Info Gov

Members of the House of Lords have given a second reading to the Cyber Security and Resilience (Network and Information Systems) Bill, backing the legislation's objectives but pressing for its scope to be widened.

The bill would amend the Network and Information Systems (NIS) Regulations 2018 to bring additional sectors within the regime and update incident reporting duties. It would also confer powers on the secretary of state to amend the legislation and issue directions to organisations where necessary for national security.

The NIS Regulations, which implement the UK's only cross-sector cyber security requirements, currently apply to operators of essential services in sectors including energy, transport, health, drinking water and digital infrastructure, with 12 regulators - among them the Information Commissioner's Office as competent authority for relevant digital service providers - responsible for enforcement.

The Conservative front bench said the Opposition supported the objective behind the legislation, noting that the cyber threat facing the UK was growing in both scale and sophistication, and that many of the reforms originated in the review of the NIS Regulations begun under the previous government following a consultation launched in 2022. The Opposition welcomed measures to improve consistency across the regulators responsible for enforcing the existing regime, but questioned whether the bill was ambitious enough, drawing on evidence submitted to the House of Lords Select Committee on National Resilience.

The Liberal Democrat benches also welcomed the bill while arguing that in a number of respects it "does not go far enough", telling peers that hostile state actors, organised crime and others were increasingly targeting systems at every level, and that attacks on energy networks, water supplies, transport systems, financial infrastructure and digital services were becoming more frequent.

Peers raised the case for closer alignment with EU regulation given British companies already comply with EU legislation in the areas covered, argued that a broader scope would drive behavioural change, and noted the minister's position that secondary legislation is available to expand the regime's reach. Lord Arbuthnot of Edrom raised the importance of the cyber security workforce and growing demand for skills, prompting questions about whether the proposed codes of practice would include a framework for workforce development and training, while Baroness Kidron addressed digital sovereignty.

The debate took place following a critical report from the House of Lords Constitution Committee. In its third report of the session, the committee recommended that the requirement in clause 40 for the secretary of state to report to Parliament on the operation of the regime "at least once every five years" be strengthened to require more regular reporting, given the fast-moving nature of the area and the significant powers granted to the secretary of state under the bill.

The committee also found that the failure to publish a full European Convention on Human Rights memorandum, setting out the reasoning behind the government's view on compatibility, inhibited parliamentary scrutiny. The Parliamentary Under-Secretary of State for the Digital Economy, Baroness Lloyd of Effra, issued a statement of compliance under section 19(1)(a) of the Human Rights Act 1998 without an accompanying memorandum.

The bill was introduced in the House of Commons on 12 November 2025, carried over at the end of the 2024-26 session, and completed its Commons passage on 16 June 2026 before its introduction in the Lords the following day. Committee stage, the first opportunity for line-by-line examination of the bill, is scheduled for Tuesday 1 September.

The Constitution Committee's report on the bill is available at: https://publications.parliament.uk/pa/ld5902/ldselect/ldconst/28/2803.htm

Also in this section

Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.
Aug 24, 2026

Ministers seek power to ban tech risky vendors from critical sectors and bar recipients from discussing the order

The government has tabled amendments to the Cyber Security and Resilience (Network and Information Systems) Bill that would allow the Secretary of State to direct operators of essential services, data centres, managed service providers and other designated organisations to stop buying from, restrict the use of, or remove and disable products from a named vendor on national security grounds, with…
Aug 12, 2026

ACRO Criminal Records Office reprimanded by ICO following cyber security failings

The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed.
Aug 06, 2026

AI agents sent malicious files to real developers and planted prompt injections in unmonitored test: AISI

The AI Security Institute (AISI) has published an incident report disclosing that AI agents under evaluation in its research environment took sustained, unsanctioned action against real people and organisations on the live internet, including researching the human maintainers of an open-source project, creating fake online identities to pressure one of them into approving malicious code, and…
Aug 05, 2026

Third AI platform goes rogue during cyber testing

The AI Security Institute (AISI) has reveaked a security incident in which AI agents being evaluated for their cyber capabilities took sustained, unsanctioned action directed at real people and organisations, including an attempted supply-chain attack on a publicly used open-source software project.

InfoGov Masthead Newsletter 800