Connected tech cybersecurity standards
Gaps in cybersecurity regimes for connected technology, particularly regarding network, storage, and cloud security standards.
Source spread
Where this theme appears
This theme appears across 12 independent accountability sources, so the source mix matters as much as the headline total.
3 PFD reports
59 committee recs
1 HSSIB rec
6 CQC actions
12 IMB recs
1 IMB report
1 patient safety alert
1 DHR rec
1 LGO/SPSO decision
1 CJINI report
2 Law Commission projects
Browse by source
Source-grouped records are useful for tracing where a concern came from. Large sections show the 50 strongest matches for that source; counts still show the full theme total.
Prevention of Future Deaths reports(3)
Mizanur Rahman
Concerns: The coroner highlighted the absence of British or European standards for lithium-ion e-bike batteries and chargers, which facilitates the sale of unsafe products and increases the risk of thermal runaway, fires, and deaths.
Response (Product Safety and Standards): • The Office for Product Safety and Standards (OPSS) published an updated standard for Electrically Power Assisted Bicycles for designation and plans to remove a restriction on battery packs. • … (AI summary)
Responded
Bobby Lee
Concerns: The coroner noted a significant rise in fires from e-bikes/e-scooters, particularly due to inferior quality lithium-ion batteries and unsuitable chargers in conversion kits. Concerns were raised about the lack of specific safety standards for these products, leading to risks like mixing batteries with incorrect voltage chargers.
Response (Product Safety and Standards): • A government taskforce has been established to determine the root causes of fires from e-bike and e-scooter batteries. • The Office for Product Safety and Standards (OPSS) has published … (AI summary)
Responded
Abdul Oryakhel
Concerns: The coroner notes a lack of public understanding regarding the dangers of lithium-ion batteries in e-bikes and e-scooters. There are also no British or European standards to control the sale of these batteries and chargers in the UK.
Response (Department of Transport): • The Department for Transport, Home Office, and Office for Product Safety and Standards have published guidance for users on e-cycle and e-scooter battery safety. • Fire and Rescue Services … (AI summary)
Response (OPSS): • OPSS initiated a dedicated programme in early 2023 to address product safety issues in e-bikes and e-scooters, undertaking regulatory interventions and publishing safety information. • OPSS commissioned a research … (AI summary)
Response (West of England Combined Authority): • The Combined Authority's contractor paused the long-term rental service for e-scooters, citing reassessed risks associated with users charging vehicles at home. • The Combined Authority continues to participate in … (AI summary)
Responded
Select committee recommendations(59)— showing 50 strongest matches
#27 —
Recommendation: The UK market for vendors is far from satisfactory. Whilst this reflects a wider consolidated ecosystem of global 5G vendors action must now be taken to ensure that 5G is in a more secure position in the years to come.
Response attribution not verified
#23 —
Recommendation: Global standards are key to 5G and future telecommunications networks. China has been very active in the standard setting bodies whilst the UK and allies have stood back. This is not satisfactory. The UK should take a leadership role in …
Response attribution not verified
#19 —
Recommendation: Pressure has been exerted by China on the UK Government to retain the presence of Huawei in its 5G infrastructure through both covert and overt threats. More recently, following the Government’s announcement for the long-term withdrawal of Huawei from its …
Response attribution not verified
#16 —
Recommendation: In the end, the Government decision was taken because of the technical considerations resulting from sanctions; however the Government should have considered the potential damage to key alliances enough of a risk to begin to remove Huawei from the UK’s …
Response attribution not verified
#15 —
Recommendation: The framing of the issue by the United States as a technical concern about the presence of Huawei in our networks has generated disagreement between the two Governments, given the contrasting conclusions of technical experts on either side of the …
Response attribution not verified
#2 —
Recommendation: We share the Government’s objective that the UK remains at the forefront of the 5G rollout as we move into the next technological era. It is imperative that the UK is amongst the first countries to benefit from the technological …
Response attribution not verified
#13 — Require providers to adopt network, storage, and cloud security standards for connected tech.
Recommendation: Improving cybersecurity of consumer connected devices is an important and positive step, but the proliferation of connected tech in enterprise settings and the gap in the regime regarding network, storage and cloud security still present likely attack vectors that will …
Response attribution not verified
#14 — Recommend successor Committee examine 5G Supply Chain Diversification, international standards, and technology rollout.
Recommendation: Should our successor Committee wish to examine the UK’s telecommunications infrastructure and domestic capability, we recommend it considers: • The implementation of the 5G Supply Chain Diversification Strategy, and relevant policy and technical developments since the then Committee’s report; • …
Response status not verified
#36 — HMRC acknowledges legacy IT systems and poor data management hinder AI adoption and increase cyber risks.
Recommendation: We asked HMRC whether the age of some of its IT systems were going to make it more difficult to adopt AI. HMRC agreed and considers the “critical thing with AI is making sure you really have a handle on …
Response attribution not verified
#31 — HMRC acknowledges security concerns with third-party Making Tax Digital software, setting strict specifications.
Recommendation: We asked HMRC whether there were potential security concerns that could be posed by the third–party MTD software taxpayers use to submit their tax returns, including whether there were risks to HMRC’s own systems.63 In written evidence provided after our …
Response attribution not verified
#26 — Prioritise introducing secure digital channels for customers to submit files and messages.
Recommendation: Last year HMRC acknowledged that is behind many other organisations in enabling customers to communicate securely through digital channels. In 2022–23, approximately 70% of the 22 million items of correspondence HMRC received came in through the post. In January 2025 …
Response attribution not verified
#24 — HMRC’s legacy IT systems pose security, reliability, and cost risks.
Recommendation: HMRC explained that there are three key risks that arise from operating legacy systems: lower levels of security; lower reliability and resilience; and higher costs of system changes. HMRC said that its executive team and its digital team track how …
Response attribution not verified
#26 — Balance digital trade and AI growth with strong protections for UK standards and industries.
Recommendation: Looking ahead, future commitments in the potential Economic Prosperity Deal must balance opportunities for growth in digital trade, AI, and services with strong protections for UK standards, tax sovereignty, and critical domestic industries. (Recommendation, Paragraph 141) 56
Response attribution not verified
#21 — Strike balance in digital trade to promote AI while safeguarding UK sovereign capabilities.
Recommendation: Any future digital trade provisions negotiated under the Economic Prosperity Deal should strike a careful balance: promoting AI adoption and cross-border collaboration to strengthen the Western technological 55 alliance, while safeguarding intellectual property, ensuring fair taxation, and enabling the development …
Response attribution not verified
#20 —
Recommendation: We recommend that the government consult within the next 12 months on introducing mandatory in-vehicle CCTV, with a view to including this requirement within national standards if it is sufficiently supported by evidence. The consultation should also seek views on …
Response status not verified
#16 —
Recommendation: Emergency services should ensure their business continuity plans highlight any areas of critical reliance on foreign internet servers, and account for temporary internet disruption in the event of a security crisis. (Recommendation, Paragraph 100) Legal Responses
Response attribution not verified
#6 —
Recommendation: The National Protective Security Authority (NPSA) and National Cyber Security Centre should require all UK landing stations to be target-hardened to sufficient levels to deter state-backed sabotage. They should require landing station operators to develop within 12 months an emergency …
Response attribution not verified
#26 —
Recommendation: Despite being a longer timeframe than some have called for, the Government’s most recent restrictions on the use of Huawei in 5G networks will delay the 5G rollout and economically damage the UK and mobile network operators. The UK Government …
Response attribution not verified
#24 —
Recommendation: The Government has faced pressure to remove Huawei more quickly than by 2027. The evidence we have received would suggest that a quicker timescale could result in signal blackouts, delay the 5G rollout significantly and cost both operators and the …
Response attribution not verified
#18 —
Recommendation: Concern about Huawei is therefore based on clear evidence of collusion between the company and the Chinese Communist Party apparatus. It is important that the West does not succumb to ill-informed anti-China hysteria and recognises the mutual benefits of Chinese …
Response attribution not verified
#18 —
Recommendation: Of Ofcom’s two principal duties, it has appeared to have given less prominence to “further[ing] the interests of citizens in relation to communications matters” than it has to “further[ing] the interests of consumers”. Ofcom must ensure that it pursues both …
Response attribution not verified
#11 — Produce an implementation plan and commit to codifying remaining IoT security guidelines.
