Your IT Team Just Got 24 Hours to Make the Right Call

A new bill gives some UK firms just 24 hours to report a serious cyber incident, and most haven't worked out who actually makes that call.

By
Charles Trivett
,
Head of IT Recruitment
of Coburg Banks
LinkedIn Profile
September 1, 2026

A managed service provider in the Midlands got hit at half two on a Tuesday morning a few weeks back. Nobody on the night shift had ever had to work out, at that hour, whether it counted as reportable.

Making that call is about to get a lot less optional. The Cyber Security and Resilience Bill reaches its first line by line examination in the House of Lords today. Buried in the detail is a rule that changes what incident response actually means for a lot of UK businesses.

Once you're in scope, you get 24 hours to tell the regulator something significant has happened. Not 24 hours to fix it, mind. Twenty four hours to notice it, judge it, and say so, with a fuller report due inside 72 hours.

Who does the 24-hour clock actually apply to?

Managed service providers are by far the biggest group being pulled in, treated as a new category in their own right because of how much access they typically hold across client systems. And data centres are being regulated for the first time too, no longer just buildings full of servers but critical national infrastructure in their own right.

Regulators also get the power to reach further still, naming specific suppliers to an already-regulated business as covered even when that supplier sits well outside the obvious sectors. A fair few ordinary mid-sized IT and managed services firms are going to find themselves in scope without ever having thought of themselves as critical anything.

Or rather, they will find out when it matters, which is worse.

What happens if a business gets it wrong?

The fines are not gentle. A serious contravention under the Bill carries a penalty of up to seventeen million pounds or four per cent of global turnover, whichever is the bigger number, with lesser breaches sitting at ten million or two per cent.

What should worry a finance director more than the headline figures is the daily rate. Keep failing to sort it and the regulator can charge up to a hundred thousand pounds a day until you do. It isn't a one-off cost. It's a bill that grows every morning nobody's dealt with it.

Second reading wrapped up back in July, and royal assent is expected before the year is out, though most of the substantive detail won't be fully in force until around 2028 while secondary legislation gets worked through underneath it. On paper, that looks like a fair bit of breathing room.

Twenty four hours sounds manageable on a slide in a boardroom, long before any of the actual enforcement kicks in. It looks very different at half two on a Tuesday, when the person on call has to decide alone whether what they're looking at meets the threshold.

And then stand behind that call three days later, when the full report lands on a regulator's desk.

Does this only matter if you're a tech company?

No, and that's the bit most businesses miss. Because regulators can designate a supplier as covered through its relationship with a regulated customer, ordinary companies that happen to sell into the newly regulated sectors can get pulled in sideways.

You don't need to run a data centre or badge yourself as an MSP for any of this to apply. Sell into the wrong client's supply chain and it can reach you anyway, whatever your own website says you do.

Worth checking your client list before assuming this one's not for you.

So who actually owns that decision in your business?

In a lot of the IT and managed services firms we talk to, the honest answer is nobody, not really. There's a support desk, and maybe a part-time head of IT already juggling infrastructure, security patching and forgotten passwords on top of a day job that was already full.

Not always someone senior enough to make that judgement call at 2am, and still feel comfortable defending it in writing three days later.

That gap is the actual risk here, not the legislation itself.

Legal analysis of the Bill published ahead of committee stage is blunt about what the 24-hour rule actually demands. Someone needs the standing to declare an incident out of hours, the authority to pull in legal advice at speed, and the judgement to write a report that will survive scrutiny three days later.

It's a different skill set to keeping the network running day to day, and one a lot of smaller IT teams have simply never needed before now.

The Bill doesn't spell out in black and white that you need one named, accountable person for this. It's less prescriptive on that point than some expected. The House of Lords may well tighten it as committee stage runs its course over the coming weeks, but the practical expectation hasn't moved regardless of what the small print eventually says.

Boards are still expected to own cyber risk, whatever happens in committee. And someone underneath the board has to be capable of actually exercising that judgement the moment a Tuesday at 2am asks for it.

Building in the judgement, not just the compliance

We spend a fair amount of our time helping businesses fill head of IT and IT director roles, and this is exactly the gap we keep running into. It's rarely about finding someone who can rack a server or patch a firewall competently, because most candidates on the market can already do that part.

What's harder to find is someone senior enough to be trusted with a call like this one, ideally someone who's made a version of it before and can talk you through how it actually went.

If you're weighing up whether to hire a head of IT for the first time, or finally replace one who's been coasting on goodwill for years, the case just got a lot more concrete. It's much cheaper to make that appointment carefully in advance than in a scramble once the 24-hour clock has already started running.

