Only one in 10 sure of meeting 24-hour breach reporting, VinciWorks finds
A small poll by a compliance training firm suggests most organizations have never tested the escalation process the Cyber Security and Resilience Bill will demand of them
- The Bill would require an initial notification to the regulator within 24 hours of becoming aware of a reportable incident, and a full report within 72 hours.
- According to VinciWorks’ summary, the most serious failures could draw fines of up to £17m or 4% of worldwide turnover, whichever is higher.
- Continuing non-compliance could attract daily fines of up to £100,000, VinciWorks says.
- Two-thirds (68%) of respondents were very or fairly concerned that a cyberattack could severely disrupt their operations.
Run a timed exercise against the Bill’s reporting clock now, from first alert to a named person deciding the incident is reportable and then to a drafted notification. Record where the process stalls, often out of hours or at the handoff between IT and legal. MSPs and data center operators should confirm whether they are likely to be in scope, and ask their own key suppliers how quickly they would raise an alert. Move staff cyber training beyond a single annual module.
“An escalation process that has never been tested under real pressure is only a guess about what will happen when an incident actually strikes.”Nick Henderson-Mayo, head of compliance, VinciWorks
Only 10% of 156 IT, compliance and security professionals polled by VinciWorks in September say they are confident they could meet the Cyber Security and Resilience Bill’s incident reporting deadlines. VinciWorks, which sells compliance and cybersecurity training, published the results on 17 September.
Almost four in 10 (38%) said they could meet the deadlines in theory but had never tested the process. A further 26% were unsure, 17% said they were working toward it and 9% said they could not currently meet them. VinciWorks gives no breakdown of respondents by sector or company size.
On training, where VinciWorks has a commercial interest, just over half (51%) said staff complete mandatory cybersecurity training only once a year, and 12% said there is none.
The Bill would bring managed service providers and data centers into scope and let regulators designate critical suppliers whatever their size. VinciWorks says the expanded rules for MSPs, data centers and critical suppliers are due to phase in through 2027 and 2028. The Bill is in its House of Lords stages, and law firm Gowling WLG said on 10 September that Royal Assent may come toward the end of 2026.
