UK Trends and Developments Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP
recommendations on media literacy and a report on the use of app stores by children. Cybersecurity Threats and Developments UK cybersecurity breaches The UK Government’s 2025 Cyber Security Breaches Survey reports an increase in cybercrime incidents from 7.78 million in 2024 to 8.58 million in 2025. The UK National Cyber Security Centre’s (“NCSC”) 2025 review reinforces this trend and warns of an “esca - lating threat” driven by an “evolving cyber intrusion sector” that lowers barriers to attack. Together, these findings demonstrate the pervasive nature of cyber risk across the UK economy, with phishing and ran - somware remaining among the most common threats. UK Government’s Cyber Growth Action Plan Cybersecurity is a key pillar of the UK Government’s efforts to drive economic growth. The Department for Science, Innovation and Technology (“DSIT”) issued its Cyber Growth Action Plan (the “Plan”) in Septem - ber 2025. The Plan is an independent, government- commissioned analysis examining how to both grow the cybersecurity sector and strengthen national cyber resilience. Certain key actions in the plan are outlined below. • Embedding “security by design” through product standards. The Plan builds on the existing UK Product Security Regime, making the require - ments therein default features instead of optional add-ons. This will prioritise features such as secure configuration, vulnerability handling and support lifecycles. • Promoting baseline frameworks to stimulate “informed demand”, such as Cyber Essentials, with the aim of shifting procurement decisions away from lowest cost and prioritising cyber outcomes. • Harmonising cyber standards and assurance path - ways to make compliance easier for businesses. This harmonisation, alongside simplification of the relevant standards and pathways, also intends to reduce duplication, including closer coordination between DSIT and NCSC. The elements of the Plan demonstrate movement towards the use of standards, procurement and product regulation as levers to drive cybersecurity
maturity and realise consequent market growth. The Plan therefore impacts how organisations deal with technology throughout the breadth of their operations, including design, procurement and assurance. DSIT Cyber Security Codes of Practice In 2025, DSIT published three codes of practice addressing both cybersecurity and software security. The codes are sets of voluntary guidance addressed to various stakeholders involved in the management and operation of technology, as outlined below. • The AI Cyber Security Code of Practice (the “AI COP”) is designed to help develop global techni - cal standards for AI system security. The AI COP provisions are centred around the three pillars of safety, security and robustness. • The Software Security Code of Practice (the “Soft - ware COP”) provides 14 principles for the estab - lishment of a consistent baseline level of software security and resilience for vendors. • The Cyber Governance Code of Practice (the “Governance COP”), aimed at board-level leaders within organisations, outlines five principles and associated actions intended to strengthen cyber governance. While these codes are non-binding, they collectively signal the direction of regulatory expectations in the UK and are likely to serve as benchmarks for assess - ing cyber maturity, governance and accountability. Cybersecurity enforcement trends Most enforcement action concerning cybersecurity in the UK is taken by the ICO in relation to security incidents under the UK GDPR. The ICO’s summary of data security incident trends recorded 3,242 incident reports being submitted to the ICO in Q2 2025. This represented a 6% increase on Q2 2024. Of the incidents reported to the ICO, 24% were classified as “cyber incidents”, in accord - ance with the definition in the ICO’s security incidents trends glossary, ie, “a clear online or technological element which involves a third party with malicious intent”.
459 CHAMBERS.COM
Powered by FlippingBook