Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Police press for a 'digital prison'

2 min read
18:20UTC

City of London Police Commander Ollie Shaw used the TfL sentencing to press for Cyber Crime Risk Orders, restrictions on a hacker's technology access that UK law does not yet provide.

TechnologyDeveloping
Key takeaway

City of London Police wants post-release technology bans for hackers, a power UK law currently lacks.

City of London Police Commander Ollie Shaw used the Transport for London sentencing on 16 July to press for Cyber Crime Risk Orders, court powers that would restrict a convicted hacker's access to devices and technology after release. Shaw described the model as a digital prison 1.

No such order exists in UK statute. The structure mirrors Sexual Harm Prevention Orders (SHPOs), which impose post-conviction restrictions on offenders, applied instead to computer misuse. City of London Police is the UK's national lead force for fraud and cybercrime, which gave Shaw a policy platform the day the sentences landed.

Shaw is pressing for the order while the Cyber Security and Resilience Bill works through the Lords , a separate vehicle that would not itself create the power he wants. A Cyber Crime Risk Order would need its own primary legislation, and it would test how far post-release monitoring can reach into a released offender's ordinary use of computers and the internet.

Deep Analysis

In plain English

A Cyber Crime Risk Order would be a new type of court order that does not exist yet in UK law. It would let a judge restrict what devices or internet access a convicted hacker has after they leave prison, similar to orders already used for other kinds of offenders. City of London Police Commander Ollie Shaw raised the idea after the Transport for London hackers were sentenced, calling it a 'digital prison' model. Because the power does not exist in current UK statute, Parliament would need to create it before any court could use it.

Deep Analysis
Root Causes

The gap Shaw is pointing to is structural: UK sentencing law can jail a convicted hacker but has no civil mechanism to restrict their access to computers or the internet after release, unlike the restrictions already available for other offence categories.

Scattered Spider's fluid, distributed membership model means individual prosecutions do not remove the technical skills or renewed internet access a released offender would have, which is the practical problem a post-release restriction order is meant to address.

Escalation

This is a policy proposal raised through a single police commander's public remarks rather than a government bill, so it remains an early-stage advocacy position rather than a confirmed legislative direction.

What could happen next?
  • Opportunity

    If enacted, Cyber Crime Risk Orders would give UK courts a civil restriction tool for cybercrime that currently only exists for other offence categories such as sexual offending.

  • Risk

    Any new power restricting internet access post-conviction is likely to draw civil-liberties scrutiny of the kind Lord Alton has pressed for elsewhere in current cyber legislation.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

National Crime Agency· 24 Jul 2026
Read original
Causes and effects
This Event
Police press for a 'digital prison'
A record conviction is being turned into a lobbying platform for post-release technology bans that would need new primary legislation.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.