How this links to the Cyber Security and Resilience Bill
The phrase anchors almost every duty in the Bill: security duties protect network and information systems, incidents are events affecting them, and managed services are defined by access to them. The Bill does not amend the 2018 definition, but it applies it more widely by changing the incident definition and adding new regulated groups.
- NIS reg 1(2) definition applies to all Part 2 amendments.
- Cl.15(2): an incident is now an event with actual or potential adverse effect on the operation or security of these systems.
- Cl.9(5), new reg 1(3B)(b): a managed service involves connecting to or accessing a customer's network and information systems.
- Cl.24(1)-(2): Part 3 uses its own similar definition for essential activities.
What is the exact definition?
Regulation 1(2) of the NIS Regulations 2018 defines a network and information system as:
- an electronic communications network within the meaning of the Communications Act 2003;
- any device or group of interconnected or related devices, one or more of which performs automatic processing of digital data under a program;
- digital data stored, processed, retrieved or transmitted by those networks or devices for the purposes of their operation, use, protection and maintenance.
How broad is it in practice?
Very broad. It covers corporate IT, cloud workloads, operational technology such as industrial control systems and building management systems, and the data those systems use to run. That breadth is why an operator of essential services must consider OT as well as IT when meeting its security duties.
The duties are not about all systems an organisation owns, though. Each duty is tied to the systems relied on to provide the regulated service, such as the essential service, the relevant digital service or the managed service.
Does Part 3 use the same definition?
Nearly. Clause 24(1) defines a network and information system for Part 3 as an electronic communications network within section 32(1) of the Communications Act 2003, or apparatus programmed to process digital data, and clause 24(2) extends that to data used for operating, using, protecting or maintaining the network or apparatus. The wording differs from the 2018 text, but the scope is similar. Part 3 powers apply to essential activities specified later in regulations.
Where it appears in the Bill
- NIS reg 1(2)The definition used for Part 2 duties; not amended by the Bill.
- Cl.15(2)Incident definition refers to operation or security of these systems.
- Cl.9(5), new reg 1(3B)Managed service defined by access to a customer's systems.
- Cl.24(1)-(2)Separate Part 3 definition.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Does the definition include operational technology?
Yes. Any device or group of devices that performs automatic processing of digital data under a program falls within the definition, which covers industrial control systems, SCADA, building management and similar operational technology. Where OT is relied on to provide a regulated service, it is within the scope of the security duties and incident reporting.
Does the Bill change the definition?
No, not for the NIS Regulations regime in Part 2. The Cyber Security and Resilience Bill keeps the 2018 definition in regulation 1(2) but widens the definition of incident that uses it. Part 3 of the Bill has its own, similarly worded definition in clause 24 for the new essential activities powers.
Is data itself a network and information system?
Partly. The definition includes digital data stored, processed, retrieved or transmitted by networks and devices, but only for the purposes of their operation, use, protection and maintenance. So configuration data, credentials and logs are within it. Business data such as customer records is protected indirectly, because incidents compromising its confidentiality or integrity are a reportability factor.