The UK Government has proposed stronger rules for telecoms companies to strengthen the cybersecurity of mobile and broadband networks.
Since becoming law in November 2021, the Telecommunications (Security) Act obligates public telecoms providers to defend their networks from cyber threats. These include attacks that could cause network failure or steal sensitive data.
The specific measures telecoms providers will need to take to fulfil their legal duties under the Act will be decided as part of a new public consultation.
In addition, it will decide on a draft code of practice on how providers can comply with the regulations.
The draft regulations will legally require telecoms providers to protect data stored by their networks and services, as well as secure the critical functions which allow them to operate and manage their systems.
Telecoms providers will also have to protect the tools that monitor and analyse their networks and services against access from hostile state actors, as well as monitor public networks to identify potentially dangerous activity. They will also need to have a deep understanding of their security risks, reporting regularly to internal boards.
In addition, they will ned to take account of supply chain risks and understand and control who has the ability to access and make changes to the operation of their networks and services.
Digital Infrastructure Minister Julia Lopez said: “Broadband and mobile networks are crucial to life in Britain and that makes them a prime target for cyber criminals.
“Our proposals will embed the highest security standards in our telecoms industry with heavy fines for any companies failing in their duties.”
The consultation seeks views on plans to place telecoms providers into three ‘tiers’ via a new code of practice according to their size and importance to UK connectivity. This will ensure steps to be taken under the code are applied proportionately and do not put an undue burden on smaller companies.
Currently, telecoms providers are responsible by law for setting their own security standards in their networks. But the Telecoms Supply Chain Review carried out by the government found providers often have little incentive to adopt the best cybersecurity practices.
To deliver the economic and social benefits of 5G and gigabit-capable broadband connections, the government created the Telecommunications (Security) Act to strengthen the overarching legal duties on providers of UK public telecoms networks and services as a way of incentivising better security practices.
Companies which fail to comply could face fines of up to 10% of turnover or, in the case of a continuing contravention, £100,000 per day. Ofcom will monitor and assess the security of telecoms providers.
Recommended
- Filament STAC adds to company cohort at Scottish IoT accelerator
- UK space science projects receive £455k funding boost
- Nvidia confirms cyberattack that saw employee log-ins leaked online
The move comes amid the Russian invasion of Ukraine, which has seen numerous cyberattacks taking place against targets in Russia and Ukraine.
These attacks have raised fears that Russian and Russia-linked hacker groups might target Western infrastructure in reprisal for sanctions place on the country.
Several groups have warned organisations that they need to ensure that their cybersecurity is ready for a potential attack. The National Cyber Security Centre (NCSC), which helped develop the proposed measures, has provided guidance to follow when the threat of a cyberattack is heightened.
In addition, the Scottish Business Resilience Centre (SBRC) has warned there may be retaliatory Russian cyberattacks against other nations.
As such, with telecoms providing essential infrastructure, ensuring they have robust cybersecurity to resist any potential disruption is vital to maintaining their services.
NCSC Technical Director Dr Ian Levy said: “Modern telecoms networks are no longer just critical national infrastructure, they are central to our lives and our economy.
“As our dependence on them grows, we need confidence in their security and reliability which is why I welcome these proposed regulations to fundamentally change the baseline of telecoms security.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





