Wednesday, 30 September 2026

Where technology leaders come to think out loud

The BriefCybersecurity

Only one in 10 sure of meeting 24-hour breach reporting, VinciWorks finds

A small poll by a compliance training firm suggests most organizations have never tested the escalation process the Cyber Security and Resilience Bill will demand of them

The facts
  • The Bill would require an initial notification to the regulator within 24 hours of becoming aware of a reportable incident, and a full report within 72 hours.
  • According to VinciWorks’ summary, the most serious failures could draw fines of up to £17m or 4% of worldwide turnover, whichever is higher.
  • Continuing non-compliance could attract daily fines of up to £100,000, VinciWorks says.
  • Two-thirds (68%) of respondents were very or fairly concerned that a cyberattack could severely disrupt their operations.
What to do now

Run a timed exercise against the Bill’s reporting clock now, from first alert to a named person deciding the incident is reportable and then to a drafted notification. Record where the process stalls, often out of hours or at the handoff between IT and legal. MSPs and data center operators should confirm whether they are likely to be in scope, and ask their own key suppliers how quickly they would raise an alert. Move staff cyber training beyond a single annual module.

“An escalation process that has never been tested under real pressure is only a guess about what will happen when an incident actually strikes.”Nick Henderson-Mayo, head of compliance, VinciWorks

Only 10% of 156 IT, compliance and security professionals polled by VinciWorks in September say they are confident they could meet the Cyber Security and Resilience Bill’s incident reporting deadlines. VinciWorks, which sells compliance and cybersecurity training, published the results on 17 September.

Almost four in 10 (38%) said they could meet the deadlines in theory but had never tested the process. A further 26% were unsure, 17% said they were working toward it and 9% said they could not currently meet them. VinciWorks gives no breakdown of respondents by sector or company size.

On training, where VinciWorks has a commercial interest, just over half (51%) said staff complete mandatory cybersecurity training only once a year, and 12% said there is none.

The Bill would bring managed service providers and data centers into scope and let regulators designate critical suppliers whatever their size. VinciWorks says the expanded rules for MSPs, data centers and critical suppliers are due to phase in through 2027 and 2028. The Bill is in its House of Lords stages, and law firm Gowling WLG said on 10 September that Royal Assent may come toward the end of 2026.

AdvertisementZoomInfo
More from The BriefAll briefs
Amazon Web Services

AWS puts Moonshot’s Kimi K3 on Bedrock with US and global routing only

Scottish Government

Scotland requires impact assessments for data centers above 50MW

Orca Security

Orca Security's new partner program rewards net retention

Insight

Insight wins consultancy role in Scotland’s AI adoption program

Get the briefs every week in The VETTDD Briefing.