The UK’s cyber laws will be getting a robust update to improve the resilience of key services to cyber attacks.
In response to a public consultation earlier this year, the government has confirmed that Network and Information Systems (NIS) Regulations will be strengthened to protect essential and digital services.
The UK NIS regulations came into force in 2018 to improve the cybersecurity of companies providing critical services, but an increase in sophistication and number of attacks has prompted the UK to reconsider and strengthen their cyber laws to protect vital services and supply chains.
Originally derived from the EU’s NIS directive, the UK is able to amend the NIS regulations due to Brexit.
The new laws will specifically focus on managed service providers (MSPs) which provide IT services like security monitoring and digital billing, often giving them privileged access to their customer’s IT networks.
MSPs are therefore attractive targets for cybercriminals, as was seen in high profile attacks like Operation CloudHopper which compromised thousands of organisations at the same time.
The new laws aim to build cyber resilience for MSPs that manage vital supply chains and sectors including water, healthcare, energy, and computing.
Outsourced IT companies will have to comply, or face fines.
“We are strengthening the UK’s cyber laws against digital threats,” cyber minister Julia Lopez said. “This will better protect our essential and digital services and the outsourced IT providers which keep them running.”
As part of the government’s £2.6 billion National Cyber Strategy, the legislative changes enable businesses to better improve their cyber resilience.
Regulators will be able to establish a cost recovery system for enforcing the NIS regulations that is more transparent and takes into account the wider regulatory burdens and other factors to reduce taxpayer burden.
After the updates are put into effect, they will initially apply to critical service providers like energy companies and the NHS, as well as providers of digital services like cloud computing and online search engines.
Essential and digital services will also be required to improve their cyber incident reporting to regulators such as Ofcom, Ofgem, and the ICO. This includes anything that disrupts service or may have a high risk or impact to their service, even if they do not immediately cause disruption.
Recommended
- New initiative offers free mentorship to tech companies
- EV charging infrastructure needs private sector investment to grow
- Now is the Time to Put Customers at the Heart of Your Business
To ensure it remains effective, the government will also be allowed to continue amending the NIS regulations, and other organisations can be brought into the scope if they become vital for essential services.
Paul Maddinson, NCSC Director of National Resilience and Strategy, said: “These measures will increase the resilience of the country’s essential services – and their managed service providers – on which we all rely.”
Commenting on this, Michael White, technical director and principal architect at the Synopsys Software Integrity Group said that this announcement was “by no means surprising” as recommendations for MSPs are turned into laws.
“For those involved in delivering IT products and services,” White said, “this is likely to require a step change in not only the diligence that is performed during construction and acquisition, but also extensive planning for the complete lifecycle of these offerings – including having the capability to respond rapidly and be able to replace vulnerable sub-components which could be identified many years into the future.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





