Skip to main content

Adapting the UK’s cyber ecosystem

Web Hosting & Remote IT Support

From malware and ransomware to phishing attacks and artificial intelligence (AI), the cybersecurity threat landscape is evolving. Threat actors are continuing to deploy increasingly advanced tools to target their chosen victims, with research by Fortinet showing 87% of organizations experienced either one or more cybersecurity breaches in 2023.

As such, it’s no longer a question of whether an organization will experience a breach – it’s when. Countries around the world are having to tighten their defenses as a result, including the UK. But as other countries make strides in their cybersecurity protection, how does the UK compare to its European counterparts, and the rest of the world? How can the UK adapt its cybersecurity ecosystem to keep up with these changing threat tactics, both now and in the future?

Global cybersecurity regulations

Several countries have introduced regulations designed to protect against threats. For example, the European Union’s NIS2 Directive requires organizations in critical sectors – such as energy and transport – to implement stronger cybersecurity measures including, risk management and incident response. It also requires organizations to report incidents within 24 hours, involve senior management in accountability, and ensure any cybersecurity risks are mitigated across the supply chain.

Further afield, the US’s National Cybersecurity Strategy also establishes minimum cybersecurity requirements for organizations in critical sectors and shifts responsibility onto them by encouraging security by design and promoting data privacy in products and services. In Asia, Singapore has introduced an Operational Technology Masterplan aiming to improve the security of the technology underpinning the country’s economy.

This includes traffic light controllers, fuel station pumps and energy grid control systems. The legislation also aims to boost cybersecurity talent through programs, threat intelligence sharing and the establishment of a Cybersecurity Centre of Excellence. So, what about the UK?

Where the UK compares

The government has taken significant steps to strengthen the UK’s cybersecurity defenses in recent years. This includes the upcoming Cybersecurity and Resilience Bill which will expand existing protections for critical infrastructure and digital services, alongside introducing mandatory incident reporting for organizations.

The UK has also introduced cybersecurity legislation targeting specific industries, particularly those facing a large number of attacks – such as healthcare, energy and education – due to the value and volume of the data they are responsible for. This includes the Telecommunications Security Act 2022, which requires telecommunications providers to implement more stringent cybersecurity measures and requirements on incident reporting.

Yet, while these regulations are a step in the right direction, it’s important we continually assess and understand gaps in the UK’s cybersecurity defenses, and address them accordingly. So how can we build on the progress that’s already being made?

Narrowing these gaps

One way the UK can strengthen its line of defense is by making legislation, including the Cybersecurity and Resilience Bill, more descriptive about how it is going to combat current and future threats. As an example, the NIS2 Directive clearly outlines what needs to be done to address attacks and improve protection, as well as establishing a risk profile of the supply chain. It is also supported by a Network and Information Systems Corporation Group to ensure compliance among member states – which the UK could potentially establish for the Cybersecurity and Resilience Bill too.

It’s important to note that many EU member states are yet to officially incorporate NIS2 into national legislation, with harmonization proving difficult due to varying economic, logistical and geographical profiles between countries. However, this also provides an opportunity for the UK to ‘cherry pick’ the best parts of the regulation and incorporate them into both the Cybersecurity and Resilience Bill and future legislation.

It’s also vital the UK addresses the growing cybersecurity threat of AI. While the benefits of the technology in cybersecurity are known, we must also acknowledge AI can be used by threat actors looking to evolve their attack methods – whether that’s through sophisticated phishing attacks or gathering data – and ensure organizations are adequately protected.

The previous UK government adopted a ‘pro-innovation’ over regulatory approach towards AI technology, in comparison to the EU’s AI Act which enforced requirements for usage and development.

While the new Labour government has promised to introduce binding regulation for certain companies, we must also ensure organizations are adequately protected against threats. To do this, leaders must be encouraged to build a culture of cybersecurity through better employee education. Basic cybersecurity measures, such as multi-factor authentication, zero-trust network access and regular software and application patching, must also be put in place.

Around the world, countries are continuing to strengthen their defenses against the tactics threat actors are deploying. While the UK has made significant progress in introducing regulations designed to protect businesses and the wider economy, continually reviewing and adapting our cyber ecosystem is critical to identifying gaps in our line of defense. This will allow us to keep up with the changing cybersecurity landscape and stay one step ahead.

We list the best IT management tool

This article was produced as part of TechRadarPro's Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro



via Hosting & Support

Comments

Popular posts from this blog

Microsoft, Google, and Meta have borrowed EV tech for the next big thing in data centers: 1MW watercooled racks

Web Hosting & Remote IT Support Liquid cooling isn't optional anymore, it's the only way to survive AI's thermal onslaught The jump to 400VDC borrows heavily from electric vehicle supply chains and design logic Google’s TPU supercomputers now run at gigawatt scale with 99.999% uptime As demand for artificial intelligence workloads intensifies, the physical infrastructure of data centers is undergoing rapid and radical transformation. The likes of Google, Microsoft, and Meta are now drawing on technologies initially developed for electric vehicles (EVs), particularly 400VDC systems, to address the dual challenges of high-density power delivery and thermal management. The emerging vision is of data center racks capable of delivering up to 1 megawatt of power, paired with liquid cooling systems engineered to manage the resulting heat. Borrowing EV technology for data center evolution The shift to 400VDC power distribution marks a decisive break from legacy sy...

The Apple Watch ban is lifted, on appeal – but the reprieve might only be temporary

Web Hosting & Remote IT Support The Apple Watch ban story has developed quickly over the last week and a bit, and there's now a new twist: the US Court of Appeals is putting a pause on the US sales and import ban while it reviews the case, which means the Apple Watch 9 and Apple Watch Ultra 2 can go back on sale for the time being. "We are thrilled to return the full Apple Watch lineup to customers in time for the new year," an Apple spokesperson told TechRadar. "We are pleased the US Court of Appeals for the Federal Circuit has stayed the exclusion order while it considers our request to stay the order pending our full appeal." The watches in question are now once again available from "select" Apple Stores, and will also be going on sale from the Apple website from 12pm PT / 3pm ET on Thursday, December 28 (that's 8pm in the UK, and early on December 29 in Australia). All Apple Stores should have stock by the weekend. As for how long t...

The Samsung Galaxy Ring could go into production as soon as next month

Web Hosting & Remote IT Support With the dust beginning to settle from the huge Samsung Unpacked 2023 event, we can turn our attention towards what Samsung might have planned next: and a smart ring seems to be in the company's near future. As per a report from South Korean outlet The Elec (via SamMobile ), mass production on a Samsung Galaxy Ring could begin as early as August, with a decision imminent on the schedule for getting the wearable manufactured and out to consumers. A full launch is slated for some point during 2024 though, rather than 2023. The nature of the device means that it'll need to clear several regulatory hurdles before it can go on sale and start tracking various vital statistics. An early 2024 launch would put the Galaxy Ring on a similar schedule to the Samsung Galaxy S24 – and it would therefore make sense to launch both gadgets at the same time, perhaps in January or February if Samsung follows its 2023 routine. The story so far Rumors ar...