UK publishes further details of proposed regulations relating to the security of communication services
Far reaching reforms, aimed at improving the security of communications services in the UK, are progressing at pace through the legislative process of the Houses of Parliament. The proposals follow the UK Telecoms Supply Chain Review Report and are principally set out in the Telecommunications (Security) Bill published in November last year. This Bill has recently been supplemented by draft regulations set out in the Electronic Communications (Security Measures) Regulations 2021 and the Government will soon consult on a further Code of Practice.
As well as providing the legal framework for the Government’s decision to ban Huawei from UK 5G networks (and to take similar action in relation to other high risk vendors), the drafts laws significantly enhance the responsibility of communications providers to ensure the security of networks and services. As well as impacting network operators, the reforms will apply to a large number of communication service providers and, by extension, a broad range of suppliers in communication ecosystems.
Key points arising from the reforms include:
International providers with network management functions overseas will need to look carefully at what capabilities (such as monitoring tools) they need to maintain in the UK in order to meet the new requirements
Communication providers will need to step up their efforts to mitigate the risks posed by third party suppliers, including an assessment of risks posed by downstream suppliers and plans to manage the transition of services to other providers
The need to ensure board level responsibility for security issues
Greater responsibilities on communication providers to notify customers and Ofcom about security incidents
Ofcom will have broader powers to monitor and enforce security requirements, with the ability to issue enforcement orders as well as the ability to issue fines of up to 10% of turnover (or £10m in respect of a failure of providers to provide information)
Current drafts of the legislation can be found at:
SI/SR Template (publishing.service.gov.uk)
We will provide a further update when the Government publishes its consultation on the Code of Practice.