Cybersecurity 2026

UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

caused to data subjects if compromised (eg, identity fraud). In addition, when considering which cybersecurity measures to adopt, the ICO recommends that organi - sations consider: • system security – security of the organisation’s net - work and information systems (particularly systems that process personal data); • data security – security of the personal data held in the organisation’s systems (eg, ensuring appropri - ate access controls are in place within the organi - sation); • actively managing software vulnerabilities –includ - ing using in-support software and the application of software update policies (patching), as well as taking other mitigating steps where patches cannot be applied; • online security – website and mobile application security; and • device security – considering information security policies for bring-your-own devices, where offered by the organisation. The UK GDPR and the DPA continue to be enforced by the ICO, including with regard to cybersecurity matters, but only to the extent that they impact per - sonal data. The ICO is required to adhere to specific procedures before undertaking enforcement action – for example, before imposing an administrative fine on an organisation for: • breaching the integrity and confidentiality principle; • inadequate security measures; or • failing to report a personal data breach to the ICO or affected data subjects. Where applicable, the ICO is required under Section 149 of the DPA to first issue the organisation with a written “enforcement notice”, which requires the organisation to take steps specified in the notice and/ or refrain from taking steps specified in the notice. If the ICO is of the view that the organisation has failed to comply with the enforcement notice, the ICO may issue a written notice (penalty notice) imposing a mon - etary penalty on the organisation of up to the greater of 4% of annual worldwide turnover or GBP17.5 mil -

lion. When determining the monetary penalty amount, the ICO will consider a number of aggravating or miti - gating factors. These factors include the nature, grav - ity and duration of the infringement – for example, personal data breach or inadequate security meas - ures – and the intentional or negligent character of the infringement. The DUA Act also expands aspects of the ICO’s toolkit (including powers to request techni - cal reports and compel witness attendance in cer - tain circumstances), which may increase regulatory expectations around demonstrable cyber governance and incident readiness. In determining whether to undertake criminal prosecu - tion under the DPA, the ICO must refer to the Code for Crown Prosecutors and the ICO’s own prosecu - tion policy. Although the ICO has several enforcement tools available to it (including providing a caution to offending organisations), the ICO’s Prosecution Policy Statement requires the ICO to consider aggravating factors in order to bring a prosecution instead of a caution. These include: • the accused breaching the law for financial gain; • abusing a position of trust; or • damage or distress being caused to data subjects. The maximum penalty for criminal offences under the DPA is an unlimited fine. Imprisonment is not available for conviction under any of the DPA offences. Defend - ants are entitled to normal rights of appeal against a conviction or sentence in the legal system. 6.2 Cybersecurity and AI On 26 November 2023, the US Cybersecurity and Infrastructure Security Agency (CISA) and the UK’s NCSC published joint Guidelines for Secure AI Sys - tem Development (the “AI Guidelines”). The AI Guide - lines aim to ensure that developers take a “secure by design” approach, integrating cybersecurity into the development process from the outset and throughout. The AI Guidelines cover: • secure design; • secure development; • secure deployment; and • secure operation and maintenance.

453 CHAMBERS.COM

Powered by