NCSC Annual Review 2021
Pages
Page 34 of 44
Informing policy through technical advice and analysis
The NCSC provided technical advice to DCMS on the development of the Telecommunications (Security) Bill. The bill expands the legislative powers of the Communications Act (2003), and proposes new powers for the Secretary of State to remove from the UK’s telecoms networks those suppliers identified as being high-risk.
The bill introduces a new security framework, constructed with the aid of NCSC analysis, which includes some 200 recommendations for operators to ensure the security and resilience of their networks. The NCSC also supported the DCMS in the creation of a Telecoms Diversification Strategy, which seeks to mitigate the risks of dependence on a limited number of equipment vendors for the UK telecoms sector.
The NCSC played an important role in the development of the National Security and Investment Act, which was introduced to the House of Commons in 2020, and is due to become law on 4 January 2022. The Act modernised the government’s powers to investigate, and if necessary, intervene in mergers, acquisitions and other business deals that may otherwise damage the UK’s national security. The Act covers 17 sensitive sectors of the UK economy, ranging from artificial intelligence to quantum computing to robotics, and investors may need to seek government approval for acquisitions in these sectors. Equally, the Act will allow for greater transparency about the types of deals that the government may need to investigate, as well as more efficient learning processes for those acquisitions.
Nicola Hudson, the NCSC’s Director of Policy said: “The Act will give investors additional certainty and clarity in investments in sensitive economics sectors as the UK enshrines its status as a global champion of free trade and investment, as well as providing an effective tool for the UK government to protect our national security in a rapidly changing world.”
The Home Secretary, Priti Patel, pledged an imminent Government review of the UK’s 30-year-old Computer Misuse Act (CMA) in a speech at the NCSC’s CYBERUK conference.
“As part of ensuring that we have the right tools and mechanisms to detect, disrupt and deter our adversaries, I believe now is the right time to undertake a formal review of the Computer Misuse Act,” she said.
Originally passed in 1990, the CMA was last significantly amended in 2008 to extend its scope and increase the maximum sentences available for core offences.
“We are launching a call for information on the Act this year,” said Ms Patel. “I urge you all to provide your open and honest views on ensuring that our legislation and powers continue to meet the challenges posed by threats to cyberspace.”