UK Seeks Secret Powers to Ban Tech Vendors from Critical Infrastructure
The British government is proposing new legislation that would grant it unprecedented powers to ban technology vendors from supplying companies within critical national infrastructure sectors. These proposals, amending the Cyber Security and Resilience Bill, could allow such bans to occur in secret, without publicly naming the vendor or even permitting the affected company to disclose the directive.
The **British government** is pushing for significant new powers that would allow it to prohibit technology vendors from supplying companies operating in the nation's critical sectors. These proposals, introduced as amendments to the **Cyber Security and Resilience Bill**, aim to enhance national security but raise concerns about transparency and accountability.
### Expanding Beyond Telecoms
The proposed powers build upon existing legislation used to restrict **Huawei** equipment in UK 5G networks, but significantly expand their scope and secrecy. Unlike the previous telecoms law, ministers would not be required to publicly identify a vendor as a security risk before taking action. Furthermore, there would be no obligation to send a copy of the order to the vendor concerned.
These new directives would extend beyond telecommunications to encompass managed service providers, data centers, digital infrastructure, and vital sectors such as energy, water, transport, and health.
### Secret Directives and Broad Authority
A senior minister would gain the authority to instruct companies in these sectors to cease purchasing from a specific supplier, restrict the use of a vendor's products or services, or even modify, disable, or remove already installed equipment.
**Liz Lloyd**, the recently reappointed cybersecurity minister, stated that these powers "mean we can act before a threat materialises, not just after the damage is done," emphasizing the government's focus on national security in supplier choices for essential services.
While ministers would be required to publish a notice that a direction has been issued, only the recipient company would necessarily be named, not the vendor. Details could be withheld on national security or commercial grounds, and the recipient could be explicitly barred from public discussion of the order. Even those consulted before a directive could be prohibited from disclosing the consultation.
### Addressing Spying and Sabotage Risks
The government justifies these new powers by stating they will enable intervention when essential service providers plan to acquire equipment from "suppliers that could pose a critical national security risk, particularly where they have ties to hostile states who may seek to use products to spy, sabotage systems or cause disruption."
Termed a "vendor-related direction" in the amendments, this mechanism closely mirrors a similar legal tool used under the **Telecommunications (Security) Act 2021**. However, the new proposals allow for sidestepping the usual process of giving both the affected company and the supplier a chance to respond, citing national security grounds.
### Transparency Concerns Remain
Despite a new publication duty requiring the government to announce an order's issuance and recipient, the lack of mandatory vendor identification and the ability to withhold details on national security or commercial grounds raise significant transparency concerns. A water company or hospital, for instance, could be publicly identified as receiving a government directive without the public ever knowing which vendor they were ordered to cease using.
The government has committed to reporting annually to Parliament on the number of directions issued, the sectors affected, and any subsequent variations or revocations.
These powers are not limited to companies within critical sectors. Ministers could extend them, through regulations, to any person deemed engaged in essential activity or providing essential goods or services in the UK.
Companies receiving such a direction would also need written government approval before appointing an outside specialist to assist with compliance, with ministers potentially relying on a list of approved specialists published by **GCHQ**.
The amendments are scheduled for committee stage consideration in the **House of Lords** in September.