Desk live·
ForensicPost
Breaches/Regulation/File 25-1119

Draft UK Bill Proposes 24-hour Initial Breach Notification

The draft Bill proposes a two-stage reporting regime: an initial notification within 24 hours and a fuller report within 72. It is the fix for a gap this desk filed in October.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUK regulated entities
ActorRegulator
S. Rosler11 min readConfidence: high2 sources reviewed

The draft UK Bill proposes an enhanced incident reporting regime with an initial notification obligation at 24 hours and a fuller report at 72 hours.

This Is The Structure This Desk Asked For

At 25-1027 the corpus recorded Marquis discovering its compromise on the day it happened and notifying client institutions 74 days later. Nobody broke a rule. The rules had no term for the interval between a vendor knowing and a controller knowing, because notification was conceived as a single event that required knowing the scope.

The file closed by observing that a rule requiring notice of the fact of a compromise on discovery, separate from notice of its scope, would close the gap — and that no regime this desk was aware of had one. This is one.

Splitting The Obligation Resolves The Real Tension

The reason single-stage notification runs long is not usually concealment. Establishing which records were affected on a shared platform is genuinely a multi-week forensic exercise, and notifying prematurely with wrong scope causes its own harm.

A two-stage clock lets both be true: the fact travels immediately, at a moment when downstream parties can act on it, and the detail follows when it is reliable.

Whether It Reaches The Right Party Is Another Question

A reporting duty running to a regulator is not the same as a duty running to affected downstream organisations. The 74 days at 25-1027 was the interval before the *banks* were told, not before a supervisor was.

Whether the regime materially shortens that path depends on details of scope and recipient that this desk cannot assess from a draft. The structure is right; the corpus will need the commencement detail to say more.

How we reported this

Built on published legal analysis of the draft Bill, listed below. Provisions are as introduced. Corrections: corrections@forensicpost.com.

Sources
  1. Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience BillGlobal Policy Watch
  2. Cyber Security and Resilience (network and information systems) Bill issued by UK governmentClifford Chance
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary