{"id":708674,"date":"2026-07-24T10:59:10","date_gmt":"2026-07-24T10:59:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/708674\/"},"modified":"2026-07-24T10:59:10","modified_gmt":"2026-07-24T10:59:10","slug":"uk-cabinet-changes-could-disrupt-cyber-security-legislation-as-lords-call-for-single-safety-regulator","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/708674\/","title":{"rendered":"UK cabinet changes \u2018could disrupt cyber security legislation\u2019 as Lords call for single safety regulator"},"content":{"rendered":"<p>&#13;<\/p>\n<p>The newly installed prime minister has dissolved the previously responsible Department for Science, Industry and Technology, with its responsibilities being split among the Cabinet Office with the elevation of a new AI minister, and cyber security transferred to the Departure for Culture, Media and Sport.<\/p>\n<p>But the move had raised concern among experts \u2013 including James Morris, head of cyber think-tank CSBR, who <a rel=\"noopener noreferrer nofollow\" href=\"https:\/\/www.mlex.com\/mlex\/articles\/2504465\/uk-cyber-defense-risks-fragmentation-with-tech-ministry-gone-tech-veteran-warns\" target=\"_blank\">had warned<\/a> that the move could stall the progress of the Cyber Security and Resilience Bill through the UK parliament. <\/p>\n<p>Morris argued that dividing responsibilities meant cyber threat regulation could lose focus, and <a href=\"https:\/\/www.pinsentmasons.com\/people\/malcolm-dowden\" rel=\"nofollow noopener\" target=\"_blank\">Malcolm Dowden<\/a>, a data and technology expert with Pinsent Masons, warned the move posed difficult questions about the impact it might have on cyber legislation <\/p>\n<p>\u201cAndy Burnham\u2019s decision to restructure the departments responsible for the digital economy and AI raises practical questions about continuity in the team responsible for the Cyber Security and Resilience Bill,\u201d he explained.<\/p>\n<p>\u201cThe Bill is prepared for its House of Lords committee stage in September, and there are consultations that were due to be launched over the summer recess on key elements of the Bill. <\/p>\n<p>\u201cThe proposed implementation period for the Bill was already lengthy, stretching into 2029. Any further delay will be a significant concern in view of enhanced threat levels.\u201d<\/p>\n<p>The legislation, <a href=\"https:\/\/www.pinsentmasons.com\/out-law\/news\/cyber-tech-suppliers-data-centres-uk-cyber-security-scrutiny\" rel=\"nofollow noopener\" target=\"_blank\">unveiled late last year<\/a>, plans to provide existing regulators with powers to enforce larger penalties based on turnover for serious cybersecurity breaches by companies with ties to significant UK critical national infrastructure, building on the existing 2018 Network and Information Systems Regulations.<\/p>\n<p>More stringent reporting requirements would also be introduced for Operators of Essential Services, and various digital service providers \u2013 including a requirement to notify regulators and the National Cyber Security Centre of incidents within the first 24 hours, and full reporting within 72 hours. Tighter triggers for notification \u2013 including near-miss incidents \u2013 are also included within the reporting requirements.<\/p>\n<p>The Bill is due for committee scrutiny from the House of Lords in September, after passing its second reading in the upper chamber earlier this month \u2013 where peers challenged whether the current, diverse regulatory regime was capable of handling cyber security threats.<\/p>\n<p>Lord Birt, former director general of the BBC, was among <a rel=\"noopener noreferrer nofollow\" href=\"https:\/\/hansard.parliament.uk\/lords\/2026-07-14\/debates\/29073BC1-AD49-48CF-A269-8E83A76AFE90\/CyberSecurityAndResilience%28NetworkAndInformationSystems%29Bill\" target=\"_blank\">several voices in the House of Lords<\/a> to question whether a single central regulator was a better approach to monitor cyber resilience in the country.<\/p>\n<p>\u201cThere is a possible vulnerability in every part of this complex network of providers, with many doors to pry open,\u201d Lord Birt said.<\/p>\n<p>\u201cOnce one door is opened by a bad actor\u2014a fraudster, a foreign power, a hacktivist or a ransom gang\u2014there is the potential to explore and disable much or all of the system.<br \/>\u201cThis is a highly demanding and ever-changing environment, and it is, frankly, preposterous to suppose that the 12 existing sector-specific regulators of our national infrastructure can acquire and constantly update the knowledge effectively to regulate cyber resilience.<\/p>\n<p>\u201cI conclude emphatically that we need a single, focused, dedicated and expert regulator, which I suggest we call the office for cyber resilience \u2013 OCR &#8211; to span both the public and private sectors, including organisations and, vitally, those who supply them with the technologies they use. <\/p>\n<p>\u201cFor clarity, the OCR should also regulate the national infrastructure providers.\u201d<\/p>\n<p>Others, including Baroness Harding, agreed with his call, or argued that one of the regulatory bodies overseeing national infrastructure should act as a single lead for the other regulators to streamline the process.