UK cyber bill set to increase scrutiny

Some technology providers used by asset managers and other financial services firms are likely to face tougher cyber security requirements under legislation currently progressing through Parliament. 

The Cyber Security and Resilience (Network and Information Systems) Bill, which begins its committee stage in the House of Lords in September, will expand the existing Network and Information Systems Regulations 2018. This will bring more organisations into scope and introduce stricter incident reporting and enforcement requirements. 

The legislation will bring medium and large managed service providers (MSPs) under direct regulation for the first time, alongside new requirements affecting data centres and provisions allowing certain suppliers to be designated as critical suppliers. 

These changes will be relevant to asset managers and other financial services firms that increasingly rely on third-party technology providers for functions ranging from IT support to cloud infrastructure. 

While financial services firms are already subject to operational resilience and cyber security requirements, the government has highlighted the systemic risks posed by MSPs. These providers can have extensive access to customers’ systems and may provide cyber criminals with a route into multiple organisations. 

The Bill will require affected regulated organisations to provide an initial notification of significant cyber incidents within 24 hours and a more comprehensive report within 72 hours. Certain providers will also be required to notify affected customers. 

The legislation will introduce stronger enforcement powers, with specified serious breaches potentially attracting fines of £17 million or 4% of worldwide turnover, whichever is higher. 

It is expected to be implemented in phases following Royal Assent, with some measures introduced through secondary legislation.  

spot_img

Latest

Magazine

Related content