Ports could face penalties for cyber attacks
Transport operators could face penalties of USD$22m if they fail to implement effective cyber security measures.
Operators in electricity, transport, water, energy, transport, health and digital infrastructure sectors might be hit by fines as much as USD$22m (£17m) or 4% of global turnover in a plan being considered by the UK Government.
Minister for Digital, Matt Hancock, said: “We want the UK to be the safest place in the world to live and be online, with our essential services and infrastructure prepared for the increasing risk of cyber attack and more resilient against other threats such as power failures and environmental hazards.”
The fines are being considered as part of a consultation by the Department for Digital, Culture, Media and Sport to decide how to implement the Network and Information Systems (NIS) Directive from May 2018.
However, according to the Government, fines would be a last resort, and they will not apply to operators that have assessed the risks adequately, taken appropriate security measures, and engaged with competent authorities but still suffered an attack.
Operators will be required to develop a strategy and policies to understand and manage their risk; to implement security measures to prevent attacks or system failures, including measures to detect attacks, develop security monitoring, and to raise staff awareness and training; to report incidents as soon as they happen; and to have systems in place to ensure that they can recover quickly after any event, with the capability to respond and restore systems.
The Government will hold workshops with operators so they can provide feedback on the proposals.