The newly installed prime minister has dissolved the previously responsible Department for Science, Industry and Technology, with its responsibilities being split among the Cabinet Office with the elevation of a new AI minister, and cyber security transferred to the Departure for Culture, Media and Sport.
But the move had raised concern among experts – including James Morris, head of cyber think-tank CSBR, who had warned that the move could stall the progress of the Cyber Security and Resilience Bill through the UK parliament.
Morris argued that dividing responsibilities meant cyber threat regulation could lose focus, and Malcolm Dowden, a data and technology expert with Pinsent Masons, warned the move posed difficult questions about the impact it might have on cyber legislation
“Andy Burnham’s decision to restructure the departments responsible for the digital economy and AI raises practical questions about continuity in the team responsible for the Cyber Security and Resilience Bill,” he explained.
“The Bill is prepared for its House of Lords committee stage in September, and there are consultations that were due to be launched over the summer recess on key elements of the Bill.
“The proposed implementation period for the Bill was already lengthy, stretching into 2029. Any further delay will be a significant concern in view of enhanced threat levels.”
The legislation, unveiled late last year, plans to provide existing regulators with powers to enforce larger penalties based on turnover for serious cybersecurity breaches by companies with ties to significant UK critical national infrastructure, building on the existing 2018 Network and Information Systems Regulations.
More stringent reporting requirements would also be introduced for Operators of Essential Services, and various digital service providers – including a requirement to notify regulators and the National Cyber Security Centre of incidents within the first 24 hours, and full reporting within 72 hours. Tighter triggers for notification – including near-miss incidents – are also included within the reporting requirements.
The Bill is due for committee scrutiny from the House of Lords in September, after passing its second reading in the upper chamber earlier this month – where peers challenged whether the current, diverse regulatory regime was capable of handling cyber security threats.
Lord Birt, former director general of the BBC, was among several voices in the House of Lords to question whether a single central regulator was a better approach to monitor cyber resilience in the country.
“There is a possible vulnerability in every part of this complex network of providers, with many doors to pry open,” Lord Birt said.
“Once one door is opened by a bad actor—a fraudster, a foreign power, a hacktivist or a ransom gang—there is the potential to explore and disable much or all of the system.
“This is a highly demanding and ever-changing environment, and it is, frankly, preposterous to suppose that the 12 existing sector-specific regulators of our national infrastructure can acquire and constantly update the knowledge effectively to regulate cyber resilience.
“I conclude emphatically that we need a single, focused, dedicated and expert regulator, which I suggest we call the office for cyber resilience – OCR - to span both the public and private sectors, including organisations and, vitally, those who supply them with the technologies they use.
“For clarity, the OCR should also regulate the national infrastructure providers.”
Others, including Baroness Harding, agreed with his call, or argued that one of the regulatory bodies overseeing national infrastructure should act as a single lead for the other regulators to streamline the process.
Broader impacts
The Lords’ comments follow concerns from MPs earlier this year over whether regulators would have both capacity and the technical expertise to manage the cyber security requirements.
Stuart Davey, a cyber readiness expert with Pinsent Masons, noted that these observations reflect the position under the EU’s comparable NIS2 Directive, where member states have identified a single competent authority with responsibility for cyber.
However, he added that this model introduces a risk of one single regulator becoming overloaded with notifications from a broad range of regulated sectors, and failed to reflect the experience the UK’s existing sector-aligned Competent Authorities have developed over the years.
“The UK government has decided that the industry regulators are better placed to know their sector than creating a new regulator,” he said.
“Most of those sectors have used - to varying degrees - the eight years since the NIS Regulations came in, to develop a cyber capability and to work with their sectors to ensure a real sector specific view. Sector regulators have maturing cyber teams, and the comments in the Lords perhaps overlook the fact that these regulators understand the nuances of their sector best.
“However, there undoubtedly can be more done to ensure shared learning, consistency and coordination between different regulators”.
Dowden added the commentary from the Lords on the regulatory issues followed previous concerns raised over AI in the chamber.
“Their observations that bills have "lacked" provisions dealing with AI have generally been met with Ministerial comments that the particular Bill was not the appropriate legislative vehicle for such provisions or – as is the case here - that sectoral regulation in likely to be more effective,” he explained.
The scope of the national infrastructure requirements was also highlighted by the Lords in the debate over the bill, with Viscount Colville of Culross among those calling for a broadening of the regulatory scope to ensure a wider range of organisations are required to have in place such enhanced cyber protection requirements.
“Noble Lords only have to imagine the effect on the country if there were successful attacks on one or two of our big supermarket chains,” he said.
“The result would throw the national food supply chain into crisis. Surely supermarkets, which provide much of our nation’s food and other services, need to be considered very carefully for coming within the scope of the Bill.
“Perhaps the Government need to set up a second tier of essential service sectors that should be preparing to be brought within the scope of the Bill.”
The government has said it believes the diverse nature of the food supply industry means there are other levers which it can employ to ensure security rather than stricter regulation.
Davey pointed out the nature of the proposed legislation allowed it to be flexible where necessary, including making changes in future without the need for new primary legislation.
“There is definitely a valid concern about regulatory divergence, as reflected in the comments in the Lords about diverging from Europe’s NIS2 requirements, and that could lead to challenges for organisation that operate globally,” he explained.
“However a balance needs to be struck, and the government is choosing to focus on those most critical sectors of critical national infrastructure. NIS2 is much broader, but there has been concerns raised in Europe about just how broad that directive is.
“For example, the very wide definitions of what constitutes manufacturing, means a broad range of manufacturing organisations are likely to get caught in scope, potentially resulting in “over-regulation”.
“The Lords identified the food sector as being brought within scope – but the CSRB allows the Government to include that in future if necessary, while also learning the lessons from NIS2, which has a very wide ranging definition of the food sector that goes far beyond just supermarkets.”
It was expected that there would be further clarity about the CSRB with publication of consultation materials due soon. However, it appears that we enter the summer period with some uncertainty as to the future direction of the CSRB.