Decoding the world of cybersecurity

Cyber bill enters detailed Lords scrutiny

Peers begin line-by-line examination of the Cyber Security and Resilience Bill on Tuesday, with proposed changes spanning AI, software, data centres, smaller providers, and executive liability.

Cyber bill enters detailed Lords scrutiny
Summary
  • House of Lords committee stage begins on 1 September, with four scrutiny days currently scheduled.
  • Amendments include proposals affecting AI providers, software manufacturers, digital platforms, data centres, and smaller service providers.
  • Peers will also consider senior-executive liability as Parliament tests how far the UK's expanded cyber regime should reach.

The UK’s Parliament will begin detailed House of Lords scrutiny of the Cyber Security and Resilience (Network and Information Systems) Bill on Tuesday, opening a stage in which peers can attempt to change its treatment of technology suppliers, data centres, artificial intelligence, and executive accountability.

Committee stage starts on 1 September and is currently scheduled to continue on 3, 7, and 9 September. Peers will examine the legislation clause by clause and can propose amendments or insert new provisions before the bill progresses further through the Lords.

The bill is intended to strengthen the security and resilience regime applying to organisations providing essential services in the UK. It would bring additional sectors into scope, update incident-reporting duties, and give government powers to instruct organisations in the interests of national security.

The first committee sitting will revisit several questions that have followed the legislation through Parliament. Proposed amendments include extending regulation to additional providers, including artificial-intelligence services, software manufacturers, and digital platforms.

Other proposals address providers that fall below existing size thresholds and how the legislation defines incidents involving data centres. Those amendments test whether regulatory scope should depend mainly on organisational size and technical classification or also reflect the consequences if a service fails.

One proposal would allow a data centre to meet a regulatory threshold regardless of rated IT load where Ofcom considers an incident could significantly affect the economy or the day-to-day functioning of society, taking account of customers and connections to essential services.

Peers are also due to consider senior-executive liability. The debate will help determine how responsibility under the regime is divided between corporate entities and individuals responsible for governance and compliance.

The issue becomes more complicated as the bill moves beyond the organisations that directly operate essential services. Managed services, data centres, digital platforms, and other suppliers can support many regulated organisations simultaneously, allowing one provider’s control failure to create a wider resilience event.

Software presents a similar boundary problem. A widely deployed product may underpin essential activities without its manufacturer operating the service itself. An AI provider may likewise supply technology that becomes embedded in automation, decision-making, development, or security processes across regulated organisations.

Explicitly extending obligations further upstream could improve regulatory visibility over concentrated dependencies, but it would also bring organisations with very different operational models into a framework developed around essential-service resilience.

Some amendments go considerably further. One proposal would create last-resort powers allowing the government to direct the shutdown of data centres or AI systems deployed at substantial scale during defined AI security or operational emergencies. It has not been agreed and remains only a proposed amendment.

That distinction is important throughout committee stage. Amendments can be debated, withdrawn, rejected, accepted, or returned to later; their appearance on the amendment paper does not mean they will become law.

Incident reporting presents another structural challenge. Regulators need enough information to detect systemic disruption and coordinate response, while thresholds set too low can generate large volumes of reports that contribute little to an understanding of material risk.

The final definitions will determine how successfully the bill captures dependencies that have become important since the existing Network and Information Systems regime was introduced. Regulation of a hospital, energy operator, or water company cannot account for every source of operational exposure if critical suppliers remain outside comparable resilience requirements.

Committee stage will not settle the legislation. The bill will still face report stage and third reading in the Lords before differences with the Commons are resolved. The September sittings will, however, provide the most detailed parliamentary test yet of where responsibility should sit across operators, suppliers, platforms, data centres, executives, and AI providers.

×