Skip to content

10 April, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • sustainability Asia

      Navigating sustainability in Asia

      Boards operating across regions need to leave aside assumptions and consider the impact of a...

      lose confidence

      What’s really behind sudden C‑suite turnover?

      Losing credibility and integrity matters more than levels of competence in the event of a...

      boards fail

      8 reasons that boards fail

      The warning signs are rarely dramatic. More often, they are familiar, human and can be...

  • Comment
      • View all
    • investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

      quotas

      Quotas provide real help for boards

      A global research study shows that effective use of gender quotas on boards will tangibly...

      board refresh

      Why you need to refresh your board

      Boardroom requirements may be changing, but one thing has not—the need for a succession pipeline...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

      stewarding AI

      AI is a ‘special case for governance’

      As AI use in the boardroom grows, it’s essential to focus on the ethical and...

  • Board Careers
      • View All
    • female CEO

      Number of women in leadership stays unchanged

      In 2021, there were only eight female CEOs in the FTSE 100—a figure that is...

      female NED

      UK female non-executives earn £73k less than male NEDs

      Although the UK’s average gender pay gap on boards is shrinking, it is still one...

      directors duties

      3 top tips on directors’ duties

      When directors fall short of their responsibilities, the consequences can be devastating. How can board...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • FRC audit approach cover march 2026

      An evolved audit supervision approach 2026

      The Financial Reporting Council outlines its revised approach to audit supervision, which focuses on firms’...

      Protiviti 2026 governance AI

      The Board’s AI Moment, 2026

      This report, from Protiviti’s 2026 Global Board Governance Survey results, focuses on artificial intelligence.

      HEIDRICK GOVERNANCE 2026

      Governing Under High Uncertainty: Opportunities for Emerging-Market Boards

      This report from Boston Consulting Group, Heidrick & Struggles and INSEAD examines how boards are...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

MPs vote against boardroom cybersecurity legislation

by Gavin Hinks on February 26, 2026

A UK bill, currently under debate, will not create liability for boards that fail to make cyber resilience a core responsibility.

cyber attack

A cyber-attack brought Jaguar Land Rover's Castle Bromwich plant to a halt. Image: JLR

Favorite

Efforts to legislate new cybersecurity responsibilities for key boardrooms failed this week, after a vote in the House of Commons.

MPs are debating a new cybersecurity and resilience bill and heard proposals to place a new clause in the law that would mandate boards to “exercise oversight” of security for networks and IT.

Contained in a new “clause 16”, the proposals would also create a liability for boards in the event of failing to properly supervise cybersecurity measures and mandate cybersecurity training to help board members identify security risks.

Liberal Democrat David Chadwick, the MP behind clause 16, said: “New clause 16 would make cyber-resilience a core responsibility of organisational leaderships.

“It would require boards to oversee security arrangements, approve risk management approaches, ratify themselves that protections are working on an ongoing basis and, importantly, be accountable.”

He added that “numerous” experts from within industry have told MPs “they desperately need this to happen”.

Testing times

Another proposal for the bill, a new clause 17, would force organisations to undertake “regular testing” of network security, and document the outcome and any “remedial” action taken as a result.

Chadwick said: “All we are saying with our new clause is that boards need to be held accountable for the cyber-risk that they pose, and that making boards responsible for that obligation helps the cyber-security professionals responsible for securing those organisations to do their jobs properly.”

The cybersecurity and resilience bill aims to expand the scope of security regulation. Currently, it applies to “critical sectors”, such as energy, transport, health and water and a limited number of digital services.

The new bill ensures the regulations would apply to data centres, more energy providers, providers of third-party IT services and other suppliers to regulated organisations.

The bill broadly requires more reporting of cyber incidents and enable regulators to impose higher fines for failures.

Many boardroom observers believe cybersecurity risks have turned into a “true measure of organisational leadership”.

Hard-hitting attacks

Last year saw a spate of high-profile cybersecurity breaches that cost a series of big brand names hundreds of billions in lost production and consumer sales.

Both Marks & Spencer and Jaguar Land Rover were hit by attacks that proved highly disruptive, taking months to resolve.

In the case of M&S, the attack is thought to have cost as much as £100m in lost sales. In Land Rover’s case, manufacturing centres were shut down, turning the event into what is thought to have been the costliest cyber event in UK history, with an estimated impact of £1.9bn.

In October last year, the National Cyber Security Centre (NCSC) warned that cybersecurity must become the responsibility of the boardroom and not just IT chiefs.

Richard Horne, chief executive of NCSC, said that “for too long, cybersecurity has been regarded as an issue predominantly for technical staff.

“This must change. All business leaders need to take responsibility for their organisation’s cyber resilience.”

MPs voted against clauses 16 and 17, but only after government science and technology minister Kanishka Narayan said security and resilience requirements would be included in secondary legislation following consultations.

He added the NCSC’s cyber assessment framework includes “comprehensive measures on good cyber governance”.

He added: “Board level engagement is a necessary part of proactively and effectively managing cyber risks.”

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • The paradox of cyber risk and business growth
    August 1, 2024
    cyber risk and business growth

    Risk consensus and confidence in cybersecurity allow boards and organisations to innovate and drive the business forward.

  • Cybersecurity ‘is a boardroom issue’
    October 15, 2025
    cyber attack

    Leaders need to take responsibility for their organisation’s cyber resilience, warns the National Cyber Security Centre.

  • Are you serious about cybersecurity?
    October 3, 2023
    cybersecurity chatbot

    Artificial intelligence chatbot hackers are just the latest in a long list of cyber threats, which are not going away any time soon.

  • Most businesses ‘vulnerable to or at high risk’ of cybercrime
    March 20, 2024
    business cybercrime

    A mere 13% of firms are ‘resilient’ to cyber-attack or disruption from AI-powered assaults, research reveals.

Search


Follow Us

Most Popular

Featured Resources

wef global risks 2025

The Global Risks Report 2025

The 20th edition of the Global Risks Report reveals an increasingly fractured global...
Supply chain management cover

Strategic Oversight in Supply Chain Management: A Guide for Corporate Boards 2025

Supply chains have become complex, interdependent and opaque and—according to research...
OB-Cyber-Security

Cyber Security: What Boards Need to Know

Maintaining firewalls, protecting servers and filtering malicious emails rarely make...

C-suite barometer: outlook 2025 - UK insights

Forvis Mazars draws UK insights from its global study and looks at UK executives’...

The IA’S Principles Of Remuneration 2024 2025

This guidance from the Investment Association is aimed at assisting remuneration...
Diligent 2024 leadership tech cover

Leadership, decision-making & the role of technology: Business survey 2024

This research report by Board Agenda and Diligent sheds light on how board directors...

Director Reference Guide: Navigating Conflict in the Boardroom

The 'Director Reference Guide' on navigating conflict in the boardroom provides practical...
Nasdaq 2024 governance report cover

Nasdaq 2024 Global Governance Pulse

This Nasdaq survey gathered data from more than 870 board members, executives, and...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...
art & science brainloop new cover

The Art & Science of Creating an Effective Board

Boards are coming under more scrutiny and pressure than ever before from regulators,...
SAA First time NED guide

First Time Guide for Non-Executive Directors

The role of the non-executive director has never been more vital: to advise, support,...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy