Skip to main content

Comment

Draft Cyber Security (Jersey) Law 202- (P.107/2025): comments

Published on: 16 January 2026

Presented by: Economic and International Affairs Panel

Debate date: 20 January 2026

Reference: P.107/2025 Com.

This content has been automatically generated from the original PDF and some formatting may have been lost, therefore it should not be relied upon to extract citations or propose amendments. Please see the PDF for the official version of the document.

STATES OF JERSEY

DRAFT CYBER SECURITY (JERSEY) LAW 202- (P.107/2025): COMMENTS

Presented to the States on 16th January 2026

by the Economic and International Affairs Scrutiny Panel

STATES GREFFE

2025  P.107 Com.

COMMENTS

Background

The draft Cyber Security (Jersey) Law 202- [P.107/2025] (hereafter referred to as "draft Law") was lodged au Greffe on 24th November 2025 and is scheduled for debate at the States' sitting commencing on 20th January 2026.

The Economic and International Affairs Scrutiny Panel (hereafter referred to as "the Panel") has conducted concurrent Scrutiny of the draft Law throughout its development, including receiving briefings from Officers and questioning the Minster for Sustainable Economic Development (hereafter referred to as "the Minister") during Quarterly Hearings. Subsequently, the Panel has formed these comments to aid the Assembly's consideration of the draft Law.

Purpose of the Draft Law

In general, the draft Cyber Security (Jersey) Law 202- seeks to strengthen the cyber security and resilience of Jersey's network and information systems that support the delivery of essential services and to protecting Jersey economy, critical infrastructure and wider community from cyber threats and incidents.

The Law places overall responsibility for national cyber security with the Minister for Sustainable Economic Development, supported by the Director of the Jersey Cyber Security Centre (JCSC) who will be granted operational independence. If adopted the draft Law formally establishes the JCSC and the role of the Director as Jersey's technical advisory body for cyber security. The objectives and functions of the Director are to prepare for, protect from, defend against and facilitate recovery from, cyber threats or cyber-attacks affecting Jersey1.

The draft Law also empowers the Director to act as the Single Point of Contact (SPOC) and the JCSC as the Computer Security Incident Response Team (CSIRT) for Jersey, ensuring coordination with domestic regulators and international networks2.

The draft Law, if adopted, also provides for identifying Operators of Essential Services (OES) and setting out their cyber security duties, including the implementation of proportionate security measures and measures to identify cyber threats and reduce the risk of cyber incidents. It also enables the establishment of Technical Advisory Councils (TAC) to provide specialist expertise, and introduces civil penalties to a maximum of £10,000, on an OES for contravention of a provision of the Law. The fine does not extend to contravention by a government service. The penalty for providing false or misleading information applies to all.

The draft Law builds on Jersey's Cyber Security Strategy published in 2017 and the subsequent creation and funding of a Cyber Emergency Response Team (more widely known as a "CERT") which was rebranded in late 2021, to become the JCSC to reflect the wider role of the facility as a technical advisory authority on cyber security on behalf of Jersey, rather than just an emergency cyber response capability3.

1 DRAFT CYBER SECURITY (JERSEY) LAW 202- 2 DRAFT CYBER SECURITY (JERSEY) LAW 202- 3 DRAFT CYBER SECURITY (JERSEY) LAW 202-

It is mentioned in the draft law that the "latest Island-wide cyber resilience exercise was completed in 2020 and continues to highlight the need on Jersey for specialised cyber security support".[4] The Panel highlights that this activity happened some years ago and suggests that a new Island-wide cyber resilience exercise may now be beneficial.

Panel Observations

The Panel has been kept informed of the draft Law, which has been updated based on feedback, throughout its development and has the following observations.

Consultation:

The Panel notes the consultation undertaken during the development of the draft Law, including two public consultations, held in December  2022/January 2023 and March/April 2024, and engagement with stakeholders from a wide range of sectors. At the Quarterly Hearing on 3 October 2024, the Panel was advised:

Assistant Minister for Sustainable Economic Development: It is currently being amended. That is after its second period of consultation and that again received lots of feedback; 50 written responses, 10 public briefings with 93 participants and 72 private briefings with interested stakeholders. I would like to thank them because I cannot over- emphasise how important cyber security is to the way in which we move forward as a community. In terms of increasing productivity, we are looking to the digital support that we get but it needs to be kept secure and there is a culture change that this law is basically spearheading. The law itself is currently being amended after that consultation. We anticipate that it is going to be lodged by the end of the year [5]

In correspondence dated 2 December 2024 and 27 February 2025, the Minister further confirmed that:

The feedback from the extended consultation in March-April 2024 has been taken into consideration and has resulted in amendments. It is proposed that the final draft will be shared with key stakeholders and the Panel before lodging. Jersey Cyber Security Centre plans to hold a number of workshops with each sector of Operators of Essential Services to develop the required guidance needed for businesses to support their compliance with the requirements of the Cyber Security (Jersey) Law 202- when it becomes enforceable. These will be planned once a copy of the final draft law is available.[6] And

Extensive public consultation on the draft law was held March-April 2024. Following the review of the consultation feedback and input from ELT members, updated drafting instructions were submitted to Law Drafters early November 2024. Once Officers have received and reviewed the amended draft, Officers expect a final drafting round will be needed before the legislation is ready to lodge. It was hoped that this project would be completed and the law ready to lodge before July 2025. This project has however been graded as "amber" within the Government's Legislative Programme which means law drafting time in 2025 is contingent on available law drafters during the year. Therefore,

a predicted lodging time cannot be provided at this stage, but I will be seeking to ensure that this project is re-prioritised by the Legislative Drafting Office and completed as soon as possible7.

Jersey Cyber Security Centre:

The draft Law establishes the Jersey Cyber Security Centre (JCSC) and role of the Director. The Panel examined whether the JCSC would operate as a regulator with responsibility for enforcement. During the Quarterly Hearing on 2 December 2025, the Panel asked:

Deputy K.M. Wilson : In terms of the Cyber Security Centre itself, can you tell us how it will have powers beyond issuing guidance and also how will compliance be monitored through the centre?

Assistant Minister for Sustainable Economic Development: It is very important to explain that the Cyber Security Centre is basically a support area and co-ordination centre. What it is not is an enforcer. It is not a regulator. So to answer your question, it does not regulate. It does have a role in advising the Minister in terms of what might be appropriate security measures to ask operators of essential services to take and indeed, possibly the Minister in, I would say extreme cases, could potentially act as an enforcer but to give advice in that respect because sometimes there is a certain amount of relative forensic work just explaining what standards have not been complied with or not. and that needs to be looked into by Jersey.8

The Panel notes that the draft Law reflects this position, with enforcement powers reserved  to  the  Minister  and  the  JCSC  focused  on  other  areas  such  as  support, coordination, guidance and information sharing.

The  Panel  also  explored  whether  the  role  of  the  JCSC  might  evolve  over  time, particularly considering technological developments:

Deputy K.M. Wilson : Do you envisage that that may change over time, particularly with the advance of A.I. (artificial intelligence)

Assistant Minister for Sustainable Economic Development: I think, yes, to some extent because Jersey is following in the wake of other more sophisticated jurisdictions and we do have the ambition to develop in this area. Indeed, we have a finance industry that is quite important to our economy that is really reliant on cyber security, so having everybody in this community begin to acknowledge that they have a role to play and to begin to assume some sort of responsibility is an important part of this work. In particular, when we refer to cyber security standards, so again, we have got regulators in different areas like data protection. There could be a data breach and there is a certain amount of work that is going hand in hand. What sort of standards of cyber security should we be expecting our operators of essential services to be implementing and from there other types of organisations.9

7 Letter-MSED to EIA regarding Legislative Programme 2025 -27 February 2025

8 Transcript - Quarterly Public Hearing with the Minister for Sustainable Economic Development - 02 December 2025 9 Transcript - Quarterly Public Hearing with the Minister for Sustainable Economic Development - 02 December 2025

The Panel notes that the draft Law allows for power to amend this law by regulations to make alternative or supplementary provision that appears to the States to be appropriate and this does not limit other powers to amend this Law by regulations or order.[7]

Operators of Essential Services and reporting obligations:

The Panel notes that the draft Law provides a framework for the designation of Operators of Essential Services, with thresholds and mechanisms for review and appeal. A significant focus for the Panel was the proposed timeframe for reporting significant cyber incidents:

Deputy M. Tadier : if I can just take over for this bit - is that we understand that there is one part of the law that is coming forward, which talks about the requirement to report significant cyber incidents. That has been settled on a 48-hour period. We have asked some questions privately about that, but could you talk to us about how that timescale was decided and how it compares to other jurisdictions, whether it is likely to stay at 48 hours, whether you are entirely happy with that and what the alternatives might be?

Head of Digital Economy, Department for the Economy: As you say, we have consulted extensively and 48 hours has been the agreed timescale. With regard to other jurisdictions, the U.K. is 72 hours, Australia is 12 hours, India is 6 hours, but I should say the U.K. is also consulting on 48 hours. It has been part of a very broad and engaged discussion with key stakeholders.[8]

The Minister went on to state their support for a reduction to 24 hours instead of the 48 hours:

The Minister for Sustainable Economic Development: I agree. I think 48 hours is very much where we are in terms of the adjustment to the new regime. I agree with Deputy Scott . I would personally prefer to see it become 24 hours over time.[9]

In correspondence dated 2nd December 2024, the Minister advised that:

The current draft of the Cyber Security (Jersey) Law 202- has a reporting timeframe of 48hours for cyber incidents that have happened and that have had or likely to have a significant impact on the continuity of the essential service. The policy intent is to reduce this to 24 hours after 1 year of enactment. This is to enable Operators of Essential Services to adjust to their legal obligations.[10]

The Panel notes that the  Draft Law now requires reporting within 24 hours and welcomes this change. The Panel also notes that reporting is intended to be minimal and proportionate:

The Minister for Sustainable Economic Development: the other element is reporting when there is a breach to report within 24 hours to the Jersey Cyber Security

Centre. That in itself is a point I was making in the past was that is not a big report. Adding It can be an email; very simply, an email.14

Inclusion of Non-Ministerial Departments:

It was indicated to the Panel during the Quarterly Hearing on 3 October 2024 that there was an aim to bring the non-Ministerial Departments into the scope of the draft Law:

The Minister for Sustainable Economic Development: Interestingly, we have had ... from the non-Ministerial departments there has been a suggestion they should not be included. I disagree with that. I think non-Ministerial is part of the makeup of the very fabric of our democracy and, therefore, is an essential service in my view.15

This aim was again highlighted to the Panel in correspondence dated 2 December 2024:

Based on feedback from key stakeholders, amendments have been made to the policy intent to enable the inclusion of Non-Ministerial bodies within the scope of law, for example, within the requirement to report significant cyber incidents. Amendments are currently being reviewed by law drafters.16

The Panel notes that it is unclear from the draft Law if non-Ministerial Departments are currently captured, which in relation to public administration sector OESs refers to: Parishes and public bodies (as specified in Schedule 2 of the Public Finances (Jersey) Law 2019, Jersey regulatory bodies (JFSC, JCRA, JDPA), and Jersey Heritage17. The Panel notes that non-Ministerial departments are in Schedule 1 of the Public Finances (Jersey) Law 201918. The Panel therefore requests that, during the Assembly debate, the Minister clarify the position of the non-Ministerial Departments in relation to the draft Law.

Business readiness:

The Panel examined whether businesses, particularly those likely to be designated as OESs, are sufficiently prepared for the requirements of the draft Law and whether the potential costs of compliance have been assessed. The Panel enquired if there would be requirements imposed on organisations to increase their security arrangements:

Deputy K.M. Wilson : Are you going to impose requirements on people and businesses and  agencies  and  departments  to  increase  their  security  arrangements  and  their practice of security around this?

Assistant Minister for Sustainable Economic Development: The law contemplates that by regulation we can do much more in the area of cyber security, but the important thing in terms of leading any community is to pace with them, so it is not to create a whole avalanche of regulation for them to digest and comply with. Somewhere down the

14 Transcript - Quarterly Public Hearing with the Minister for Sustainable Economic Development - 02 December

2025

15 Transcript - Quarterly Public Hearing with the Minister for Sustainable Economic Development - 03 October 2024 16 Letter – MSED Quarterly Hearing follow-on – 02 December 2024

17 DRAFT CYBER SECURITY (JERSEY) LAW 202-

18 PUBLIC FINANCES (JERSEY) LAW 2019

line, yes, that is possible but for now we have got this obligation about reporting. There is a huge education piece. Talking about prevention, yes, that is included in education, but in terms of the J.C.S.C. when people report to it, we are talking about things that can spread and it is about containing that. At some point in the future there could even be that capacity for an agency to physically remove viruses from individual computers. Now, we are not legally structured to enable that but I think that will be something for the community to think about down the line: should we be allowing people to continue on that basis? But as I say, we are just having to get people thinking about this whole need to keep the system secure and how we do that and why we need to do that. I very much hope that the panel will support us in that objective.[11]

During the Quarterly Hearing on 2 December 2025, the Panel asked if an assessment of the costs for implementation of this law, particularly on small businesses:

Deputy K.M. Wilson : has the Government made any assessment of the costs around the implementation of this law, particularly on small businesses?

