Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

UK cyber bill drops payment regime

3 min read
18:20UTC

The UK Cyber Security and Resilience Bill reached report stage and third reading in the Commons on 10 June, but the consulted ransomware-payment ban and economy-wide reporting duty are absent from the published text.

TechnologyDeveloping
Key takeaway

The UK bill expands reporting duties but leaves the ransomware-payment ban out of the published text.

The UK Cyber Security and Resilience Bill reached its report stage and third reading in the House of Commons on Wednesday 10 June, the stage before it passes to the House of Lords 1. The bill widens the reportable-incident definition to cover integrity and security compromises, pre-positioning, and ransomware, building on the framework that reached an earlier stage in March and the £14.7bn UK cyber sector the government counted last month .

The ransomware-payment ban for CNI (critical national infrastructure) operators, and the economy-wide payment-reporting duty the government consulted on, are absent from the published bill text 2. That gap matters because mandatory payment reporting is the only instrument that collapses the distance between what victims disclose and what attackers actually claim. Without it, defenders, regulators and insurers keep working from incompatible numbers, which is precisely the visibility problem the briefing's ransomware-market section below describes.

The omission also reshapes the lobbying ahead. Industry was always going to contest the £17 million or 4%-of-turnover penalty ceiling when the bill reaches the Lords; with the payment regime already dropped, that fight now has a softer target and one fewer flank to defend. Canada's Bill C-8, building an equivalent CNI cyber framework, cleared its Senate the same week, so the Five Eyes are legislating in parallel on critical-infrastructure duties while diverging on the payment question 3.

Deep Analysis

In plain English

In the UK, critical services like power, water, hospitals, and banks are required to follow rules about cybersecurity. A new law called the Cyber Security and Resilience Bill, which the government has been developing for over a year, cleared a major stage in Parliament on 10 June 2026 and will now move to the House of Lords for further consideration. The bill widens the list of cyber incidents that organisations must report to regulators, including cases where attackers have quietly positioned themselves inside a network ahead of a future attack, alongside the existing requirement to report service disruptions. Companies found to have failed to report incidents could face fines of up to £17 million or 4 per cent of their global turnover. A proposal to require organisations to disclose when they pay a ransom to ransomware attackers was considered during development but does not appear in the published bill text. Canada passed a similar law the same week.

What could happen next?
  • Consequence

    The payment-reporting regime's absence from the Commons bill text means the UK will lack mandatory ransomware payment data collection for at least the duration of the Lords stage and likely into 2027.

    Medium term · Assessed
  • Opportunity

    Canada's Bill C-8 clearing Senate the same week creates a Five Eyes window for UKNCSC-ACSC-CCCS (Canadian Centre for Cyber Security) data-sharing on CNI incident reporting using parallel legislative frameworks.

    Medium term · Reported
  • Risk

    The £17 million fine ceiling or 4 per cent global turnover threshold aligns with GDPR enforcement levels; insurers may adjust cyber policy pricing in anticipation of enforcement rather than waiting for the Lords passage.

    Short term · Reported
First Reported In

Update #7 · VPN zero-day, no-patch KEV, late Exchange

JURIST· 14 Jun 2026
Read original
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.