Cyber Conference
– Cybersecurity Business Network (CBN)

LONDON – Britain’s cybersecurity authority has more work to do on the regulation front, as enterprises call on the U.K. government for more detail on its recent Cyber Security and Resilience Bill.

At the inaugural Parliament & Cyber Conference, director for rational resilience at the National Cyber Security Centre (NCSC), Jonathon Ellison, called the Bill a step in the right direction after a perhaps laissez-faire approach in the past to fortifying security legislation for Britain’s businesses.

“We are not where we need to be, and we know we are not where we need to be. The exhibit in terms of the applicability of existing regulations has not led to the level of resilience across the economy that it should be,” Ellison admitted, deeming the current Bill a work in progress.

Introduced this month, the Cyber Bill was drawn up in response to a spate of cyber attacks in recent years, affecting British giants such as vehicle makers Jaguar Land Rover (JLR), retail brand Marks & Spencer (M&S), and the National Health Service (NHS).

At the conference, CrowdStrike Field CTO Europe Zeki Turedi claimed the U.K. is one of the most targeted countries in the world, with every one of its industries at risk from cybercrime.

The Bill also added data centers to the operators of essential services (OES) category, as well as managed service providers (MSPs) providing outsourced IT services.

But at the Parliament-based event, Ellison confessed “regulation also has a cost,” and saw the NCSC’s remit more as making sure tools and approaches are available for companies to meet cybersecurity standards.

This encompasses smaller companies to those designated as Critical National Infrastructure (CNI): telecoms, energy and water supply, transportation, and health.

Perhaps falling outside of the NCSC remit are large companies not designated into the CNI category, and which are too large to be properly served by the NCSC’s more small business-focused Cyber Essentials guidance service.

“You've got a problem in the middle, the large companies that are key to our economy,” said Ellison.

Arguably one of those companies is SAP, which with CrowdStrike co-sponsored the event for the Cybersecurity Business Network (CBN).

Chris Francis, director of government relations at SAP, said that despite the Bill being a much-welcomed move, the enterprise giant wants “increased legal certainty.”

“It needs to be clearly focused on the actual services,” explained Francis. “Now it wanders between service and company, and it's a little unfair. If you've got one app that is a digital service, your entire automotive industry is suddenly affected by the Bill.

Francis deemed it “absolutely essential” that all necessary details go through mandatory consultation with businesses, and not solely between regulators, calling for a specific regulatory impact assessment that also goes through the standard review process.

“Because that's actually where we will understand what this bill actually means, in practice. It's not in the Bill. The Bill is [merely] filling in details about how to comply with the Bill."

Representing the British defense think tank view was Jen Ellis, associate fellow in Cyber & Tech for the Royal United Services Institute (RUSI), who saw the current Bill as providing neither carrots nor sticks for British businesses.

“We're just sort of giving them a wagged finger at the moment and a disapproving look,” said Ellis.

While urging caution on regulation, Ellis did see a potential ‘stick’ in pushing cybersecurity in the workforce in the same way as health and safety mandates do.

“That intersection between physical and virtual means we are talking about safety,” she explained. “We should stop just doing the 'disappointed parent' and get really specific if we want to see change … And then we can also start talking about whether there are carrots we can offer as well to help with that. Otherwise, we won't see change but more dissatisfaction all the way around.”

Perhaps surprisingly, AI was not a major theme at the conference, with the Government seemingly keen to ensure British companies are getting the basics right before going down that particular rabbit hole.

Also not up for discussion were internet outages, despite recent mega-failovers such as the global snafu Amazon Web Services (AWS) encountered in October.

The two themes have some relation, with recent telecom-focused Nokia research reporting that 52% of DDoS attacks hit multiple hosts simultaneously, with 58% using multiple vectors, and 78% finishing within five minutes – stats that the vendor giant said will likely get worse as bad actors employ AI in their toolkit.

Ellison told SDxCentral that while cyber attackers can lead to internet collapses, outages didn’t fall under his national resilience remit at the NCSC. That presumably falls onto the shoulders of the independent, government-approved authority Office of Communications (Ofcom).

With more of a focus on the U.K. telecom industry, Ofcom is not mandated with keeping hyperscalers such as AWS in check. Yet as hyperscale dominance underpins more and more national infrastructure, there have been growing calls for the U.S. giants to be treated as telecom carriers by being forced to follow statutory obligations and be held accountable for when systems go awry.

But with little appetite to regulate everyday businesses on the security front, there is likely to be little challenge from Britain on hyperscaler authority any time soon.