Duties of providers of public electronic communications networks and servicesU.K.

2Duty to take measures in response to security compromisesU.K.

After section 105B of the Communications Act 2003 insert—

105CDuty to take measures in response to security compromises

(1)This section applies where a security compromise occurs in relation to a public electronic communications network or a public electronic communications service.

(2)The provider of the network or service must take such measures as are appropriate and proportionate for the purpose of preventing adverse effects (on the network or service or otherwise) arising from the security compromise.

(3)If the security compromise has an adverse effect on the network or service, the provider of the network or service must take such measures as are appropriate and proportionate for the purpose of remedying or mitigating that adverse effect.

105DDuty to take specified measures in response to security compromise

(1)The Secretary of State may by regulations provide that, where a security compromise of a specified description occurs in relation to a public electronic communications network or a public electronic communications service, the provider of the network or service must take specified measures or measures of a specified description.

(2)A measure or description of measure may be specified under subsection (1) only if the Secretary of State considers that taking that measure or a measure of that description would be appropriate and proportionate for the purpose of preventing adverse effects (on the network or service or otherwise) arising from a security compromise of the specified description.

(3)The Secretary of State may by regulations provide that, where a security compromise occurs in relation to a public electronic communications network or a public electronic communications service and has an adverse effect of a specified description on the network or service, the provider of the network or service must take specified measures or measures of a specified description.

(4)A measure or description of measure may be specified under subsection (3) only if the Secretary of State considers that taking that measure or a measure of that description would be appropriate and proportionate for the purpose of remedying or mitigating an adverse effect of the specified description.

(5)In this section “specified” means specified in the regulations.

(6)Nothing in this section or regulations under it affects the duty imposed by section 105C.