Hong Kong CPD/RME HK
Book an intro

UK organisations not ready for new 24-hour cyber breach reporting deadline, VinciWorks poll finds.

cybersecurity

Compliance and security professionals also admit widespread confusion over who the incoming Cyber Security and Resilience Bill actually covers

As the UK’s Cyber Security and Resilience Bill enters its committee stage in the House of Lords this month, a new poll suggests more organisations are nowhere near ready for its toughest new duty. VinciWorks surveyed 156 IT, compliance and security professionals in September 2026 and found that only one in ten (10%) are confident they could meet the Bill’s tight new breach reporting deadlines.

What the Bill’s 24-hour reporting deadline requires

The Cyber Security and Resilience (Network and Information Systems) Bill will require organisations in scope to send an initial notification to their regulator within 24 hours of becoming aware of a reportable cyber incident, followed by a full report within 72 hours. The expanded rules for managed service providers, data centres and critical suppliers are due to be phased in through 2027 and 2028, narrowing the window for organisations to prepare. 

Almost four in ten (38%) compliance and security professionals said they would meet the 24-hour and 72-hour deadlines in theory, but had never actually tested the process, and more than a quarter (26%) admitted they were not sure. A further 17% said they were working towards it and nine per cent said they could not currently meet the deadline at all.

Nick Henderson-Mayo, head of compliance at VinciWorks, said, “Cyber incidents rarely happen in office hours, on a good day, with everyone available. An escalation process that has never been tested under real pressure is only a guess about what will happen when an incident actually strikes. Confidence needs to come from running a genuine dry run, recording what breaks and fixing it, rather than assuming a document sitting on a shared drive will hold up once the clock is already running.”

Who does the Bill actually cover?

The Bill creates a new critical supplier regime, allowing regulators to bring any organisation into scope if its services are significant enough to a regulated customer, regardless of the supplier’s own size or sector. 

Fines and enforcement powers under the Bill

Getting this wrong carries a real financial cost. Under the Bill, regulators will be able to impose fines of up to £10m or 2% of an organisation’s worldwide turnover for less serious breaches, rising to £17m or 4% of worldwide turnover, whichever is higher, for more serious failures. Continuing non-compliance can attract daily fines of up to £100,000 on top of new powers for regulators to issue enforcement notices demanding corrective action and to carry out audits. 

Concern about the risk itself is already high, even where readiness is not. When asked how worried they were that a cyber attack could severely disrupt their organisation’s operations, over a third (34%) said they were very concerned and a further 34% said they were fairly concerned. Not a single respondent said they were not concerned at all.

Training gaps add to the risk

Training habits suggest that concern has not yet translated into consistent action.  A little over half of respondents (51%) said staff complete mandatory cyber security training only once a year, and more than one in eight (12%) said their organisation has no mandatory cyber security training at all. A further six per cent said training happens but is not tracked consistently, meaning almost one in five organisations cannot reliably show that training took place at all.

The findings land against a backdrop of escalating attacks and cost. The National Cyber Security Centre (NCSC) managed 429 incidents requiring its support in the year to August 2025, of which 204 were classed as nationally significant, more than double the 89 recorded the year before. Government data shows 43% of UK businesses experienced a cyber breach or attack in the past year, rising to 65% among medium-sized businesses and 69% among large ones, yet only a quarter have a formal incident response plan in place. Independent research published for the government in November 2025 put the annual cost of significant cyber attacks to UK businesses at £14.7bn, an average of around £195,000 per organisation. 

Nick Henderson-Mayo added, “Mapping your suppliers, testing your escalation plan and properly tracking training aren’t the most glamorous of tasks, but they are exactly what regulators, and increasingly customers, will expect to see evidence of once this Bill is in force.”

Five steps to prepare this week

VinciWorks recommends five steps organisations can take this week to start preparing for the Bill:

  • Map which services your organisation provides that could bring it into scope directly, as a managed service provider, data centre or critical supplier
  • Test your incident escalation process with a live exercise, not just a document, so it holds up once the reporting clock is actually running
  • Review supplier contracts for breach notification clauses, audit rights and security warranties, and flag any that are silent or weak ahead of renewal
  • Confirm who has the authority to decide whether an incident meets the reporting threshold, and record that decision, and the reasoning behind it, either way
  • Check that cyber security training is properly tracked, not just delivered, so there is evidence to show a regulator if asked

If you’re interested in learning more about VinciWorks’ cyber security courses, take a free trial here. Alternatively, if you’re looking for what a multi-year learning plan looks like for cyber security awareness courses, download our sample training plan here.