Refine By
Clear all filter
About 703 results for "cybersecurity"
CHECKLISTS
This Checklist is designed to highlight key cybersecurity considerations which arise during the negotiation and drafting of technology services outsourcing agreements in the UK. For further guidance on wider (non-cybersecurity-specific) IT outsourcing agreement issues, see: IT outsourcing agreement—checklist. For template outsourcing agreements, see Precedents: Outsourcing agreement—long form and Outsourcing agreement—short form. UK law generally takes a ‘principles’ or ‘outcomes’-based approach to cybersecurity, often leaving it for organisations to determine how best to assess, monitor and tackle its cyber risks. For contracting, this means that there are few prescriptive contractual requirements. However, organisations may need to flow down terms to their suppliers so that they can meet their own obligations under other contractual arrangements they are party to. Regulators will also expect that, in the event of an incident, an organisation is able to demonstrate that they took appropriate measures, including contractual measures, to manage their cybersecurity risk (as well as complying with their contractual commitments to their customers). For further information on how cybersecurity is addressed under UK law, see: Cybersecurity, threats and risk management—overview.
PRACTICE NOTES
This Practice Note provides an overview of the key cybersecurity implications that artificial intelligence (AI) presents in the context of cybersecurity obligations under UK law such as those under the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). It also provides advice on how to incorporate AI as a consideration into existing cybersecurity compliance regimes. The developments in AI raise concerns about the implications for cybersecurity and as the use of AI grows, so do cybersecurity concerns. In January 2024, the UK National Cyber Security Centre (NCSC) (the UK’s technical authority for cyber threats) cautioned that AI will almost certainly make cyberattacks against UK organisations more impactful and prevalent. In April 2026, the government issued an open letter to businesses on AI cyber threats, cautioning that the development of AI models is vastly increasing the speed and scale at which cyber attacks are being carried out, and that businesses must adapt the way they respond to cyber risk accordingly (see: LNB News 16/04/2026 14). In May 2026, the government
PRACTICE NOTES
ARCHIVED: This Practice Note has been archived and is not maintained. This Practice Note explores the effect of Brexit on UK cybersecurity with a particular focus on the network and information systems legislation. It covers: • overview of cybersecurity regulation in the UK prior to the end of the implementation period • background to Directive (EU) 2016/1148, the Network and Information Systems Directive (the NIS Directive) and UK implementation • general impact of Brexit on UK implementation of the NIS Directive • impact of the end of the transition period on relevant digital service providers (RDSPs) • an overview of the impact on qualified trust services under Regulation (EU) 910/2014 (the eIDAS Regulation) • impact of the end of the transition period on UK cybersecurity cooperation with the EU The significance of cybersecurity has been highlighted in recent years by high-profile attacks affecting businesses and public services. These involved a diverse range of attack methods, motivations and targets as explored further in Cybersecurity, threats and risk management—overview. The EU’s recognition of the importance of ensuring Member States’
PRACTICE NOTES
STOP PRESS: This Practice Note reflects the current legislative position, however please note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025 pursuant to the Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. Introduction The importance of implementing cybersecurity measures has been highlighted in recent years by high profile security failures involving the internet, the technology, and the services which support and make use of it. Against this backdrop, cybersecurity is of growing significance both to businesses and individuals. On 16 December 2020, the Commission and the High Representative of the Union for Foreign Affairs and Security Policy presented an EU Cybersecurity Strategy. This strategy covers the security of essential services in the EU (eg hospitals, energy grids and railways) but also the security of connected objects in homes, offices and factories. The strategy focuses on building collective capabilities to respond to major cyber-attacks and working internationally to ensure international security and stability in cyberspace. The EU has recently adopted several cybersecurity
PRACTICE NOTES
FORTHCOMING CHANGE: On 12 November 2025, the Cyber Security and Resilience (Network and Information Systems) Bill (CSRB) was introduced to the House of Commons. The CSRB makes provision to amend the Network and Information Systems Regulations 2018, SI 2018/506, including by extending their application to data centres, managed service providers and large load controllers, and by enabling regulators to designate ‘critical suppliers’. The CSRB also updates incident reporting requirements, introduces a two-stage reporting structure (initial notification within 24 hours and full notification within 72 hours), and expands the definition of reportable incidents to capture a broader range of security compromises. The Secretary of State gains the power to make regulations relating to the security and resilience of network and information systems, to designate a statement of strategic priorities for regulatory authorities, and to issue a code of practice. The CSRB also provides powers to give directions to regulated persons and regulatory authorities where threats pose a risk to
