The legislative challenges of cybersecurity Technology is constantly evolving at a pace that legislation struggles to keep up with. Is it possible for governments to develop cybersecurity legislation that will not be obsolete before it is enacted? People in the technology sector often joke that anything new in winter will be obsolete by spring. This is especially the case in cybersecurity, where hacker groups and cybersecurity teams are locked in an ever-escalating war of attrition. The speed of obsolescence far outpaces the legislative process: it can take up to two years for government bills to be enacted into law. This is due to the parliamentary process, where various readings, committee hearings and reports are required to ensure that bills are adequately scrutinized. An outdated system “The legislative process in this country is essentially a Victorian process, in the sense it takes a long time,” says James Morris, chairman of CSBR, who spoke to ITPro earlier this month at InfoSecurity Europe in London. “Meanwhile, the world is changing every day. How you deal with that is, I think, a question of not wanting to try and do everything at once.” Legislation tends to lag behind technology as the speed of technical innovation far outpaces the law-making process. Therefore, cybersecurity legislation risks becoming redundant before it is enacted. Compounding this challenge is the intensification of cyber threats, in particular the problem of state-sponsored hacker teams and organized crime groups repeatedly targeting national infrastructure for financial or political gain. “The Cyber Security and Resilience Bill represents a step change to our national security that will protect the services people rely on every day - reducing the risk of disruption to public services and businesses, and ensuring a faster national response when threats emerge,” said a spokesperson for the government. Sign up today and