The Secretary of State for Business, Energy and Industrial Strategy, Kwasi Kwarteng, has published the first report on the UK's new national security and investment system.
The National Security and Investment Act 2021 ("NSI Act") grants the Secretary of State powers to scrutinise and intervene in certain acquisitions to safeguard the UK’s national security. Although the powers cover all areas of the economy, some acquisitions of entities that carry out work in 17 sensitive areas of the economy must be notified to the Secretary of State and receive approval before completion.
The report shows the new system has been an operational success for screening investments for national security concerns and has provided certainty for businesses, with all assessments completed within their legal deadlines. As a recent example, on 20 July 2022 the Secretary of State made a final order under the NSI Act in respect of a licence agreement entered into between a British university and a Chinese company for the use of know-how relating to certain motion camera technology to develop, test and verify, manufacture, use and sell licensed products.
The Secretary of State considered that the technology (that can be embedded in children's toys, drones and other surveillance equipment) has dual applications and that there is potential that the technology could be used to build defence or technology capabilities that may present a national security risk to the UK and that those risks would arise on the transfer of intellectual property to the acquirer.
The Government has also published the second post-implementation review of the Network and Information Systems Regulations 2018 ("NIS Regulations") (the "Review"). The Review finds that the NIS Regulations are largely working and should be retained with some improvements to their implementation.
The NIS Regulations came into force on 10 May 2018 with the overarching objective of improving the security of the network and information systems of operators of essential services, which if disrupted, could cause significant economic and social harm. The NIS Regulations apply to sectors such as transport, energy, water and health as well as relevant digital service providers (i.e. cloud computing services, online marketplaces, and online search engines). The NIS Regulations derive from the NIS EU Directive and in the UK, the finance and banking sectors are excluded from the NIS Regulations because those sectors are covered by equivalent legislation that was already in place.
According to the Review, evidence suggests that cyber security is being prioritised at a senior level and that the majority of operators have either introduced new policies, improved existing ones, or improved their incident response management, and there is a wider awareness of guidance and available support from the competent authorities. Findings of more voluntary reporting is considered to be an indication of a mature cyber sector, willing to take steps and address the threats to essential services.
The Review recommends the following areas for improvement:
- Relevant guidance needs to make it easier to identify whether firms are within scope of the NIS Regulations and ensure that organisations that need to be included in the NIS Regulations are designated.
- More should be done to secure the supply chains of operators of essential services, where the supplier is critical to the provision of that essential service.
- Competent authorities need more resources to carry out what they deem to be an effective job of enforcing the NIS Regulations.
- Work needs to be done to ensure that the right cyber incidents are captured because the NIS Regulations are not effective at capturing relevant cyber incidents that occur in the sectors regulated.
- The Department for Digital, Culture, Media and Sport needs to conduct work to assess why the enforcement regime is not being utilised where it is merited.
- Greater consistency in regulatory implementation across sectors is required, alongside the creation of performance metrics so that the Government can better measure the impact and effectiveness of the NIS Regulations.