Only 10% Confident They Can Meet UK Cyber Reporting Rule

VinciWorks finds just 10% of UK IT, compliance and security professionals are confident they can meet a proposed 24-hour cyber reporting rule.

Written By
Luis Millares
Luis Millares
Sep 21, 2026
3 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Only one in ten UK IT, compliance, and security professionals surveyed by VinciWorks are confident their organizations could meet a proposed 24-hour cyber incident notification requirement as the Cyber Security and Resilience Bill moves through Parliament.

The proposed legislation would extend the UK’s existing cyber security regime to managed service providers (MSPs), data centers, and certain critical suppliers, while introducing tighter incident reporting requirements.

Most organizations have not tested 24-hour reporting readiness

VinciWorks surveyed 156 IT, compliance, and security professionals in September 2026. While 10% said they were confident they could meet the proposed reporting deadlines, 38% said they could meet them in theory but had never tested the process.

Another 26% were unsure whether they could comply, 17% said they were working toward readiness, and 9% said they could not currently meet the deadline.

Under the Bill, organizations in scope would be required to provide an initial notification to their regulator within 24 hours of becoming aware of a reportable cyber incident, followed by a full report within 72 hours.

“Cyber incidents rarely happen in office hours, on a good day, with everyone available,” said Nick Henderson-Mayo, head of compliance at VinciWorks. “An escalation process that has never been tested under real pressure is only a guess about what will happen when an incident actually strikes.”

Henderson-Mayo said organizations should conduct dry runs to identify problems in their escalation processes rather than relying solely on documented procedures.

MSPs and critical suppliers face expanded requirements

The legislation is particularly relevant to the channel because managed service providers would come within its scope, alongside a new framework for critical suppliers.

Under the proposed critical supplier regime, regulators could bring suppliers into scope when their services are sufficiently important to a regulated organization, regardless of the supplier’s own size or sector.

The Bill also gives regulators expanded enforcement powers. According to UK government guidance, financial penalties could reach £10 million or two percent of worldwide turnover for certain breaches and £17 million or 4% of worldwide turnover, whichever is higher, for more serious failures. Continuing non-compliance could result in daily penalties of up to £100,000.

Advertisement

The new requirements affecting MSPs, data centers, and critical suppliers are expected to be phased in through 2027 and 2028.

Cyber concern outpaces incident-response preparation

The VinciWorks poll also found that great concern about cyber threats has not consistently translated into preparedness.

More than two-thirds expressed concern that a cyberattack could severely disrupt operations, with 34% very concerned and another 34% fairly concerned. No respondents said they were not concerned at all.

Training practices were also inconsistent. According to the survey:

  • 51% said employees complete mandatory cyber security training only once a year.
  • 12% said their organization has no mandatory cyber security training.
  • 6% said training takes place but is not consistently tracked.

Broader UK figures point to similar incident-response challenges. The government’s Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses experienced a cyber security breach or attack in the previous 12 months, rising to 65% of medium-sized businesses and 69% of large businesses.

VinciWorks recommends organizations begin preparing by mapping services that could bring them within the Bill’s scope, testing incident escalation procedures, reviewing supplier contracts, establishing who has authority to determine whether an incident is reportable, and ensuring cyber security training is properly tracked.

What the Cyber Security and Resilience Bill means for MSPs

The proposed reporting deadlines could put greater attention on how quickly MSPs communicate incidents to customers. Organizations subject to the rules may depend on their service providers for information needed to assess an incident and meet their own notification obligations.

That could increase scrutiny of breach-notification clauses, escalation procedures, audit rights, and the division of incident-response responsibilities between MSPs and customers. 

For MSPs directly covered by the expanded regime, the VinciWorks findings also underscore the value of putting those processes through a live exercise rather than relying solely on documented plans.

TD SYNNEX and Google recently expanded their European partnership, giving channel partners broader portfolio access and go-to-market support. Read more about the expanded partnership and what it means for Google-focused channel partners.

Luis Millares

Luis Millares has extensive experience reviewing virtual private networks (VPNs), password managers, and other security software. He has tested and reviewed numerous forms of tech, covering consumer technology like smartphones and laptops, all the way to enterprise software and cybersecurity products. He has authored over 450 online articles on technology and has worked for the leading tech journalism site in the Philippines, YugaTech.com. He currently contributes to the Daily Tech Insider newsletter, providing well-researched insights and coverage of the latest in technology.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.