Generic filters

DCMS Security Regulations and Codes of Practice consultation FCS response

Introduction

The Federation of Communication Services represents companies which provide professional communications solutions to (primarily) business users.  Our members deliver telecommunications services via mobile and fixed line telephony networks, broadband, satellite, wi-fi, IP and business radio.  

Our members’ customers range from SMEs, home-workers and micro-businesses up to the very largest national and international private enterprises and public-sector users.  FCS is the largest trade organisation in the professional communications arena in the UK, representing the interests of circa 300 businesses who supply B2B services nationwide. FCS welcome the opportunity to respond to this consultation.  

 

Questions asked by DCMS in this consultation 

Impact of regulations and CoP on providers 

Q1. Do you agree that the requirements set out in the draft regulations and the guidance measures set out in the draft code of practice are an appropriate and proportionate response to address the risks of a security compromise to public telecoms networks and services under the new duties (s.105A and 105C) in the Act? If no please set out why, specifically referencing the particular risk of a security compromise, requirements in the draft regulations, guidance measures in the draft code of practice, and objectives of each section. FCS response – in principle FCS agree, but have some concerns regarding implementation and the definition of the Tiers (by definition of financial turnover only and not whether they have responsibility and capability). 

Q2. Do you agree it is sufficiently clear which guidance measures in the draft code of practice relate to which regulation (or regulations) within the draft regulations? If no please explain why. FCS response – it is clear, but we feel that going forward, there is a need to ensure CPs/FCS members are made aware of their responsibilities via clear comms. We would encourage ongoing comprehensive publicity and industry workshops to ensure clarity of requirements for each individual Tier is made clear to CPs. 

Q3. Do you expect the draft regulations and draft code of practice to have cost impacts on your business? If yes, please respond to the separate cost survey. FCS response – FCS believe that there will be costs dependent on Tier status, (where a provider is in a supply chain of services) and the technology that they provide. Additionally, the speed of implementation has an impact, (faster = more cost).   

Tiering   

Q4. Do you agree that differences between public telecoms providers should be recognised within the code of practice via a system of tiering? If no, please explain the reasons for your answer. FCS response – FCS believes the principle of the Tiering proposal is sound but, how a provider is allocated to a Tier requires careful consideration and risk assessment. 

Q5. Do you agree that relevant turnover should be used as the metric for determining which tier applies to a given provider? If not, are there other metrics that should be used as an alternative or in combination? FCS response – FCS question the relevant turnover metric (being used in isolation) to decide Tiers. Capabilities should also be considered (i.e. some FCS members who reach the T2 threshold, are largely resellers of services, with little/no security implications/risk as this would be provided by their own supplier’s security compliance. For T3 providers who interact with T1/T2 CP suppliers, in most cases they should be able to take assurance from their associated T1/T2 supplier or wholesaler. supply chain. FCS question whether a central registration list that T3 CPs can reference, would be helpful I.e. a list of T1/T2 suppliers who are security compliant. FCS also feels that T3 could have fundamental impact on T1/T2 security due to the capability a T3 CP provides. Proposed Tier rules are financially based only and therefore do not consider capability, which FCS believe to be equally important and a major factor for consideration. 

Q6. If YES to question 5 above, do you agree that the existing definition of relevant turnover should be adopted for the purpose of the code of practice? FCS response – FCS question the relevant turnover metric being used in isolation. Capabilities also need to be considered (see answer to Q5 above). 

Q7. Do you agree that the thresholds for each tier should be as below? If no, what alternatives would be most appropriate? FCS response – The proposed thresholds look appropriate but should also contain capabilities and responsibilities measures. Most pure resellers have no or very limited capabilities, thus pose no or a minimal security risk. 

Q8. If you would be impacted by the proposed tiers, would the tier within which you are placed impact the costs of implementing the requirements? FCS response – FCS believes for our members placed in Tier 2, the requirements are onerous and the timescales challenging as the faster required the higher the cost. Please see capability response in Q5 above.  

