Data Centres Given Critical National Infrastructure Status In Britain

In September, the Technology Secretary Peter Kyle declared that UK data centres will now be classified as Critical National Infrastructure (UK CNI), marking the first new CNI designation since 2015.

UK CNI constitutes critical elements of infrastructure of which the loss or compromise could result in major detrimental impact on essential public services, emergency systems, national security, defence, or the functioning of the state. 
 
This new designation places data centres on par with essential services, ensuring they receive prioritised support during critical incidents such as cyber-attacks, environmental disasters, and IT blackouts.

This follows the Science and Technology Committee’s recent inquiry into the cyber resilience of the UK CNI sector, during which the importance of bolstering the digital infrastructure against potential cyber-attack was emphasised. 

Key Aspects  

Data centres are crucial to the UK’s digital economy, powering essential services like healthcare, finance, and increasingly AI applications. Investment in data centres has surged recently, particularly within the UK; for example, Chancellor Rachel Reeves confirmed that Amazon Web Services plans to invest £8 billion in the UK over the next five years to build, operate, and maintain data centres.

Important aspects and implications of their designation as UK CNI include as follows: 

  • Strengthening UK’s digital Infrastructure:  The UK Government’s growing investment in the digital sector necessitates parallel enhancements in protections to ensure its resilience and security. A notable recent development is the proposed £3.75 billion investment welcomed by the UK Government in Europe’s largest data centre in Hertfordshire, which is anticipated to create nearly 14,000 jobs across the UK. As technological advancement and development become increasingly central to government policy and integral to the daily lives of UK citizens, such as in NHS records, financial information, and personal data stored on smartphones, it is increasingly critical to ensure the digital infrastructure storing this data is secure.
  •  Recent Cybersecurity Incidents: The need for greater resilience in the UK’s Digital infrastructure can be highlighted by two significant incidents this year. The first was a ransomware attack affecting services provided by Synnovis, a pathology firm, causing severe disruptions at healthcare sites including Guy’s and St Thomas’ Hospital and King’s College Hospital which resulted in the cancellation of operations and the diversion of emergency patients.

Additionally, the faulty CrowdStrike software update that caused a global computing outage was estimated as causing approximately £7.8 billion in damages, indicating the potential financial damage arising from such incidents. The greater protection given to datacentres by the new CNI classification will reduce and mitigate the impact of such incidents. 

  •  NIS Regulations: The UK Network and Information Systems Regulations 2018 (NIS) are a crucial cyber security framework applicable to to ‘operators of essential services’ and ‘relevant digital service providers’, enhancing the security and resilience of network and information systems across sectors like energy, healthcare, and finance. The NIS2 Directive came into force across the European Union in January 2023, which is aimed at CNI sectors and expanded the original scope of the NIS Directive to include other critical sectors such as space, waste, water, food, and manufacturing.

Although the EU’s NIS 2 Directive does not apply directly to the UK, the UK government plans to align its NIS regime with the EU’s updated framework to strengthen cyber defences, particularly for digital service providers and future-proofing the regulations. Proposed reforms include expanding the scope to cover ‘managed services’ and implementing a flexible risk-based assessment regime regulated by the UK Information Commissioner. These measures aim to ensure high levels of cyber-resilience and safeguard essential services against cyber threats. 

  •  Cyber Security and Resilience Bill:  The government plans to introduce the Cyber Security and Resilience Bill to strengthen the country’s cyber defences, as announced in the King’s Speech in July. This legislation will mandate that providers of essential infrastructure (i.e., UK CNIs) protect their supply chains from cyber threats, as well as expanding the scope of the current NIS Regulations, safeguarding a wider range of digital services and supply chains than currently protected. 
  • Enhanced Government Support: The new classification means UK data centres will receive additional government support in anticipating and recovering from emergencies. This includes the creation of a dedicated CNI data infrastructure team of senior officials who will monitor potential threats and coordinate priority access to government security agencies (including the National Cyber Security Centre) and emergency services to ensure rapid response and recovery during critical incidents.

 Takeaways
The classification of data centres as Critical National Infrastructure marks a pivotal moment for the UK’s digital economy. By providing enhanced protections and support, the UK government aims to ensure the resilience and security of data centres, fostering a secure environment for investment and growth.

This move not only intends to safeguard vital data but reinforce the UK’s position as a leader in data security and technological innovation.

David Varney and Victoria McCarron are Technoloy & Data lawyers at Burges Salmon

Image: Unsplash

You Might Also Read: 

Proposed British Digital Information & Smart Data Bill:

DIRECTORY OF SUPPLIERS - Critical Infrastructure Security:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« Remote Pager Attack Begins A New Era Of Warfare
Attackers Can Use RAM To Steal Data From Air-Gapped Networks »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Security Weekly

Security Weekly

Security Weekly provides free content within the subject areas of IT security news, vulnerabilities, hacking, and research.

ID-SIRTII/CC

ID-SIRTII/CC

Security Incident Response Team for Internet Infrastructure in Indonesia.

Data Resolve Technologies

Data Resolve Technologies

Data Resolve offer a mechanism through which customers can detect and tackle various kinds of sensitive activities pertaining to data loss and data theft.

InstaSafe Technologies

InstaSafe Technologies

InstaSafe®, a Software Defined Perimeter based (SDP) one-stop Secure Access Solution for On-Premise and Cloud Applications.

Scantist

Scantist

Scantist is a cyber-security spin-off from Nanyang Technological University (Singapore) which leverages its expertise to provide vulnerability management solutions to enterprise clients.

ColorTokens

ColorTokens

ColorTokens Xtended ZeroTrust Platform protects from the inside out with unified visibility, micro-segmentation, zero-trust network access, cloud workload and endpoint protection.

QuoLab

QuoLab

QuoLab empowers security professionals to analyze, investigate and respond to threats within an integrated ecosystem.

Graylog

Graylog

Graylog provides answers to your team’s security, application, and IT infrastructure questions by enabling you to combine, enrich, correlate, query, and visualize all your log data in one place.

Mosaic Insurance

Mosaic Insurance

Mosaic is a next-generation global specialty insurer distinguished by an exceptional team, agile technology, and a structure that combines Lloyd’s of London strength with a global distribution network

PhishFirewall

PhishFirewall

PhishFirewall is an advanced AI-driven CyberSecurity Awareness Education, Threat Emulation, and Human Security Analytics Platform.

Morpheus Enterprises

Morpheus Enterprises

Morpheus Enterprises offer managed security solutions designed to keep your web applications secure and your business running smoothly.

Protect AI

Protect AI

Protect AI is a cybersecurity company focused on AI & ML systems. Through innovative security products and thought leadership in MLSecOps, we help our customers build a safer AI powered world.

Protecto

Protecto

Make privacy and governance effortless. Brakes allow you to drive faster. Stronger data privacy and security enable companies to unlock the full potential of the data.

OryxLabs

OryxLabs

OryxLabs provide advanced enterprise digital risk protection solutions. Learn more about how 24x7 continuous assessment, monitoring, and improvement can secure your network.

Seal Security

Seal Security

Seal Security revolutionizes software supply chain security operations, empowering organizations to automate and scale their open source vulnerability remediation and patch management.

Omnex

Omnex

Omnex provides consulting and training services in Quality, Environmental, and Health and Safety standards-based management systems including Automotive Cybersecurity.