Your IT provider will get 24 hours to report a breach, and a duty to tell you about it
Compliance & Data

Your IT provider will get 24 hours to report a breach, and a duty to tell you about it

Peers spent Tuesday arguing about AI and lost. The quieter clause in the Cyber Security and Resilience Bill is the one that reaches ordinary customers: an incident at your IT provider becomes something they have to tell you about, on a timetable.

7 September 20265 min read

The Cyber Security and Resilience (Network and Information Systems) Bill reached Grand Committee in the House of Lords on Tuesday 1 September, and the coverage that followed was about artificial intelligence. Peers pushed amendments to bring AI vendors within the scope of the bill. The government rejected them.

Cyber security minister Baroness Lloyd of Effra told the committee that bringing providers of AI services into scope "would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors". She pointed instead to the AI Security Institute, which works with vendors to test model security before release, and to the voluntary AI Cyber Security Code of Practice that informed the ETSI EN 304 223 standard. Peers were not persuaded. Baroness Kidron, a crossbench peer and online safety campaigner, asked: "Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?"

The clause with a clock on it

We covered the scope change back in July, when the bill reached the Lords: managed service providers, data centre operators and designated critical suppliers come under the regime for the first time, with small and micro enterprises exempt from the managed service provider measure. What has had almost no coverage is what an in-scope provider has to do on the day something goes wrong, and that is the part a customer actually feels.

The government's factsheet sets out a defined clock. An initial notification goes in within 24 hours of the provider becoming aware that an incident is taking place, and a full report follows after 72 hours. Both go to the provider's regulator and to the National Cyber Security Centre at the same time. An incident is reportable where it has adversely affected, or is adversely affecting, the operation or security of network or information systems, where the impact has been, is, or is likely to be significant, and where that impact relates to the whole or part of the UK. The factsheet gives ransomware and pre-positioning attacks as examples, including ones likely to have a significant UK impact even where they have not caused one yet.

And they have to tell you

Here is the sentence worth reading twice. Managed service providers, digital service providers and data centre operators will have to identify whether any of their customers are likely to have been adversely affected by an incident, and notify those customers with details of the incident and the reasons behind that assessment.

Today, whether you hear that your IT provider has been broken into depends entirely on how forthcoming they choose to be. There is no timetable, no defined trigger, and no obligation to explain their reasoning. Under the bill there is all three. For any business whose supplier holds administrative access to its systems, which is most firms using outsourced IT, that is a real change in what you are owed.

Three questions worth asking now

None of this needs Royal Assent to be useful. Ask your IT provider whether they expect to be in scope as a relevant managed service provider, because a provider who has not looked at the bill has told you something already. Ask what their incident notification process is today, and how quickly you would hear from them if their own systems were hit. And ask what access they hold into your environment, because that answer decides what a breach at their end means at yours, and very few business owners have ever seen it written down.

The bill has stages to go and peers signalled that the AI question will return, so the detail can still move. The direction will not.

What this means for your business

If you are a small or micro business, this bill does not regulate you. It regulates the company holding the keys to your systems, and that is the more useful way to read it. Once it is law, an in-scope provider has to notify its regulator and the NCSC within 24 hours of becoming aware of a significant incident, file a full report after 72 hours, and work out which of its customers were likely affected and tell them why. The sensible move while the bill is still in the Lords is to have that conversation calmly rather than during an incident: who is in scope, what gets reported, how fast you hear, and what access your provider holds. If you would like a hand working out what to ask, that is worth doing before the rules land rather than after.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.