The 24-Hour Clock
The UK is about to place a 24-hour reporting obligation on a workforce that a new report says is already short of the people needed to meet it. That, not the fine schedule, is the story boards should be paying attention to.
On 14 July 2026 the Cyber Security and Resilience (Network and Information Systems) Bill received its second reading in the House of Lords, passing with cross-party support and without a division. Committee stage, the first line-by-line examination, is scheduled for 1 September. Royal Assent is expected late in 2026. Eight days after that second reading, a report from The CSBR warned that the legislation risks becoming what its founder called a paper tiger unless government addresses the cyber skills shortage before the duties bite.
Both things are true at once. The Bill is the most significant expansion of UK cyber regulation since 2018, and the capability to comply with it is not evenly distributed across the economy. Organisations that treat this as a legal review exercise will discover the gap at the worst possible moment: during an incident, on a 24-hour clock, with a regulator waiting.
What the Bill actually does
Expanded scope. The 2018 regime covered energy, transport, health, drinking water, digital infrastructure and a narrow set of digital services. The Bill brings in medium and large data centres, classed as essential services with Ofcom as operational regulator; medium and large managed service providers, regulated by the Information Commissioner; large load controllers managing electrical load for smart appliances and EV charging; and a new category of designated critical suppliers, which regulators will be able to bring into the regime individually, modelled on the critical third parties regime in financial services.
That last provision is the one most organisations have underweighted. You do not need to be in a listed sector to be regulated. You need to be important enough to one.
Faster, broader reporting. Under the current regime, regulators hear about an incident only once it has caused significant disruption. The Bill lowers that threshold to incidents with the potential to cause significant impact, and imposes an initial notification within 24 hours and a fuller report within 72 hours. The NCSC is informed at the same time as the sector regulator. Data centres, digital service providers and managed service providers will also have to notify customers likely to have been affected.
Enforcement with teeth. Penalty bands are being restructured to sit alongside UK GDPR. The standard maximum is the greater of £10 million or 2% of worldwide annual turnover. The higher maximum, which applies to security duty failures and incident notification failures, is the greater of £17 million or 4% of worldwide annual turnover. Ongoing contraventions can attract daily penalties of up to £100,000.
Why this one is different
The clock starts before you understand the incident. Twenty-four hours is not an investigation window. It is barely a triage window. Most organisations discover during their first real test that the binding constraint is not detection tooling but decision rights: who is authorised to declare a reportable incident at 03:00 on a Sunday, and on what evidence. Firms that have not pre-delegated that authority will spend the first twelve hours seeking approval rather than reporting.
The threshold is potential impact, not realised impact. This is a material widening. An intrusion that has been contained before disruption occurred may still be reportable. Boards used to a no outage, no report heuristic need to retire it.
Regulatory exposure now travels through your supply chain in both directions. If you are a managed service provider or data centre operator, you are in scope directly. If you buy from one, your provider now has a customer notification duty that will surface incidents you previously never heard about. And if a regulator designates you a critical supplier, you inherit the full regime regardless of your own sector.
The capability problem nobody has priced
The CSBR report draws on the Government Cyber Action Plan, the NCSC Annual Review 2025 and the Cyber Security Breaches Survey 2025. Its central finding is uncomfortable: 49% of UK businesses and 58% of government organisations already report a basic cyber skills gap.
The shape of the shortage matters more than its size. The report describes an hourglass labour market. In 2024, 63% of core cyber job postings required mid-level experience, while entry-level roles accounted for just 17%. Employers cannot find experienced practitioners, and are creating too few junior roles for anyone to become one. The public sector compounds this with what the report calls a leaky bucket: it trains people, then loses them to better-paid private sector roles that rigid pay structures cannot match.
Now overlay the Bill. Expanded scope plus faster reporting plus a new class of regulated entities creates a step change in demand for compliance and assurance expertise. The warning is that organisations will meet it by redeploying the scarce security people they already have, moving them from threat detection and response into evidence production for regulators.
A regime that improves the documentation of resilience while quietly reducing the practice of it. That is what a paper tiger looks like in operational terms.
