google.com, pub-8701563775261122, DIRECT, f08c47fec0942fa0
UK

New laws to bolster UK’s defences against cyber attacks on NHS, transport and energy

IT companies that provide services to the UK’s energy, water and transport infrastructure, as well as the NHS, will face tough new security standards under new legislation introduced by ministers to reduce the threat of cyber attacks.

The Cyber ​​Security and Resilience Bill will be introduced on Wednesday in a move ministers hope will strengthen national security by increasing cyber protections for the services people and businesses rely on.

The aim is to ensure the taps stay on, the lights stay on and the UK’s transport services continue, as businesses, transport hubs and government agencies continue to be targets of cyber attacks.

Last month, the National Cyber ​​Security Center said a “significant threat” from Chinese and Russian hackers was contributing to a record number of serious online attacks.

The OBR has warned that a cyber attack on critical national infrastructure could temporarily increase borrowing by more than £30bn (1.1 per cent of the UK’s GDP).

Further research published on Wednesday shows that the average cost of a significant cyber attack in the UK is now over £190,000, equivalent to £14.7bn a year across the economy, or 0.5 per cent of GDP.

The proposed laws would regulate IT management, IT help desk support and cybersecurity companies that provide services to private and public sector organisations.

Heathrow was hit by a cyber attack earlier this year (Maja Smiejkowska/PA) (PA Wire)

Medium and large companies with reliable access to critical infrastructure and business networks will need to meet clear security duties and report major cyber incidents to the government and their customers.

Key providers of the UK’s essential services, such as those supplying healthcare diagnostics to the NHS or chemicals to a water company, may be classed as critical suppliers by regulators. This will mean they must meet minimum security requirements to close gaps in the supply chain that criminals can exploit, a new power for regulators.

Tougher penalties will be introduced to prevent companies from cutting corners when it comes to providing services to taxpayers. Liz Kendall will have new powers as technology secretary to instruct regulators and the organizations they oversee to take further steps to prevent cyber attacks.

“Cybersecurity is national security,” Ms. Kendall said. “This legislation will enable us to confront those who would disrupt our way of life. I am sending them a clear message: the UK is not an easy target.”

“We all know the disruption caused by daily cyber attacks. Our new laws will make the UK safer from these threats. This will mean fewer canceled NHS appointments, less disruption to local services and businesses, and a faster national response when threats arise.”

The new bill was commented by National Cyber ​​Security Center CEO Dr. Support came from Richard Horne, who said: “The Cybersecurity and Resilience Act represents a significant step towards ensuring the nation’s most critical services are better protected and prepared to face an increasingly complex threat landscape.

New laws hope to curb a major threat from cyber attacks (Dominic Lipinski/PA)

New laws hope to curb a major threat from cyber attacks (Dominic Lipinski/PA) (PA Wire)

“The real-world impacts of cyber attacks have never been more evident than in recent months, and we therefore welcome the move to strengthen legislation and regulatory powers to help increase the level of defense and resilience in critical national infrastructures.

“Cybersecurity is a shared responsibility and foundation for prosperity and that is why we urge all organisations, no matter how large or small, to follow the advice and guidance available at ncsc.gov.uk and act on it with the urgency the risk demands.”

Phil Huggins, National Chief Information Security Officer for NHS England Health and Care, said: “The Act represents a huge opportunity to strengthen cybersecurity and resilience to protect the safety of the people we care about.

“The reforms will make fundamental updates to our approach to addressing the biggest risks and harms, such as new powers to identify critical suppliers.

“By working with the healthcare industry, we can deliver a step change in cyber maturity and help keep services available, protect data and maintain trust in our systems in the face of an evolving threat landscape.”

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button