PRECEDENTS
1 General information Date of review [Insert date] Person(s) conducting review [Insert name of person(s) conducting review] 2 Review and findings Are your cybersecurity/cybercrime plans, policies and procedures up to date and fit for purpose? ☐ Yes☐ NoIf no, ensure you set an action point at section 3 to update your policy and processes Are your Website—cybercrime—monitoring form and Cybersecurity IT update log
PRECEDENTS
1 Background information Name of[ prospective] supplier [To be completed by customer] Address [To be completed by customer] Brief description of services[ to be] supplied [To be completed by customer] Date questionnaire completed by[ prospective] supplier [To be completed by customer] Signature of authorised representative of[ prospective] supplier [To be completed by supplier/third party] Name of authorised representative [To be completed by supplier/third party] 2 Governance Who is ultimately responsible within your organisation for information and cybersecurity management? [To be completed by supplier/third party] When did the board last consider information security, cybersecurity and cybercrime risk? [To be completed by supplier/third party] 3 Security policies and procedures Do you have an information security and/or cybersecurity policy?If yes, please provide a copy ☐ Yes☐ No Please describe your arrangements for ensuring physical security of your premises and processing areas, including physical entry controls (if any) [To be completed by supplier/third party] Please describe your arrangements for equipment security and maintenance [To be completed by supplier/third party] Please describe your arrangements for password and access controls, including whether:—you enforce a password policy that is in line with recognised good practice—all staff and contractors are assigned individual accounts to log onto the organisation’s IT systems—you enforce the use of multi-factor
PRACTICE NOTES
The government has published a number of Codes of Practice relating to different aspects of cybersecurity, to create a framework for compliance with cybersecurity obligations (which can often be expressed in broad or vague terms under UK law). Each of these codes addresses different aspects of cybersecurity. This Practice Note provides a summary of each code, setting out the objective, scope, and key requirements of each and relevant related materials such as National Cyber Security Centre (NCSC) guidance. Cybersecurity obligations under UK law and the relevance of Codes of Practice Cybersecurity obligations under UK law are set out under several different laws that each have the security of information systems and data as part of their aims. Where personal data is involved, the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) and the Data Protection Act 2018 are central to the regulation of data security. For further information, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Security. In addition to the cybersecurity obligations applicable to general commercial organisations
PRECEDENTS
This Precedent presentation has been designed as an aid to train your staff on cybercrime/cybersecurity. This training presentation is not a technical guide, but rather guidance designed to help organisations train their staff on steps taken to manage the risk of cybercrime. Although it contains a number of references to some technical aspects of cybercrime and cybersecurity, these are intended as signposts for organisations only. This Precedent is not
CHECKLISTS
This Checklist is designed to help you determine whether you have the systems in place to prevent and deal with cybercrime. It is intended for compliance professionals in general commercial organisations and is not intended to cover sector-specific requirements applying to the telecommunications, financial services or other essential services sectors. This Checklist should be read in conjunction with subtopics: Cybersecurity and Information security (or for law firms, Information security—law firms). Cybercrime prevention Recommended document or action ☐ Ensure your board/senior management is actively involved in your cybersecurity and cybercrime prevention programme.See Practice Note: Cybercrime prevention. ☐ Consider the extent to which your organisation is at risk from cybercrime.See Precedent: Cybercrime risk assessment. ☐ Consider what IT and information systems you have and whether the operating systems, software, etc is up-to-date.See Precedent: Cybersecurity IT log. ☐ Conduct an audit of your information and cybersecurity arrangements
PRECEDENTS
Please click for the Precedent Cybersecurity IT update log. Please note that this log has been prepared in Excel and it therefore cannot be downloaded to Word. This
PRACTICE NOTES
Jurisdictions covered The following jurisdictions are covered in this report: China; Germany; Greece; Hong Kong; Italy; Japan; Netherlands; Nigeria; Türkiye; United Kingdom Questions The set of questions relating to the topic of privacy and cybersecurity and answered by the guide for each jurisdiction covered include: