Legislation guide

UK Cyber Security Legislation

A general overview of key cyber security legislation and regulatory frameworks affecting UK businesses - covering common pitfalls, legal consequences, and compliance checklists.

We've put together this guide to help organisations understand their compliance obligations and implement best practices in data protection, system security, and operational resilience. As cyber threats evolve, legislation continues to adapt, reinforcing the importance of robust data security practices across all sectors.

This guide is not exhaustive and does not constitute legal advice. Readers should seek independent legal counsel to ensure compliance with applicable laws and regulations specific to their circumstances.

#01
ICO

GDPR & Data Protection Act 2018

Failure to comply with the UK GDPR and Data Protection Act 2018 - including robust data protection, staff training, breach notification, and internal system security - can result in severe financial penalties. The ICO is the UK's independent authority responsible for upholding information rights and enforcing data protection legislation.

Scope

Came into effect 25th May 2018 and has been through amendment post Brexit. Applies to all personal data processing within the UK.

Common pitfalls
  • Inadequate infrastructure protection
  • Lack of staff training
  • Delayed breach notification
  • Poor internal system security
Consequences
  • Tier 1: Up to £17.5 million or 4% of global turnover for breaches of core principles
  • Tier 2: Up to £8.7 million or 2% of global turnover for procedural failures
  • ICO notification must be made within 72 hours of awareness of a breach
Compliance checklist
  • Implement technical and organisational measures to secure personal data
  • Conduct regular staff training on data protection and breach response
  • Ensure breach notification procedures meet the 72-hour ICO requirement
Read more
How HackRisk helps
#02
2025

Data (Use and Access) Act 2025

Non-compliance with the Data (Use and Access) Act 2025 may lead to significant penalties - particularly where AI, data transparency, or auditability requirements are not met. This Act modernises UK data protection law and introduces new requirements for AI and automated systems.

Scope

Received Royal Assent on 19th June 2025 and modernises and clarifies parts of the UK data protection law, covering both personal and non-personal data.

Common pitfalls
  • Unclear lawful basis for AI and automated decision-making
  • Lack of transparency in data sharing
  • Inadequate audit trails for data access
Consequences
  • Tier 1: Up to £17.5 million or 4% of global turnover for breaches of core principles
  • Tier 2: Up to £8.7 million or 2% of global turnover for procedural failures
Compliance checklist
  • Update privacy notices and DPIAs to reflect DUAA requirements
  • Maintain clear audit trails for all data access and sharing activities
  • Review contracts with data intermediaries and digital ID providers
Read more
How HackRisk helps
#03
NIS2 / CSR

EU NIS2 Directive & UK Cyber Security and Resilience Act

The forthcoming UK Cyber Security and Resilience Act, aligned with the EU NIS2 Directive, will significantly heighten compliance demands. Organisations must promptly address cyber hygiene, supply chain risks, and resilience planning.

Scope

EU NIS2 came into force 16th January 2023; member states were required to transpose it by 17th October 2024. The UK Cyber Security and Resilience Bill aligns with NIS2 and is due to be introduced to Parliament in 2025.

Common pitfalls
  • Inadequate cyber hygiene (failure to patch)
  • Inadequate supply chain management for high-impact suppliers
  • Poor resilience planning
Consequences
  • Potential daily fines of £100,000 or 10% of turnover for each day the breach continues
  • Expanded scope includes more sectors and stricter reporting thresholds
Compliance checklist
  • Conduct regular cyber risk assessments and resilience testing
  • Implement incident detection and reporting mechanisms
  • Embed robust supply chain security requirements
  • Ensure compliance with sector-specific NIS guidance
Read more
How HackRisk helps
#04
CMA

Computer Misuse Act 1990

Organisations that fail to prevent unauthorised internal or external access, modification, or impairment of computer systems risk severe criminal penalties under the Computer Misuse Act 1990, including substantial fines and imprisonment.

Scope

Commenced August 1990. Criminalises unauthorised access or modification of data. Currently under review for reform to modernise it for today's threat landscape.

Common pitfalls
  • Internal misuse of systems
  • External breaches due to poor access controls
Consequences
  • Section 1 (unauthorised access): up to 2 years' imprisonment and/or a fine
  • Section 2 (access with intent to commit further offences): up to 5 years' imprisonment
  • Section 3 (unauthorised acts to impair systems): up to 10 years' imprisonment
  • Section 3ZA (serious damage): up to life imprisonment in the most severe cases
Compliance checklist
  • Enforce strict access controls and user authentication
  • Monitor system logs for unauthorised activity
  • Educate staff on legal consequences of misuse
Read more
How HackRisk helps
#05
DORA

Digital Operational Resilience Act (DORA)

Organisations that do not meet DORA requirements from January 17th, 2025 may face regulatory sanctions, increased audit scrutiny, licence suspension, and fines. This primarily affects financial services and their ICT supply chains.

Scope

EU regulation from 17th January 2025. Applies to UK financial services providers, UK companies supplying ICT services to financial institutions, and any company with a subsidiary operating in the EU.

Common pitfalls
  • Lack of resilience testing
  • Failure to report ICT-related incidents
  • Inconsistent cross-border compliance
Consequences
  • Fines of up to 2% of total annual worldwide turnover
  • Up to 1% of the company's average daily worldwide turnover
  • Regulatory sanctions including licence suspension or mandatory corrective actions
  • Increased audit scrutiny
Compliance checklist
  • ICT risk management - evaluate ICT services and assess their impact
  • Implement robust incident reporting processes
  • Conduct operational resilience testing
Read more
How HackRisk helps
#06
NCSC / ISO

Cyber Essentials, Cyber Essentials Plus & ISO/IEC 27001

Although non-statutory in nature, non-compliance with Cyber Essentials, Cyber Essentials Plus, or ISO/IEC 27001 can result in significant contractual repercussions, including loss of certification and increased regulatory scrutiny.

Scope

Non-statutory but often contractually required. Cyber Essentials is mandatory for UK government contracts. ISO 27001 is increasingly required in enterprise and regulated sector procurement.

Common pitfalls
  • Lack of patching and access controls
  • No formal training or awareness programme
  • Lack of internal auditing
Consequences
  • Loss of certification
  • Disqualification from public sector contracts
  • Reputational damage with clients and partners
  • Increased regulatory scrutiny
Compliance checklist
  • Maintain certification through regular audits and updates
  • Implement a formal information security training programme
  • Ensure compliance with ISO 27001 Annex A controls
Read more
How HackRisk helps

How does your business score?

HackRisk continuously monitors your external posture against the same controls these frameworks require. Get your HackRisk Score in minutes.

Start Your Free Trial