Regulation is changing the security landscape
Technology suppliers are used to being the innovative partner in the operator-supplier relationship. The image conjured is of utility operators in their dusty offices, celebrating the “newbie’s” 20-year work anniversary, akin to a Flash the sloth scene from Zootopia.
Meanwhile, the trailblazing Silicon Valley adjacent technology supplier occupies a swanky London office with something called a “breakout room”, lamenting their clients’ languid progress toward moving into the 21st century.
But UK regulatory pressures are changing the utility operator landscape, and suppliers who rest on their laurels are at risk of falling behind in areas that matter most to their clients.
EU CRA and UK NIS changes mean suppliers need to prepare
The EU Cyber Resilience Act is a significant step change for suppliers. Security practices that for years had been considered option best practice, nice to haves that the team would get to “one day”, are now barriers to entering the EU market.
The implementation of the Cyber Security and Resilience Bill will push operators even further than existing NIS regulations and they’ll adapt accordingly. Suppliers need to be ready to meet the inevitable increased maturity of operators’ security questionnaires.
Operators are adopting modern platforms to help manage the changing regulatory landscape when it comes to third party risk management. While their newly implemented risk management platform might be the thin end of the wedge today, it becomes a problem for suppliers who aren’t prepared when the operator need only flip a switch to start demanding answers to more thorough criteria aligned to the Cyber Security and Resilience Bill.
The truth is, it’s not just the operators that feel the sharp end of new cyber regulation, because much of that pressure ends up pushed down the supply chain, and all else being equal, it will be the suppliers ready to meet that challenge with minimal disruption to their day to day operations who will flourish and succeed.
More rigorous evidence will be needed more frequently
As a supplier to critical infrastructure, it doesn’t matter how innovative and revolutionary a solution might be; if their cyber risk profile doesn’t meet the operator’s requirements and they can’t get into the client’s supply chain, then they have a problem.
But there’s a more insidious danger waiting for the chosen ones who do make it through, and that is in the regular reviews of third-party risk that operators now conduct. Procurement is no longer the only moment when suppliers are expected to answer cyber security questions and so that heavy lift to get the deal over the line becomes a regular burden that commonly spans across multiple teams.
By operating in the classic model of point in time evidence gathering, suppliers put themselves at risk of the dual threat of operators requiring answers not only to more thorough security questions, but also of those same operators asking more often.
If suppliers don’t adapt, they will end up with more of their people spending more time on cyber reviews: time which could otherwise be spent on operational delivery.
Smarter product security is the solution
Utility operators are responding as a result of top-down regulatory pressure. But their technology suppliers are uniquely positioned to innovate.
If suppliers update working practices and the way they approach security so that evidence is generated naturally as part of their daily operations, then there is real opportunity to get ahead and not just respond to customer demand but do what they have always done: trailblaze.