Our IT recruitment team spends most of its working week on exactly this kind of senior appointment, and our hiring guides go into more detail on what good actually looks like at head of IT and director level.

And if you're the one currently fielding that 2am call for someone else, and quietly wondering whether you fancy doing it on better terms, it's worth keeping half an eye on what else is out there.

Coburg Banks IT Recruitment
We help outstanding IT professionals get brilliant jobs in top companies.

Continue reading

Coburg Banks IT Recruitment Agency

Your Best IT Leader Might Be About to Do Paperwork

Why the Cyber Security and Resilience Bill could quietly pull your best IT people off technical work and onto compliance paperwork instead.
Coburg Banks IT Recruitment Agency

What Football Can Teach You About Tech Hiring

Building a tech team is like creating a winning football squad—strategy, role clarity, and teamwork are essential. Learn how football-inspired hiring principles can transform your recruitment success.
Coburg Banks IT Recruitment Agency

Why Technical Ability Isn't Enough in Developer Hiring

Technical skills alone aren’t enough when hiring developers. Discover why prioritizing soft skills like communication and adaptability is key to building stronger, more efficient teams.
Coburg Banks IT Recruitment Agency

The Property Firm That Just Hired Its First Tech Chief

One property firm just created its first-ever CTO role. It's a sign more growing UK businesses are about to face this same call soon.
Coburg Banks IT Recruitment Agency

Hiring Senior Developers in the UK Just Got Harder. And Immigration Policy Isn't Helping

As immigration policy tightens and the UK developer workforce ages, employers chasing senior software talent face a squeeze from every direction. We explore what TechUK's July analysis means for IT hiring strategy and share practical steps to compete for scarce technical candidates.
Coburg Banks IT Recruitment Agency

Why Over-Screening Is Costing You the Best People

Over-screening IT candidates could be driving top talent away. Learn how to streamline your hiring process and attract the best with fewer roadblocks.
Coburg Banks IT Recruitment Agency

There Are Now Two Very Different UK Tech Job Markets

One developer on our books turned down three job offers in a week, because that's the new normal in senior tech hiring right now.
Coburg Banks IT Recruitment Agency

What Lloyds' AI Investment Means For Your Hiring Plans

Lloyds is spending billions to build an AI-ready team over four years. Here's what that scarcity means for your senior tech hiring.
Coburg Banks IT Recruitment Agency

A New Cyber Law Is About To Land On IT Leaders' Desks

A new UK cyber law is about to pull MSPs and data centres into a strict compliance regime, and the businesses starting the search for security leadership now will be well ahead of the ones scrambling later.
Coburg Banks IT Recruitment Agency

How Our Hiring Tools Make Interviews Easier for You

Struggling to manage time-consuming IT interviews effectively? Discover simple strategies to streamline your process and hire top tech talent faster.
Coburg Banks IT Recruitment Agency

Why Our Onboarding Process Helps Clients Hire Faster

Struggling to hire IT talent quickly? Discover how a streamlined, specialised process can cut delays, attract top candidates, and keep your projects on track.
Coburg Banks IT Recruitment Agency

Why Our Clients Trust Us With Senior Dev Roles

Struggling to hire senior developers? Discover why traditional methods fall short and how tailored IT recruitment can help you secure top talent effortlessly.
Coburg Banks IT Recruitment Agency

Why Our Clients Recommend Us Internally

Internal referrals for IT recruiters prove exceptional results and trust. Learn how consistent value and tailored solutions can transform your hiring success.
Coburg Banks IT Recruitment Agency

How We Work With Fast-Growth Tech Teams

Struggling to scale your tech team as your business grows? Discover smarter hiring strategies to keep pace with demand and drive success.
Coburg Banks IT Recruitment Agency

What Sets Our Dev Shortlists Apart

Struggling with shortlists full of mismatched candidates? Learn how high-quality IT shortlists save time, cut costs, and deliver the perfect fit for your team.
Coburg Banks IT Recruitment Agency

Why Our Clients Recommend Us Internally

Internal referrals for IT recruiters prove exceptional results and trust. Learn how consistent value and tailored solutions can transform your hiring success.
Coburg Banks IT Recruitment Agency

How We Work With Fast-Growth Tech Teams

Struggling to scale your tech team as your business grows? Discover smarter hiring strategies to keep pace with demand and drive success.
Coburg Banks IT Recruitment Agency

What Sets Our Dev Shortlists Apart

Struggling with shortlists full of mismatched candidates? Learn how high-quality IT shortlists save time, cut costs, and deliver the perfect fit for your team.