Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Cyber resilience bill at Lords committee

1 min read
12:09UTC

The Cyber Security and Resilience Bill reached House of Lords committee stage with a running amendment paper dated 23 July. The status of Lord Alton's transnational-repression amendment could not be confirmed from the published record.

TechnologyDeveloping
Key takeaway

The bill's operative detail is now being settled clause by clause in the Lords.

The Cyber Security and Resilience Bill is at committee stage in the House of Lords, with a running list of amendments dated 23 July on the Parliament publications page 1. The bill extends the Network and Information Systems Regulations 2018, the UK's existing regime for critical-service operators, with wider incident-reporting duties and a broader set of organisations inside scope. It cleared the Commons at third reading on 10 June .

Committee stage in the Lords is the point where every clause is examined in turn and amendments are debated without a time limit, which is why a bill's operative detail often changes more here than at any other stage. Reporting thresholds, the definition of a relevant incident and the powers a regulator gets to compel information are the provisions that determine what the legislation costs an organisation to comply with, and they are settled in exactly this room.

Lord Alton has proposed an amendment on transnational repression, the practice of states pursuing dissidents and diaspora communities abroad. Whether it has been tabled formally or adopted could not be established from the published record, so its standing stays open. Nothing in the amendment paper resolves it.

Deep Analysis

In plain English

The UK's Cyber Security and Resilience Bill is a law working its way through Parliament that would force more organisations, including IT support companies and data centres, to report serious cyberattacks and meet tougher security standards. Getting a law through the UK Parliament involves several stages, and this bill has now reached committee stage in the House of Lords, where members go through it line by line and can propose changes, called amendments. One peer, Lord Alton, is reported to want an amendment addressing transnational repression, foreign governments targeting critics or diaspora communities abroad, though it isn't yet confirmed whether that amendment has actually been tabled or debated.

What could happen next?
  • Meaning

    The bill's progress from Commons third reading to Lords committee stage keeps it on track for eventual Royal Assent, though the specific fate of individual amendments remains unclear from public sources.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

UK Parliament· 3 Aug 2026
Read original
Causes and effects
This Event
Cyber resilience bill at Lords committee
Committee stage in the Lords is where the bill's reporting duties acquire or lose their teeth, line by line.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.