Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Cyber resilience bill at Lords committee

1 min read
16:08UTC

The Cyber Security and Resilience Bill reached House of Lords committee stage with a running amendment paper dated 23 July. The status of Lord Alton's transnational-repression amendment could not be confirmed from the published record.

TechnologyDeveloping
Key takeaway

The bill's operative detail is now being settled clause by clause in the Lords.

The Cyber Security and Resilience Bill is at committee stage in the House of Lords, with a running list of amendments dated 23 July on the Parliament publications page 1. The bill extends the Network and Information Systems Regulations 2018, the UK's existing regime for critical-service operators, with wider incident-reporting duties and a broader set of organisations inside scope. It cleared the Commons at third reading on 10 June .

Committee stage in the Lords is the point where every clause is examined in turn and amendments are debated without a time limit, which is why a bill's operative detail often changes more here than at any other stage. Reporting thresholds, the definition of a relevant incident and the powers a regulator gets to compel information are the provisions that determine what the legislation costs an organisation to comply with, and they are settled in exactly this room.

Lord Alton has proposed an amendment on transnational repression, the practice of states pursuing dissidents and diaspora communities abroad. Whether it has been tabled formally or adopted could not be established from the published record, so its standing stays open. Nothing in the amendment paper resolves it.

Deep Analysis

In plain English

The UK's Cyber Security and Resilience Bill is a law working its way through Parliament that would force more organisations, including IT support companies and data centres, to report serious cyberattacks and meet tougher security standards. Getting a law through the UK Parliament involves several stages, and this bill has now reached committee stage in the House of Lords, where members go through it line by line and can propose changes, called amendments. One peer, Lord Alton, is reported to want an amendment addressing transnational repression, foreign governments targeting critics or diaspora communities abroad, though it isn't yet confirmed whether that amendment has actually been tabled or debated.

What could happen next?
  • Meaning

    The bill's progress from Commons third reading to Lords committee stage keeps it on track for eventual Royal Assent, though the specific fate of individual amendments remains unclear from public sources.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

UK Parliament· 3 Aug 2026
Read original
Causes and effects
This Event
Cyber resilience bill at Lords committee
Committee stage in the Lords is where the bill's reporting duties acquire or lose their teeth, line by line.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.