Recommendation: The introduction of the product security regime, which codifies three of the original thirteen guidelines set out in the Government’s internationally recognised 2018 Code of Practice for Consumer IoT Security, is an important first step in improving cybersecurity for connected …
Response attribution not verified
#28 —
Recommendation: The Bank told us that it will continue adapting RTGS to respond to developments in the wider payments landscape, to provide both the infrastructure and the technological platform to support innovation. It explained that payment technologies and settlement models are …
Response attribution not verified
#6 —
Recommendation: However, we recognise the rapidly evolving nature of digital technologies and the increasing sophistication of methods used to conduct TNR. It is therefore essential that the legal framework remains agile and responsive to evolving threats. We recommend that the Government …
Response attribution not verified
#28 —
Recommendation: The Government should further explore cable protection zones for critical areas of cable concentration, policed by early warning indicators and heightened monitoring and response capabilities. This would require close co-operation with European partners, given the need to manage other maritime …
Response attribution not verified
#21 —
Recommendation: The Government should support the subsea cable industry in rolling out more extensive cable monitoring technology and should explore incentives to encourage such investment. This could include Government commitments to make better use of existing measures and data—for example more …
Response attribution not verified
#5 —
Recommendation: Many cable landing stations are vulnerable to attack. The Government and operators must take the risk of state-backed sabotage seriously, including against targets in Europe. (Conclusion, Paragraph 47)
Response attribution not verified
#4 —
Recommendation: The Government should update its public and private risk scenarios to cover extensive co-ordinated sabotage to subsea and terrestrial internet infrastructure, including onward connections to Europe. (Recommendation, Paragraph 39) System vulnerabilities
Response attribution not verified
#21 —
Recommendation: It is evident that the UK’s lack of industrial capacity in telecommunications is not unique, with China dominating the industry. In order to combat this dominance, we support the principle of proposals for forming a D10 alliance of democracies to …
Response attribution not verified
#3 —
Recommendation: In part, this global competition is driven by geo–political change. But this global competition is also a battle between competing visions and mindsets. And the global competition is increasingly one between different technical systems.
Response attribution not verified
#1 —
Recommendation: The Integrated Review is a timely and necessary response to a world characterised by ever-strengthening interconnection and rapid technological change.
