In a press release dated January 28, 2018, 1, the UK government announced that companies and organizations responsible for critical infrastructure could face fines of up to £17 million (approximately ¥2.5 billion) if they fail to implement effective cybersecurity measures. The organizations covered include those in energy, such as electricity, gas, and water; transportation, such as railways; water supply and sewerage; and healthcare, such as hospitals. The competent authority for each industry will be designated. In addition to implementing security measures, organizations will be required to report incidents through a simple interface that will be provided. Fines are a last resort and will not be imposed on companies or organizations that have taken proper measures.

On the same date, the National Cyber Security Centre also published new guidance for industry, 2.

Failing to implement proper security measures is a classic form of pollution with externalities, so I think internalizing those externalities through taxes or fines is the standard approach.

I have probably been saying this since around 2011, so it is deeply gratifying.
Come to think of it, I visited No. 10 Downing Street 3 in 2013, in October. If I recall correctly, I think I spoke about externalities then as well.

In truth, using insurance might be better because it works through the market. ISO has finally begun developing a cyber insurance standard, 4, but there is still insufficient actuarial data, so fines will probably be the practical option for the time being. In that sense, I think the newly introduced reporting requirement will also help build up actuarial data.

UK Government acts to protect essential services from cyber attack

 

 

Footnotes

  1. Government acts to protect essential services from cyber attack — https://www.gov.uk/government/news/government-acts-to-protect-essential-services-from-cyber-attack
  2. The NIS Guidance Collection — https://www.ncsc.gov.uk/guidance/nis-guidance-collection
  3. the official residence of the UK Prime Minister
  4. ISO/IEC 27102 Information technology — Security techniques — Information security management guidelines for cyber insurance https://www.iso.org/standard/72436.html

Related posts