Download the full outcome
Detail of outcome
The main changes the Government proposes to make are clarifying:
- the thresholds required to identify operators of essential services;
- the role of the Competent Authority and how powers may be delegated to agencies;
- that the role of the National Cyber Security Agency is limited to cyber security;
- the expectations on operators within the first year or so; and
- the definitions of Digital Service Providers.
The Government also intends to simplify:
- the incident response regime, to separate incident response procedures from incident reporting procedures; and
- the penalty regime slightly, to reduce the risk of fines in excess of £17m.
The Government believes these changes will provide further reassurance to industry. The Government again reiterates that our approach will remain reasonable, proportionate and appropriate and that the Government and Competent Authorities will work closely with industry to ensure that this legislation will be a success.
Read the full outcome in the Government response above.
Detail of feedback received
The Government received 358 responses to this consultation. These responses showed there was broad support for the Government’s approach and that in the main, the Government’s proposals were thought to be appropriate and proportionate. Respondents also highlighted areas of concern and the Government has attempted to address these through changes to its approach.
More detailed analysis of the responses to the consultation can be found in the accompanying Analysis Paper.
As our reliance on technology grows, the impact of failure in those systems and the opportunities for those who would seek to compromise our systems and data increase. Responding to this threat and ensuring the safety and security of cyberspace is an essential requirement for a prosperous UK economy. We need to secure our technology, data and networks in order to keep our businesses, citizens and public services protected.
The European Commission, in cooperation with Member States, have agreed a Directive with the aim of increasing the security of Network and Information Systems (NIS) within the European Union (EU). The Government supports the aims of the Directive and sets out in this consultation the proposed implementation approach in the UK.
The NIS Directive will help make sure UK operators in electricity, transport, water, energy, transport, health and digital infrastructure are prepared to deal with the increasing numbers of cyber threats. It will also cover other threats affecting IT, such as power failures, hardware failures and environmental hazards.
This consultation seeks views from industry, regulators and other interested parties on the Government’s plans to transpose the Directive into UK legislation. It sets out the Government’s proposed transposition approach and asks a series of questions on a range of detailed policy issues relating to transposition.
The consultation covers:
- The essential essential services the directive needs to cover
- The penalties
- The competent authorities to regulate and audit specific sectors
- The security measures we propose to impose
- Timelines for incident reporting
- How this affects Digital Service Providers
You can respond to the consultation online here, or via the other ways set out in the consultation document.
The consultation closes at 11:45pm on 30 September 2017.