The Security Briefing

The 72-hour cyber reporting clock is still being argued over in the Lords

Written by Karyee Lee | Sep 4 2026

How quickly should an organisation be expected to explain a cyberattack while it is still trying to understand what has happened?

That question was at the centre of debate in the House of Lords this week as peers examined the Cyber Security and Resilience Bill and its proposed incident reporting requirements.

Among those pressing the Government for changes was Dido Harding, Baroness Harding of Winscombe, who knows from experience what it is like to manage a major cyber incident from inside an organisation. Harding was chief executive of TalkTalk when the telecommunications company suffered a cyberattack in 2015, an incident that became one of the UK's most closely watched corporate breaches.

During committee stage on 3 September, Harding argued that the Bill's proposed reporting timetable does not give organisations enough opportunity to establish what has happened before they are expected to provide increasingly detailed information to regulators.

Under the current proposals, organisations covered by the legislation would have to make an initial notification within 24 hours of becoming aware of a reportable incident, followed by a fuller report within 72 hours. The Government describes the first notification as a light-touch requirement, with basic information about the organisation, service and incident, while the second report would provide more detail where it is known.

Harding proposed retaining those initial deadlines while introducing two further stages of reporting. Her amendments would have added an intermediate report within 14 days and a final report within one month, bringing the structure closer to the approach used under the EU's NIS2 Directive.

Her argument was shaped by what she experienced at TalkTalk. In the immediate aftermath of an attack, an organisation may know that something serious has happened without knowing who is responsible, how far an attacker has moved through its systems or exactly what information has been accessed. Harding told peers that the picture develops over time, with substantially more information available after 72 hours and a clearer understanding of the incident emerging over the following weeks.

That experience also informed her concern about how organisations behave when faced with regulatory reporting obligations during a crisis. Harding argued that there can be a corporate incentive to keep quiet while the facts are uncertain, particularly when organisations are worried about the consequences of making statements that later prove incomplete or inaccurate.

The Government defended the 24-hour and 72-hour model. Baroness Lloyd of Effra said the timetable was intended to strike a balance between giving regulators information quickly enough to act and allowing organisations to concentrate on dealing with the incident itself. Regulators would also be able to request additional information where required.

The reporting timetable was not the only part of Clause 15 to come under scrutiny. Baroness Neville-Jones questioned the Bill's use of the phrase "capable of having" an adverse effect, arguing that the threshold could capture incidents that were merely capable of causing significant harm rather than those that were likely to do so. She raised particular concerns about the potential effect on data centres and the prospect of organisations reporting large numbers of incidents that ultimately have little impact.

The Government has said that significant-impact thresholds will be clarified through secondary legislation and consultation. Its wider policy position is that the new regime is intended to provide a level of protection comparable with, and no more onerous than, the equivalent requirements under NIS2.

The debate also produced a change to the Bill's treatment of compromised data. Government amendments agreed during committee stage broadened the wording from data belonging to "users of" a service to data connected with the service. That could give the reporting regime a wider reach when determining whether a cyber incident involves reportable data.

Harding ultimately withdrew her amendments after the Government offered further discussions ahead of the Bill's Report stage. That means the argument over the reporting timetable is still open, rather than settled.

For security and incident response teams, the distinction matters. A 24-hour notification followed by a fuller report at 72 hours creates a very different operational requirement from a process that allows organisations to develop their understanding over several weeks. The Government's model prioritises early visibility for regulators, while Harding's proposed amendments recognise that the most useful account of an attack may take considerably longer to establish.

The Bill is still making its way through the Lords, so the final requirements are not yet in force. What emerged from this week's debate is that the UK's future cyber reporting regime is being shaped around a difficult practical question: how do you demand useful information quickly when, in the first hours of an attack, the organisation experiencing it may still be trying to work out what happened?

Register your interest for The Security Event 2027  

Subscribe to The Security Briefing for monthly updates!