UK Seeks Powers to Block Tech Suppliers in Secret on National Security Grounds

Server racks in a data centre
  • Homepage
  • >
  • All News
  • >
  • UK Seeks Powers to Block Tech Suppliers in Secret on National Security Grounds

The government is seeking new powers to ban technology suppliers from the country’s critical sectors on national security grounds, and in some cases to do so without publicly naming the vendor involved.

Amendments to the Cyber Security and Resilience Bill, published on Monday, adapt powers first used to force Huawei equipment out of Britain’s 5G networks under the Telecommunications (Security) Act 2021. But the new proposals remove some of the transparency safeguards built into that regime.

Unlike under the telecoms law, ministers would not have to publicly designate a vendor as a security risk before acting, and there would be no duty to send the supplier a copy of the order. The powers would extend beyond telecoms to managed service providers, data centres and digital infrastructure, as well as the energy, water, transport and health sectors.

A senior minister could order companies in those sectors to stop buying from a particular supplier, restrict the use of its products, or modify, disable and remove equipment already installed. The mechanism, called a “vendor-related direction”, is aimed at suppliers with “ties to hostile states who may seek to use products to spy, sabotage systems or cause disruption”, according to the government.

Cybersecurity minister Liz Lloyd said the powers meant the government could “act before a threat materialises, not just after the damage is done”, adding that national security would be put “at the heart of how essential services choose their suppliers”.

There is one notable safeguard the telecoms act lacked: a duty to publish a notice that a direction has been issued, naming the company affected. However, the vendor would not necessarily be identified, and details could be withheld on national security or commercial grounds. Recipients could be barred from discussing the order publicly, and anyone consulted in advance could be barred from revealing the consultation took place.

The government would report annually to Parliament on how many directions had been issued, which sectors were affected and how many were later varied or revoked. Companies given a direction would need written government approval before appointing an outside specialist to help them comply, with ministers able to draw on a list of approved specialists published by GCHQ.

The amendments, published with the bill documents, are due to be considered at committee stage in the House of Lords in September. The Record reports that security officials have previously pushed for greater transparency in similar cases, including the government’s attempt to force Apple to weaken end-to-end encryption in iCloud, which experts described as unsustainable and unjustifiable.

Share Article
Facebook
LinkedIn
X
UK Petrol Prices Pass 163p a Litre, the Highest Since the Iran Conflict Began
Smart Ring Maker Oura Files for Nasdaq Listing Above an $11 Billion Valuation
Volkswagen Board Approves a Further 50,000 Job Cuts Across Europe
Secret Link