News: 1642698913

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK mulls making MSPs subject to mandatory security standards where they provide critical infrastructure

(2022/01/20)


Small and medium-sized managed service providers (MSPs) could find themselves subject to the Network and Information Systems Regulations under government plans to tighten cybersecurity laws – and have got three months to object to the tax hikes that will follow.

Plans to amend the EU-derived Network and Information Systems Regulations (NIS) are more likely than ever to see SMEs brought into scope, as The Register [1]reported last year when these plans were first floated .

NIS is the main law controlling security practices in the UK today. Currently a straight copy of the EU NIS Directive, one of the benefits of Brexit leapt upon by the Department for Digital, Culture, Media and Sport (DCMS) is the [2]new ability to amend NIS's reporting thresholds.

[3]

Bringing MSPs under NIS "would provide a baseline for expected cybersecurity provision and better protect the UK economy and critical national infrastructure from cyber security threats," as UK.gov said in a [4]consultation document issued on Wednesday. Its plans are for MSPs, currently not subject to NIS, to be brought into the fold. This includes defining what an MSP does, legally, and possibly ending NIS' existing exemption on SMEs.

[5]

[6]

"The government recognises the strong need to minimise regulatory burden on small and micro-businesses particularly in a rapidly evolving industry such as this. However, recent incidents have highlighted the scale of risk that can be associated with managed service providers – regardless of their size," said the consultation document.

[7]Not only MSPs: All cloudy firms are in line for UK security law crackdown

[8]The UK loves cybersecurity so much, it's going to regulate managed service providers' infosec practices in law

[9]UK infrastructure firms to face £17m fine if their cybersecurity sucks

[10]EU cybersecurity directive will reach Britain, come what May

In essence, if an "operator of essential services" or a critical national infrastructure business outsources something to your MSP, prepare for NIS compliance.

And the flip side: money

Enforcement of NIS is carried out by the ICO, which is getting a funding bonus if Parliament nods through the NIS amendments. Initially coming from general taxation, in time DCMS wants to "extend the existing cost recovery provisions to allow regulators (for example, Ofcom, Ofgem, and the ICO) to recover the entirety of reasonable implementation costs from the companies that they regulate."

[11]

SMEs across the whole British economy are already familiar with this kind of "cost recovery" activity through stealth taxes such as the ICO's data protection registration fee.

Andy Kays, chief exec of a managed detection and response firm in London called Socura, agreed that "further market intervention is required to help raise the bar to protect the UK economy."

"However," he added, "I do believe that interventions like Cyber Essentials, GDPR and NIS have raised the profile of cyber and data security in the UK, and have improved understanding and investment where they are applicable among businesses."

[12]

Jake Moore, global cybersecurity advisor with Slovakian infosec firm ESET, also agreed, saying in a statement: "Essential services are desperately in need of better protection so these new laws will help direct businesses into a more secure offering with the help and direction required. Laws often may seem like they do not go far enough but digital crime is fast paced and the goal posts constantly move making such plans difficult to project or even become out of date by the time they land."

The consultation closes on 22 April. As well as questions about money, DCMS is also asking about whether the regs should be extended to SMEs and how detailed they ought to be. Have your say via [13]theses 66 pre-formatted questions . ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2021/05/18/ukgov_cybersecurity_reviews_supply_chain_cma/

[2] https://www.theregister.com/2021/07/27/uk_security_breach_reporting_law_thresholds/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YenpmWbaDR4WV8zmOYtD3QAAAIg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.gov.uk/government/consultations/proposal-for-legislation-to-improve-the-uks-cyber-resilience/proposal-for-legislation-to-improve-the-uks-cyber-resilience

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YenpmWbaDR4WV8zmOYtD3QAAAIg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YenpmWbaDR4WV8zmOYtD3QAAAIg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/11/16/ukgov_dcms_msp_cyber_security_crackdown_widens/

[8] https://www.theregister.com/2021/05/18/ukgov_cybersecurity_reviews_supply_chain_cma/

[9] https://www.theregister.com/2018/01/29/infrastructure_firms_to_be_slapped_with_17m_fine_for_poor_cyber_security/

[10] https://www.theregister.com/2016/07/11/eu_nis_directive/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YenpmWbaDR4WV8zmOYtD3QAAAIg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YenpmWbaDR4WV8zmOYtD3QAAAIg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.gov.uk/government/consultations/proposal-for-legislation-to-improve-the-uks-cyber-resilience/proposal-for-legislation-to-improve-the-uks-cyber-resilience#pillar-i-proposals-to-amend-provisions-relating-to-digital-service-providers

[14] https://whitepapers.theregister.com/



MSP

Anonymous Coward

I did wonder what Members of the Scottish Parliament had got involved in now, when I saw the headline!

Re: MSP

Arthur the cat

The same here. Then I realised the idea of them providing critical infrastructure was unlikely.

The problem with Moderately Secure Providers..

Anonymous Coward

.. is that security is still seen as a COST, ditto for most companies.

If they want to go that route, could we start with much, MUCH higher fines for banks that get breached, because they're presently very good at dodging decent fines for it which is why it keeps happening. A breach should cost a bank at least four times as much as it has saved by 'good enough" security, which usually isn't, but they get away with it. Stop the volume discount and apply the same fines as a poor SME would get if they lost the details of 10 customers, multiplied by actual.

Sure, getting MSPs up to scratch would be good, but you'd have to start with getting people people interested in IT and security. In case you didn't notice, the combination of Brexit and allowing HMRC to scare away talent with its IR35 gaming has rather reduced the amount of people willing to stay here, and there are not enough in school to cover the gap, also because the newbies first have to build up a bit of experience. Even DISorganised crime does better.

Nice words, little substance.

bonfire

Smelly Socks

This is part of the promised bonfire of red tape (lighting the way to the sunny uplands?)

Oh wait, it's about suffocating smaller organisations in bureaucracy. Business as usual, then! Carry on!

Re: bonfire

Yet Another Anonymous coward

That's the plan.

Make the fee £££ per company with ever increasing registration and reporting costs.

So only GS4/Crapita/etc can afford to play - and non of them can be fined or cancelled because they are a vital part of infrastructure.

It's about time

emfiliane

The MSP I joined in 2017 and was bought out a year later looked slick and professional from the outside, but as soon as you get in you realize their security was an absolute joke, with the vast majority of management and remote user access being done over RDP with an administrator password of, I kid you not, Magic123. I'm surprised ransomware didn't hit earlier, but it rolled through like a bulldozer in 2018. The clients I actively serviced were mostly immune, since I shut things off and instituted some best practices (even though I'm no CISSP), but I seemed to be the only person who gave two shits and wasn't surprised when the worst hit and they had to sell. Plus staffing was way too lean to do anything but fight fires all day, taking home work was the only way to get anything longer done.

There should definitely be some sort of compliance regulation, though I worry it'd be watered down to overbearing yet useless, like PCI.

Bringing MSPs under NIS

Howard Sway

But how are the PHBs going to understand all these TLAs?

After a number of decimal places, nobody gives a damn.