Cybersecurity 2026

UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

2.3 Incident Response and Notification Obligations Under the NIS Regulations, different incident reporting obligations apply to OESs and RDSPs. For OESs, cybersecurity event notification is required when an incident has a “significant impact” on the continuity of the essential service they provide. Deter - mining this requires a fact-specific analysis of the number of users affected by the disruption of the ser - vice, the duration of the incident, and the geographi - cal area affected by the incident, as well as any other relevant guidance issued by their designated “com - petent authority”. For RDSPs, notification is required where there will be a “substantial impact” on the provision of a relevant service. From 12 January 2022, the ICO (the lead reg - ulator for RDSPs) must be notified by an RDSP of any incident that has a substantial impact on the provision of any digital services, including online marketplaces, online search engines, and cloud computing services. It should be noted that, in comparison with the UK GDPR, notifiable incidents under the NIS Regulations need not always involve personal data – that is, cyber - security incidents that do not involve personal data (such as cyber-attacks on industrial control systems) could be notifiable under the NIS Regulations, but would not be notifiable under the UK GDPR if they do not involve personal data. Under the NIS Regulations, as with the UK GDPR, OESs and RDSPs must notify their relevant compe - tent authority and the ICO, respectively, of an inci - dent “without undue delay” and, in any event, no later than 72 hours after the OES or RDSP (as applica - ble) becomes aware of the incident. Under proposed amendments in the CS&R Bill, there will be an addi - tional requirement to submit an “initial” notification no later than 24 hours after becoming aware of the incident. The NIS Regulations require that OESs and RDSPs adopt “appropriate and proportionate” technical and organisational security measures, as well as “appro - priate” measures to prevent and minimise the impact of incidents affecting those systems (considering the state of the art), so as to ensure the continuity of the

• monitoring, auditing and testing – measures should establish and maintain policies and processes con - cerning the assessment, inspection and verification of systems; • compliance with international standards – meas - ures are not specified by the DSP Regulation, but instead, the NIS Regulations refer to “standards” as: (a) standards adopted by an international stand - ardisation body as specified in Regulation 1025/2012; and/or (b) any European, national or internationally accepted standards and specifications relevant to the security of networks and information systems. The ICO notes that examples of appropriate standards may include the International Organisation for Stand - ardisation/International Electrotechnical Commission (ISO/IEC) 27001 on information security management systems and ISO/IEC 22301 on business continuity management systems, as well as any other related standards. OESs OESs are subject to similar requirements as RDSPs in that they must also take appropriate and proportion - ate technical and organisational measures to man - age risks posed to the security of the network and information systems on which their essential service relies, and subject to guidance from the relevant com - petent authority (which, as noted in 1.3 Cybersecurity Regulators (NIS Regulations) , is on a sector-specific basis). Supply Chain Security Requirements The NCSC has published guidance on supply chain security. This sets out 12 principles designed to assist organisations in establishing “effective control and oversight” of their supply chains. The principles are divided into four distinct stages:

• understand the risks; • establishing control; • checking arrangements; and • continuous improvement.

446 CHAMBERS.COM

Powered by