Site navigation

UK’s Cyber Laws Updated to Boost Resilience to Attacks

Elizabeth Greenberg

,

Ransomware toolkit Cryptonite
Outsourced IT providers will be brought into scope of cyber regulations to strengthen UK supply chains.

The UK’s cyber laws will be getting a robust update to improve the resilience of key services to cyber attacks.

In response to a public consultation earlier this year, the government has confirmed that Network and Information Systems (NIS) Regulations will be strengthened to protect essential and digital services. 

The UK NIS regulations came into force in 2018 to improve the cybersecurity of companies providing critical services, but an increase in sophistication and number of attacks has prompted the UK to reconsider and strengthen their cyber laws to protect vital services and supply chains. 

Originally derived from the EU’s NIS directive, the UK is able to amend the NIS regulations due to Brexit. 

The new laws will specifically focus on managed service providers (MSPs) which provide IT services like security monitoring and digital billing, often giving them privileged access to their customer’s IT networks. 

MSPs are therefore attractive targets for cybercriminals, as was seen in high profile attacks like Operation CloudHopper which compromised thousands of organisations at the same time. 

The new laws aim to build cyber resilience for MSPs that manage vital supply chains and sectors including water, healthcare, energy, and computing. 

Outsourced IT companies will have to comply, or face fines. 

“We are strengthening the UK’s cyber laws against digital threats,” cyber minister Julia Lopez said. “This will better protect our essential and digital services and the outsourced IT providers which keep them running.”

As part of the government’s £2.6 billion National Cyber Strategy, the legislative changes enable businesses to better improve their cyber resilience. 

Regulators will be able to establish a cost recovery system for enforcing the NIS regulations that is more transparent and takes into account the wider regulatory burdens and other factors to reduce taxpayer burden. 

After the updates are put into effect, they will initially apply to critical service providers like energy companies and the NHS, as well as providers of digital services like cloud computing and online search engines. 

Essential and digital services will also be required to improve their cyber incident reporting to regulators such as Ofcom, Ofgem, and the ICO. This includes anything that disrupts service or may have a high risk or impact to their service, even if they do not immediately cause disruption.


Recommended


To ensure it remains effective, the government will also be allowed to continue amending the NIS regulations, and other organisations can be brought into the scope if they become vital for essential services. 

Paul Maddinson, NCSC Director of National Resilience and Strategy, said: “These measures will increase the resilience of the country’s essential services – and their managed service providers – on which we all rely.”

Commenting on this, Michael White, technical director and principal architect at the Synopsys Software Integrity Group said that this announcement was “by no means surprising” as recommendations for MSPs are turned into laws. 

“For those involved in delivering IT products and services,” White said, “this is likely to require a step change in not only the diligence that is performed during construction and acquisition, but also extensive planning for the complete lifecycle of these offerings – including having the capability to respond rapidly and be able to replace vulnerable sub-components which could be identified many years into the future.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data