How this links to the Cyber Security and Resilience Bill
The NIS Regulations 2018 have no general duty to tell customers about incidents. Clause 16 adds one for the three groups whose customers are themselves organisations relying on the service. It matters because customers of a managed or cloud service may have their own reporting duties and need the information to meet them.
- New reg 11C: data centre operators, after the full notification under reg 11A(2)(b).
- New reg 12C: relevant digital service providers, after the full notification under reg 12A(1)(b).
- New reg 14G: relevant managed service providers, after the full notification under reg 14E(1)(b).
- Operators of essential services outside data centres have no equivalent duty in the Bill.
- Failure to notify customers, or to include the required content, is in the higher penalty band (new reg 18(11)).
What exactly must the provider do?
After giving the full incident report, the provider must, as soon as reasonably practicable, take reasonable steps to establish which of its customers in the United Kingdom are likely to be adversely affected by the incident, and then notify those customers.
The notification must give details of the nature of the incident and explain why the provider considers the customer is likely to be adversely affected. There is no fixed hour count and no prescribed form in the Bill.
How does a provider decide which customers are affected?
The provider must take reasonable steps to identify affected customers, which means knowing which customers rely on which systems before an incident happens. Regulations 11C(3), 12C(2) and 14G(2) list the same three factors, adjusted for the service:
- the extent of any actual or likely disruption to the service provided to that customer;
- whether the confidentiality, authenticity, integrity or availability of any data relating to the customer is likely to be compromised;
- any other impact on the network and information systems of the customer.
Why does this matter for customers?
Many customers of a relevant managed service provider, relevant digital service provider or data centre service are regulated themselves. A hospital trust or energy company whose provider is compromised may face its own 24-hour clock. The customer duty gives them a legal route to the facts, though it only arises after the provider's full notification, so customers should also agree faster contractual notice.
The duty covers only customers in the United Kingdom. It sits alongside other laws, so a provider may also have to tell individuals about a personal data breach under UK GDPR.
Incident notification rules compared: OES, data centre, RDSP and RMSP
| Rule | OES (non-data centre) | Data centre OES | RDSP | RMSP |
|---|---|---|---|---|
| Regulation | Reg 11 | Reg 11A | Reg 12A | Reg 14E |
| Who you notify | Designated competent authority for the OES | Designated competent authority (Ofcom, cl.4(2)) | Information Commission | Information Commission |
| What makes it reportable | Has affected or is affecting the operation or security of the systems, and impact has been, is or is likely to be significant (reg 11(3)-(4)) | Could have had, has had, is having or is likely to have a significant impact (reg 11A(3)) | Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 12A(2)-(3)) | Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 14E(2)-(3)) |
| 24-hour initial notification | From first awareness (reg 11(6)(a)) | From first awareness (reg 11A(5)(a)) | From first awareness (reg 12A(5)(a)) | From first awareness (reg 14E(5)(a)) |
| 72-hour full notification | From the same moment of first awareness (reg 11(6)(b)) | From the same moment (reg 11A(5)(b)) | From the same moment (reg 12A(5)(b)) | From the same moment (reg 14E(5)(b)) |
| Customer notification duty | None in the Bill | Yes, reg 11C | Yes, reg 12C | Yes, reg 14G |
| Copy to the CSIRT (NCSC) | At the same time, reg 11(8) | At the same time, reg 11A(7) | At the same time, reg 12A(7) | At the same time, reg 14E(7) |
Where it appears in the Bill
- Cl.16(2), new reg 11CData centre operators must notify affected UK customers.
- Cl.16(3), new reg 12CRDSPs must notify affected UK customers.
- Cl.16(4), new reg 14GRMSPs must notify affected UK customers.
- New reg 18(11)Failures under 11C(2)(b) and (4), 12C(1)(b) and (3), 14G(1)(b) and (3) are in the higher band.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
How quickly must customers be told?
The Bill sets no hour count. The provider must act as soon as reasonably practicable after giving its full notification to the regulator, which itself is due within 72 hours of first awareness. It must first take reasonable steps to identify affected UK customers, then notify them. Customers who need faster notice should secure it in their contracts.
Do operators of essential services have to notify customers?
Only data centre operators. Regulation 11C applies to an OES so far as it provides a data centre service. Other operators of essential services, such as energy or transport operators, have no customer notification duty under the Cyber Security and Resilience Bill, although other laws such as UK GDPR may still require them to tell people about personal data breaches.
What must a customer notification say?
It must give details of the nature of the incident and explain why the provider considers that the customer is likely to be adversely affected. The Bill does not prescribe a form. In deciding who is affected, the provider must consider service disruption, likely compromise of the customer's data, and any other impact on the customer's own systems.