Glossary · Enforcement and powers

Higher maximum penalty

Definition

The higher maximum penalty is the top fine ceiling under new regulation 18(9) of the NIS Regulations, inserted by the Cyber Security and Resilience Bill. For an undertaking it is the greater of £17 million and 4% of worldwide turnover. It covers security duty, incident notification, direction, inspection and information notice failures.

Which failures fall in the higher band?

New regulation 18(11) is a closed list. It covers the substantive duties for each type of regulated person, plus the failure to comply with an information notice.

  • OESs (reg 17(1)): security duties under reg 10(1) and (2); notifying an incident under reg 11(2); the timing and content rules in reg 11(6) and (7); data centre incident notification under reg 11A(2) and its timing and content under reg 11A(5) and (6); a direction under reg 11B(6)(b); customer notification under reg 11C(2)(b) and (4); and an inspection direction under reg 16(1)(c) or the inspection duties in reg 16(3).
  • RDSPs (reg 17(2)): security duties under reg 12(1); notifying an incident under reg 12A(1) and complying with reg 12A(5) and (6); a direction under reg 12B(4)(b); customer notification under reg 12C(1)(b) and (3); and an inspection direction under reg 16(2)(c) or reg 16(3).
  • RMSPs (reg 17(2ZA)): security duties under reg 14B(1); notifying an incident under reg 14E(1) and complying with reg 14E(5) and (6); a direction under reg 14F(4)(b); customer notification under reg 14G(1)(b) and (3); and an inspection direction under reg 16(2)(c) or reg 16(3).
  • Any person (reg 17(2ZB)): failing to comply with an information notice under reg 15.

Why does the higher band matter for incident reporting?

Under the amended regulations an incident report has two deadlines: an initial notification within 24 hours and a full report within 72 hours. Both run from the moment the organisation first became aware of the incident, not one after the other. Missing either deadline, or leaving out the required content, is a failure under reg 11(6) and (7) or its equivalents, and new reg 18(11) puts all of these in the higher band.

This is a change of emphasis. A significant incident that is handled well but reported late can attract the same maximum as a failure of the underlying security duties, although the actual amount must still be proportionate under new reg 18(5) and (6).

Penalty caps across the Bill compared

RegimeMaximum for an undertakingMaximum for othersWhat it coversSource
NIS standard bandGreater of £10m and 2% of turnover£10mThreshold and registration notifications, UK representatives, copying notifications to the CSIRT, further disclosureNew reg 18(8), (10)
NIS higher bandGreater of £17m and 4% of turnover£17mSecurity duties, incident notification and its timing and content, directions, inspections, information noticesNew reg 18(9), (11)
Part 3 regulations (future)May not exceed the greater of £17m and 10% of turnover£17mWhatever future cl.29 regulations impose; none exist yetcl.32(3)
Part 4 direction£17m; the greater of £17m and 10% of turnover only once s.49(5) regulations are in force£17mContravening a national security direction or the skilled person approval rulecl.49(2)(a), (b)
Part 4 daily rate£100,000 a day£100,000 a dayA continuing contravention of a directioncl.49(3)(a)
Part 4 information and inspection£10m; £50,000 a day if continuingSamePart 4 information notices and inspection requirementscl.49(2)(c), (3)(b)

Common misconceptions

Myth: Fines under the Bill are capped at £17 million.

Reality: For an undertaking the higher maximum is the greater of £17 million and 4% of worldwide turnover. £17 million is only the ceiling for a small undertaking or a non-undertaking.

Myth: The 10% of turnover and £100,000 a day figures apply to NIS breaches.

Reality: No. They belong to Part 4 national security directions (cl.49), and 10% is also the cap on future Part 3 penalties (cl.32(3)). The amended NIS Regulations have no daily penalty.

Where it appears in the Bill

  • New reg 18(9)Defines the higher maximum amount.
  • New reg 18(11)Lists the failures to which the higher maximum applies, including information notices at (d).
  • cl.32(3)Caps penalties in future Part 3 regulations at the greater of £17m and 10% of turnover.
  • cl.49(2)-(3)Part 4 penalty amounts, including the conditional 10% limb and daily rates.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

What is the biggest fine under the Cyber Security and Resilience Bill?

Under the amended NIS Regulations, the largest is the higher maximum: the greater of £17 million and 4% of worldwide turnover. Future Part 3 regulations may go up to the greater of £17 million and 10% (cl.32(3)). Part 4 directions reach 10% only once s.49(5) regulations are in force, and they alone carry a £100,000 daily rate.

Is a late 72-hour report in the higher band?

Yes. Failing to comply with reg 11(6) and (7), and the equivalent rules for data centres, RDSPs and RMSPs, is listed in new reg 18(11). Both the 24-hour initial notification and the 72-hour full report run from first awareness of the incident. A late or incomplete report therefore faces the same ceiling as a security duty failure.

Will regulators always fine at the maximum?

No. New reg 18(5) requires every penalty to be appropriate and proportionate. Under reg 18(6) the regulator must consider the impact of the failure, the steps taken to remedy or mitigate it, and the person’s previous compliance. The band sets the ceiling, not the starting point, and a penalty notice can be appealed to the First-tier Tribunal.

Related guidance

Official sources

More in Enforcement and powers

Full glossary