Government consults on cyber security measures

Image

The government is consulting on plans to implement the EU’s security of network and information systems (NIS) directive, which could see businesses facing fines of up £17m or 4% of global turnover for the failure to have effective cyber security measures in place to safeguard against IT hacking attacks and breaches

The Department for Digital, Culture, Media and Sport (DCMS) says fines would be a last resort, and they will not apply to operators that have assessed the risks adequately, taken appropriate security measures, and engaged with competent authorities but still suffered an attack.

The NIS directive relates to loss of service rather than loss of data, which falls under the General Data Protection Regulations (GDPR). The GDPR requirements are being dealt with under separate legislation, but the DCMS is considering having the same tariff of fines for breaches of both sets of requirements.

The NIS requirements apply to UK operators in electricity, transport, water, energy, transport, health and digital infrastructure, and will cover cyber security as well as other threats affecting IT such as power failures, hardware failures and environmental hazards.

The directive will compel essential service operators to make sure they are taking the necessary action to protect their IT systems.

Under the government’s plans, operators will be required to develop a strategy and policies to understand and manage their risk; to implement security measures to prevent attacks or system failures, including measures to detect attacks, develop security monitoring, and to raise staff awareness and training; to report incidents as soon as they happen; and to have systems in place to ensure that they can recover quickly after any event, with the capability to respond and restore systems.

The consultation is considering the essential services the directive needs to cover; the penalties; the competent authorities to regulate and audit specific sectors; the security measures the government proposes to impose; timelines for incident reporting; and how this affects digital service providers.

The consultation closes on 30 September.

Details of the consultation on the security of network and information systems (NIS) directive are here.

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe