Wary of cyber security laws, UK eyes softly-softly approach

Comments print
Agencies: London, Dec 04 2012, 12:04 IST
to report cyber attacks, an obligation that supporters of such legislation believe keeps directors on their toes and helps ensure cyber defences are up to scratch because of the fear of reputational damage.

However, Britain believes obligatory reporting risks having the opposite effect and becoming a "perverse incentive" that would prompt directors to actually turn a blind eye to online breaches in order to escape unwanted publicity.

Even when companies did reveal such attacks, company directors would be likely to say as little as possible about such incidents, the official said.

Mandatory reporting "would be positively harmful from the point of view of getting people to share information," he said.

In a related move, the government said on Monday it would extend a pilot scheme under which 160 firms in the defence, finance, pharmaceuticals, energy and telecommunications sectors shared information about cyber attacks confidentially.

Alan Calder, head of British cyber consultancy IT Governance, questioned the government's approach, saying the U.S. model of mandatory reporting was a good discipline for directors.

"Being forced to disclose information would be a very good thing, it would put a lot of pressure on companies," he said.

Ads by Google
   Previous | 1 | 2
Previous Story  US auto sales race to 5-year high for November Next Story  Congress MPs from Telangana boycott party meeting on FDI
Reader's Comments| Post a Comment

Be the first to comment.

Post your Comment

Your email address will not be published. Required fields are marked *

Name *
Email *
Message *
 
captcha
please enter the above characters in the box below