Refine By
Clear all filter
About 91280 results for "*"
PRACTICE NOTES
The UK has one of the most web-based economies in the world, with the UK internet market valued in the order of billions of pounds a year. With this comes greater vulnerability. The threat of cybercrime to individuals, businesses and national and global security is very real. A number of organisations and schemes operate to combat that risk. This Practice Note contains a table of information on the most significant of these. National Hundreds of millions of pounds of public money is allocated to strengthen the UK’s cyber capacity and combat cyber threats. The following table gives an indication of how some of that money is
NEWS
The Department for Science, Innovation and Technology (DSIT) and the Home Office have announced that cyberflashing will be designated as a priority offence under the Online Safety Act 2023 (OSA 2023), requiring dating apps and social media platforms to take proactive steps to prevent users from receiving unsolicited nude images.
PRECEDENTS
Please click for the Precedent Cybersecurity IT update log. Please note that this log has been prepared in Excel and it therefore cannot be downloaded to Word. This
NEWS
Regulation (EU, Euratom) 2023/2841 (Cybersecurity Regulation) laying down measures for a high common level of cybersecurity at the EU’s institutions, bodies, offices and agencies has entered into force on 7 January 2024. The Cybersecurity Regulation provides for the establishment of an internal cybersecurity risk management, governance and control framework for each EU entity, and sets up a new Interinstitutional Cybersecurity Board (IICB) to monitor and support its implementation by EU entities. It provides an extended mandate of the Computer Emergency Response Team for the EU institutions, bodies, offices and agencies (CERT-EU), as a threat intelligence, information exchange and incident response co-ordination hub, a central advisory body, and a service provider. In line with its mandate, CERT-EU is renamed to ‘Cybersecurity Service for the Union institutions, bodies, offices and agencies’, but retains the short name CERT-EU.
PRECEDENTS
1 General information Date of review [Insert date] Person(s) conducting review [Insert name of person(s) conducting review] 2 Review and findings Are your cybersecurity/cybercrime plans, policies and procedures up to date and fit for purpose? ☐ Yes☐ NoIf no, ensure you set an action point at section 3 to update your policy and processes Are your Website—cybercrime—monitoring form and Cybersecurity IT update log
PRACTICE NOTES
FORTHCOMING CHANGE: On 12 November 2025, the Cyber Security and Resilience (Network and Information Systems) Bill (CSRB) was introduced to the House of Commons. The CSRB makes provision to amend the Network and Information Systems Regulations 2018, SI 2018/506, including by extending their application to data centres, managed service providers and large load controllers, and by enabling regulators to designate ‘critical suppliers’. The CSRB also updates incident reporting requirements, introduces a two-stage reporting structure (initial notification within 24 hours and full notification within 72 hours), and expands the definition of reportable incidents to capture a broader range of security compromises. The Secretary of State gains the power to make regulations relating to the security and resilience of network and information systems, to designate a statement of strategic priorities for regulatory authorities, and to issue a code of practice. The CSRB also provides powers to give directions to regulated persons and regulatory authorities where threats pose a risk to
PRACTICE NOTES
This Practice Note is intended to provide an overview of the laws and regulations relating to cybersecurity in the EU, with a particular focus on: • Regulation (EU) 2016/679, the EU General Data Protection Regulation (EU GDPR) • Directive (EU) 2022/2555, the second EU’s Network and Information Systems Directive (NIS 2 Directive), which replaced Directive (EU) 2016/1148 (NIS Directive) • Directive (EU) 2022/2557, the EU Critical Entities Resilience Directive, (CER Directive) • Directive 2002/58/EC, the EU ePrivacy Directive • Directive (EU) 2018/1972, the European Electronic Communications Code (EECC) • financial legislation such as Regulation (EU) 2022/2554, the Digital Operational Resilience Act (DORA) and Directive (EU) 2015/2366, the second EU Payment Services Directive (PSD2), and • Regulation (EU) 2024/2847, the EU Cyber Resilience Act ( CRA) • Regulation (EU) 2024/1689, the EU AI Act These laws and regulations are discussed in the context of: • the entities that are required to comply with such rules • the security obligations
