Article 787F6 Peers ask why UK cyber bill leaves execs off the personal liability hook

Peers ask why UK cyber bill leaves execs off the personal liability hook

by
from www.theregister.com - Articles on (#787F6)
Story ImagePeers have questioned why the UK's Cyber Security and Resilience Bill does not allow regulators to penalize senior executives when an organization's failure to comply involves their consent, connivance, or deliberate or careless neglect. Echoing arguments heard across the industry for years, Baronesses Kidron and Ludford backed probing amendments that would introduce personal civil liability for senior execs and make cybersecurity a board-level responsibility. "The intention behind the amendment is to change the culture of an organization, to ensure preventative action is taken, to avoid penalties," said Baroness Kidron. "As I said at the outset, culture change starts at the top." The Register has previously reported on calls for NHS organizations, some of which would be covered by the bill's reforms, to treat cybersecurity as a board-level priority. More recently, 60 organizations committed to the aims of the UK government's Cyber Resilience Pledge, promising to ensure their boards take responsibility for their organization's cybersecurity. Peers supporting the amendments pointed to financial sector rules introduced over the past decade that can impose regulatory or criminal liability on the C-suite for serious failings. They argued that the amendments would bring the bill closer to the EU's NIS2 directive, which includes senior management accountability measures. Personal liability is not mandatory under NIS2, however, and member states have implemented it differently. Supporting the personal liability proposal, Lord Clement-Jones said: "If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it." Despite support from several peers, the government defended its existing plan to impose substantial maximum fines and introduce security, resilience, and governance requirements through secondary legislation. "It is absolutely right that organizations, especially those delivering our essential services, are held properly accountable for their activities," said cybersecurity minister Baroness Lloyd of Effra, who did not support the personal liability amendment. She cited the maximum fines of 17 million or 4 percent of the offending organization's annual turnover, whichever is higher, calling it "a meaningful enforcement regime." Baroness Lloyd said the forthcoming security and resilience requirements would mandate board-level governance in line with the NCSC's Cyber Assessment Framework. The government has yet to consult on the details. "That will cover issues such as organisational capability, senior responsibility, and accountability for security and resilience and effective risk escalation, and it is in that way that we will connect the clarity on what is expected of boards with the accountability through the enforcement regime." Reporting requirements and other matters Separately, peers quizzed the government on the structure of the bill's strict reporting requirements, warning that the current wording threatens to overwhelm regulators with an administrative burden. One of the CSR bill's primary objectives is to collect more data about the threats facing UK organizations by imposing stricter reporting requirements on in-scope entities. The bill requires regulated organizations to issue an initial notification within 24 hours and a fuller report within 72 hours. It defines an incident as an event that has, or is capable of having, an adverse effect on an operation. Former security minister Baroness Neville-Jones suggested changing the wording from "capable of" to "likely to have," to reduce the reporting burden on regulated organizations. Lord Clement-Jones agreed, warning that the current wording would "unleash an administrative tsunami of defensive reporting." He also argued that the government's definition of a data compromise was overly broad and "dramatically expanding the notification net to include technical data anomalies that cause zero disruption or loss to actual customers." He said the reporting rules and broad definition of compromise could leave responsible operators of essential services spending more time on paperwork than improving their defenses. The government was unmoved, and Baroness Lloyd said that the more stringent reports were crucial in achieving the aims of the bill, which seeks to update the existing NIS Regulations 2018. While some peers were looking to ease the burden of reporting, others sought to increase it in other areas. Baroness Harding, who is uniquely placed to weigh in on cyberattack response, proposed a 14-day intermediate report and a final report due one month after the attack first occurred. Drawing on her experience as the former TalkTalk CEO, she said that after 72 hours, attacked organizations start to get "real data," but "it's really only after a couple of weeks that you've got a proper sense of what has happened." The final report comes at the one-month mark, when "the fog is starting to clear and you have a proper sense of the real scale of the problem," she said. Harding said that senior executives are typically told from all sides not to say anything about a cyberattack, but this only serves the criminals, who meanwhile may be attacking other victims. "If you share this information in the fog with regulators and with law enforcement agencies, that's how the law can prevail," she said. "It's how regulators can work out what's happening, it's how they can warn others who might be affected, and it's how the law enforcement agencies can do their work to actually try and find the bad guys." Baroness Lloyd defended the bill's existing two-stage process, arguing that it already provides information at the points when regulators need it. She reaffirmed that the initial 24-hour report alerts the NCSC and allows it to determine whether other organizations are affected, while the 72-hour report will contain the necessary details to enable a more actionable response. "We believe that the stages we set out meet that. They have been carefully developed to provide the right notification at the appropriate time," she told peers. "They have been developed in consultation with industry, as many noble Lords exhorted in the previous group. "Crucially, under the information-gathering powers in Clause 15, regulators can also request further information about an incident that has been reported to them if they consider this necessary to understanding the incident and how it is being managed. "Obviously, that may be appropriate in some incidents and not in others. That kind of practical balance is enabled by the bill." Separately, the Grand Committee spent the second day scrutinizing the bill, fleshing out datacenters' responsibilities, as well as examining requirements to notify affected downstream customers within 24 hours of a breach instead of 72 hours. The government also rejected concerns that cybersecurity data collected under the reporting rules could contribute to unfair overseas proceedings. Baroness Lloyd said ministers had considered the issue and assessed the risk as very low. (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments