[FINAL] 2. Executive summary As our reliance on technology grows, improving the security and resilience of the UK’s essential services is increasingly important and is an essential requirement for a prosperous UK economy. We need to secure our technology, data and networks in order to keep our businesses, citizens and public services protected. The ​National Cyber Security Strategy published on 1 November 2016 set our vision for the UK in 2021 as secure and resilient to cyber threats, prosperous and confident in the digital world. On 8 August 2017, the Government published its proposals for improving the security of the UK’s essential services, through its plans to implement the Security of Network and Information Systems Directive (known as the NIS Directive), in a ​public consultation​. This consultation covered six main topics ● ● ● ● ● ● How to identify essential services A national Framework to manage implementation The security requirements for operators of essential services The incident reporting requirements for operators of essential services The requirements on Digital Service Providers The proposed penalty regime The Government received over 350 responses to its consultation. These responses showed that there was broad support for the Government’s approach and that in the main, the Government’s proposals were thought to be appropriate and proportionate. More detailed analysis of the responses to the consultation can be found in the accompanying analysis paper on the consultation web page: www.gov.uk/government/consultations/consultation-on-the-security-of-network-and-informati on-systems-directive​. Respondents also highlighted areas of concern and the Government has attempted to address these through changes to its approach. The main changes that the Government proposes to make are clarifying: ● ● ● ● ● the thresholds required to identify operators of essential services; the role of the Competent Authority and how powers may be delegated to agencies; that the role of the National Cyber Security Agency is limited to cyber security; the expectations on operators within the first year or so; and the definitions of Digital Service Providers The Government also intends to simplify: ● ● the incident response regime to separate incident response procedures from incident reporting procedures; and the penalty regime slightly, to reduce the risk of fines in excess of £17m. The Government believes that these changes will provide further reassurance to industry. The Government again reiterates that our approach will remain reasonable, proportionate and appropriate and that the Government and Competent Authorities will work closely with industry to ensure that this legislation will be a success. Page 4

Select target paragraph3