M
Member
Speaking in the House of Lords on 3 September 2026
Debate
Cyber Security and Resilience (Network and Information Systems) BillContribution
72: After Clause 16, insert the following new Clause—
“Notification of near misses, cyber threats and sub-threshold incidentsAfter regulation 14G of the NIS Regulations (inserted by section 16) insert—“Notification of near misses, cyber threats and sub-threshold incidents(1) A regulated person must notify the designated competent authority without undue delay and in any event no later than 72 hours after becoming aware of—(a) a cyber threat,(b) a near miss, or(c) a sub-threshold incident,affecting the regulated person’s network and information systems.(2) A person other than a regulated person may notify the designated competent authority on a voluntary basis of a cyber threat or a near miss or a sub-threshold incident affecting that person’s network and information systems, regardless of whether that person is subject to any requirement under these Regulations.(3) Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, a person who gives a notification under paragraph (1) or (2) is not, by reason only of that notification, subject to any additional duty, liability or requirement to which that person would not otherwise have been subject.(4) In this regulation—“cyber threat” means any potential circumstance, event or action that could, if it occurred, adversely affect the network and information systems of a person, or the users of a service provided by means of such systems;“near miss” means an event that could have compromised the availability, authenticity, integrity or confidentiality of data, or of a service provided by means of network and information systems, but that was prevented from having that effect or did not in fact have that effect;“regulated person” means an OES, an RDSP, an RMSP or a critical supplier;“sub-threshold incident” means an incident affecting the regulated person’s network and information systems which the regulated person is not otherwise required to notify under regulation 11(2), 11A(2), 12A(1) or 14E(1) but which is close to the thresholds for notification under those regulations.”” Member’s explanatory statement
This new clause seeks to ensure that regulated persons must report to their designated competent authority any near miss incident, cyber threat, or sub-threshold incident that could adversely affect the network and information systems of a person, or the users of a service provided by means of such systems.
About Hansard
Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.