Skip to main content

The UK ICO and UK National Crime Agency Sign Cyber Security Memorandum

The UK ICO and UK National Crime Agency Sign Cyber Security Memorandum
Tuesday, September 17, 2024

On September 10, 2024, the UK Information Commissioner’s Office (the “ICO”) announced that it signed a memorandum of understanding with the UK National Crime Agency (the “NCA”) related to cyber resilience. The memorandum sets out broad principles of collaboration, and the legal framework regarding the sharing of relevant information and intelligence, between the organizations. 

Specifically, the memorandum explains how the ICO and the NCA will work together in areas such as influencing improvements in cybersecurity of regulated organizations, information sharing regarding cyber threats and incidents (including on an anonymized basis and, where appropriate, regarding organizations which have suffered a cyberattack), and “deconfliction” between the ICO and the NCA regarding incident management. With regard to the latter, this will include, for example, where an organization has reported an incident to the NCA which the NCA believes the organization is legally required to the report to the ICO, the NCA will “remind” the organization of its reporting obligations. Furthermore, where the ICO and the NCA are engaged in managing the same incident, they will “seek to coordinate their work.”

The operation of the memorandum will be continually monitored by the ICO and the NCA. The memorandum will be reviewed every two years.

Copyright © 2024, Hunton Andrews Kurth LLP. All Rights Reserved.