Q9. If you would fall into Tier 3 under the proposals, do you consider it is sufficiently clear how the draft code of practice applies to you and how you would implement relevant guidance measures? If not, would you want additional guidance and if so, on what aspects of the draft regulations? FCS response – The majority of our FCS members will be in T3, with some in T2. Providers need clarity on exactly what their responsibilities are in each Tier. DCMS/Ofcom publicity, workshops and training for CPs on a Tier basis, would aid providers (FCS is very willing to help with comms and reaching out to our members, to help DCMS/Ofcom to augment messaging). 

Q10. Do you agree with the proposed approach to preventing excessive fluctuation between tiers, with a tier designation applying if a provider meets either of the following criteria? If no, what alternatives would be most appropriate and why? FCS response – FCS believe that a risk assessment needs to be completed in each individual case where this occurs. If a CP moves from T3 to T2 or T2 to T1 but is just a reseller, there is potentially a very low security risk, which can then be appropriately assessed. The proposed method is a high-impact approach based on an assumed high security risk, as once a CP is in for example a higher Tier structure, they need to be compliant with that Tier requirements and if they are not, will be liable to sanctions.   

Enforcement 

Q11. Do you agree that the guidance measures set out in the draft code of practice should be completed in three phases for Tier 1 providers: by 31 March 2023: by 31 March 2025, by 31 March 2026. If NO, please set out what you consider appropriate timelines for expected implementation, making reference to the guidance measures set out in the draft code of practice. FCS response – FCS currently have no proposed T1 members but feel that it will be important to test these proposed timescales, by gaining feedback from T1 Providers which could then be carefully reviewed and the risks assessed.  

Q12. Do you agree that Tier 2 providers should be afforded an additional two years for each of the phases set out above? If no please set out what you believe is an appropriate extension (if any) and why. FCS response – FCS believes the DCMS need to test these timescales. Feedback from T2 CPs should be carefully reviewed and the risks assessed i.e. a predominantly infrastructure Tier2 Provider may be very high risk, whereas a predominantly reseller-based Tier 2 Provider may be a potentially low security risk. 

Q13. If you expect to fall into Tier 2 what impact on your incurred costs do you expect from an additional two years to implement measures? FCS response – FCS questions where a parent company is involved, will the proposed DCMS turnover calculation, used to define a Tier, be based on the legal entity or does it apply to the parent company providing service? 

Q14. Do you agree that the draft code of practice should apply a consistent set of end dates for implementation phases across all providers in relevant tiers, regardless of entry timing to that tier? If no, please explain the reasons for your answer. FCS response – Please see response to Q5 (above) regarding Tiering implementation and feedback. 

How things work in practice 

Q15. Do you agree that a blanket approach to exempting specific equipment systems as ‘legacy networks’ is not appropriate given the variation between networks? If no, please explain the reasons for your answer. FCS response. FCS agrees that a blanket approach to exempting specific equipment systems as ‘legacy networks’, is not appropriate and proposes that each system should be carefully risk assessed (individually).  

Q16. Do you agree that implementation timetables for actions in the draft code of practice should align with existing change programmes such as the planned PSTN switchoff? If no, please explain the reasons for your answer. FCS response – This proposal makes sense but needs to align with activity required to achieve the legacy network risk review identified by the FCS in Question 1 as there are potentially severe cost/resource constraints on providers. 

Q17. Do you agree with the proposals in the draft regulations and draft code of practice to address risks arising from legacy systems and equipment (such as Regulation 3(1)(b), guidance in section 2 of the draft code of practice and guidance measures including 5.07, 10.14 and 11.05)? If no, please explain the reasons for your answer. FCS response – FCS propose that a security risk assessment is completed on legacy systems and equipment individually as each will have its own level of security risk.

Other Consulations

Join us today

Members benefit from telecoms regulatory checks, dedicated compliance and regulatory expert team support, templates for Ofcom compliant consumer & complaint codes, dispute resolution support, bite-size on-demand online regulatory training covering Ofcom’s General Conditions, represented interests and more to avoid fines, save time and strengthen your reputation with customers and partners.