How this links to the Cyber Security and Resilience Bill
Clause 15 replaces the single 2018 notification rule with four tailored tests, one for each regulated group. The tests look at actual and likely impact, and they are the gate between an ordinary incident and one that starts the 24-hour clock. Failing to notify, or notifying late or incompletely, sits in the higher penalty band.
- Reg 11(3)-(4): OES incident test with five impact factors.
- Reg 11A(3): data centre incident test, which includes impact the incident "could have had".
- Regs 12A(2)-(3) and 14E(2)-(3): RDSP and RMSP tests with seven factors, adding impact on users' systems and on the economy or society.
- New reg 18(11): failure to notify, and breach of the timing and content rules, fall in the higher penalty band.
What is the test for operators of essential services?
Under new regulation 11(3), an incident is an "OES incident" if it has affected or is affecting the operation or security of the network and information systems relied on to provide the essential service, and its impact in the UK or any part of it has been, is or is likely to be significant. Data centre services are carved out to regulation 11A.
Regulation 11(4) lists the factors to weigh:
- the extent of actual or likely disruption to the essential service;
- the number of users affected or likely to be affected;
- the duration of the incident;
- the geographical area affected or likely to be affected;
- whether the confidentiality, authenticity, integrity or availability of user data is or is likely to be compromised.
How is the data centre test different?
Regulation 11A(3) defines a "data centre incident" as an incident which could have had, has had, is having or is likely to have a significant impact on the operation or security of the systems relied on to provide the data centre service, a significant impact on the continuity of that service, or any other significant impact in the UK.
There is no requirement that the systems have already been affected, and no statutory list of factors. This is the one test in the Bill that clearly reaches events which did not cause harm but could have, which is the closest the Bill comes to mandatory near miss reporting.
What do the RDSP and RMSP tests add?
Regulations 12A(2) and 14E(2) mirror the OES structure: the incident must have affected or be affecting the systems relied on to provide the relevant digital service or managed service, and its impact must be or be likely to be significant.
Their factor lists in 12A(3) and 14E(3) contain the five OES factors plus two more: whether there has been or is likely to be any impact on the network and information systems of users of the service, and any impact on the economy or the day-to-day functioning of society. The first matters for a relevant managed service provider, whose privileged access means one compromise can reach many customer networks.
Incident notification rules compared: OES, data centre, RDSP and RMSP
| Rule | OES (non-data centre) | Data centre OES | RDSP | RMSP |
|---|---|---|---|---|
| Regulation | Reg 11 | Reg 11A | Reg 12A | Reg 14E |
| Who you notify | Designated competent authority for the OES | Designated competent authority (Ofcom, cl.4(2)) | Information Commission | Information Commission |
| What makes it reportable | Has affected or is affecting the operation or security of the systems, and impact has been, is or is likely to be significant (reg 11(3)-(4)) | Could have had, has had, is having or is likely to have a significant impact (reg 11A(3)) | Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 12A(2)-(3)) | Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 14E(2)-(3)) |
| 24-hour initial notification | From first awareness (reg 11(6)(a)) | From first awareness (reg 11A(5)(a)) | From first awareness (reg 12A(5)(a)) | From first awareness (reg 14E(5)(a)) |
| 72-hour full notification | From the same moment of first awareness (reg 11(6)(b)) | From the same moment (reg 11A(5)(b)) | From the same moment (reg 12A(5)(b)) | From the same moment (reg 14E(5)(b)) |
| Customer notification duty | None in the Bill | Yes, reg 11C | Yes, reg 12C | Yes, reg 14G |
| Copy to the CSIRT (NCSC) | At the same time, reg 11(8) | At the same time, reg 11A(7) | At the same time, reg 12A(7) | At the same time, reg 14E(7) |
Worked example (illustrative)
Illustrative example: one event, two answers
A managed service provider detects an attacker using a stolen administrator credential on its remote management platform. The session is cut off within minutes and no customer system was touched. The platform was affected, so this is an incident, and the provider weighs reg 14E(3), including the possible reach into customer networks. A data centre operator facing the same blocked attempt on its building management network would also ask whether it "could have had" a significant impact, which is a lower bar.
Where it appears in the Bill
- New reg 11(3)-(4)OES incident test and factors.
- New reg 11A(3)Data centre incident test.
- New reg 12A(2)-(3)RDSP incident test and factors.
- New reg 14E(2)-(3)RMSP incident test and factors.
- New reg 18(11)Notification failures in the higher penalty band.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Is there a numeric threshold for a significant incident?
Not in the Bill. The tests in regulations 11, 11A, 12A and 14E are qualitative: they list factors such as users affected, duration, geography and data compromise. Regulators may publish guidance on how they expect the factors to be applied, and regulated persons must have regard to relevant guidance, but no user counts or outage durations are fixed in the text.
Who decides whether an incident is significant?
The regulated organisation makes the first judgement, because the duty to notify arises when it is aware that a reportable incident has occurred or is occurring. The regulator can later test that judgement using information notices and inspections. Keeping a written record of each significance assessment, including those that concluded no notification was needed, is the practical safeguard.
What is the penalty for failing to report a significant incident?
Failure to notify, and failure to meet the timing and form rules, sit in the higher band under new regulation 18(11). For an undertaking the maximum is the greater of £17 million and 4% of worldwide turnover, so large firms face a cap above £17 million. Failing to copy the notification to the CSIRT sits in the standard band instead.