What Might ‘Brexit’ Mean For Cybersecurity In The UK?

After 43 years of inclusion, the UK has voted to leave the European Union in the historically unprecedented “Brexit” referendum vote. Aside from causing uncertainty in the world’s financial markets and across the political landscape, the result has implications for cybersecurity too.

While some cybersecurity pros say that Brexit will have little ill effect on the space, others aren't so sure. For one, Michaela Menting, research director for ABI Research, noted that the UK will need to review its role Europol and the European Cybercrime Centre (EC3), which is the focal point in the EU’s fight against cybercrime.

“Organized online criminal activities are undeniably best tackled from a cooperative, supra-national perspective, and the UK’s isolation that may result from Brexit would be an unwelcome development in the fight against cybercrime,” she said. “Further to this, new cybersecurity information and asset sharing structures will need to be put in place between the EU and the UK.”

There may also be a dampening impact on the country with regards to the UK workforce skills pool.

Brian Spector, CEO of Miracl, a cybersecurity firm based and operating in UK, told the International Business Times, "The UK has a well-documented shortage of tech talent that means it simply cannot compete globally without tapping into highly-skilled overseas workers. Splitting away from Europe would make it even more difficult for UK tech firms to compete with the US tech giants, because their talent pool would be so much larger than ours. To cut ourselves off from the rest of Europe therefore does nothing to protect the UK's reputation as being open for business."

Companies are also evaluating whether to keep outposts in the post-Brexit capital.

"Our R&D department in Shoreditch, London, comprises of developers from several different EU nations—including Italy, Finland and Germany," Jamie Moles, security consultant for Lastline, American cybersecurity firm, told the International Business Times. “These guys live and work in London and travel around Europe for research purposes—as well as to return home to visit family. 

There is an obvious concern post-Brexit that the rules might change regarding their ability to stay in the UK and or travel freely around Europe. We will have to wait and see if these concerns are founded or not and will of course support our team to remain employed and productive.”

From a data privacy and protection perspective, there’s also the question of whether the UK will align with the upcoming GDPR and NIS Directive. Further, according to Menting, the decision whether to retroactively repeal or keep all past EU legislation adopted to date for data protection and privacy.

“Currently, all EU laws still apply in the UK; at least over the course of the next two years as the UK untangles itself from the Union,” she said. “However, the UK will need to determine not only whether they will (unilaterally) implement similar legislation in the future.”

There are directives on e-commerce and data protection that date back to the early 2000s, the EU Directive on Data Retention from 2006, and the Directive on Attacks against Information Systems, adopted in August 2013. The UK has adapted all of these in some shape or form into national legislation.

“The UK will have to rule on the continued applicability of these instruments, as well as how they will address the incoming GDPR and NIS Directive,” Menting said.

Many US companies find the EU regulations onerous and an impediment to trans-Atlantic commerce; which on the one hand would point to Brexit being helpful from a US trade perspective. However, both the GDPR and the NIS Directive state that operators and data controllers will be covered by the legislative requirements if they operate within EU markets and involve EU citizens—which leaves Britain in a position of little power to forge its own path.

“Seeing the high level of trade that the open market has brought in the UK in the past four decades, many UK organizations will need to comply if they want to continue trading and operating in EU markets,” she said. 

She said that the EU stands to lose in a lack of free-flowing resources too—especially when it comes to the UK’s allocation of funding to cybersecurity startups.

“While the UK government has placed significant investments in the cybersecurity startup scene in the past few years, it is also uncertain whether this funding will continue to be allocated to EU and UK firms indiscriminately as it has in the past,” the analyst noted. “it would be unfortunate, and detrimental to the cybersecurity industry in the long run, for the UK to take a
similar direction with these currently highly successful investment projects.”

Despite the uncertainty around these issues, it's important to keep a level head, according to AN Ananth, CEO of EventTracker. “Brexit is affecting everything," he told Infosecurity via email. "Security always suffers in times of uncertainty. What’s happened is unprecedented and there is a lot of confusion as to the next steps. This is the kind of chaotic environment in which insecurity thrives."

He added, "This is reminiscent of 2008 when the US financial system suffered. That type of environment hurts security, which is already hard enough to maintain. At times like this, process and discipline can help. You should train like you fight, because you’ll fight like you train, as the saying goes. I would recommend that everyone keep calm and carry on.”

Infosecurity

« Lessons Learned From Major Healthcare Breaches
Edward Snowden’s Lawyer Wants Obama To Give Him A Pardon »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

HANDD Business Solutions

HANDD Business Solutions

HANDD are independent specialists in data protection with expertise at every stage of the Protect, Detect and Respond cycle, from consultancy and design, right through to installation.

TZ-CERT

TZ-CERT

TZ-CERT is the National Computer Emergence Response Team of Tanzania.

INSUREtrust

INSUREtrust

INSUREtrust is a pioneer in the industry, inventing the concept of cyber insurance.

Avanan

Avanan

Avanan is The Cloud Security Platform. Protect all your SaaS applications using tools from over 60 industry-leading vendors in just one click.

MailGuard

MailGuard

MailGuard delivers a full suite of security solutions across email and web to protect your business before threats reach your environment.

MixMode

MixMode

MixMode's PacketSled platform delivers network monitoring, deep forensic analysis and incident response.

CryptTalk

CryptTalk

CryptTalk is an easy-to-use secure communication service.

National Cybersecurity Society (NCSS)

National Cybersecurity Society (NCSS)

The National Cybersecurity Society is a non-profit organization focused on providing cybersecurity education, awareness and advocacy to small businesses.

Strategic Cyber Ventures (SCV)

Strategic Cyber Ventures (SCV)

SCV grow cybersecurity companies that disrupt advanced cyber adversaries and revolutionize the cyber product marketplace.

SecureNation

SecureNation

SecureNation offers a wide variety of cutting-edge technologies and IT services to address almost any of your information security, network security and information assurance needs.

Otorio

Otorio

OTORIO delivers industrial cybersecurity and digital risk-management solutions and services. We help our customers to keep their revenue-generating operations resilient, efficient, and safe.

StickmanCyber

StickmanCyber

At StickmanCyber we are on a mission to create a digital world that is safe for everyone - we are your trusted cybersecurity partner.

Dig Security

Dig Security

Dig Security offers the first data detection and response (DDR) solution, providing real-time visibility, control and protection of your data assets across any cloud.

Tracebit

Tracebit

Tracebit uses decoys to detect and respond to cloud intrusions in minutes.

SOCRadar

SOCRadar

SOCRadar is an Extended Threat Intelligence (XTI) SaaS platform that combines External Attack Surface Management (EASM), Digital Risk Protection Services (DRPS), and Cyber Threat Intelligence (CTI).

Cyber Grant

Cyber Grant

Cyber Grant excel in designing cybersecurity solutions for data protection. Our approach and vision, centered on ease-of-use, establish us as a benchmark in the industry for safeguarding information.