The UK Government has officially classified data centres as Critical National Infrastructure (CNI) bringing them inline with other essential services such as Transport, Energy and Water, reinforcing their importance to national security and the economy. This means data centres must now comply with stricter cyber security regulations under the NIS framework. In this article, we explore what this classification means for data centre security, regulatory compliance, and how Arcanum can help navigate these changes through securing CNI.
Why Data Centres Are Critical to National Infrastructure
Data centres are at the heart of the modern digital world. They host the servers and storage infrastructure that store, process and distribute vast amounts of data, supporting everything from online banking and e-commerce to social media and cloud computing. The uninterrupted operation of these facilities is critical to maintaining the services that businesses and individuals rely on every single day.
What the CNI Classification Means for UK Data Centres
The classification of the UK’s circa 500 data centres as CNI signifies the government’s recognition of the critical role these facilities play as CNI designation will allow the government to support the sector in the event of critical incidents, minimising impacts on the economy. But in return, this new status as Operators of Essential Services under the NIS Regulations will require data centres to meet the CNI cyber security standards. Although many data centres have ISO27001 or something similar, it’s likely that they will have to implement stronger protection against cyber threats and physical disruption than they currently have in place. And not only to have it, they will also need to evidence their cyber maturity to the Department for Science, Innovation and Technology (DSIT) as the UK Competent Authority. At least initially, this is likely to be in the form of Self Assessments against the National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF) which will then be marked by an independent Assessor under DSIT’s guidance. Some of the larger data centre providers operating in the UK, such as CyrusOne; Digital Realty and Interxion also have data centres in Ireland or mainland Europe. As such, not only are they subject to the UK’s NIS Regulations, they must also abide by the EU’s implantation of NIS2 which comes into force next month as well as Regulation (EU) 2022/2554 for digital operational resilience for the financial sector, commonly referred to as ‘DORA’, will apply as of January 2025.
Arcanum’s Expertise in CNI Cyber Security
Arcanum has a proven track record in securing CNI. With years of experience and expertise in cyber security, Arcanum has been at the forefront of protecting vital systems and networks from sophisticated threats since 2008. Underpinned by our status as a NCSC Assured Cyber Security Consultancy, we have been helping CNI Competent Authorities, Operators of Essential Services and their supply chains understand and manage their cyber security risks and compliance since the NIS Directive / Regulations were introduced in the EU and UK respectively in 2018. Arcanum’s team comprises highly skilled professionals with extensive backgrounds in cyber security, risk management, and Defence. Their deep understanding of the specific needs and vulnerabilities of the UK’s CNI sectors enables them to deliver tailored security strategies that are both effective and resilient. In the process, we’ve built up a huge understanding of the NIS Regulations and are very familiar with CAF Self Assessments, having guided organisations from multiple CNI sectors through the process. Having also worked with the EU Finance Industry, we’ve also developed a thorough understanding of both the NIS/NIS2 Directives and DORA.
Summary: How Data Centres Must Prepare for CNI Compliance
The designation of data centres as CNI marks a significant step in bolstering UK cyber security resilience. However, being subject to NIS and the CAF means that data centre operators are liable to face some significant challenges, particularly with a need to allocate more time, money and resource, and to find suitably qualified and experienced people to meet the heightened cyber security requirements.
Concerned about how the NIS Regulations and CAF Self-Assessments will impact your data centre? Arcanum Cyber can help you meet CNI cyber security requirements. Contact us today.