Just one in ten UK IT, compliance, and security professionals believe their organizations could meet a proposed 24-hour cyber incident notification requirement, according to a survey published by VinciWorks in September 2026. The findings come as the Cyber Security and Resilience Bill advances through Parliament, legislation that would expand the UK's existing cyber security framework to cover managed service providers, data centers, and certain critical suppliers while imposing stricter incident reporting deadlines. The survey points to a stark gap between regulatory ambition and organizational readiness.

VinciWorks polled 156 IT, compliance, and security professionals in September 2026. While 10% expressed confidence they could meet the proposed deadlines, 38% said they could comply in theory but had never tested the process in practice. Another 26% were uncertain whether they could meet the requirement, 17% reported they were working toward readiness, and 9% acknowledged they currently could not meet the deadline. Under the proposed Bill, organizations falling within its scope would need to provide an initial notification to their regulator within 24 hours of becoming aware of a reportable cyber incident, followed by a complete report within 72 hours. The survey also revealed widespread concern about cyber threats outpacing preparedness: more than two-thirds of respondents expressed concern that a cyberattack could severely disrupt operations, with 34% very concerned and another 34% fairly concerned. No respondents said they were not concerned at all.

Training practices showed significant inconsistency, the report found. Half of respondents said employees complete mandatory cyber security training only once a year, 12% said their organization has no mandatory cyber security training at all, and 6% said training occurs but is not consistently tracked. Nick Henderson-Mayo, head of compliance at VinciWorks, noted that "cyber incidents rarely happen in office hours, on a good day, with everyone available," adding that "an escalation process that has never been tested under real pressure is only a guess about what will happen when an incident actually strikes." The report emphasized that organizations should conduct dry runs to identify problems in their escalation processes rather than relying solely on documented procedures. Broader UK figures cited in the report show that 43% of UK businesses experienced a cyber security breach or attack in the previous 12 months, rising to 65% of medium-sized businesses and 69% of large businesses, according to the government's Cyber Security Breaches Survey 2025/26.

The legislation carries particular significance for the channel because managed service providers would fall within its scope, alongside a new framework for critical suppliers. Under the proposed critical supplier regime, regulators could bring suppliers into scope when their services are sufficiently important to a regulated organization, regardless of the supplier's own size or sector. Regulators would gain expanded enforcement powers, with financial penalties potentially reaching £10 million or two percent of worldwide turnover for certain breaches and £17 million or 4% of worldwide turnover, whichever is higher, for more serious failures, according to UK government guidance. Continuing non-compliance could result in daily penalties of up to £100,000. The new requirements affecting MSPs, data centers, and critical suppliers are expected to be phased in through 2027 and 2028.

VinciWorks recommends organizations begin preparing by mapping services that could bring them within the Bill's scope, testing incident escalation procedures, reviewing supplier contracts, establishing who has authority to determine whether an incident is reportable, and ensuring cyber security training is properly tracked. The report notes that the proposed reporting deadlines could put greater attention on how quickly MSPs communicate incidents to customers, since organizations subject to the rules may depend on their service providers for information needed to assess an incident and meet their own notification obligations. That could increase scrutiny of breach-notification clauses, escalation procedures, audit rights, and the division of incident-response responsibilities between MSPs and customers. The supply chain's role in incident response is shifting from a contractual formality to a regulatory necessity, with service providers now facing the same pressure to perform under crisis conditions as their clients. Whether organizations choose to test those processes before the law takes effect may determine whether the 24-hour clock becomes a catalyst for resilience or a trigger for penalties.