[FINAL]
2. Executive summary
As our reliance on technology grows, improving the security and resilience of the UK’s
essential services is increasingly important and is an essential requirement for a prosperous
UK economy. We need to secure our technology, data and networks in order to keep our
businesses, citizens and public services protected. The National Cyber Security Strategy
published on 1 November 2016 set our vision for the UK in 2021 as secure and resilient to
cyber threats, prosperous and confident in the digital world.
On 8 August 2017, the Government published its proposals for improving the security of the
UK’s essential services, through its plans to implement the Security of Network and
Information Systems Directive (known as the NIS Directive), in a public consultation. This
consultation covered six main topics ●
●
●
●
●
●
How to identify essential services
A national Framework to manage implementation
The security requirements for operators of essential services
The incident reporting requirements for operators of essential services
The requirements on Digital Service Providers
The proposed penalty regime
The Government received over 350 responses to its consultation. These responses showed
that there was broad support for the Government’s approach and that in the main, the
Government’s proposals were thought to be appropriate and proportionate. More detailed
analysis of the responses to the consultation can be found in the accompanying analysis
paper on the consultation web page:
www.gov.uk/government/consultations/consultation-on-the-security-of-network-and-informati
on-systems-directive.
Respondents also highlighted areas of concern and the Government has attempted to
address these through changes to its approach. The main changes that the Government
proposes to make are clarifying:
●
●
●
●
●
the thresholds required to identify operators of essential services;
the role of the Competent Authority and how powers may be delegated to agencies;
that the role of the National Cyber Security Agency is limited to cyber security;
the expectations on operators within the first year or so; and
the definitions of Digital Service Providers
The Government also intends to simplify:
●
●
the incident response regime to separate incident response procedures from incident
reporting procedures; and
the penalty regime slightly, to reduce the risk of fines in excess of £17m.
The Government believes that these changes will provide further reassurance to industry.
The Government again reiterates that our approach will remain reasonable, proportionate
and appropriate and that the Government and Competent Authorities will work closely with
industry to ensure that this legislation will be a success.
Page 4