Government Regulations, Incident Response, Supply chain, Europe, MSP

UK organizations lack confidence in 24-hour cyber reporting deadline

Only one in ten UK IT, compliance, and security professionals are confident their organizations can meet a proposed 24-hour cyber incident notification requirement as the Cyber Security and Resilience Bill moves through Parliament, according to a recent report by Channel Insider.

The proposed legislation expands the UK's cyber security regime to managed service providers (MSPs), data centers, and critical suppliers, introducing stricter incident reporting. A survey by VinciWorks found that while 10% of professionals are confident in meeting the deadline, 38% have never tested their processes. The bill mandates an initial notification within 24 hours and a full report within 72 hours. This is particularly relevant to the channel, as MSPs and critical suppliers will be directly impacted.

Regulators can also bring suppliers into scope based on the importance of their services. Enforcement powers are expanded, with potential financial penalties reaching up to 4% of worldwide turnover for serious failures. Concerns about cyber threats are high, with over two-thirds expressing worry about operational disruption, yet preparedness remains inconsistent, with only 51% of employees completing annual cybersecurity training. VinciWorks recommends organizations test escalation procedures and review contracts to ensure compliance.

Source: Channel Insider

You can skip this ad in 5 seconds