Response attribution not verified
#14 —
Recommendation: The Government should align its strategy for diversifying the 5G vendor market with its support for rolling out 5G network coverage. Wherever the Government provides funds for expanding 5G coverage, it should look for opportunities to simultaneously support vendor diversification, …
Response attribution not verified
#2 —
Recommendation: The Government is seeking to attract existing vendors to the UK market in order to diversify the telecommunications vendor market in the short-term. One of the major barriers faced by such companies is the requirement of British network operators for …
Response attribution not verified
#19 —
Recommendation: The regulatory system for product safety is facing multiple new challenges that it will need the skills and resources to be able to respond to. For example: the OPSS and Trading Standards services will need to give greater consideration to …
Response attribution not verified
#18 —
Recommendation: The OPSS estimated that 15% of products bought for the home now include ‘smart’ technology. Products that are connected to the internet create new product safety risks, such as cyber-security risks in the example of a baby monitor which could …
Response attribution not verified
#31 — Ensure government-provided education devices receive regular software updates for security and reduced e-waste
Recommendation: Since the pandemic, the Government has provided over 1.35 million laptops and tablets to schools, trusts, local authorities and further education providers for disadvantaged children and young people. Edtech has more malware than all other sectors combined, and therefore it …
Response attribution not verified
#15 —
Recommendation: The Government identified the concentration of intellectual property rights in the hands of established vendors as a barrier to market entry. It commits in its diversification strategy to working with industry bodies to address this, although the proposed work is …
Response attribution not verified
#11 —
Recommendation: In addition to conducting security testing and validation, the Government should ensure that the research and testing facilities established through the diversification strategy also drive market diversification by stimulating collaboration and supporting the development and commercialisation of new technologies. (Paragraph …
Response attribution not verified
#14 —
Recommendation: Responding to the key challenges the regulatory system faces requires collaboration with other government departments. For example, the Department told us of its engagement with the Department for Digital, Culture, Media and Sport regarding cyber- security threats in products that …
Response attribution not verified
#18 —
Recommendation: The Government should set out in the renewed Women’s Health Strategy a rigorous approach to tackling the risks from ineffective, unsafe and exploitative for-profit FemTech apps. To combat demand for these apps the Government must increase resourcing of the NHS’s …
Response attribution not verified
#12 — Work with OPSS to promote data protection and security guidelines for IoT devices.
Recommendation: As the guidelines set out in the 2018 Code of Practice for Consumer IoT Security imply, cybersecurity and data protection are mutually reinforcing. Without cybersecurity, data cannot be meaningfully protected, while data protection can manage the risk and impact of …
Response attribution not verified
#32 — Set out funding, renewal, and disposal strategies for government-provided school digital devices.
Recommendation: Digital devices provided to schools by the Government must be maintained and kept secure through regular renewals and software updates. The Department for Education must set out a funding and renewal strategy for device management alongside a strategy for disposing …
Response attribution not verified
#16 —
Recommendation: Long-standing factors have driven consolidation in the telecommunications vendor market over many years, so it is critical that the Government adopts measures to maintain market diversity as well as to drive the initial diversification. Network operators will be integral to …
Response attribution not verified
#12 —
Recommendation: Testing facilities do not need to be situated in one physical location. The Government should ensure that any new testing facilities complement existing facilities, and are designed with potential developments in 5G technology in mind to guard against future redundancy.
Response attribution not verified
#17 —
Recommendation: The Government needs to act as a consolidator and facilitator to draw together disparate approaches to cybersecurity in the maritime sector. The 2017 Cyber Security Code of Practice for Ships should be updated as soon as possible. The Government should …
Response attribution not verified
#14 —
Recommendation: There is a fine balance that needs to be struck when it comes to regulating for smart shipping and autonomous vessels. It is important that innovation is able to flourish whilst ensuring that safety standards are maintained and that there …
Response attribution not verified
#7 — Connected vehicles pose new complex challenges for safety, data access, and legal liability.
Recommendation: Connected vehicles pose new dangers, which the law must evolve to meet. A safety- led culture will require wide access to data, and this must be a higher priority than commercial confidentiality. Ensuring self-driving vehicles are roadworthy will be more …
Response attribution not verified
#21 — Seven million smart meter communication hubs require replacement by 2033 due to network closures.
Recommendation: The Department also estimates that 7 million communications hubs (a modular component of the smart meter set) will need to be replaced in the South and Central regions ahead of 2033, when 2G and 3G communications networks are closed. These …
Response attribution not verified
#19 — One point four million smart meters lost communication; replacement incentives for suppliers are weak.
Recommendation: According to the Department and Energy UK, the third category included around 1.4 million meters that were working at the point of installation but had since lost communication.59 This includes first generation meters, known as SMETS1, that needed to be …
Response attribution not verified
#5 — Ensure suppliers prioritise replacing faulty smart meters and deploy future-proofed technology.
