I am repeating the following written ministerial statement made today in the other place by my noble Friend, the Parliamentary Under-Secretary of State for Digital Economy, Baroness Lloyd of Effra.
The UK telecoms supply chain review 2019 identified the need to establish an enhanced legislative framework for telecoms security. In response, the Government established a stronger telecoms security framework, which consists of:
The Telecommunications (Security) Act 2021—primary legislation that established new duties on public telecoms providers to prevent security compromises within their networks and services.
The Electronic Communications (Security Measures) Regulations 2022—secondary legislation setting out specific cyber-security requirements with which the public telecoms providers must comply.
The Telecommunications Security Code of Practice 2022—technical guidance on how providers can comply with the requirements set out in the regulations.
The UK’s future prosperity rests on the public electronic communications networks and services—PECN and PECS—that provide our telecoms and internet connectivity. It is important therefore that the telecoms security framework keeps pace with the scale of the threat to UK telecoms networks and services, adapting to evolving threats to network security and new innovations in telecoms technology.
The UK National Cyber Security Centre’s annual review 2025 highlights how state actors continue to pose a persistent and escalating cyber-threat to UK critical national infrastructure, including telecoms, leveraging sophisticated cyber-capabilities and working closely with a growing commercial intrusion market. This threat is becoming increasingly diffuse and dangerous, with cyber-attacks a key tool in geopolitical competition. The volume of nationally significant incidents managed by the NCSC continues to grow, and we are seeing high-profile campaigns like Salt Typhoon, targeting over 80 countries worldwide.
At the same time, innovations in technology are redefining both the cyber-security threat and the tools available for cyber-security and resilience. The growing use of AI, for example, delivers significant operational benefits for telecoms, but it also introduces new risks. Adversaries can exploit AI to automate the discovery of network vulnerabilities, and more rapidly identify high-value targets within networks. Maintaining a proactive, adaptive security posture is essential to safeguard the UK’s telecoms networks and services against these evolving and increasingly sophisticated threats.
Within the code of practice, to account for this changing threat landscape, the Government stated their intent to
“review and update the Code of Practice periodically as new threats emerge and technologies evolve.”