How this links to the Cyber Security and Resilience Bill
The Bill keeps the risk-based duty in regulations 10 and 12, adds an equivalent duty for managed service providers, and removes wording that tied incident prevention to service continuity. It also gives the Secretary of State power to issue a code of practice describing recommended measures. Breach of the security duties is in the higher penalty band.
- Cl.10 inserts reg 14B: RMSPs must take appropriate and proportionate measures, having regard to the state of the art.
- Cl.8 amends reg 12(2)(b) so RDSP measures prevent and minimise incident impact on security, not only continuity, and adds reg 12(2A) on regard to Information Commission guidance.
- Sch 2 para 8 removes "with a view to ensuring the continuity of those services" from reg 10(2).
- Cl.36: the Secretary of State may issue a code of practice describing recommended measures for compliance.
- New reg 18(11): security duty failures under regs 10(1)-(2), 12(1) and 14B(1) are in the higher band.
What do the security duties require?
The duties are outcome-based rather than a checklist. An operator of essential services must take appropriate and proportionate technical and organisational measures to manage risks to the network and information systems its essential service relies on, and to prevent and minimise the impact of incidents (reg 10).
A relevant digital service provider has an equivalent duty under reg 12. New reg 14B gives a relevant managed service provider the same structure: measures must, having regard to the state of the art, ensure security appropriate to the risk and prevent and minimise the impact of incidents.
What does the Bill change?
Three things. First, managed service providers gain security duties for the first time. Second, the OES and RDSP duties are refocused: the 2018 wording tied incident prevention to continuity of service, and the Bill removes or replaces that wording, so protecting confidentiality and integrity counts as well as keeping the service running. Third, the wider incident definition means measures must address events capable of adverse effect, not only actual harm.
The Bill also lets the Secretary of State issue a code of practice under clause 36 describing measures recommended for compliance. No code has been published yet.
How do the duties relate to the Cyber Assessment Framework?
The NCSC Cyber Assessment Framework is the main tool regulators use to assess whether operators meet the security duties, and many competent authorities already ask OES to self-assess against it. The Bill does not name the CAF, so whether it will be the benchmark for managed service providers and digital service providers depends on Information Commission guidance and any code of practice. That is not yet settled.
In practice, the CAF's four objectives cover managing risk, protecting against attack, detecting events and minimising impact. They map closely onto what regulations 10, 12 and 14B require.
Where it appears in the Bill
- NIS reg 10OES security duties; reg 10(2) amended by Sch 2 para 8.
- Cl.8, NIS reg 12RDSP duties refocused on security; reg 12(2A) guidance.
- Cl.10, new reg 14BNew RMSP security duties.
- Cl.36Power to issue a code of practice on recommended measures.
- New reg 18(11)Security duty failures in the higher penalty band.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Are the security duties a checklist of controls?
No. They require appropriate and proportionate measures based on risk, and for managed service providers the measures must reflect the state of the art. Regulators judge compliance against guidance and frameworks such as the NCSC Cyber Assessment Framework, and a future code of practice under clause 36 may describe recommended measures, but the legal test remains risk-based.
Do managed service providers have to use the CAF?
The Bill does not say so. New regulation 14B requires managed service providers to have regard to relevant Information Commission guidance, and the Secretary of State may issue a code of practice. Whether either adopts the Cyber Assessment Framework as the benchmark is not settled, although it is the established framework under the existing NIS regime.
What is the penalty for breaching the security duties?
Breach of the security duties in regulations 10(1)-(2), 12(1) and 14B(1) falls in the higher band under new regulation 18(11). For an undertaking the maximum is the greater of £17 million and 4% of worldwide turnover; for others it is £17 million. Regulators also have enforcement notices, information notices and inspections.