Recommendation: Too many smart meters are not fully functioning and millions more will be impacted when the 2G and 3G mobile communication networks close. In March 2023, around 3 million (9%) of smart meters were not working properly in total. Of …
Response attribution not verified
CQC inspection actions(6)
North Manchester General Hospital
The trust should continue to ensure that improvements are made to its IT infrastructure and reduce the risk in cyber vulnerability, system failure and downtime and the associated disruption to clinical services and risk to patient safety.
Should Do
Fairfield General Hospital
The trust should continue to ensure that improvements are made to its IT infrastructure and reduce the risk in cyber vulnerability, system failure and downtime and the associated disruption to clinical services and risk to patient safety.
Should Do
Newham University Hospital
The services should ensure all computers remain locked when unattended.
Should Do
Queen Elizabeth The Queen Mother Hospital
The trust must ensure all computer terminals are locked when not in use
Must Do
Rochdale Infirmary
The trust should continue to ensure that improvements are made to its IT infrastructure and reduce the risk in cyber vulnerability, system failure and downtime and the associated disruption to clinical services and risk to patient safety.
Should Do
Montagu Hospital, Mexborough
ThetrustshouldensurethatK2technologyisupdatedwithnationalupdatesassoonastheyarereleased.
Should Do
IMB individual recommendations(12)
Long Lartin (2023)
Security. The current unreliable and faulty security systems pose a serious safety risk. Is high priority to be given to enable repairs and improvements?
Governor / Director
In Progress
Long Lartin (2023)
Security systems. The maintenance contractor, Amey, has been unable to restore or maintain the ageing surveillance equipment to enable it to provide the prison with adequate security cover. What measures are being taken to install and maintain effective and reliable electronic surveillance?
HMPPS
In Progress
Low Newton (2021)
Are more handsets needed to allow more staff to access prisoners via the in-cell phones? This contact seems to have been particularly beneficial during lockdown.
Governor / Director
Grendon (2021)
Is there a date for Grendon to have in-cell telephony installed (see 7.5.2)?
HMPPS
In Progress
Hollesley Bay (2024)
The Board asks if there any plans to introduce in-cell telephony at Hollesley Bay.
Governor / Director
Wormwood Scrubs (2025)
Prisoners using in-cell phones experience frequent breakdowns, long waits for repairs and call costs far higher than those in the community. What will the Prison Service do to improve this?
HMPPS
In Progress
Thorn Cross (2021)
It is imperative to ensure that the learning from the positive use of mobile phones is not lost and that this temporary measure becomes a permanent feature of the open estate.
HMPPS
Noted
Parc (2021)
It was identified that a proportion of prisoners were positive about the Purple Visits service, and it is hoped that this will continue to be fully funded, with improved software to avoid random disconnections in the service.
HMPPS
In Progress
Bure (2021)
Will HMPPS make funding available to the prison to enable prisoners to have access to in-cell telephony?
HMPPS
In Progress
Stafford (2022)
The need to introduce modern in-cell phone technology (fixed or mobile)
HMPPS
Deerbolt (2020)
The Minister should agree that the use of video-links for visits and funerals has shown benefits, and that it would be worth trying to develop these techniques with the best of modern technology for regular use in future, albeit not replacing all face-to-face visits, or funeral attendance.
Ministry of Justice
In Progress
London STHF (2023)
The Board would like to see a quick completion of the Wi-Fi trial in the holding rooms, so a decision can be made on how to introduce internet access.
Home Office
National patient safety alerts(1)
Independent reviews(14)
Caldicott Review 2016 — Rec 4
All health and social care organisations should provide evidence that they are taking action to improve cyber security, for example through the 'Cyber Essentials' scheme. The 'Cyber Essentials' scheme should be tested in a wider number of GP practices, Trusts and social care settings.
Health & Social Care
Caldicott Review 2016 — Rec 3
Trusts and CCGs should use an appropriate tool to identify vulnerabilities such as dormant accounts, default passwords and multiple logins from the same account. These tools could also be also used by the IT companies that provide IT systems to GPs and social care providers.
