UK government exempting itself from flagship cyber law inspires little confidence


From May’s cyberattack on the Legal Aid Agency to the Foreign Office breach months later, cyber incidents have become increasingly common in UK government.

The scale extends far beyond these high-profile cases: the NCSC reports that 40 percent of attacks it managed between September 2020 and August 2021 targeted the public sector, a figure expected to grow. Given this threat landscape, why does the UK’s flagship Cyber Security and Resilience (CSR) Bill exclude both central and local government?

Read more…
Source: The Register News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Northern Ireland: Hoax bomb accused takes legal action in bid to stop police accessing mobile phone material

    September 26, 2024

    A Co Tyrone man accused of buying parts for a hoax bomb left outside a police station is taking High Court action in a bid to stop detectives extracting messages and photos from his mobile phone. Sean Pearson claims the plans to obtain any information stored on devices seized during a raid on his home breaches ...

  • UK railway stations Wi-Fi affected by cyber attack

    September 26, 2024

    The wi-fi has been hacked at 19 UK railway stations to display a message about terror attacks. Network Rail confirmed that the wi-fi systems at stations including London Euston, Manchester Piccadilly, Liverpool Lime Street, Birmingham New Street, Edinburgh Waverley and Glasgow Central were affected. People reported logging on to the wi-fi at the stations on Wednesday ...

  • ‘Two-factor authentication may have stopped Synnovis cyber attack’

    September 25, 2024

    The cyber attack on pathology provider Synnovis could have been prevented by two-factor authentication, according to Beverley Bryant, strategic advisor in the frontline digitisation team at NHS England. Speaking at the Health Excellence Through Technology (HETT) conference on 24 September 2024, in a session titled ‘Best practice in cyber security: Achieving excellence in the health and ...

  • UK: Cyber incident ‘was an accident – not an attack’

    September 23, 2024

    A cyber incident which forced a council to shut down its IT systems was not an “attack, it was an accident”, it is understood. Tewkesbury Borough Council declared a major incident on 4 September after the incident, which a source said was its “own systems testing its own security”. People selling or buying homes in the ...

  • UK: Customer data exposed in Harvey Nichols data breach

    September 22, 2024

    Luxury British department store has announced that it has been the victim of a data breach, in a notification sent to affected customers. The incident, which the store discovered on 16th September, involved the compromise of sensitive data such as names, email addresses, phone numbers and home addresses. Read more… Source: Computing News Sign up for our Newsletter Related:

  • Sunken superyacht believed to contain watertight safes with sensitive intelligence data

    September 21, 2024

    Specialist divers surveying the wreckage of the $40 million superyacht that sank off Sicily in August, killing seven people including British tech tycoon Mike Lynch, have asked for heightened security to guard the vessel, over concerns that sensitive data locked in its safes may interest foreign governments, multiple sources told CNN. Italian Prosecutors who have opened ...