Infosecurity

Britain wants new powers to quietly blacklist tech suppliers — here’s what it means

Published

on

A quiet shift in how Britain polices its tech supply chain

London is moving to give ministers a blunt new tool: the power to quietly cut risky technology vendors out of the country’s most vital industries. And in some cases, the public may never know which company got the boot.

The changes, tucked into amendments to the Cyber Security and Resilience Bill published on Monday, borrow heavily from the legal playbook used to push Huawei out of Britain’s 5G networks. But they strip away several of the transparency safeguards that came with that earlier regime.

Under the current telecoms law, the government must publicly designate a vendor as a security threat before it can act. Not so with these new proposals. Ministers would be able to issue a so-called “vendor-related direction” without naming the supplier publicly, and without even sending the vendor a copy of the order. The company on the receiving end could also be barred from talking about it.

Beyond telecoms: who’s in the crosshairs?

The scope is what makes this different. The powers wouldn’t stop at phone networks. They’d extend to managed service providers, data centers, digital infrastructure, and the energy, water, transport and health sectors.

A senior minister could order a company in any of those areas to stop buying from a specific supplier, restrict how its products are used, or even force the removal of equipment that’s already installed. Think of it as a national security off-switch for the supply chain.

What the government says — and what critics worry about

Liz Lloyd, the recently reappointed cybersecurity minister, framed the powers as a preventive measure. “We can act before a threat materialises, not just after the damage is done,” she said, adding that the goal is to put “national security at the heart of how essential services choose their suppliers.”

But the secrecy provisions are raising eyebrows. While the government would have to publish a notice that a direction had been issued, only the recipient company would be named. The vendor itself could stay anonymous. Details could be withheld on national security or commercial grounds, and anyone consulted before the order — including the vendor — could be gagged from even acknowledging the consultation took place.

Security officials have previously pushed back against similar secret powers in other high-profile cases. When Apple sought to introduce end-to-end encryption for iCloud, officials reportedly described such covert measures as unsustainable and unjustifiable. This new bill seems to lean in the opposite direction.

How it mirrors the Huawei 5G ban — and where it breaks from it

The mechanics will feel familiar to anyone who followed the Huawei saga. The Telecommunications (Security) Act 2021 gave ministers the authority to intervene on national security grounds, which they used to force the Chinese equipment maker out of UK 5G infrastructure.

Both laws share that core premise. But the new bill goes further by allowing ministers to skip the usual step of giving both the affected company and the supplier a chance to respond before an order is issued — if national security demands it.

A partial transparency compromise

There is one nod to openness: the amendments add a publication duty that the telecoms act lacks. The government would have to announce publicly that an order had been issued and identify the recipient. But that notice wouldn’t necessarily reveal which vendor was targeted, and details could still be withheld.

So a water utility, a hospital trust, or a data center operator could be named as having received a direction, while the public is left guessing which supplier triggered the alarm.

The government would also have to report annually to Parliament on how many directions were issued, which sectors were affected, and how many were later varied or revoked. That’s a small accountability window, but it’s something.

Who else could get caught up in this?

Here’s a wrinkle: the powers wouldn’t just apply to companies already regulated as part of critical national infrastructure. Ministers could use regulations to sweep in any person or business they deem to be engaged in essential activity in the UK, or providing essential goods or services. That’s a broad net.

There’s also a layer of bureaucratic control. A company issued a direction would need written government approval before hiring an outside specialist to help it comply. And in deciding whether to grant that approval, ministers could rely on a list of pre-approved specialists published by GCHQ. That’s a notable expansion of the intelligence agency’s role in commercial decisions.

What happens next

The amendments are scheduled for committee stage in the House of Lords in September. That’s where the details will get picked apart — and where critics will likely push for more transparency.

The bill’s trajectory is worth watching. If it passes as drafted, Britain will have a powerful new way to quietly sever ties with risky tech suppliers, but at the cost of a more opaque decision-making process.

For companies operating in critical sectors, the takeaway is clear: supplier choices could soon carry national security implications, and the government may not always tell you why.

For a deeper look at how the UK has handled similar threats, check out our coverage of Huawei’s removal from UK 5G networks and the broader debate over national security and technology supply chains.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version