How this links to the Cyber Security and Resilience Bill
The CSIRT already exists under the 2018 Regulations. The Bill makes it a direct recipient of every incident notification, at the same time as the regulator, and sets out what the CSIRT may do with that information. This gives the NCSC early national visibility of incidents across sectors.
- Regs 11(8), 11A(7), 12A(7) and 14E(7): regulated persons must copy notifications to the CSIRT at the same time.
- Regs 11B, 12B and 14F: the CSIRT may alert overseas authorities, give the notifying organisation help, and share information with other regulated persons.
- The CSIRT, like the regulator, may inform the public about an incident where awareness is needed, after consultation.
- Failure to send the CSIRT copy is in the standard penalty band (new reg 18(10)).
Who is the UK CSIRT?
Regulation 5 of the NIS Regulations 2018 designates GCHQ as the CSIRT for the UK for the relevant sectors and digital services. The work is done by the National Cyber Security Centre, which is part of GCHQ, so in practice "the CSIRT" means the NCSC.
Its statutory functions include monitoring incidents in the UK, providing early warnings and alerts, responding to notified incidents, providing risk analysis and situational awareness, and cooperating with international CSIRT networks.
What does the Bill require organisations to send the CSIRT?
Each incident notification, both the initial notification and the full notification, must be copied to the CSIRT at the same time as it is sent to the designated competent authority or the Information Commission. The duty applies to operators of essential services, data centre operators, digital service providers and managed service providers.
Missing the CSIRT copy is a separate failure from missing the regulator notification. It carries the standard maximum penalty: for an undertaking, the greater of £10 million and 2% of turnover.
What can the CSIRT do with a notification?
Under new regulations 11B, 12B and 14F the CSIRT may:
- notify an authority in another country if the incident has or is likely to have a significant impact there;
- give the notifying organisation information to help it deal with the incident or prevent another;
- disclose information to other regulated persons to help prevent similar incidents;
- inform the public, or require the organisation to do so, where public awareness is necessary, after consultation.
Where it appears in the Bill
- NIS reg 5Designates GCHQ as the CSIRT; unchanged by the Bill.
- New regs 11(8), 11A(7), 12A(7), 14E(7)Copy notifications to the CSIRT at the same time.
- New regs 11B, 12B, 14FCSIRT and regulator functions on notified incidents.
- New reg 18(10)Failure to copy the CSIRT is in the standard band.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Is the CSIRT the NCSC or GCHQ?
Both, in a sense. Regulation 5 of the NIS Regulations 2018 designates GCHQ as the UK CSIRT. The National Cyber Security Centre is part of GCHQ and carries out the CSIRT functions, so organisations deal with the NCSC in practice. The Cyber Security and Resilience Bill does not change the designation.
Is the CSIRT a regulator?
No. The CSIRT does not enforce the NIS Regulations or impose penalties. Enforcement sits with the designated competent authorities and the Information Commission. The CSIRT receives copies of notifications, provides technical help and situational awareness, shares warnings, and may inform overseas authorities or the public where appropriate.
What happens if we notify the regulator but forget the CSIRT?
That is a separate breach. Failing to send the copy under regulation 11(8), 11A(7), 12A(7) or 14E(7) falls in the standard penalty band, with a maximum of the greater of £10 million and 2% of turnover for an undertaking. Build the CSIRT copy into the same step as the regulator notification.