Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

UK cyber bill drops payment regime

3 min read
12:09UTC

The UK Cyber Security and Resilience Bill reached report stage and third reading in the Commons on 10 June, but the consulted ransomware-payment ban and economy-wide reporting duty are absent from the published text.

TechnologyDeveloping
Key takeaway

The UK bill expands reporting duties but leaves the ransomware-payment ban out of the published text.

The UK Cyber Security and Resilience Bill reached its report stage and third reading in The House of Commons on Wednesday 10 June, the stage before it passes to The House of Lords 1. The bill widens the reportable-incident definition to cover integrity and security compromises, pre-positioning, and ransomware, building on the framework that reached an earlier stage in March and the £14.7bn UK cyber sector the government counted last month .

The ransomware-payment ban for CNI (critical national infrastructure) operators, and the economy-wide payment-reporting duty the government consulted on, are absent from the published bill text 2. That gap matters because mandatory payment reporting is the only instrument that collapses the distance between what victims disclose and what attackers actually claim. Without it, defenders, regulators and insurers keep working from incompatible numbers, which is precisely the visibility problem the briefing's ransomware-market section below describes.

The omission also reshapes the lobbying ahead. Industry was always going to contest the £17 million or 4%-of-turnover penalty ceiling when the bill reaches the Lords; with the payment regime already dropped, that fight now has a softer target and one fewer flank to defend. Canada's Bill C-8, building an equivalent CNI cyber framework, cleared its Senate the same week, so the Five Eyes are legislating in parallel on critical-infrastructure duties while diverging on the payment question 3.

Deep Analysis

In plain English

In the UK, critical services like power, water, hospitals, and banks are required to follow rules about cybersecurity. A new law called the Cyber Security and Resilience Bill, which the government has been developing for over a year, cleared a major stage in Parliament on 10 June 2026 and will now move to the House of Lords for further consideration. The bill widens the list of cyber incidents that organisations must report to regulators, including cases where attackers have quietly positioned themselves inside a network ahead of a future attack, alongside the existing requirement to report service disruptions. Companies found to have failed to report incidents could face fines of up to £17 million or 4 per cent of their global turnover. A proposal to require organisations to disclose when they pay a ransom to ransomware attackers was considered during development but does not appear in the published bill text. Canada passed a similar law the same week.

What could happen next?
  • Consequence

    The payment-reporting regime's absence from the Commons bill text means the UK will lack mandatory ransomware payment data collection for at least the duration of the Lords stage and likely into 2027.

    Medium term · Assessed
  • Opportunity

    Canada's Bill C-8 clearing Senate the same week creates a Five Eyes window for UKNCSC-ACSC-CCCS (Canadian Centre for Cyber Security) data-sharing on CNI incident reporting using parallel legislative frameworks.

    Medium term · Reported
  • Risk

    The £17 million fine ceiling or 4 per cent global turnover threshold aligns with GDPR enforcement levels; insurers may adjust cyber policy pricing in anticipation of enforcement rather than waiting for the Lords passage.

    Short term · Reported
First Reported In

Update #7 · VPN zero-day, no-patch KEV, late Exchange

JURIST· 14 Jun 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.