Desk live·
ForensicPost
Breaches/Regulation/File 25-1121

Draft UK Bill Proposes Fines up to £17 Million or 4% of Turnover

The draft Bill proposes penalties of up to £17 million or 4% of worldwide turnover. The corpus can now compare a maximum fine against the actual cost of an incident.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUK regulated entities
ActorRegulator
D. Kennedy11 min readConfidence: high2 sources reviewed

The draft Bill proposes strengthened enforcement with maximum penalties of £17 million or 4% of worldwide turnover, whichever is higher.

Compare It With The Incidents In This Database

JLR booked £196 million against a single quarter at 25-0902, in an incident whose wider economic cost has been estimated at £1.9 billion. M&S reported a nine-figure impact at 25-0430. Coinbase estimated $180–400 million at 25-0530.

The fixed ceiling is an order of magnitude below what a serious incident costs the affected organisation directly. For a large company, the regulator is not the most expensive consequence of a failure — the failure is.

Which Means The Fine Is Not The Deterrent

That sounds like criticism and mostly is not. Where an incident is already ruinous, a penalty adds little marginal deterrence, and the turnover-based alternative exists precisely to bite where the fixed sum would not.

The place a penalty regime does real work is on organisations whose own losses would be survivable — the ones holding other people’s data while bearing little of the consequence. Marquis at 25-0814, Chain IQ at 25-0613, the servicing platform at 25-0701. For those, the regulator may genuinely be the largest consequence available.

And A Maximum Is Not A Distribution

Headline ceilings are quoted constantly and imposed rarely. What determines behaviour is the penalty an organisation expects, which is the ceiling multiplied by the probability of enforcement and discounted by everything a regulator weighs.

This corpus has no data on that for a regime not yet in force, and the accountability files at 26-0419 and 26-0223 record how little consequence has historically attached. The ceiling is the least informative number in the Bill.

How we reported this

Built on published legal analysis of the draft Bill, listed below. Comparisons with incident costs are our arithmetic on separately reported figures. Corrections: corrections@forensicpost.com.

Sources
  1. The UK Cyber Security and Resilience Bill: a practitioner’s guidearXiv
  2. UK Bill would increase cybersecurity standards for critical infrastructure operatorsSkadden
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary