Amendments to the Computer Misuse Act 1990 made by the Serious Crime Act 2015 (sections 41–44) take effect today, implementing the EU Directive on attacks against information systems.
Key changes
- A new section 3ZA offence of unauthorised acts causing, or creating a significant risk of, serious damage to human welfare, the environment, the economy or national security, with a maximum sentence of life imprisonment for the most serious cases.
- Section 3A extended to cover obtaining tools for use in computer misuse offences.
- Wider extraterritorial jurisdiction, so UK nationals committing offences abroad can be prosecuted.
What it means for you: make sure access rights are clearly defined and documented (staff who exceed their authorised access can commit an offence), and ensure all penetration testing and vulnerability scanning is expressly authorised in writing by the system owner.
Source: Serious Crime Act 2015, Part 2 (legislation.gov.uk)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.