Info Gov

Members of the House of Lords have given a second reading to the Cyber Security and Resilience (Network and Information Systems) Bill, backing the legislation's objectives but pressing for its scope to be widened.

The bill would amend the Network and Information Systems (NIS) Regulations 2018 to bring additional sectors within the regime and update incident reporting duties. It would also confer powers on the secretary of state to amend the legislation and issue directions to organisations where necessary for national security.

The NIS Regulations, which implement the UK's only cross-sector cyber security requirements, currently apply to operators of essential services in sectors including energy, transport, health, drinking water and digital infrastructure, with 12 regulators - among them the Information Commissioner's Office as competent authority for relevant digital service providers - responsible for enforcement.

The Conservative front bench said the Opposition supported the objective behind the legislation, noting that the cyber threat facing the UK was growing in both scale and sophistication, and that many of the reforms originated in the review of the NIS Regulations begun under the previous government following a consultation launched in 2022. The Opposition welcomed measures to improve consistency across the regulators responsible for enforcing the existing regime, but questioned whether the bill was ambitious enough, drawing on evidence submitted to the House of Lords Select Committee on National Resilience.

The Liberal Democrat benches also welcomed the bill while arguing that in a number of respects it "does not go far enough", telling peers that hostile state actors, organised crime and others were increasingly targeting systems at every level, and that attacks on energy networks, water supplies, transport systems, financial infrastructure and digital services were becoming more frequent.

Peers raised the case for closer alignment with EU regulation given British companies already comply with EU legislation in the areas covered, argued that a broader scope would drive behavioural change, and noted the minister's position that secondary legislation is available to expand the regime's reach. Lord Arbuthnot of Edrom raised the importance of the cyber security workforce and growing demand for skills, prompting questions about whether the proposed codes of practice would include a framework for workforce development and training, while Baroness Kidron addressed digital sovereignty.

The debate took place following a critical report from the House of Lords Constitution Committee. In its third report of the session, the committee recommended that the requirement in clause 40 for the secretary of state to report to Parliament on the operation of the regime "at least once every five years" be strengthened to require more regular reporting, given the fast-moving nature of the area and the significant powers granted to the secretary of state under the bill.

The committee also found that the failure to publish a full European Convention on Human Rights memorandum, setting out the reasoning behind the government's view on compatibility, inhibited parliamentary scrutiny. The Parliamentary Under-Secretary of State for the Digital Economy, Baroness Lloyd of Effra, issued a statement of compliance under section 19(1)(a) of the Human Rights Act 1998 without an accompanying memorandum.

The bill was introduced in the House of Commons on 12 November 2025, carried over at the end of the 2024-26 session, and completed its Commons passage on 16 June 2026 before its introduction in the Lords the following day. Committee stage, the first opportunity for line-by-line examination of the bill, is scheduled for Tuesday 1 September.

The Constitution Committee's report on the bill is available at: https://publications.parliament.uk/pa/ld5902/ldselect/ldconst/28/2803.htm

Also in this section

Jul 16, 2026

Scattered Spider pair jailed over TfL hack

Two members of the Scattered Spider hacking collective have each been jailed for five and a half years at Woolwich Crown Court on 16 July over a 2024 cyber attack on Transport for London that compromised the personal data of millions of customers and cost the transport authority £39 million.
Jul 15, 2026

Government introduces mandatory data breach reporting protocol

The Cabinet Office has published a Model Action Plan setting out a single cross-government framework that all departments and arms-length bodies must follow when responding to significant personal data breaches, introducing mandatory central reporting of such incidents for the first time.
Jun 29, 2026

"Five eyes" warn on accelerating cyber security threat from AI

The National Cyber Security has called on organisational leaders to treat cyber resilience as a core business and governance responsibility rather than a technical matter in the light of a report by the Five Eyes intelligence alliance on the "fundamental" impact of AI on the speed and scale of cyber threats.
Jun 15, 2026

Government AI hackathons uncover 407 vulnerabilities across nine departments, including critical remote code execution flaw

A pilot programme using frontier AI models to scan public-sector code repositories has identified 407 security findings across nine government organisations, including a critical vulnerability that could have allowed an external attacker to execute arbitrary code on a key digital service, the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC)…

InfoGov Masthead Newsletter 800