Glossary · Duties and incidents

Security duties

Definition

Security duties are the legal requirements under the NIS Regulations 2018 to take appropriate and proportionate measures to manage risks to network and information systems and to prevent and minimise incident impact. The Cyber Security and Resilience Bill extends them to managed service providers (reg 14B) and refocuses them on security, not only continuity.

What do the security duties require?

The duties are outcome-based rather than a checklist. An operator of essential services must take appropriate and proportionate technical and organisational measures to manage risks to the network and information systems its essential service relies on, and to prevent and minimise the impact of incidents (reg 10).

A relevant digital service provider has an equivalent duty under reg 12. New reg 14B gives a relevant managed service provider the same structure: measures must, having regard to the state of the art, ensure security appropriate to the risk and prevent and minimise the impact of incidents.

What does the Bill change?

Three things. First, managed service providers gain security duties for the first time. Second, the OES and RDSP duties are refocused: the 2018 wording tied incident prevention to continuity of service, and the Bill removes or replaces that wording, so protecting confidentiality and integrity counts as well as keeping the service running. Third, the wider incident definition means measures must address events capable of adverse effect, not only actual harm.

The Bill also lets the Secretary of State issue a code of practice under clause 36 describing measures recommended for compliance. No code has been published yet.

How do the duties relate to the Cyber Assessment Framework?

The NCSC Cyber Assessment Framework is the main tool regulators use to assess whether operators meet the security duties, and many competent authorities already ask OES to self-assess against it. The Bill does not name the CAF, so whether it will be the benchmark for managed service providers and digital service providers depends on Information Commission guidance and any code of practice. That is not yet settled.

In practice, the CAF's four objectives cover managing risk, protecting against attack, detecting events and minimising impact. They map closely onto what regulations 10, 12 and 14B require.

Where it appears in the Bill

  • NIS reg 10OES security duties; reg 10(2) amended by Sch 2 para 8.
  • Cl.8, NIS reg 12RDSP duties refocused on security; reg 12(2A) guidance.
  • Cl.10, new reg 14BNew RMSP security duties.
  • Cl.36Power to issue a code of practice on recommended measures.
  • New reg 18(11)Security duty failures in the higher penalty band.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Are the security duties a checklist of controls?

No. They require appropriate and proportionate measures based on risk, and for managed service providers the measures must reflect the state of the art. Regulators judge compliance against guidance and frameworks such as the NCSC Cyber Assessment Framework, and a future code of practice under clause 36 may describe recommended measures, but the legal test remains risk-based.

Do managed service providers have to use the CAF?

The Bill does not say so. New regulation 14B requires managed service providers to have regard to relevant Information Commission guidance, and the Secretary of State may issue a code of practice. Whether either adopts the Cyber Assessment Framework as the benchmark is not settled, although it is the established framework under the existing NIS regime.

What is the penalty for breaching the security duties?

Breach of the security duties in regulations 10(1)-(2), 12(1) and 14B(1) falls in the higher band under new regulation 18(11). For an undertaking the maximum is the greater of £17 million and 4% of worldwide turnover; for others it is £17 million. Regulators also have enforcement notices, information notices and inspections.

Related guidance

Official sources

More in Duties and incidents

Full glossary