Health & Social Care
Caldicott Review 2013 — Rec 17
The NHS Commissioning Board, clinical commissioning groups and local authorities must ensure that health and social care services that offer virtual consultations and/or are dependent on medical devices for biometric monitoring are conforming to best practice with regard to information governance and will do so in the future.
Health & Social Care
Coates Prison Education Review — Rec 23
The security arrangements that currently underpin the use of ICT in the prison estate should be reviewed. Governors should be allowed to develop an approach that allows suitably risk-assessed prison learners to have controlled access to the internet to support their studies and enable applications for jobs on release.
Justice & Legal
Caldicott Review 2016 — Rec 5
NHS England should change its standard financial contracts to require organisations to take account of the data security standards. Local government should also include this requirement in contracts with the independent and voluntary sectors. Where a provider does not meet the standards over a reasonable period of time, a contract …
Health & Social Care
Goldacre Review — Rec TRE 9
Evaluate new developments in privacy engineering; adapt accordingly The use of TREs is likely to remain best practice for the protection of disclosive NHS data for some time to come. It is however reasonable to expect that the core technical design features of a good TRE will shift as technology …
Health & Social Care
Jackson Review — Rec 102
Consideration should be given to establishing an IT network for the courts which is separate from, and therefore not constrained by the security requirements of, the gsi system. This network should have its own appropriate level of security.
Other
Anderson Review — Rec 113
The jurisdiction of the IPT should be expanded (or clarified) to cover circumstances where it is a CSP rather than a public authority which was at fault (for example, by intercepting the wrong communications address and/or disclosing the wrong communications data).
Other
Anderson Review — Rec 16
The rules regarding retention of data by CSPs should comply (to the extent that it may be applicable) with EU law as contained e.g. in Joined Cases C-293/12 and C594/12 Digital Rights Ireland and with the ECHR, particularly as regards: (a) limits on the data whose retention may be required; …
Other
Anderson Review — Rec 15
In relation to the subject matter of the 2012 Communications Data Bill, Government should initiate an early and intensive dialogue with law enforcement and CSPs in order to formulate an updated and coordinated position, informed by legal and technical advice, on the operational case for adding web logs (or the …
Other
Anderson Review — Rec 12
The definitions of content and of communications data, and any subdivisions, should be reviewed, with input from all interested parties including service providers, technical experts and NGOs, so as to ensure that they properly reflect both current and anticipated technological developments and the privacy interests attaching to different categories of …
Other
Coates Prison Education Review — Rec 22
The planned investment in digital infrastructure should be used to enable more flexible learning across prisons. As part of this there should be a prompt and rigorous strategic review of the Virtual Campus (VC) to assess if and how it can be made fit for purpose. The review should: assess …
Justice & Legal
Wade-Gery Review — Rec 9
Recommendation 9: re-prioritise NHSEI spend to lift the quantum devoted to digitally enabled system transformation. Assess the level of ‘technical debt’ across the wider NHSEI system and update estimates of technology spend required to enable the delivery of safe technology operations. In conjunction with DHSC, make the case for increased …
Health & Social Care
Kerslake Review — Rec 19
In order to safeguard the future integrity of the National Mutual Aid Telephony system, the Home Office should urgently secure appropriate guarantees from Vodafone that the necessary fall-back and disaster recovery arrangements are in place to address the failures which occurred on 22nd / 23rd May 2017
Policing & Security
Accepted
CJINI inspection reports(1)
Law Commission projects(2)
Digital Assets
The Property (Digital Assets etc) Act received Royal Assent on 2 December 2025. Two further recommendations are being considered by HM Treasury.
In Process of Implementation
2023
Automated Vehicles
The Automated Vehicles Act received Royal Assent in May 2024. The implementation programme intends to finish implementing the Act in the second half of 2027.
In Process of Implementation
2022