news.mlab.sh
Back to the feed
supply-chain

UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

High
Summary

The UK is moving to implement the Cyber Security and Resilience Bill (CSRB), now set to become the Cyber Security and Resilience Act (CSRA), to address the growing threat of supply chain attacks targeting critical infrastructure. Specifically, the bill will allow the government to block critical sector organizations from using technology suppliers deemed high risk, recognizing that attackers often exploit vulnerabilities within the supply chain rather than directly targeting well-defended organizations. This proactive measure aims to bolster the nation’s cybersecurity resilience by holding suppliers accountable and mitigating risks at the source.

The UK is enacting new legislation – the Cyber Security and Resilience Act (CSRA) – to tackle the escalating risk of supply chain attacks against its critical infrastructure. The Cyber Security and Resilience Bill (CSRB), which has successfully navigated through Parliament, is nearing Royal Assent, transforming into a fully-fledged law. A recent incident involving a UK energy facility, reportedly targeted by Iran-linked adversaries and resulting in a four-day outage, highlighted the vulnerability of relying on external suppliers.

The CSRA will empower the government to proactively block critical sector organizations from utilizing technology providers identified as posing a significant security risk. This approach acknowledges that attackers frequently bypass robust defenses by exploiting weaknesses within the supply chain – through less secure vendors, managed service providers, or suppliers with outdated security practices. The legislation builds upon existing stringent requirements within the CSRB, including strict incident reporting timelines and substantial penalties for non-compliance.

Keeper Security’s CEO, Darren Guccione, noted that 34% of UK organizations report incidents stemming from third-party vendors and suppliers. CyberSmart’s CEO, Jamie Akhtar, emphasized that even small and medium-sized enterprises (SMEs) providing technology or services to critical sectors are vital to the overall resilience of the UK’s infrastructure, and that their cybersecurity practices directly impact the security of larger organizations.

The CSRA represents a shift towards greater accountability for third-party risk, aiming to improve cybersecurity across the entire supply chain. The message to SMEs serving critical infrastructure is clear: enhance their own security posture to avoid potential repercussions from the UK government when the CSRA is fully implemented.

Read the full article at SecurityWeek