The UK Government has warned that businesses involved in providing critical services like energy will face large fines if they fail to uphold robust cybersecurity standards. Other industries affected include: health, transport, water and IT infrastructure.
The new UK sanctions were brought forward after a recent consultation, and follow on from the European Union’s Network and Information Systems Directive. The measures are designed to shore up critical national infrastructure, and follow a series of targeted high profile attacks, most notably the WannaCry ransomware attack which caused mass outages to NHS services in 2017.
Regulators will be able to assess critical industries to ensure adequate security measures are in place. Sanctions for security failings include fines of up to £17 million, and are intended to signal a warning to company executives.
The new regulations will work alongside the General Data Protection Regulation (GDPR) which focuses on data security within all businesses.
IT Breaches or Failures
A new reporting system will be established to quickly identify IT failures or breaches and ensure that appropriate action can be taken. The reporting rules would also apply to other issues affecting information systems, such as hardware failures and power outages. Any such incidents would have to be reported to the industry regulators who would determine whether appropriate measures were in place.
Speaking about the new measures, Margot James, Minister for Digital and the Creative Industries, said: “We are setting out new and robust cyber security measures to help ensure the UK is the safest place in the world to live and be online.
“We want our essential services and infrastructure to be primed and ready to tackle cyber attacks and be resilient against major disruption to services.
“I encourage all public and private operators in these essential sectors to take action now and consult NCSC’s advice on how they can improve their cyber security.”
NCSC Guidance
The National Cyber Security Centre (NCSC) has published extensive security guidance detailing the measures which needed to be implemented.





