UK seeks to tighten security of supply chains after Iran-linked cyber attack
The UK government is seeking to change the law so that it can block companies from buying products from high-risk suppliers, in a move that comes shortly after news that a hacking group had shut down a small energy facility.
Ministers could demand companies in critical sectors such as energy, healthcare and telecoms take extra security measures such as implementing a phased removal of certain vendors or be banned from acquiring technology from them under proposals announced on Monday.
The vulnerability of key UK infrastructure was highlighted by Sunday’s revelation that hackers thought to be linked to Iran had forced a small gas plant offline. The National Cyber Security Centre has also warned that companies must do more to guard against cyber attacks.
The government’s plans were introduced via amendments to the Cyber Security and Resilience Bill and are subject to parliamentary approval. They will seek to safeguard the supply chains of companies, which are often used as a “soft underbelly” by hackers seeking to target larger groups.
Baroness Liz Lloyd, cyber security minister, said the new powers meant the government could act “before a threat materialises, not just after the damage is done”.
“This is about staying ahead of a growing threat, and giving the public confidence that the everyday services we depend on like water and energy supplies, our transport network and hospitals are protected,” she said.
The proposals could pose challenges for energy companies, which are heavily reliant on supplies from China, which manufactures over 90 per cent of the world’s solar panels and dominates supplies of batteries and electric vehicles.
“The implication is that we will end up spending more money to get the same amount of stuff,” said one energy industry executive. “There are alternatives but they are more expensive and they take longer.”
The Cyber Security and Resilience Bill, which was introduced last year, would force regulated companies to report significant attacks to the National Cyber Security Centre within 24 hours and deliver an incident report within 72 hours.
Regulated companies would also face fines if they fail to adhere to a framework covering issues such as data protection and staff training.