{"id":283520,"date":"2025-11-26T01:40:10","date_gmt":"2025-11-26T01:40:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/283520\/"},"modified":"2025-11-26T01:40:10","modified_gmt":"2025-11-26T01:40:10","slug":"uk-parliamentary-committee-recommends-software-liability","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/283520\/","title":{"rendered":"UK Parliamentary Committee Recommends Software Liability"},"content":{"rendered":"<p class=\"text-muted\">\n                                            <a href=\"https:\/\/www.bankinfosecurity.com\/geo-focus-united-kingdom-c-520\" id=\"asset_topic_1_1\" rel=\"nofollow noopener\" target=\"_blank\">Geo Focus: The United Kingdom<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/geo-specific-c-518\" id=\"asset_topic_1_2\" rel=\"nofollow noopener\" target=\"_blank\">Geo-Specific<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/standards-regulations-compliance-c-435\" id=\"asset_topic_1_3\" rel=\"nofollow noopener\" target=\"_blank\">Standards, Regulations &amp; Compliance<\/a>\n                                                    <\/p>\n<p>                    Security by Design or Be Fined, Committee Suggests<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/akshaya-asokan-i-2924\" rel=\"nofollow noopener\" target=\"_blank\">Akshaya Asokan<\/a> (<a href=\"https:\/\/www.twitter.com\/asokan_akshaya\" rel=\"nofollow noopener\" target=\"_blank\">asokan_akshaya<\/a>)                                                    \u2022<br \/>\n                        November 25, 2025 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/uk-parliamentary-committee-recommends-software-liability-a-30132#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/11\/uk-parliamentary-committee-recommends-software-liability-image_large-4-a-30132.jpg\" alt=\"UK Parliamentary Committee Recommends Software Liability\" class=\"img-responsive \"\/><br \/>\n                Image: Cristian Gusa\/Shutterstock            <\/p>\n<p>A U.K. parliamentary committee is recommending a new statute forcing software publishers to hew to secure-by-design principles or else face financial penalties.<\/p>\n<p>See Also: <a href=\"https:\/\/www.bankinfosecurity.com\/webinars\/how-payment-service-directive-psd2-changing-digital-banking-are-you-w-1378?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">How Payment Service Directive (PSD2) is Changing Digital Banking &#8211; Are You Ready?<\/a><\/p>\n<p>The British government, <a href=\"https:\/\/www.bankinfosecurity.com\/technology-giants-join-cisas-secure-by-design-pledge-a-25160\" rel=\"nofollow noopener\" target=\"_blank\">like the U.S. government<\/a>, has pushed the tech sector to voluntarily integrate security into product design, a policy driven by frustration over the sheer quantity of disruptive ransomware attacks, incidents of nation-state cyberespionage and fears over the potential for remote sabotage by foreign hackers (see: <a href=\"https:\/\/www.bankinfosecurity.com\/uk-software-security-code-practices-earns-mixed-reviews-a-26054\" rel=\"nofollow noopener\" target=\"_blank\"> UK Software Security Code of Practice Earns Mixed Reviews<\/a>).<\/p>\n<p>The U.K. Commons Business and Trade Committee nonetheless <a href=\"https:\/\/ismg-cdn.nyc3.cdn.digitaloceanspaces.com\/asset_files\/external\/7nmzl1jv.pdf\" target=\"_blank\" rel=\"nofollow noopener\">endorsed<\/a> liability for software developers in a Monday report containing recommendations to improve economic security. The committee called for &#8220;enforcement agencies&#8221; empowered to levy fines for noncompliance with secure-by-design principles.<\/p>\n<p>Making secure-by-design mandatory &#8211; whether by exposing tech companies to customer lawsuits or through government enforcement &#8211; has so far been an impossible goal for American proponents and a difficult one for British backers. U.K. supporters  <a href=\"https:\/\/www.bankinfosecurity.com\/secure-by-design-uk-enforces-iot-device-cybersecurity-rules-a-24964\" rel=\"nofollow noopener\" target=\"_blank\">succeeded<\/a> in imposing minimum cybersecurity standards for internet of things devices such as no universal default passwords but otherwise has had to rely on tech sector cooperation. <\/p>\n<p>In the United States, backers <a href=\"https:\/\/www.bankinfosecurity.com\/shifting-software-liability-creates-info-sharing-challenges-a-21356\" rel=\"nofollow noopener\" target=\"_blank\">including<\/a> the Biden administration, have been unable to overcome opposition from Silicon Valley and arguments that imposing liability onto the tech industry would constrain America&#8217;s economic engine. President Donald Trump in June <a href=\"https:\/\/www.whitehouse.gov\/presidential-actions\/2025\/06\/sustaining-select-efforts-to-strengthen-the-nations-cybersecurity-and-amending-executive-order-13694-and-executive-order-14144\/\" target=\"_blank\" rel=\"nofollow noopener\">undid<\/a> a Biden-era requirement for software developers to submit attestations validating their use of secure software development practices when selling to the federal government (see: <a href=\"https:\/\/www.bankinfosecurity.com\/trump-rewrites-biden-era-cyber-rules-in-new-executive-order-a-28617\" rel=\"nofollow noopener\" target=\"_blank\">Trump Rewrites Cybersecurity Policy in Executive Order<\/a>).<\/p>\n<p>Observers may have a chance to observe the real-world applicability of anti-liability arguments starting in late 2027, when secure-by-design standards for &#8220;products with digital elements&#8221; <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/qanda_22_5375\" target=\"_blank\" rel=\"nofollow noopener\">sold in Europe<\/a> come into effect. But not even European rules will cover all software, since the regulation, the Cyber Resilience Act, excludes software-as-a-service.<\/p>\n<p>Whether the U.K. succeeds in imposing wide-ranging software liability when Europe and the United States have not is now a political question. Lawmakers could software liability by expanding <a href=\"https:\/\/www.bankinfosecurity.com\/uk-labour-introduces-cyber-security-resilience-bill-a-25788\" rel=\"nofollow noopener\" target=\"_blank\">already proposed<\/a> cybersecurity legislation, said Andrew Churchill, policy director at non-profit Cybersecurity and Business Resilience.<\/p>\n<p>The parliamentary committee additionally called for a change to tax law that would allow companies to deduct payments to subscription-based IT services that enhance resilience. Current laws, the committee said, de-incentives subscription payments for cybersecurity software by not allowing companies to write off the costs.<\/p>\n<p>            <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Geo Focus: The United Kingdom , Geo-Specific , Standards, Regulations &amp; Compliance Security by Design or Be Fined,&hellip;\n","protected":false},"author":2,"featured_media":283521,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[92203,26925,92190,92193,92192,92191,92199,87344,92200,59,92201,57,58,5736,968,92196,92198,92197,92195,92194,50,5208,25471,92202,56,54,55],"class_list":["post-283520","post","type-post","status-publish","format-standard","has-post-thumbnail","category-united-kingdom","tag-anti-money-laundering","tag-authentication","tag-bank-information-security","tag-bank-information-security-regulations","tag-bank-regulations","tag-banking-information-security","tag-fdic","tag-fincen","tag-gao","tag-gb","tag-glba","tag-great-britain","tag-greatbritain","tag-identity-theft","tag-information-security","tag-information-security-articles","tag-information-security-events","tag-information-security-news","tag-information-security-webinars","tag-information-security-white-papers","tag-news","tag-phishing","tag-risk-management","tag-sarbanes-oxley-sox","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/283520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=283520"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/283520\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/283521"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=283520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=283520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=283520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}