PRACTICE NOTES
The government has published a number of Codes of Practice relating to different aspects of cybersecurity, to create a framework for compliance with cybersecurity obligations (which can often be expressed in broad or vague terms under UK law). Each of these codes addresses different aspects of cybersecurity. This Practice Note provides a summary of each code, setting out the objective, scope, and key requirements of each and relevant related materials such as National Cyber Security Centre (NCSC) guidance. Cybersecurity obligations under UK law and the relevance of Codes of Practice Cybersecurity obligations under UK law are set out under several different laws that each have the security of information systems and data as part of their aims. Where personal data is involved, the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) and the Data Protection Act 2018 are central to the regulation of data security. For further information, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Security. In addition to the cybersecurity obligations applicable to general commercial organisations
PRACTICE NOTES
This Practice Note offers a concise overview of cybersecurity challenges for life sciences companies, providing practical advice for EU-based organisations. It covers the regulatory landscape regarding cybersecurity in the EU, including NIS 2 Directive, Medical Devices Regulations (MDR and IVDR), EU AI Act, EU Cyber Solidarity Act, EU Cyber Resilience Act, European Health Data Space Regulation or EHDS, among others, and their compliance obligations and their sanctions or enforcement consequences in the event of non-compliance. It also highlights key regulatory authorities and industry bodies, concluding with insights into cybersecurity legislation trends and future outlooks. The cybersecurity landscape in the life sciences sector The life sciences sector, covering research and development (R&D) of pharmaceuticals, medical devices, and biotechnology; clinical trials; and healthcare services, increasingly integrates digital technologies like telemedicine, health apps, and artificial intelligence (AI) to boost operations and innovation. This digital adoption, however, introduces cybersecurity risks. For the purpose of the current Practice Note, cybersecurity refers to the protection of data and systems from unauthorised or malicious
PRACTICE NOTES
This Practice Note considers cybersecurity in international arbitration. An introduction to cybercrime and cybersecurity in international arbitration A single arbitration can involve numerous participants from multiple jurisdictions, including parties, their funders and insurers, arbitrators, counsel, experts, witnesses, an arbitral institution or other administering organisation and third-party service providers (broadly referred to here as ‘Participants’). Within the arbitral process, those Participants may share material which is not in the public domain. Access to this material may have the potential to cause commercial damage, influence share prices, corporate strategies or even government policy. The outcome of an arbitration could have significant repercussions in the financial markets. This means that obtaining a draft form of an arbitral award before release to the parties themselves could be very lucrative for cybercriminals. As such, the arbitral process is a target for cyberattacks, particularly if hackers can identify a weak link in
PRACTICE NOTES
This Practice Note summarises key points from the Cyber Threat Report: UK Legal Sector published by the National Cyber Security Centre (NCSC), and incorporates data from the SRA’s Cyber security thematic review, published September 2020, together with the SRA’s Information security and cybercrime risk outlook. Headline facts and figures The cyber threat to the UK legal sector is significant, as is the financial and reputational impact of cyber attacks on law firms. Costs arise from: • the attack itself • remediation, and • repairing reputational damage The SRA thematic review found that three quarters of the firms it visited reported they had been the target of a cyber attack. Other firms reported that cyber criminals had directly targeted their clients during a legal transaction. While not all incidents culminated in a financial loss for clients, 23 of the 30 cases in which firms were directly targeted saw a total of more than £4m of client money stolen. While £3.6m of this was ultimately claimed against insurance policies, £400,000 had to be repaid directly from
GLOSSARY
A term introduced by science fiction author William Gibson in 1984. 'Cyberspace' is where human interaction occurs over computer networks, through email, games or simulations.