UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP
Sidley Austin LLP 70 St Mary Axe London EC3A 8BE UK
Tel: +44 20 7360 3600 Fax: +44 20 7626 7937 Email: marketingdepteurope@sidley.com Web: www.sidley.com
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy The UK cybersecurity legal system is well-developed and similar to those across the European Economic Area (EEA), rather than the USA, although post-Brexit divergence in the approach to cybersecurity regula - tion between the EU and the UK is starting to emerge. Since the General Data Protection Regulation (GDPR) came into force in 2018, the enforcement of cyberse - curity rules in the UK has remained a focus, particu - larly by the UK data protection regulator, the Informa - tion Commissioner’s Office (ICO). In November 2025, the UK government introduced the Cyber Security and Resilience (Network and Information Systems) Bill (the “CS&R Bill”) to address the changing cyberthreat landscape and more closely align UK law with devel - opments in the EU (such as the Network and Infor - mation Systems Directive 2, which was enacted after Brexit) (see 2. Critical Infrastructure Cybersecurity Regulation for further details). The UK government has signalled an enhanced approach to supporting and promoting cybersecu - rity through its national cyber strategy for 2022 (the “National Cyber Strategy”) and its (government- specific) Government Cyber Security Strategy for 2022–30. The National Cyber Strategy takes a “whole of society” approach, aiming to shift the burden of cybersecurity from individual citizens to the organisa - tions and professionals best placed to manage cyber risks. The National Cyber Strategy is comprised of five pillars as follows:
• strengthening the UK cyber ecosystem – by invest - ing in people and skills, and deepening the partner - ship between government, academia and industry; • building a resilient and prosperous digital UK – by reducing cyber-risks so that businesses can max - imise the economic benefits of digital technology and provide more security for UK citizens online; • taking the lead in technologies vital to cyber power – by building industrial capacity and developing frameworks to secure future technologies; • advancing UK global leadership and influence for a more secure, prosperous and open international order – by working with government and industry partners and sharing the expertise that underpins UK cyber power; and • detecting, disrupting and deterring adversaries to enhance UK security in and through cyberspace – by making more integrated, creative and routine use of the UK’s full spectrum of levers. The National Cyber Strategy also proposed a number of regulatory reforms, including, but not limited to, expanding the scope of the Network and Information Systems Regulations (the “NIS Regulations”) (see 2. Critical Infrastructure Cybersecurity Regulation for further details). In addition to the National Cyber Strategy, a UK cyber growth action plan commissioned by the Department for Science, Innovation and Technology (“DSIT”) was published in September 2025 (the “Growth Plan”). The Growth Plan focuses on the UK’s cybersecurity sector and market, rather than on prospective legisla - tive developments. However, the UK government has
442 CHAMBERS.COM
Powered by FlippingBook