{"id":5694,"date":"2022-02-03T19:31:44","date_gmt":"2022-02-03T18:31:44","guid":{"rendered":"https:\/\/telecomkh.info\/?p=5694"},"modified":"2022-02-03T19:31:44","modified_gmt":"2022-02-03T18:31:44","slug":"new-laws-proposed-to-strengthen-the-uks-resilience-from-cyber-attack","status":"publish","type":"post","link":"https:\/\/telecomkh.info\/?p=5694","title":{"rendered":"New laws proposed to strengthen the UK\u2019s resilience from cyber attack"},"content":{"rendered":"<p><strong>Government is consulting on new measures to boost British businesses\u2019 cyber security after recent high profile attacks<\/strong><\/p>\n<p>New laws are needed to drive up security standards in outsourced IT services used by almost all UK businesses, the government says.<br \/>\nOther proposals being published today include making improvements in the way organisations report cyber security incidents and reforming legislation so that it is more flexible and can react to the speed of technological change.<br \/>\nThe UK Cyber Security Council, which regulates the cyber security profession, also needs powers to raise the bar and create a set of agreed qualifications and certifications so those working in cyber security can prove they are properly equipped to protect businesses online.<br \/>\nThe plans follow recent high-profile cyber incidents such as the cyber attack on SolarWinds and on Microsoft Exchange Servers which showed vulnerabilities in the third-party products and services used by businesses can be exploited by cybercriminals and hostile states, affecting hundreds of thousands of organisations at the same time.<br \/>\nThey also follow an increase in ransomware threats to organisations, including some in critical national infrastructure such as the Colonial Pipeline attack in the US.<br \/>\nMinister of State for Media, Data, and Digital Infrastructure, Julia Lopez, said: \u201cCyber attacks are often made possible because criminals and hostile states cynically exploit vulnerabilities in businesses\u2019 digital supply chains and outsourced IT services that could be fixed or patched.<br \/>\nThe plans we are announcing will help protect essential services and our wider economy from cyber threats<br \/>\nEvery UK organisation must take their cyber resilience seriously as we strive to grow, innovate and protect people online. It is not an optional extra.<br \/>\nTo make the UK more secure and help prevent these types of attacks the government is aiming, through new legislation, to take a stronger approach to getting at-risk businesses to improve their cyber resilience as part of its new \u00a32.6 billion National Cyber Strategy.\u201d<\/p>\n<p><strong>Updating the NIS regulations<\/strong><br \/>\nNetwork and Information Systems (NIS) Regulations came into force in 2018 to improve the cyber security of companies which provide essential services such as water, energy, transport, healthcare and digital infrastructure. Organisations which fail to put in place effective cyber security measures can be fined as much as \u00a317 million.<br \/>\nThe government wants to update the NIS Regulations and widen the list of companies in scope to include Managed Service Providers (MSPs) which provide specialised online and digital services. MSPs include security services, workplace services and IT outsourcing. These firms are crucial to boosting the growth of the country\u2019s \u00a3150.6 billion digital sector and have privileged access to their clients\u2019 networks and systems.<br \/>\nThe NIS regulations require essential service providers to undertake risk assessments and put in place reasonable and proportionate security measures to protect their network. They have to report significant incidents and have plans to ensure they quickly recover from them.<br \/>\nWhile the regulations apply to some digital services such as online marketplaces, online search engines and cloud computing, there has been an increase in the use and dependence on digital services for providing corporate needs such as information storage, data processing and running software.<br \/>\nResearch by the Department for Digital, Culture, Media and Sport shows only 12 per cent of organisations review the cyber security risks coming from their immediate suppliers and only one in twenty firms (5 per cent) address the vulnerabilities in their wider supply chain.<\/p>\n<p>The government is launching a consultation on amending the NIS regulations which includes proposals to:<br \/>\n\u2022 Expand the scope of the NIS Regulations\u2019 to include managed services. These are typically provided by companies which manage IT services on behalf of other organisations.<br \/>\n\u2022 Require large companies to provide better cyber incident reporting to regulators such as Ofcom, Ofgem and the ICO, including a requirement to notify regulators of all cyber security attacks they suffer, not just those which impact their services.<br \/>\n\u2022 Give the government the ability to future-proof the NIS regulations by updating them and if necessary bring into scope more organisations in the future which provide critical support to essential services.<br \/>\n\u2022 Transfer all relevant costs incurred by regulators for enforcing the NIS regulations from the taxpayer to the organisations covered by the legislation to create a more flexible finance system and reduce the taxpayers\u2019 burden.<br \/>\n\u2022 Update the regulatory regime so the most critical digital service providers in the economy have to demonstrate proactively they are following NIS Regulations to the ICO, and take a more light-touch approach with the remaining digital providers.<\/p>\n<p>NCSC Technical Director Dr Ian Levy, said: \u201cI welcome these proposed updates to the NIS regulations, which will help to enhance the UK\u2019s overall cyber security resilience.<br \/>\nThese measures will ensure that cyber security risks are properly managed by organisations and those on whom they rely.\u201d<\/p>\n<p><strong>Empowering the cyber security profession<\/strong><br \/>\nCyber security is a core part of the UK\u2019s booming tech sector which already has hundreds of successful cyber startups and more than a hundred tech \u2018unicorns\u2019 &#8211; companies worth more than \u00a31 billion. As more people are drawn into cyber careers it can be difficult for businesses to know which skills to look for and whether a job candidate has those skills and the necessary qualifications or experience.<br \/>\nIn March the government established and funded the UK Cyber Security Council, a new independent body to lead the cyber workforce and put it on a par with established professions such as engineering.<br \/>\nToday\u2019s proposals would give the council the ability to define and recognise cyber job titles and link them to existing qualifications and certifications. People would have to meet competency standards set by the council before they could utilise a specific job title across the range of specialisms in cyber security.<br \/>\nThis would make it easier for employers to identify the specific cyber skills they need in their organisations and create clearer information on career pathways for young people as well as existing practitioners, without providing unnecessary barriers to entry and progression.<br \/>\nThe proposals include the creation of a Register of Practitioners, similar to what exists in the medical and legal professions, setting out the practitioners who are recognised as ethical, suitably-qualified or senior.<br \/>\nSimon Hepburn, CEO, UK Cyber Security Council, said: \u201cThe UK Cyber Security Council is delighted that these proposals recognise our cyber workforce lead role that will help to define and recognise cyber job roles and map them to existing certifications and qualifications.<br \/>\nWe look forward to being involved in and contributing to this important government consultation and would encourage all key stakeholders to participate too.\u201d<\/p>\n<p><span style=\"color: #999999;\"><em>Above, rackmount LED console in server room data center &#8211; 3d illustration \/ image credited to GovUK<\/em><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Government is consulting on new measures to boost British businesses\u2019 cyber security after recent high profile attacks New laws are needed to drive up security standards in outsourced IT services used by almost all UK businesses, the government says. Other proposals being published today include making improvements in the way organisations report cyber security incidents &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/telecomkh.info\/?p=5694\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> \u00abNew laws proposed to strengthen the UK\u2019s resilience from cyber attack\u00bb<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":5695,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[24],"tags":[],"_links":{"self":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/5694"}],"collection":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5694"}],"version-history":[{"count":1,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/5694\/revisions"}],"predecessor-version":[{"id":5696,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/5694\/revisions\/5696"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/media\/5695"}],"wp:attachment":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}