Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
17APR

UK 24-hour reporting bill at Report

4 min read
13:56UTC

The Cyber Security and Resilience Bill passed Public Bill Committee. ICO fined Capita £14m for missing PAM and AD tiering, citing NCSC guidance as the GDPR baseline.

TechnologyAssessed
Key takeaway

NCSC guidance has effectively become enforceable GDPR baseline in the UK through ICO precedent.

The UK Cyber Security and Resilience (CS&R) Bill reached Report Stage on 2 March 2026, after the Public Bill Committee concluded in February and a carry-over motion was passed; the bill is expected to reach the House of Lords in the next parliamentary session 1. The substantive provisions rewrite the operating model for UK in-scope organisations. Initial incident reports become due within 24 hours, full reports within 72 hours. Data centres are classified as essential services under joint oversight from the communications regulator Ofcom and the Department for Science, Innovation and Technology (DSIT). The definition of organisations covered by statutory cyber standards widens beyond the current Network and Information Systems (NIS) perimeter.

The 24-hour clock is the operational change. For UK-listed companies, board-level incident-escalation playbooks now have to land within a single trading day, which is a tighter cycle than most legal and communications Teams have tested. Tabletop exercises run on a 72-hour assumption become out of date on the day the bill receives Royal Assent.

The enforcement template is already set. Per a decision by the UK Information Commissioner's Office (ICO), the information regulator fined outsourcing firm Capita £14 million in October 2025 for its 2023 breach, and the technical basis has become the 2026 template 2. The ICO cited Capita's absence of Privileged Access Management (PAM) controls, the tooling that gates and audits access to the highest-risk admin accounts, and the absence of Active Directory (AD) tiering, the Microsoft reference model for separating admin credentials by privilege level, as the General Data Protection Regulation (GDPR) security failures that enabled the attacker's privilege escalation. Precedent from Capita and the earlier Advanced Computer Software decision (£3.07m, March 2025) treats NCSC guidance as the GDPR technical baseline. For any organisation in ICO scope, NCSC cyber hygiene advice now carries the force of enforceable data-protection standard.

Deep Analysis

In plain English

The UK government is passing a law called the Cyber Security and Resilience Bill that will require certain organisations to report cyber attacks to the government within 24 hours, and provide a full report within 72 hours. Data centres will be classified as critical national infrastructure, meaning they will be regulated for security in the same way as power grids and water systems. Separately, the UK's privacy regulator (the ICO, Information Commissioner's Office) fined Capita, a large UK outsourcing company, £14 million for a 2023 data breach. The ICO said Capita failed to implement basic security controls that the NCSC (the UK's national cybersecurity agency) recommends: specifically, Privileged Access Management (which restricts who can access sensitive systems) and Active Directory tiering (which organises computer accounts by risk level). The ICO effectively said: if you ignore NCSC guidance and get breached, it is a legal breach of data protection law.

Deep Analysis
Root Causes

Data centres were excluded from the original Network and Information Systems (NIS) Regulations 2018 that implemented the EU NIS Directive in UK law. The CS&R Bill's essential-services classification for data centres corrects that structural gap, reflecting the fact that major cloud and co-location facilities now underpin critical infrastructure operations that the original regulations covered.

The ICO's decision to treat NCSC guidance as the GDPR technical baseline resolves a legal ambiguity that has existed since GDPR came into force: Article 32's 'appropriate technical and organisational measures' standard is deliberately non-prescriptive, and UK organisations have argued successfully in past ICO engagements that 'appropriate' is subjective.

The Capita decision operationalises NCSC guidance as the benchmark, converting a subjective standard into a specific published control catalogue.

What could happen next?
  • Consequence

    UK organisations in scope for the CS&R Bill must rebuild their incident-escalation procedures to guarantee board notification and regulator submission within a trading day, transforming cyber incident response from an IT function to a C-suite operational protocol.

  • Precedent

    The ICO Capita precedent means that any UK organisation that has not implemented PAM and AD tiering in line with NCSC guidance, and subsequently suffers a breach, faces a materially higher fine risk than before the October 2025 decision.

First Reported In

Update #1 · Stryker MDM wipe exposes identity perimeter

Skadden· 17 Apr 2026
Read original
Causes and effects
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.