On The Effectiveness of the UK NIS Regulations as a Mandatory Cybersecurity Reporting Regime

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Ali, Junade, Hicks, Chris
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910272746160128
author Ali, Junade
Hicks, Chris
author_facet Ali, Junade
Hicks, Chris
contents Existing cybersecurity literature lacks a source of empirical, representative data as to the true nature of cyberattacks on Critical National Infrastructure. We have obtained UK-wide data on incidents reported under the Network and Information Systems (NIS) Regulations in 2024 causing "a significant impact on the continuity" of essential services and comparator data from intelligence agencies. We find that 29% of NIS reports already concern cybersecurity incidents. As the UK Government seeks to extend cybersecurity reporting, we find the NIS Regulations are limited in their effectiveness; whilst our requests revealed 30 cybersecurity incidents reported under the NIS regulations, there were 89 incidents classified as "highly significant and significant" captured by the National Cyber Security Centre in the 2024 reporting year. Whereas 36% of Cybersecurity and Infrastructure Security Agency reported attacks concerned espionage, from NIS data we find 100% NIS-reportable cyberattacks concerning healthcare systems in England in 2024 were ransomware.
format Preprint
id arxiv_https___arxiv_org_abs_2603_19084
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle On The Effectiveness of the UK NIS Regulations as a Mandatory Cybersecurity Reporting Regime
Ali, Junade
Hicks, Chris
Cryptography and Security
Computers and Society
Existing cybersecurity literature lacks a source of empirical, representative data as to the true nature of cyberattacks on Critical National Infrastructure. We have obtained UK-wide data on incidents reported under the Network and Information Systems (NIS) Regulations in 2024 causing "a significant impact on the continuity" of essential services and comparator data from intelligence agencies. We find that 29% of NIS reports already concern cybersecurity incidents. As the UK Government seeks to extend cybersecurity reporting, we find the NIS Regulations are limited in their effectiveness; whilst our requests revealed 30 cybersecurity incidents reported under the NIS regulations, there were 89 incidents classified as "highly significant and significant" captured by the National Cyber Security Centre in the 2024 reporting year. Whereas 36% of Cybersecurity and Infrastructure Security Agency reported attacks concerned espionage, from NIS data we find 100% NIS-reportable cyberattacks concerning healthcare systems in England in 2024 were ransomware.
title On The Effectiveness of the UK NIS Regulations as a Mandatory Cybersecurity Reporting Regime
topic Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2603.19084