Commercial exposure for UK organisations
Regulatory. Turnover-based penalties change the risk calculus. A £17 million or 4% ceiling moves cyber non-compliance from an operational nuisance to a figure that appears in board risk registers next to competition and data protection exposure.
Financial. Cyber attacks are estimated to cost UK businesses £14.7 billion a year, equivalent to 0.5% of GDP. Over 40% of UK businesses, more than 600,000 organisations, experienced an attack in the most recent survey period. The government’s own impact assessment puts the cost of the legislation at under £150 million a year across the economy. The regulation is cheap relative to the harm. That asymmetry is the argument to take to your board, not the penalty schedule.
Contractual. This is where the effect will be felt first, and earliest. Regulated buyers will push their obligations down through procurement. Expect 24 and 72 hour notification clauses, audit rights, and evidence-of-control requirements to appear in enterprise contracts well before the secondary legislation lands. Suppliers who cannot evidence their posture will be screened out of tenders before any regulator ever contacts them.
Reputational and governance. Customer notification duties for data centres, digital and managed service providers mean incidents that were previously handled privately become disclosed events. Combined with the Cyber Governance Code of Practice, the direction is unambiguous: cyber is being formalised as a board accountability, not a technical one.
Operational. In the year to September 2025 the NCSC managed 429 incidents, of which 204 were nationally significant, more than double the previous year. An independent study found 95% of UK critical national infrastructure organisations experienced a data breach in 2024. The threat environment is not waiting for the parliamentary timetable.
What to do now
Five moves, in order. Pre-delegate authority to declare a reportable incident, including named out-of-hours deputies. Rehearse the 24-hour path end to end, not the 72-hour one. Map notification obligations in both directions across your supply chain. Retire the no disruption, no report assumption in your incident policy. Then decide whether your compliance capacity is being added, or taken from your detection team.
The last one is where most organisations will go wrong, because it is a budget decision disguised as a resourcing decision.
Three questions for leadership
Who can declare a reportable incident, and how fast? Name the individuals, name their deputies, and confirm they can act without waiting for an executive who may be unreachable. If the answer requires a meeting, you will miss 24 hours.
Which of our suppliers would we have to notify, and which would have to notify us? Map contractual notification obligations in both directions, then check whether any supplier is important enough to be designated a critical supplier, because their regulatory burden becomes your operational dependency.
Is our compliance capacity additive or extractive? If meeting these duties means moving your existing security people onto evidence production, you have not improved resilience. You have relabelled it.
The strategic takeaway
The Bill’s substantive duties arrive through secondary legislation, after consultation, with an adjustment period. That sounds like time. It is not.
Two things will move faster than the statute. Contracts will move first, because regulated buyers will not wait for commencement dates to protect themselves. And capability will move slowest, because you cannot hire experienced practitioners into a market with a 49% reported gap on a twelve-week notice period. The organisations that come through this well will be the ones that started building capability while everyone else was still reading the Bill.
The right sequence is not legal review, then gap analysis, then hiring. It is capability first, evidence second, legal confirmation third. Know what you can actually do under pressure before you write down what you claim you can do.
At Garzon Cyber Solutions we work with UK organisations on both sides of this problem: reporting playbooks that survive a 24-hour clock, supply chain mapping and control evidence that stands up to a regulator, alongside the specialist compliance and assurance recruitment the market is about to compete hard for. If your organisation is in scope directly, or supplies someone who is, the useful conversation happens before Royal Assent, not after it.
Are you ready for a 24-hour reporting clock?
A focused discussion about your declaration authority, supply chain notification map, and the compliance capacity you will need before Royal Assent.
Discuss More →Sources: GOV.UK, Cyber Security and Resilience (Network and Information Systems) Bill factsheets, Department for Science, Innovation and Technology. House of Lords Library research briefing LLN-2026-0032. UK Parliament, Lords second reading, 14 July 2026. The CSBR report on UK cyber skills, July 2026. Cyber Security Breaches Survey 2025. NCSC Annual Review 2025. DSIT, Cyber security skills in the UK labour market 2025. Bridewell, Cyber Security in Critical National Infrastructure Organisations 2025. This article is general information and does not constitute legal advice.
Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability for organisations scaling into enterprise markets.