Glossary · Duties and incidents

Significant incident

Definition

A significant incident is an incident that must be notified to a regulator under the Cyber Security and Resilience Bill. The test differs by category: operators of essential services (reg 11), data centres (reg 11A), digital service providers (reg 12A) and managed service providers (reg 14E). Each asks whether impact is or is likely to be significant.

What is the test for operators of essential services?

Under new regulation 11(3), an incident is an "OES incident" if it has affected or is affecting the operation or security of the network and information systems relied on to provide the essential service, and its impact in the UK or any part of it has been, is or is likely to be significant. Data centre services are carved out to regulation 11A.

Regulation 11(4) lists the factors to weigh:

  • the extent of actual or likely disruption to the essential service;
  • the number of users affected or likely to be affected;
  • the duration of the incident;
  • the geographical area affected or likely to be affected;
  • whether the confidentiality, authenticity, integrity or availability of user data is or is likely to be compromised.

How is the data centre test different?

Regulation 11A(3) defines a "data centre incident" as an incident which could have had, has had, is having or is likely to have a significant impact on the operation or security of the systems relied on to provide the data centre service, a significant impact on the continuity of that service, or any other significant impact in the UK.

There is no requirement that the systems have already been affected, and no statutory list of factors. This is the one test in the Bill that clearly reaches events which did not cause harm but could have, which is the closest the Bill comes to mandatory near miss reporting.

What do the RDSP and RMSP tests add?

Regulations 12A(2) and 14E(2) mirror the OES structure: the incident must have affected or be affecting the systems relied on to provide the relevant digital service or managed service, and its impact must be or be likely to be significant.

Their factor lists in 12A(3) and 14E(3) contain the five OES factors plus two more: whether there has been or is likely to be any impact on the network and information systems of users of the service, and any impact on the economy or the day-to-day functioning of society. The first matters for a relevant managed service provider, whose privileged access means one compromise can reach many customer networks.

Incident notification rules compared: OES, data centre, RDSP and RMSP

RuleOES (non-data centre)Data centre OESRDSPRMSP
RegulationReg 11Reg 11AReg 12AReg 14E
Who you notifyDesignated competent authority for the OESDesignated competent authority (Ofcom, cl.4(2))Information CommissionInformation Commission
What makes it reportableHas affected or is affecting the operation or security of the systems, and impact has been, is or is likely to be significant (reg 11(3)-(4))Could have had, has had, is having or is likely to have a significant impact (reg 11A(3))Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 12A(2)-(3))Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 14E(2)-(3))
24-hour initial notificationFrom first awareness (reg 11(6)(a))From first awareness (reg 11A(5)(a))From first awareness (reg 12A(5)(a))From first awareness (reg 14E(5)(a))
72-hour full notificationFrom the same moment of first awareness (reg 11(6)(b))From the same moment (reg 11A(5)(b))From the same moment (reg 12A(5)(b))From the same moment (reg 14E(5)(b))
Customer notification dutyNone in the BillYes, reg 11CYes, reg 12CYes, reg 14G
Copy to the CSIRT (NCSC)At the same time, reg 11(8)At the same time, reg 11A(7)At the same time, reg 12A(7)At the same time, reg 14E(7)

Worked example (illustrative)

Illustrative example: one event, two answers

A managed service provider detects an attacker using a stolen administrator credential on its remote management platform. The session is cut off within minutes and no customer system was touched. The platform was affected, so this is an incident, and the provider weighs reg 14E(3), including the possible reach into customer networks. A data centre operator facing the same blocked attempt on its building management network would also ask whether it "could have had" a significant impact, which is a lower bar.

Where it appears in the Bill

  • New reg 11(3)-(4)OES incident test and factors.
  • New reg 11A(3)Data centre incident test.
  • New reg 12A(2)-(3)RDSP incident test and factors.
  • New reg 14E(2)-(3)RMSP incident test and factors.
  • New reg 18(11)Notification failures in the higher penalty band.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Is there a numeric threshold for a significant incident?

Not in the Bill. The tests in regulations 11, 11A, 12A and 14E are qualitative: they list factors such as users affected, duration, geography and data compromise. Regulators may publish guidance on how they expect the factors to be applied, and regulated persons must have regard to relevant guidance, but no user counts or outage durations are fixed in the text.

Who decides whether an incident is significant?

The regulated organisation makes the first judgement, because the duty to notify arises when it is aware that a reportable incident has occurred or is occurring. The regulator can later test that judgement using information notices and inspections. Keeping a written record of each significance assessment, including those that concluded no notification was needed, is the practical safeguard.

What is the penalty for failing to report a significant incident?

Failure to notify, and failure to meet the timing and form rules, sit in the higher band under new regulation 18(11). For an undertaking the maximum is the greater of £17 million and 4% of worldwide turnover, so large firms face a cap above £17 million. Failing to copy the notification to the CSIRT sits in the standard band instead.

Related guidance

Official sources

More in Duties and incidents

Full glossary