DCMS security regulations and codes of practice consultation  Â
https://www.gov.uk/government/consultations/proposal-for-new-telecoms-security-regulationsand-code-of-practice Â
Telecoms security: proposal for new regulations and code of practice Â
Summary Â
The government is consulting on proposals for new regulations and a code of practice to improve the security and resilience of public telecoms networks and services. Â
Description Â
The Telecommunications (Security) Act 2021 provided the government with new powers to make security regulations and issue codes of practice. The government is now proposing to use those powers to help secure the UK’s public telecoms networks and services.  The UK is becoming ever more dependent on such networks and services. The increased reliance of the economy, society and critical national infrastructure (CNI) on public telecoms networks and services means it is important to have confidence in their security. As the value of our connectivity increases, it becomes a more attractive target to cyber attackers. It is important to make sure that our networks and services are secured in this evolving threat landscape. Â
Link to draft CoP (containing what needs to be done by when)  https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1057446 /Draft_telecoms_security_code_of_practice__accessible_.pdf Â
LInk to The Electronic Communications (Security Measures) Regulations 2022 Â
https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1056862
/Draft_Electronic_Communications__Security_Measures__Regulations.pdf Â
The government is consulting on proposals for new regulations and a code of practice that are intended to address security risks to public telecoms networks and services. This process meets the statutory requirement for the government to consult with affected parties before issuing a code of practice, under section 105F of the Communications Act 2003 (inserted by the Telecommunications (Security) Act 2021). This consultation seeks informed views from Ofcom, providers of public networks and services, as well as those who may have experience in these matters on the proposals within the draft code of practice, which has been published alongside this document. As the regulations will be the first to be issued under the new telecoms security framework, the government has also decided to consult on the draft regulations.
Key points and overview information on this consultation and the proposed FCS response  The DCMS Communication Provider Tiering proposal is based on a providers’ annual relevant turnover (data on turnover is readily available, providers are already familiar with this definition and it is currently provided to Ofcom on an annual basis, meaning it does not create more work for providers/Ofcom). FCS is concerned that ‘annual relevant turnover’ considered in isolation is an inappropriate measure/threshold, which could impact our members unfairly. Many FCS members are resellers (some potentially in T2) for who the proposed security requirements are an inappropriate and unnecessary burden as they largely resell and as a provider pose a very low or do not pose any, security risk.  The regulations apply to all public telecom providers except those classified as microentities (which some FCS members may potentially be). A company is a ‘micro entity’ if it meets two of the following three criteria: 1. Not more than 10 employees, 2. Annual turnover of not more than £632k, 3. Balance sheet total of not more than £316k Â
The draft code of practice provides guidance measures on how providers could meet their overarching security duties in the Act and the draft regulations. Â
For CPs with Tier 3 status, the impact will be limited but there are aspects to consider if for example you supply parts of networks and/or services owned by larger Tier 1 or Tier 2 providers. Draft regulation proposals stipulate that where a provider acts as a third-party supplier to another provider they must take security measures that are equivalent to those taken by the provider receiving their services.
Tier 2 CP’s have onerous security requirements to meet, with cost, resource and time constraint impacts. Â
Private networks are not in scope. Â
Providers must be able to identify their tier – Tier 1 (annual relevant turnover >£1bn), Tier 2
(annual relevant turnover >£50m but less than £1bn), Tier 3 (less than £50m) – so that they are able to make the relevant business decisions to meet their regulatory obligations and ensure compliance. Â
The smallest, Tier 3, telecoms providers, including small businesses and micro enterprises, will need to comply with the law but it is not anticipated that the code of practice will be applied to Tier 3 providers.
Questions asked by DCMS in this consultation  Impact of regulations and CoP on providers Â
Q1. Do you agree that the requirements set out in the draft regulations and the guidance measures set out in the draft code of practice are an appropriate and proportionate response to address the risks of a security compromise to public telecoms networks and services under the new duties (s.105A and 105C) in the Act? If no please set out why, specifically referencing the particular risk of a security compromise, requirements in the draft regulations, guidance measures in the draft code of practice, and objectives of each section. FCS – in principle agree, but have some concerns regarding implementation and the definition of the Tiers (by definition of financial turnover only and not whether they have responsibility and capability). Â
Q2. Do you agree it is sufficiently clear which guidance measures in the draft code of practice relate to which regulation (or regulations) within the draft regulations? If no please explain why. FCS – it is clear, but need to ensure FCS members are made aware of their responsibilities via clear comms. We would encourage more publicity and industry workshops to ensure clarity of requirements for each individual Tier. Â
Q3. Do you expect the draft regulations and draft code of practice to have cost impacts on your business? If yes, please respond to the separate cost survey. FCS – yes there will be costs dependent on Tier status, where a provider is in a supply chain of services and the technology that they provide. Additionally, the speed of implementation has an impact, (faster = more cost). FCS members will have the opportunity to respond in the survey link above and we will encourage them to do so (highlight survey link above to FCS members). Â
Tiering  Â
Q4. Do you agree that differences between public telecoms providers should be recognised within the code of practice via a system of tiering? If no, please explain the reasons for your answer. FCS – FCS believes the principle of the Tiering proposal is sound but, how a provider is allocated to a Tier requires careful consideration and risk assessment. Â
