Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

UK cyber bill drops payment regime

3 min read
16:08UTC

The UK Cyber Security and Resilience Bill reached report stage and third reading in the Commons on 10 June, but the consulted ransomware-payment ban and economy-wide reporting duty are absent from the published text.

TechnologyDeveloping
Key takeaway

The UK bill expands reporting duties but leaves the ransomware-payment ban out of the published text.

The UK Cyber Security and Resilience Bill reached its report stage and third reading in The House of Commons on Wednesday 10 June, the stage before it passes to The House of Lords 1. The bill widens the reportable-incident definition to cover integrity and security compromises, pre-positioning, and ransomware, building on the framework that reached an earlier stage in March and the £14.7bn UK cyber sector the government counted last month .

The ransomware-payment ban for CNI (critical national infrastructure) operators, and the economy-wide payment-reporting duty the government consulted on, are absent from the published bill text 2. That gap matters because mandatory payment reporting is the only instrument that collapses the distance between what victims disclose and what attackers actually claim. Without it, defenders, regulators and insurers keep working from incompatible numbers, which is precisely the visibility problem the briefing's ransomware-market section below describes.

The omission also reshapes the lobbying ahead. Industry was always going to contest the £17 million or 4%-of-turnover penalty ceiling when the bill reaches the Lords; with the payment regime already dropped, that fight now has a softer target and one fewer flank to defend. Canada's Bill C-8, building an equivalent CNI cyber framework, cleared its Senate the same week, so the Five Eyes are legislating in parallel on critical-infrastructure duties while diverging on the payment question 3.

Deep Analysis

In plain English

In the UK, critical services like power, water, hospitals, and banks are required to follow rules about cybersecurity. A new law called the Cyber Security and Resilience Bill, which the government has been developing for over a year, cleared a major stage in Parliament on 10 June 2026 and will now move to the House of Lords for further consideration. The bill widens the list of cyber incidents that organisations must report to regulators, including cases where attackers have quietly positioned themselves inside a network ahead of a future attack, alongside the existing requirement to report service disruptions. Companies found to have failed to report incidents could face fines of up to £17 million or 4 per cent of their global turnover. A proposal to require organisations to disclose when they pay a ransom to ransomware attackers was considered during development but does not appear in the published bill text. Canada passed a similar law the same week.

What could happen next?
  • Consequence

    The payment-reporting regime's absence from the Commons bill text means the UK will lack mandatory ransomware payment data collection for at least the duration of the Lords stage and likely into 2027.

    Medium term · Assessed
  • Opportunity

    Canada's Bill C-8 clearing Senate the same week creates a Five Eyes window for UKNCSC-ACSC-CCCS (Canadian Centre for Cyber Security) data-sharing on CNI incident reporting using parallel legislative frameworks.

    Medium term · Reported
  • Risk

    The £17 million fine ceiling or 4 per cent global turnover threshold aligns with GDPR enforcement levels; insurers may adjust cyber policy pricing in anticipation of enforcement rather than waiting for the Lords passage.

    Short term · Reported
First Reported In

Update #7 · VPN zero-day, no-patch KEV, late Exchange

JURIST· 14 Jun 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.