Skip to content

12 August, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

      create value

      4 ways to help your CFO create value

      The chief financial officer has a vital contribution to make to the board’s strategy on...

      leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

  • Comment
      • View all
    • create value

      4 ways to help your CFO create value

      The chief financial officer has a vital contribution to make to the board’s strategy on...

      leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

      AI behaviour

      How do you measure AI adoption?

      It’s easy to produce metrics on AI software deployment, but these are pointless without tracking...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • board skills clash

      When board skills clash

      Board composition in terms of expertise has a clear impact on entrepreneurial decision-making and strategy,...

      female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • FRC Annual Review of Audit Quality 2026

      This Financial Reporting Council report uses findings from its supervisory activities to assess audit quality...

      Governance Guide: How Boards Drive Growth

      This Board Agenda Governance Guide investigates how directors can evolve to drive performance and growth...

      Organizational Transformation in the Age of AI

      This World Economic Forum paper looks at how organisations must re-architect their workflows and operating...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

MPs vote against boardroom cybersecurity legislation

by Gavin Hinks on February 26, 2026

A UK bill, currently under debate, will not create liability for boards that fail to make cyber resilience a core responsibility.

cyber attack

A cyber-attack brought Jaguar Land Rover's Castle Bromwich plant to a halt in 2025. Image: JLR

Favorite

Efforts to legislate new cybersecurity responsibilities for key boardrooms failed this week, after a vote in the House of Commons.

MPs are debating a new cybersecurity and resilience bill and heard proposals to place a new clause in the law that would mandate boards to “exercise oversight” of security for networks and IT.

Contained in a new “clause 16”, the proposals would also create a liability for boards in the event of failing to properly supervise cybersecurity measures and mandate cybersecurity training to help board members identify security risks.

Liberal Democrat David Chadwick, the MP behind clause 16, said: “New clause 16 would make cyber-resilience a core responsibility of organisational leaderships.

“It would require boards to oversee security arrangements, approve risk management approaches, ratify themselves that protections are working on an ongoing basis and, importantly, be accountable.”

He added that “numerous” experts from within industry have told MPs “they desperately need this to happen”.

Testing times

Another proposal for the bill, a new clause 17, would force organisations to undertake “regular testing” of network security, and document the outcome and any “remedial” action taken as a result.

Chadwick said: “All we are saying with our new clause is that boards need to be held accountable for the cyber-risk that they pose, and that making boards responsible for that obligation helps the cyber-security professionals responsible for securing those organisations to do their jobs properly.”

The cybersecurity and resilience bill aims to expand the scope of security regulation. Currently, it applies to “critical sectors”, such as energy, transport, health and water and a limited number of digital services.

The new bill ensures the regulations would apply to data centres, more energy providers, providers of third-party IT services and other suppliers to regulated organisations.

The bill broadly requires more reporting of cyber incidents and enable regulators to impose higher fines for failures.

Many boardroom observers believe cybersecurity risks have turned into a “true measure of organisational leadership”.

Hard-hitting attacks

Last year saw a spate of high-profile cybersecurity breaches that cost a series of big brand names hundreds of billions in lost production and consumer sales.

Both Marks & Spencer and Jaguar Land Rover were hit by attacks that proved highly disruptive, taking months to resolve.

In the case of M&S, the attack is thought to have cost as much as £100m in lost sales. In Land Rover’s case, manufacturing centres were shut down, turning the event into what is thought to have been the costliest cyber event in UK history, with an estimated impact of £1.9bn.

In October last year, the National Cyber Security Centre (NCSC) warned that cybersecurity must become the responsibility of the boardroom and not just IT chiefs.

Richard Horne, chief executive of NCSC, said that “for too long, cybersecurity has been regarded as an issue predominantly for technical staff.

“This must change. All business leaders need to take responsibility for their organisation’s cyber resilience.”

MPs voted against clauses 16 and 17, but only after government science and technology minister Kanishka Narayan said security and resilience requirements would be included in secondary legislation following consultations.

He added the NCSC’s cyber assessment framework includes “comprehensive measures on good cyber governance”.

He added: “Board level engagement is a necessary part of proactively and effectively managing cyber risks.”

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • The paradox of cyber risk and business growth
    August 1, 2024
    cyber risk and business growth

    Risk consensus and confidence in cybersecurity allow boards and organisations to innovate and drive the business forward.

  • Cybersecurity ‘is a boardroom issue’
    October 15, 2025
    cyber attack

    Leaders need to take responsibility for their organisation’s cyber resilience, warns the National Cyber Security Centre.

  • Are you serious about cybersecurity?
    October 3, 2023
    cybersecurity chatbot

    Artificial intelligence chatbot hackers are just the latest in a long list of cyber threats, which are not going away any time soon.

  • Most businesses ‘vulnerable to or at high risk’ of cybercrime
    March 20, 2024
    business cybercrime

    A mere 13% of firms are ‘resilient’ to cyber-attack or disruption from AI-powered assaults, research reveals.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy