Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Police press for a 'digital prison'

2 min read
18:20UTC

City of London Police Commander Ollie Shaw used the TfL sentencing to press for Cyber Crime Risk Orders, restrictions on a hacker's technology access that UK law does not yet provide.

TechnologyDeveloping
Key takeaway

City of London Police wants post-release technology bans for hackers, a power UK law currently lacks.

City of London Police Commander Ollie Shaw used the Transport for London sentencing on 16 July to press for Cyber Crime Risk Orders, court powers that would restrict a convicted hacker's access to devices and technology after release. Shaw described the model as a digital prison 1.

No such order exists in UK statute. The structure mirrors Sexual Harm Prevention Orders (SHPOs), which impose post-conviction restrictions on offenders, applied instead to computer misuse. City of London Police is the UK's national lead force for fraud and cybercrime, which gave Shaw a policy platform the day the sentences landed.

Shaw is pressing for the order while the Cyber Security and Resilience Bill works through the Lords , a separate vehicle that would not itself create the power he wants. A Cyber Crime Risk Order would need its own primary legislation, and it would test how far post-release monitoring can reach into a released offender's ordinary use of computers and the internet.

Deep Analysis

In plain English

A Cyber Crime Risk Order would be a new type of court order that does not exist yet in UK law. It would let a judge restrict what devices or internet access a convicted hacker has after they leave prison, similar to orders already used for other kinds of offenders. City of London Police Commander Ollie Shaw raised the idea after the Transport for London hackers were sentenced, calling it a 'digital prison' model. Because the power does not exist in current UK statute, Parliament would need to create it before any court could use it.

Deep Analysis
Root Causes

The gap Shaw is pointing to is structural: UK sentencing law can jail a convicted hacker but has no civil mechanism to restrict their access to computers or the internet after release, unlike the restrictions already available for other offence categories.

Scattered Spider's fluid, distributed membership model means individual prosecutions do not remove the technical skills or renewed internet access a released offender would have, which is the practical problem a post-release restriction order is meant to address.

Escalation

This is a policy proposal raised through a single police commander's public remarks rather than a government bill, so it remains an early-stage advocacy position rather than a confirmed legislative direction.

What could happen next?
  • Opportunity

    If enacted, Cyber Crime Risk Orders would give UK courts a civil restriction tool for cybercrime that currently only exists for other offence categories such as sexual offending.

  • Risk

    Any new power restricting internet access post-conviction is likely to draw civil-liberties scrutiny of the kind Lord Alton has pressed for elsewhere in current cyber legislation.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

National Crime Agency· 24 Jul 2026
Read original
Causes and effects
This Event
Police press for a 'digital prison'
A record conviction is being turned into a lobbying platform for post-release technology bans that would need new primary legislation.
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.