Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

UK opens telecoms security law review

2 min read
12:09UTC

DSIT and DCMS opened a call for evidence on 17 August covering sections 1 to 13 of the Telecommunications (Security) Act 2021, the regulations made under it and the accompanying code of practice.

TechnologyAssessed
Key takeaway

The UK is reviewing its telecoms security regime as a whole, not amending a clause.

DSIT, the Department for Science, Innovation and Technology, and DCMS, the Department for Digital, Culture, Media and Sport, opened a call for evidence on 17 August covering sections 1 to 13 of the Telecommunications (Security) Act 2021, the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice 1. A call for evidence is the stage before a decision: government asks who is affected what the current rules cost and achieve, then decides whether to change them.

The three documents named form one regime rather than three. The Act carries the duties, the regulations made under it set out the specific measures, and the code of practice describes how a provider is expected to meet them. Reviewing all three at once means the question on the table is the shape of the regime, not the wording of a clause inside it.

The reason a telecoms security regime exists at all was put on the record in June, when the head of Britain's National Cyber Security Centre told an audience at RUSI that the agency had handled more than 200 incidents affecting UK critical national infrastructure, three quarters of them state-linked . Telecoms is the layer every other piece of that infrastructure runs across, which is why it got its own statute rather than a place inside a general one.

France published in a different register the same fortnight. ANSSI, its national cyber agency, released a Wi-Fi security guide on 31 August pitched as good practice for readers at any level rather than detailed technical recommendation 2. One government asks its industry whether the law is working; another hands out advice with no legal force behind it. Both are what the quiet end of cyber policy actually looks like between enforcement moments.

Deep Analysis

In plain English

DSIT and DCMS are UK government departments covering technology and culture/media respectively. They opened a public consultation on 17 August asking whether the main law setting security rules for UK telecoms networks, passed in 2021, is still working as intended. Separately, France's cyber agency ANSSI published a general Wi-Fi security guide on 31 August, aimed at readers of any skill level rather than technical specialists.

Deep Analysis
Root Causes

The Telecommunications (Security) Act 2021 set duties for UK telecoms providers but left detailed technical thresholds to secondary regulations and a code of practice.

A review of sections 1 to 13 tests whether those thresholds have kept pace with the threat picture five years on, not whether the law's underlying duties themselves need to change.

First Reported In

Update #13 · Four privileged platforms under live attack

Department for Science, Innovation and Technology and Department for Digital, Culture, Media and Sport· 5 Sept 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.