislation."It is absolutely right that organizations, especially those delivering our essential services, are held properly accountable for their activities," said cybersecurity minister Baroness Lloyd of Effra, who did not support the personal liability amendment.She cited the maximum fines of £17 million or 4 percent of the offending organization's annual turnover, whichever is higher, calling it "a meaningful enforcement regime."Baroness Lloyd said the forthcoming security and resilience requirements would mandate board-level governance in line with the NCSC's Cyber Assessment Framework. The government has yet to consult on the details.









