Today the Government have published a policy statement on proposed legislative measures to bolster the UK’s cyber-security and resilience.
Our digital economy and essential services are increasingly being attacked by cyber-criminals and state actors, threatening essential public services and infrastructure. This poses a serious risk not only to UK citizens, with core services like hospitals being targeted, but also to the performance of our economy. UK businesses lost around £87 billion from cyber-attacks between 2015 and 2019—that is £87 billion taken from our economy, much of which went into the hands of cyber-criminals.
Enhanced cyber-security is an essential pillar not only of our national security, but of the UK’s economic growth. We cannot have economic growth without stability, and we cannot have stability without national security.
The UK’s only existing cross-sector cyber legislation—the Network and Information Systems (NIS) Regulations—was introduced in 2018 when the UK was still an EU member state. The rapidly evolving threat landscape and changing nature of digital services mean that these regulations need to be updated, and we no longer have powers in primary legislation to make the amendments needed.
That is why we committed to introduce a cyber-security and resilience Bill in the King’s Speech in July last year. As set out in the policy statement published today, the Bill will strengthen the UK’s cyber-defences and make sure that the critical infrastructure and digital services UK citizens and business rely on are more secure. This will enhance the UK’s level of cyber-security and resilience at a time when similar steps are being taken by our international counterparts, such as the EU, which has updated the NIS framework through its own updated directive.
The policy statement provides more detail to the Bill’s measures announced in the King’s Speech:
Expanding the scope of regulations to protect more digital services and supply chains. The Bill will bring managed IT service providers that provide digital services into the scope of the regulatory framework. The Bill will allow individual regulators to designate a small number of important suppliers to regulated entities as “critical suppliers”, including those that would otherwise be exempted from regulation as SMEs. This, in addition to embedding supply chain security requirements directly into our regulatory framework, will address supply chain vulnerabilities and reduce the threat of significant disruptions to critical services. This will build a better picture of the threats facing our critical national infrastructure and protect a broader range of services from cyber-attacks.
Empowering regulators and enhancing oversight. Regulators will be better equipped with the tools they need to perform their duties effectively, including enhanced oversight of cyber-incidents affecting regulated entities and improved cost recovery powers. The Information Commissioner’s information gathering powers will be strengthened, to improve its understanding of the landscape of cyber-security threats affecting the expanded portfolio of digital service providers that it will oversee.