Q5. Do you agree that relevant turnover should be used as the metric for determining which tier applies to a given provider? If not, are there other metrics that should be used as an alternative or in combination? FCS question the relevant turnover metric being used in isolation to decide Tiers. Capabilities should also be considered (i.e. some FCS members who hit the T2 threshold, are largely resellers of services, with little/no security implications/risk as this would be provided by their own suppliers security compliance. For T3 providers who interact with T1/T2 CP suppliers, in most cases they should be able to take assurance from their associated T1/T2 supplier or wholesaler. supply chain. FCS question whether a central registration list that T3 CPs can reference, would be helpful I.e. a list of T1/T2 suppliers who are security compliant. T3 could have fundamental impact on T1/T2 because of the capability a T3 CP provides. Proposed Tier rules are financially based only and therefore do not consider capability, which FCS believe to be equally important and a major consideration factor. Â
Q6. If YES to question 5 above, do you agree that the existing definition of relevant turnover should be adopted for the purpose of the code of practice? FCS – FCS question the relevant turnover metric being used in isolation. Capabilities also need to be considered (see answer to Q5 above). Â
Q7. Do you agree that the thresholds for each tier should be as below? If no, what alternatives would be most appropriate? FCS – The proposed thresholds look appropriate but should also contain capabilities and responsibilities measures. (most pure resellers have no or very limited capabilities, thus pose no or a minimal security risk).Â
- Tier 1: Annual relevant turnover >£1bn
- Tier 2: Annual relevant turnover >£50m but less than £1bn
Q8. If you would be impacted by the proposed tiers, would the tier within which you are placed impact the costs of implementing the requirements? FCS – FCS believes for our members placed in Tier 2, the requirements are onerous and the timescales challenging as the faster required the higher the cost. Please see capability response in Q5 above.  Q9. If you would fall into Tier 3 under the proposals, do you consider it is sufficiently clear how the draft code of practice applies to you and how you would implement relevant guidance measures? If not, would you want additional guidance and if so, on what aspects of the draft regulations? FCS – The majority of our FCS members will be T3, with some in T2. Providers need clarity on exactly what their responsibilities are in each Tier. DCMS/Ofcom publicity and workshops and training for CPs on a Tier basis, would aid providers (FCS can help with comms and reaching out to our members to help DCMS/Ofcom to augment messaging). Â
Q10. Do you agree with the proposed approach to preventing excessive fluctuation between tiers, with a tier designation applying if a provider meets either of the following criteria? If no, what alternatives would be most appropriate and why? FCS – FCS believe that a risk assessment needs to be completed in each individual case where this occurs. If a CP moves from T3 to T2 or T2 to T1 but is just a reseller, there is potentially a very low security risk, which can then be appropriately assessed. The proposed method is a high-impact approach based on an assumed high security risk, as once a CP is in for example a higher Tier structure, they need to be compliant with that Tier requirements and if they are not, will be liable to sanctions. Â
- a designated tier should apply until annual relevant turnover is recorded as above or below a threshold for two years
- an existing tier designation should apply until the provider is above or below their existing tier’s range by more than £10 million.
Enforcement Â
Q11. Do you agree that the guidance measures set out in the draft code of practice should be completed in three phases for Tier 1 providers: by 31 March 2023: by 31 March 2025, by 31 March 2026. If NO, please set out what you consider appropriate timelines for expected implementation, making reference to the guidance measures set out in the draft code of practice. FCS – To test these proposed timescales, feedback from T1 Providers should be carefully reviewed and risks assessed. Â
Q12. Do you agree that Tier 2 providers should be afforded an additional two years for each of the phases set out above? If no please set out what you believe is an appropriate extension (if any) and why. FCS – FCS believes the DCMS need to test these timescales. Feedback from T2 CPs should be carefully reviewed and the risks assessed i.e. a predominantly infrastructure Tier2 Provider may be very high risk, whereas a predominantly reseller-based Tier 2 Provider may be a potentially low security risk. Â
. Can FCS T2 members provide any feedback to us on this please? Â
Q13. If you expect to fall into Tier 2 what impact on your incurred costs do you expect from an additional two years to implement measures? FCS – FCS welcome any T2 member feedback to enhance our response to this question. FCS does however question where a parent company is involved, will the proposed DCMS turnover calculation, used to define a Tier, be based on the legal entity or does it apply to the parent company providing service?  Q14. Do you agree that the draft code of practice should apply a consistent set of end dates for implementation phases across all providers in relevant tiers, regardless of entry timing to that tier? If no, please explain the reasons for your answer. FCS proposed response – Please see response to Q5 (above) regarding Tiering implementation and feedback. Â
How things work in practice Â
Q15. Do you agree that a blanket approach to exempting specific equipment systems as ‘legacy networks’ is not appropriate given the variation between networks? If no, please explain the reasons for your answer. FCS proposed response. FCS agrees that a blanket approach to exempting specific equipment systems as ‘legacy networks’, is not appropriate and proposes that each system should be carefully risk assessed (individually). Â
Q16. Do you agree that implementation timetables for actions in the draft code of practice should align with existing change programmes such as the planned PSTN switch-off? If no, please explain the reasons for your answer. FCS proposed response – This proposal makes sense but needs to align with activity required to achieve the legacy network risk review identified by the FCS in Q1 as there are potentially severe cost/resource constraints on providers. Â
Q17. Do you agree with the proposals in the draft regulations and draft code of practice to address risks arising from legacy systems and equipment (such as Regulation 3(1)(b), guidance in section 2 of the draft code of practice and guidance measures including 5.07, 10.14 and 11.05)? If no, please explain the reasons for your answer. FCS – FCS propose that a security risk assessment is completed on legacy systems and equipment individually. Â
If members have any feedback or wish to discuss this consultation and/or our proposed FCS response further, please contact us on fcs@fcs.org.uk Â
