Well Britain, you’ve done it. The referendum is over and it’s time to start thinking ahead about how the UK will reconcile its new laws and regulations. I believe that the UK could be at the beginning of a cybersecurity Renaissance, and I’ll explain why.
At this point, it is uncertain how long it will take the United Kingdom to fully leave the EU, although the plan is that there will be a two-year transition phase. The next step in the process, according to Article 50 of the Lisbon Treaty, is for the UK to notify the EU council, although I’m sure this will come as no surprise.
Discussions will ensue that negotiate the process of the departure. If no discussions take place and no agreements are in place in two years, the UK will no longer fall under EU jurisdiction.
Let’s take a look at some of the EU cybersecurity laws, directives and initiatives and how their absence could affect the UK.
European Union Cybersecurity Plan
What is it?
Directives, laws and regulations are best implemented when there is an overarching strategy in place to support the plans, ideals and goal or the legislation. The EU Cybersecurity Plan is a bit antiquated, and the UK government has a real opportunity to put forth a new, strong, technically savvy plan that addresses cyber-resilience in this new age of cyber threats.
What is the UK’s next move?
Much like the United States’ Cybersecurity National Action Plan (CNAP), the UK should focus on building up its cybersecurity workforce and building new ways for businesses to detect, respond, track and share information on threats. The UK has an opportunity to not only bolster its security posture, but become a major cybersecurity player in the world by encouraging information security businesses, professionals and educators to work toward a common goal to address and respond to threats.
Network and Information Security Directive (NIS)
What is it?
Stemming from the EU’s Cybersecurity Plan, the NIS is a directive that was adopted on 17 May 2016 to go into full effect in August 2016. The NIS seeks to improve the EU’s cyber-resilience by:
What is the UK’s next move?
The UK is on track with creating its own CSIRT as the UK-CERT already exists. As for classifying critical businesses and organisations, if they haven’t already done so, this should be relatively easy for the UK. The hard part will be in introducing legislation to parliament that will focus on the laws that will govern them. This would naturally include information and technology standards, guidelines, policies and response plans.
There are three recommendations that I have for the UK in replacing the NIS with its own directives:
General Data Protection Regulation (GDPR)
What is it?
The GDPR is the EU’s latest legislation and its aim is to alleviate the continent’s privacy concerns by:
What is the UK’s next move?
Historically, from compromises such as last year’s TalkTalk breach, we have seen that UK citizens take their personal data very seriously. It will be imperative for the government to act quickly in establishing personal data protection regulations, standards and authorities. The first step should be for the UK to form a comprehensive definition of what personal data actually is. Once completed, this should naturally lead to a ‘domino effect’ for laws and regulations to fall into place to support the confidentiality, integrity and availability of the data. Perhaps the United States and the United Kingdom could work together on this, since the US hasn’t completed this first step yet!
Safe Harbor & EU-US Privacy Shield
What is it?
Finally, we come to the long anticipated Safe Harbor Framework which was designed to facilitate the exchange of personal data between the United States and EU member states. Since the EU data protection directives differ from the United States’ privacy laws, it was necessary to streamline this process between the two. In October 2015, partially stemming from the Snowden Revelations, the EU issued a judgment declaring Safe Harbor as invalid. Since then, the EU and the US have been working closely on a new framework called Privacy Shield.
What’s next in the UK move?
The UK could be in congruence with the EU-US Privacy Shield agreement. Transfer of sensitive data across borders has become critical in this new cloud and mobile age, and having a tri-lateral agreement on this subject would be very beneficial for all parties involved. Too much investment is at stake for the UK not to be in the middle of these agreements by participating and influencing the next iteration of the framework.
Summing it All Up
For right or wrong, good or bad, the UK has decided to leave the European Union. The sole intent of the referendum was to make the right decision for the government, businesses and citizens. Now that the decision has been made, it is critically important for all of us to look ahead and challenge ourselves to make the best decisions and plans…not just for today, but also for tomorrow.
With that in mind, I think that the UK has a chance to reinvent its economy and identify itself as a world leader when it comes to cybersecurity. Because threats know no borders. Threats do not respect laws, regulations, directives, frameworks or referendums. Threats transcend privacy and confidentiality. It will be a paramount for the UK and EU to find common-ground, and keeping the lines of sharing open, in a post-referendum world.
Fidelis stands with both the United Kingdom and the European Union in leaving attackers no place to hide.
God save the Queen.
-Justin Harvey, Fidelis Cybersecurity CSO