UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP
side the NIS Regulations. Please refer to 4.2 Key Obli- gations Under Legislation for more information. 4.2 Key Obligations Under Legislation PSTI Act Under the PSTI Act, manufacturers (the person responsible for manufacturing, designing or otherwise marketing a product under their own name or trade mark) of “UK consumer connectable products” are required to comply with obligations to manage cyber - security risks for connected products made available in the UK. Similar obligations also apply to importers and distributors. These include: • duty to comply with security requirements as defined by the Secretary of State; • duty to investigate and take action in relation to compliance failures – this may include preventing the product from being made available in the UK and/or remedying the compliance failure and noti - fying enforcement authorities, other manufacturers, importers and distributors; and • duty to maintain records of investigations and compliance failures for a minimum of ten years – these records may be requested by the Secretary of State in the course of investigating and enforc - ing the legislation. The PSTI Act provides the Secretary of State with the power to deem compliance with security require - ments. This is further elaborated in the Product Secu - rity and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 (the “2023 PSTI Regulations”), as amended by the Product Security and Telecommu - nications Infrastructure (Security Requirements for Relevant Connectable Products) (Amendment) (No 2) Regulations 2025 (the “2025 PSTI Regulations Amendment”), which set out conditions for deemed compliance with security standards, including compli - ance with relevant parts of ETSI EN 303 645 or – in some cases – ISO/IEC 29147. Schedule 1 of the 2023 PSTI Regulations includes the following security requirements for manufacturers:
• all passwords for UK consumer-connected prod - ucts must be unique and incapable of being reset to any universal factory setting; • manufacturers, importers and/or distributors of UK consumer-connected products must provide a public point of contact for reporting vulnerabilities and these must be acted on in a timely manner; and • manufacturers, importers and/or distributors of UK consumer-connected products must explicitly state the minimum length of time for which the device will receive security updates at the point of sale. CMA As mentioned in1.2 Cybersecurity Laws, a key offence under the CMA (Section 1) is where a defend - ant obtains “unauthorised access” to a computer. Although the CMA primarily applies to offences com - mitted within the UK, it allows for prosecutions to be brought in the UK where some or all of the offending acts were committed outside the UK – reflecting the cross-border nature of many cybersecurity-related offences. By way of example, Section 1 of the CMA can apply to offending acts committed outside the UK and can – as a result – be prosecuted in the UK where there is “at least one significant link with the domestic jurisdiction”. A significant link can include where: • the accused is in a relevant country of the UK (Eng - land, Wales, Scotland and Northern Ireland) at the time of the offence; • the target of the CMA offence is in a relevant coun - try of the UK; or • the technological activity that has facilitated the offending may have passed through a server based in a relevant country of the UK. An offence committed under the CMA is prosecut - ed by the CPS in the UK courts. When determining whether to bring a prosecution under the CMA, the CPS must be satisfied that there is enough evidence to provide a “realistic prospect of conviction” against each defendant and that the public interest factors tending against prosecution outweigh those tending in favour. Offences under the CMA can carry imprison - ment or a fine (or both). In addition, a serious crime prevention order can be made against an individual or an organisation in relation to a breach of the CMA.
450 CHAMBERS.COM
Powered by FlippingBook