Last week the House of Lords Grand Committee spent its second day picking through the Cyber Security and Resilience Bill, and the most interesting exchange of the day was reported by Connor Jones at The Register. A group of peers, led on this point by Baroness Kidron and Baroness Ludford with Lord Clement-Jones in support, wanted to know why the Bill does not allow a regulator to penalise a senior executive when an organisation's failure to comply involves that executive's consent, connivance, or deliberate or careless neglect. The Government, in the person of the cyber security minister Baroness Lloyd of Effra, said no. Fines of up to £17 million or four per cent of annual turnover were, in her words, meaningful, and board-level governance duties would follow in secondary legislation aligned to the NCSC's Cyber Assessment Framework.
I want to set out, as plainly as I can, why I think the Government has this wrong, and why I hold what some will regard as a hard line: until there is personal responsibility for the people at the top, the organisations this Bill is aimed at are not going to change anything of substance. I say that not as a policy theorist but as someone who has sat as CISO in FTSE 250 boardrooms, who runs a security operations centre that watches the consequences arrive in real time, and who has spent the best part of three decades in the gap between the two.
What the peers actually asked for
It is worth being precise about the amendment, because the phrase at its heart is not new and not radical. "Consent, connivance or neglect" is the standard formulation Parliament has used for fifty years when it wants a corporate offence to reach the individuals who caused it. It sits in section 37 of the Health and Safety at Work etc. Act 1974. It sits in section 14 of the Bribery Act 2010. It sits in section 198 of the Data Protection Act 2018. In each case the mechanism is the same: the company commits the offence, and where a director, manager or officer consented to it, connived in it, or was neglectful in a way that allowed it, that individual is liable as well. The peers were not inventing a new species of law. They were asking why a Bill that governs the security of the country's critical national infrastructure should be the one place this well-worn clause does not appear.
Baroness Kidron put the purpose of the amendment in a single sentence that I would happily put on the wall of every boardroom in the country: the intention is to change the culture of an organisation, to ensure preventative action is taken, to avoid penalties. Culture change, she said, starts at the top. Lord Clement-Jones was blunter still. If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility.
Why corporate fines do not do the job
The minister's answer rests on an assumption that a large enough corporate fine will produce the same behavioural change as personal liability. I have watched that assumption fail, repeatedly, from the inside.
A corporate fine is a line on a risk register. It is estimated, discounted for probability, insured against where possible, and weighed against the cost of the controls that would prevent it. That is not cynicism on the part of the board; it is the job the board is there to do. Every pound spent on security is a pound not spent on something with a clearer return, and a fine that might land in three years' time at some fraction of the maximum, against an event that might not happen at all, is a very weak signal when set against a quarterly number that certainly will. The four per cent of turnover figure sounds severe until you remember that the ICO's headline GDPR penalties have been reduced on appeal, negotiated down, or set at a small fraction of the cap. Boards notice that. They are very good at noticing that.
More importantly, a corporate fine is paid by the company, which is to say by the shareholders, and by the time it lands the executives who made the decisions have very often moved on with their bonuses intact. The person who chose to defer the identity programme, who accepted the risk on the unpatched estate, who signed off the outsourcing contract with no security schedule, does not pay. Somebody else does. No amount of secondary legislation about board-level governance changes that arithmetic. A duty on the board to have a governance framework is a duty to produce a document. A personal liability for neglect is a reason to read it.
What personal responsibility actually changes
The evidence for this is not theoretical. The Health and Safety at Work Act is the clearest example we have of a regime that transformed the culture of an entire sector of British industry, and it did so precisely because directors could, and occasionally did, go to prison. Construction sites in this country are unrecognisable from those of the 1970s not because companies feared fines but because the site manager and the director above him knew the consequences would be theirs. The Senior Managers and Certification Regime did the same in financial services after 2016: the moment named individuals had to sign a statement of responsibilities and could be personally sanctioned for what happened under it, the quality of attention paid to those responsibilities changed overnight. I was in that industry. I saw the difference in the room.
What personal liability does is collapse the distance between decision and consequence. It makes cyber security a thing the chief executive asks about unprompted rather than a thing the CISO is allowed twenty minutes to present on twice a year. It turns "we accept the risk" from a phrase that closes a meeting into a phrase that someone has to be willing to put their name to. And it changes the internal politics in the CISO's favour, because a board that is personally on the hook wants to hear the bad news early, rather than wanting it managed away. Every CISO who has been quietly encouraged to soften a risk paper before it reaches the audit committee knows exactly what I mean.
The objection, and why it fails
The standard objection is that personal liability will make it impossible to recruit good people to run critical providers, or that it will drive defensive, box-ticking behaviour. I have some sympathy with the second point in the context of incident reporting, and the peers were right to raise it: the Bill's definition of a reportable incident as an event that has, or is capable of having, an adverse effect on an operation is far too broad, and Baroness Neville-Jones's proposal to replace "capable of" with "likely to have" is sensible. Twenty-four hours for initial notification, seventy-two for the full report, and a further twenty-four to notify downstream customers is a demanding cadence, and Lord Clement-Jones's warning of an administrative tsunami of defensive reporting is well founded. We should fix the reporting threshold.
But the recruitment objection does not survive contact with the other regimes. Nobody has struggled to fill the chief executive's chair at a bank since the SMCR arrived. Nobody has struggled to find directors for construction firms. The people who are deterred by the prospect of being held responsible for their own consent, connivance or neglect are, with respect, precisely the people we do not want running the water, the power, the hospitals and the telecoms. The clause does not punish the honest executive who did their best and was beaten by a capable adversary. It punishes the one who knew, or should have known, and chose not to act. That is the correct target.
Governance by secondary legislation is a promise, not a lever
The minister's fallback, that board-level governance requirements will arrive later by regulation, deserves a specific response. I have read a great many governance frameworks. I have helped write some. They are useful, and the Cyber Assessment Framework is a good one. But a framework describes what a competent organisation looks like; it does not supply the reason to become one. Every organisation that has suffered a serious breach in the last decade had a governance framework. Most of them had a board paper, a risk appetite statement and a policy that said all the right things. What they lacked was a director who believed the consequences of those documents being fiction would be theirs personally.
The Bill, as drafted, gives us the same again. It updates the NIS Regulations 2018, extends scope, raises the fine ceiling, and tightens reporting. All of that is welcome and overdue. But it leaves the incentive structure at the top of the organisation exactly where it was, and it is that incentive structure, not the absence of frameworks, that has produced the results we have.
What I would like to see
I would like the Government to accept the consent, connivance or neglect clause in the form that Parliament has used for half a century, applied to the directors and senior officers of the regulated entities the Bill covers. I would like it paired with a sensible reporting threshold so that the regime is feared for the right reasons rather than resented for the wrong ones. And I would like the accompanying guidance to make explicit that the clause reaches decisions, not outcomes: that the test is whether the individual knew or ought to have known, and whether they acted, not whether the organisation was ultimately breached.
That is a regime I could stand in front of a board and explain in five minutes, and it is a regime that would change what happens in the next five minutes of that meeting. The Bill as it stands will change the compliance paperwork. It will not change the conversation. And in cyber security, as in health and safety before it, the conversation at the top is the only thing that has ever really mattered.