Westminster seeks powers to intervene in high-risk technology purchases by essential services

Share On LinkedIn
Share on X

The UK government plans to grant itself new powers to intervene when providers of essential services propose buying technology from suppliers linked to hostile foreign states that could be used for cyber espionage, sabotage or other malicious activity.

Amendments tabled to the Cyber Security and Resilience Bill by life peer Elizabeth Lloyd, Baroness Lloyd of Effra, a former policy adviser to Tony Blair, introduce a “vendor-related directions” clause. This would allow ministers to step in where they judge that “risks to national security could arise from the use of goods, services or facilities in connection with network and information systems linked to essential activities or the provision of essential goods or services”.

The measures would apply to operators of essential services including electricity and water suppliers and NHS bodies. The government said cyber attacks and sabotage against such services are a growing reality, pointing to a July 2026 incident at a small UK-based “peaker” power plant attributed to Iran. It described tech suppliers with connections to hostile states as posing a “serious and growing threat” to the security of millions.

Government figures suggested a hypothetical cyber attack on electricity networks in London and south-east England could cost the economy as much as £442bn over the following five years.

Cyber security minister Liz Jones commented: “These new powers mean we can act before a threat materialises, not just after the damage is done. By working together with industry, we’re putting national security at the heart of how essential services choose their suppliers. This is about staying ahead of a growing threat, and giving the public confidence that the everyday services we depend on like water and energy supplies, our transport network and hospitals, are protected.”

The proposals also aim to create “cyber-safe” procurement guidance for essential service providers. Those bodies would be able to refer themselves for a risk assessment if they have concerns about a potential supplier. The package would give the government legal powers to issue binding directions that could require extra cyber security measures or the phasing out of technology judged potentially dangerous.

Image source: Wikipedia

STORY OF THE WEEK

Technology PR, search and social agency

Trending Now

Leave a Reply

Your email address will not be published. Required fields are marked *