A managed service provider in the Midlands got hit at half two on a Tuesday morning a few weeks back. Nobody on the night shift had ever had to work out, at that hour, whether it counted as reportable.
Making that call is about to get a lot less optional. The Cyber Security and Resilience Bill reaches its first line by line examination in the House of Lords today. Buried in the detail is a rule that changes what incident response actually means for a lot of UK businesses.
Once you're in scope, you get 24 hours to tell the regulator something significant has happened. Not 24 hours to fix it, mind. Twenty four hours to notice it, judge it, and say so, with a fuller report due inside 72 hours.
Who does the 24-hour clock actually apply to?
Managed service providers are by far the biggest group being pulled in, treated as a new category in their own right because of how much access they typically hold across client systems. And data centres are being regulated for the first time too, no longer just buildings full of servers but critical national infrastructure in their own right.
Regulators also get the power to reach further still, naming specific suppliers to an already-regulated business as covered even when that supplier sits well outside the obvious sectors. A fair few ordinary mid-sized IT and managed services firms are going to find themselves in scope without ever having thought of themselves as critical anything.
Or rather, they will find out when it matters, which is worse.
What happens if a business gets it wrong?
The fines are not gentle. A serious contravention under the Bill carries a penalty of up to seventeen million pounds or four per cent of global turnover, whichever is the bigger number, with lesser breaches sitting at ten million or two per cent.
What should worry a finance director more than the headline figures is the daily rate. Keep failing to sort it and the regulator can charge up to a hundred thousand pounds a day until you do. It isn't a one-off cost. It's a bill that grows every morning nobody's dealt with it.
Second reading wrapped up back in July, and royal assent is expected before the year is out, though most of the substantive detail won't be fully in force until around 2028 while secondary legislation gets worked through underneath it. On paper, that looks like a fair bit of breathing room.
Twenty four hours sounds manageable on a slide in a boardroom, long before any of the actual enforcement kicks in. It looks very different at half two on a Tuesday, when the person on call has to decide alone whether what they're looking at meets the threshold.
And then stand behind that call three days later, when the full report lands on a regulator's desk.
Does this only matter if you're a tech company?
No, and that's the bit most businesses miss. Because regulators can designate a supplier as covered through its relationship with a regulated customer, ordinary companies that happen to sell into the newly regulated sectors can get pulled in sideways.
You don't need to run a data centre or badge yourself as an MSP for any of this to apply. Sell into the wrong client's supply chain and it can reach you anyway, whatever your own website says you do.
Worth checking your client list before assuming this one's not for you.
So who actually owns that decision in your business?
In a lot of the IT and managed services firms we talk to, the honest answer is nobody, not really. There's a support desk, and maybe a part-time head of IT already juggling infrastructure, security patching and forgotten passwords on top of a day job that was already full.
Not always someone senior enough to make that judgement call at 2am, and still feel comfortable defending it in writing three days later.
That gap is the actual risk here, not the legislation itself.
Legal analysis of the Bill published ahead of committee stage is blunt about what the 24-hour rule actually demands. Someone needs the standing to declare an incident out of hours, the authority to pull in legal advice at speed, and the judgement to write a report that will survive scrutiny three days later.
It's a different skill set to keeping the network running day to day, and one a lot of smaller IT teams have simply never needed before now.
The Bill doesn't spell out in black and white that you need one named, accountable person for this. It's less prescriptive on that point than some expected. The House of Lords may well tighten it as committee stage runs its course over the coming weeks, but the practical expectation hasn't moved regardless of what the small print eventually says.
Boards are still expected to own cyber risk, whatever happens in committee. And someone underneath the board has to be capable of actually exercising that judgement the moment a Tuesday at 2am asks for it.
Building in the judgement, not just the compliance
We spend a fair amount of our time helping businesses fill head of IT and IT director roles, and this is exactly the gap we keep running into. It's rarely about finding someone who can rack a server or patch a firewall competently, because most candidates on the market can already do that part.
What's harder to find is someone senior enough to be trusted with a call like this one, ideally someone who's made a version of it before and can talk you through how it actually went.
If you're weighing up whether to hire a head of IT for the first time, or finally replace one who's been coasting on goodwill for years, the case just got a lot more concrete. It's much cheaper to make that appointment carefully in advance than in a scramble once the 24-hour clock has already started running.
Our IT recruitment team spends most of its working week on exactly this kind of senior appointment, and our hiring guides go into more detail on what good actually looks like at head of IT and director level.
And if you're the one currently fielding that 2am call for someone else, and quietly wondering whether you fancy doing it on better terms, it's worth keeping half an eye on what else is out there.















