UK proposes new powers for comms regulator to legally unleash avenging hordes on security-breached telcos
- Reference: 1608121931
- News link: https://www.theregister.co.uk/2020/12/16/telco_security_bill_sueball_power/
- Source link:
The far-ranging proposal is in the [1]new bill , which was introduced to Parliament back in November amid lots of government boasts of a [2]crackdown on Huawei and other Chinese telco equipment makers.
Yet buried in the details away from the China-bashing stuff is a potentially heavy stick to be wielded by telco regulator Ofcom, pitting baying crowds against telecoms operators. Currently, these operators face a maximum fine of £2m (enforced by Ofcom itself) for failing to adequately secure their networks ( [3]PDF ). The new situation opens telcos up to civil litigation.
Clause 8 of the bill
[4]PDF
would allow anyone who suffered "loss or damage" as a result of a security breach by a "provider of a public electronic communications network" to sue that operator. The legal language means the barrier to starting a lawsuit here is noticeably low.With mobile network operators having millions of consumers on their books, it's not hard to imagine an ambulance-chasing law firm [5]cooking up a Safari Workaround-style sueball to start pursuing telcos for billions of pounds in damages – and then there's the wrath of biz customers.
The liability itself stretches "not just [to] your customers (in respect of whom you may be able to limit your liability contractually for the impact of a breach, since that is not excluded by the current draft)," blogged tech lawyer Neil Brown of decoded:legal, who spoke to The Register for this article. "Every. Person. Who. May. Be. Affected."
It's not just direct customers affected by a breach who could be sued but anyone downstream that could plausibly say they were affected by a system breach. Brown continued in his [6]blog post : "You get compromised, and an attacker uses that compromise to pivot onto another network/service, and so on and so on? It looks like the initial point of compromise could, if they have breached any of their duties relating to security, be liable to everyone downstream who has been affected."
We have asked Ofcom for comment on this potential new power for it to wield but the regulator declined to comment, as did MobileUK, the trade association for mobile network operators. ®
Get our [7]Tech Resources
[1] https://services.parliament.uk/bills/2019-21/telecommunicationssecuritybill.html
[2] https://www.theregister.com/2020/11/30/dcms_huawei_rip_replace_schedule/
[3] https://www.ofcom.org.uk/__data/assets/pdf_file/0021/51474/ofcom-guidance.pdf
[4] https://publications.parliament.uk/pa/bills/cbill/58-01/0216/200216.pdf
[5] https://www.theregister.com/2020/10/29/facebook_you_owe_us_high_court_campaign/
[6] https://decoded.legal/blog/2020/12/what-could-the-telecommunications-security-bill-mean-for-isps-and-telcos
[7] https://whitepapers.theregister.com/
Good as far as it goes but perhaps a better option would be to require regular security audits by an OfCom appointed auditor.
I think it's very bad, but you make a good suggestion.
I think it's bad because of the risk, and potential penalties. Over the decades I've had some interesting conversations around consequential losses vs contracted compensation. Generally those revolve around risk, ie what happens if/when the network goes down or events like DDOS or hacking. And generally that lead to mitigating those risks by changing the design. But obviously that increases the cost of the design to something rather more substantial than the cost of the xDSL circuits the client thought they could run their business on.
Worst example was the proposed fire control service consolidation where the bidder I was working with wanted xDSL to fire stations. Or 'fully diverse xDSL'. Bidder was one of the big name consultancies, yet didn't understand how the technology worked. Luckily for the fire service, that idea was canned.
But in other jobs where clients have demanded non-standard penalties, the solution's been fairly simple. Calculate an estimate for the number of outage events we'd expect over the contract, the penalties for those events, and add that into the fee schedule. And if penalties were particularly high, buy insurance against those charges and add the cost of that into the contract.
Obviously that makes services more expensive, and the network would still go down. But I've never worked on a network where consequential losses were accepted simply because the risk was too high, or the cost of insurance against that risk was too high for the client. But then businesses can & do buy business continuity insurance, or at least the smart ones do.
But TL;DR is the proposal would place enormous risk on service providers, which would then get passed onto it's customers.
But I like your suggestion. If government wants to pass this risk/cost onto service providers, then it should provide 'Best Practice' guidance to industry. If industry doesn't follow that guidance, well, then it takes the risk. Which is something relatively easily done. I've often argued that GCHQ/CESG should provide that Best Practice to industry.. which it partly does, eg the classified guidance for public sector networks. Or thanks to CESG being turned into a revenue generating outfit, it'll sell consultancy. But I've always though that given their role as commsec experts, and risks to UK Plc, their guidance (or at least some of it) should be public.
But there's also an element of the can being kicked down the road & consequential losses being passed onto hardware and software vendors. So Cisco/Juniper publish an advisory & patch due to a vulnerability being detected/exploited. Contractually they carry very little risk, but that could change with enough industry pressure. Which would again increase costs, and still would probably lead to exploits. After all, Cisco's IOS is 30 or so years old, so should be exploit free.. Shouldn't it?
Good as far as it goes but perhaps a better option would be to require regular security audits by an OfCom appointed auditor. Or alternative might be some kite-mark style accreditation for comms companies, those claiming to offer security services etc (a couple of companies currently in the news here would serve as examples) based on 3rd party auditors. Given the prevalence of things like hard-coded credentials it seems that securing critical infrastructure can't be left to those who run it and users/customers need to have the ability to see for themselves just what state it's in.