<\/p>\n<p>Broader impacts<\/p>\n<p>The Lords\u2019 comments follow <a href=\"https:\/\/www.pinsentmasons.com\/out-law\/news\/uk-cyber-security-law-economic-impact-regulatory-limits\" rel=\"nofollow noopener\" target=\"_blank\">concerns from MPs<\/a>\u00a0earlier this year over whether regulators would have both capacity and the technical expertise to manage the cyber security requirements. <\/p>\n<p><a href=\"https:\/\/www.pinsentmasons.com\/people\/stuart-davey\" rel=\"nofollow noopener\" target=\"_blank\">Stuart Davey<\/a>, a cyber readiness expert with Pinsent Masons, noted that these observations reflect the position under the EU\u2019s comparable NIS2 Directive, where member states have identified a single competent authority with responsibility for cyber. <\/p>\n<p>However, he added that this model introduces a risk of one single regulator becoming overloaded with notifications from a broad range of regulated sectors, and failed to reflect the experience the UK\u2019s existing sector-aligned Competent Authorities have developed over the years.<\/p>\n<p>\u201cThe UK government has decided that the industry regulators are better placed to know their sector than creating a new regulator,\u201d he said.<\/p>\n<p>\u201cMost of those sectors have used &#8211; to varying degrees &#8211; the eight years since the NIS Regulations came in, to develop a cyber capability and to work with their sectors to ensure a real sector specific view. Sector regulators have maturing cyber teams, and the comments in the Lords perhaps overlook the fact that these regulators understand the nuances of their sector best.\u00a0 <\/p>\n<p>\u201cHowever, there undoubtedly can be more done to ensure shared learning, consistency and coordination between different regulators\u201d. <\/p>\n<p>Dowden added the commentary from the Lords on the regulatory issues followed previous concerns raised over AI in the chamber.<\/p>\n<p>\u201cTheir observations that bills have &#8220;lacked&#8221; provisions dealing with AI have generally been met with Ministerial comments that the particular Bill was not the appropriate legislative vehicle for such provisions or \u2013 as is the case here &#8211; that sectoral regulation in likely to be more effective,\u201d he explained. <\/p>\n<p>The scope of the national infrastructure requirements was also highlighted by the Lords in the debate over the bill, with Viscount Colville of Culross among those calling for a broadening of the regulatory scope to ensure a wider range of organisations are required to have in place such enhanced cyber protection requirements.<\/p>\n<p>\u201cNoble Lords only have to imagine the effect on the country if there were successful attacks on one or two of our big supermarket chains,\u201d he said.<\/p>\n<p>\u201cThe result would throw the national food supply chain into crisis. Surely supermarkets, which provide much of our nation\u2019s food and other services, need to be considered very carefully for coming within the scope of the Bill.<\/p>\n<p>\u201cPerhaps the Government need to set up a second tier of essential service sectors that should be preparing to be brought within the scope of the Bill.\u201d<\/p>\n<p>The government has said it believes the diverse nature of the food supply industry means there are other levers which it can employ to ensure security rather than stricter regulation.<\/p>\n<p>Davey pointed out the nature of the proposed legislation allowed it to be flexible where necessary, including making changes in future without the need for new primary legislation. <\/p>\n<p>\u201cThere is definitely a valid concern about regulatory divergence, as reflected in the comments in the Lords about diverging from <a href=\"https:\/\/www.pinsentmasons.com\/out-law\/news\/netherlands-moves-closer-to-delayed-nis2-implementation\" rel=\"nofollow noopener\" target=\"_blank\">Europe\u2019s NIS2 requirements<\/a>, and that could lead to challenges for organisation that operate globally,\u201d he explained.<\/p>\n<p>\u201cHowever a balance needs to be struck, and the government is choosing to focus on those most critical sectors of critical national infrastructure. NIS2 is much broader, but there has been concerns raised in Europe about just how broad that directive is. <\/p>\n<p>\u201cFor example, the very wide definitions of what constitutes manufacturing, means a broad range of manufacturing organisations are likely to get caught in scope, potentially resulting in \u201cover-regulation\u201d. <\/p>\n<p>\u201cThe Lords identified the food sector as being brought within scope \u2013 but the CSRB allows the Government to include that in future if necessary, while also learning the lessons from NIS2, which has a very wide ranging definition of the food sector that goes far beyond just supermarkets.\u201d<\/p>\n<p>It was expected that there would be further clarity about the CSRB with publication of consultation materials due soon. However, it appears that we enter the summer period with some uncertainty as to the future direction of the CSRB.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"&#13; The newly installed prime minister has dissolved the previously responsible Department for Science, Industry and Technology, with&hellip;\n","protected":false},"author":2,"featured_media":708675,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[59,57,58,50,56,54,55],"class_list":["post-708674","post","type-post","status-publish","format-standard","has-post-thumbnail","category-united-kingdom","tag-gb","tag-great-britain","tag-greatbritain","tag-news","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/708674","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=708674"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/708674\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/708675"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=708674"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=708674"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=708674"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}