The UK Government has called for new laws to create stronger cybersecurity standards for outsourced IT services used by British businesses.
Under the existing Network and Information Systems (NIS) Regulations, which came into force in 2018, organisations lacking effective cybersecurity can be fined as much as £17 million.
With the NIS currently covering essential service providers, such as water, energy, transport, healthcare and digital infrastructure, the new proposals seek to widen this list of companies.
This would include Managed Service Providers (MSPs) which provide specialised online and digital services. MSPs include security services, workplace services and IT outsourcing.
Affected organisations would be required to undertake risk assessments and put in place reasonable and proportionate security measures to protect their network. They must report significant incidents and have plans to ensure they quickly recover from them.
Among the newly published proposals are plans to reform legislation to make it more flexible to react to technological change as well as improving the way organisations report cybersecurity incidents.
It also calls for giving more powers to the UK Cyber Security Council, which regulates the cybersecurity profession. This would help it create a set of agreed qualifications and certifications to help cybersecurity professionals prove they can protect businesses online.
The new regulations aim to transfer costs incurred by regulators for enforcing the NIS regulations from the taxpayer to the organisations covered by the legislation to create a more flexible finance system and reduce the taxpayers’ burden.
Minister of State for Media, Data, and Digital Infrastructure Julia Lopez said: “Cyber-attacks are often made possible because criminals and hostile states cynically exploit vulnerabilities in businesses’ digital supply chains and outsourced IT services that could be fixed or patched.
“The plans we are announcing today will help protect essential services and our wider economy from cyber threats
“Every UK organisation must take their cyber resilience seriously as we strive to grow, innovate and protect people online. It is not an optional extra.”
Recommended
- Contributed | Implementing a zero trust mindset
- Could automation of jobs replace 12 million workers in Europe by 2040?
- 5G safety fears lead British Airways to cancel flights to US
Research by the Department for Digital, Culture, Media and Sport shows only 12% of organisations review the cybersecurity risks coming from their immediate suppliers and only 5% of firms address the vulnerabilities in their wider supply chain.
The plans come in the shadow of multiple high-profile cyberattacks over the past two years. Kaseya, SolarWinds, Microsoft Exchange and Log4j all revealed vulnerabilities in third-party products and services, exposing hundreds of thousands of organisations across the world to cybercriminals and hostile states.
They also follow an increase in ransomware threats to organisations, including some in critical national infrastructure, such as the Colonial Pipeline attack in the US.
The UK Government cybersecurity standards will now be subject to a consultation to amend the NIS regulations. The new legislation would complement the UK’s new £2.6 billion National Cyber Strategy.
UK Cyber Security Council CEO Simon Hepburn said: “The UK Cyber Security Council is delighted that these proposals recognise our cyber workforce lead role that will help to define and recognise cyber job roles and map them to existing certifications and qualifications.
“We look forward to being involved in and contributing to this important government consultation and would encourage all key stakeholders to participate too.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.
Click here to subscribe.