Assistant Minister for Sustainable Economic Development: At this stage, in terms of small business, because that is not really the focus, that is not what we have done, because the focus is on operator essential services so we need to rule that out. We already are working in terms of issuing guidance with them, we have been consulting with them. Indeed, when we come to the point where we are expanding law we would expect there to be consultation phases there. It is not a matter of just suddenly saying, right, now it is you. It is intending to consult.[12]

The Panel went on to ask if there are any businesses that may struggle to meet the requirements put on them by draft Law:

Deputy K.M. Wilson : Are there any businesses that may be struggling with this in terms of any undue burden that has been placed on them by the law being implemented?

Assistant Minister for Sustainable Economic Development: This has been extensively consulted with. We have had 2 public consultations in 2022 and 2024 but, on top of that, anybody that we could imagine would be operating essential services, there have been discussions with them, which really has shaped the nature of this law. So as we have explained, it has been quite important that J.C.S.C. (Jersey Cyber Security Centre) is very much there as a co-ordinator and a support centre primarily. The real obstacle in terms of co-ordination has been that we have not had a law that requires people to share this information, otherwise they have got no right to. So, I think any kind of objection that I personally have been aware of has been more that the law has not been in place, and I have had certain people in the cyber security area just say: "Where is this law, why have you not delivered it yet?" Well, here we are. Just for that reason, because it needs to be in place to achieve a really important part of what we might call cyber 23

resilience, which is sharing information to anticipate types of attacks that may follow up on other organisations.21

The Panel further asked:

Deputy M. Tadier : I was just going to ask, is there a concern that any businesses will struggle with this ultimately and that this will be just another added cost at a time when some are struggling with both red tape, allegedly, and also costs?

Assistant Minister for Sustainable Economic Development: Yes, the concern we have been really conscious of - a potential concern - that it could be regarded as red tape insofar as those reporting requirement. Two aspects to that. Number one, if you are the subject of a cyber security attack you are putting a lot of energy into trying to deal with that attack, so having a number of different areas or agencies that you need to report to adds to the stress of managing that. The cyber security strategy that we have published is so that to the extent that we will be aiming to minimise any potential overlap there. So the most obvious overlap is you get a data breach, you need to advise our Information Commissioner as well as potentially the J.C.S.C. so the extent to which there could be some. But then it is not.22

Implementation and resourcing:

The Panel questioned the implementation and the capacity of the JCSC. At the Quarterly Hearing on 3 October 2024 the Panel asked about the possible expansion of the Law to additional sector

Deputy M. Tadier : Are there any other sectors or businesses that are currently not envisaged to be included as operators or essential services but which may be included later on?

Assistant Minister for Sustainable Economic Development: Well, phase 2, which will come into play after the law is brought in, does contemplate that we look at other businesses that are important to the economy. There have been discussions going on in the finance industry in terms of that because we have a trillion-dollar industry there, but again in terms of just beginning this culture change with a law that refers to essential operators and just getting the bare bones of having people understand what is essential to the infrastructure, to what is essential23

The Assistant Minister added:

Assistant Minister for Sustainable Economic Development: We just need to get ... what we have been doing with other sectors is talking about thresholds, so this is a staged thing, bearing in mind the J.C.S.C. has to keep up with this. It has got limited resources and so as we expand the net it needs to keep up with that itself. There have been discussions about the thresholds in terms of income and assets that should be considered to be the bar in terms of requiring the obligation, bearing in mind all the

21 Transcript - Quarterly Public Hearing with the Minister for Sustainable Economic Development - 02 December 2025

22 Transcript - Quarterly Public Hearing with the Minister for Sustainable Economic Development - 02 December 2025

23 Transcript - Quarterly Public Hearing with the Minister for Sustainable Economic Development - 03 October 2024 same that everybody is encouraged to report things, incidents to the J.C.S.C. and I hope that people just will because it is a community-minded thing to do.[13]

In correspondence dated 2nd December 2024, the Minister confirmed that:

It is currently proposed that the clauses imposing obligations on Operators of Essential Services will become enforceable 3 months later. This will provide sufficient time for Jersey Cyber Security Centre (JCSC) to publish the required guidance for each Operators of Essential Services. JCSC will support the enactment of the new Cyber Security (Jersey) Law 202- with targeted communications activities.[14]

The Panel was also advised in the same correspondence that JCSC staffing and resourcing would not be greatly impacted by the draft Law coming into force:

Currently, it is not anticipated that the staffing and resourcing of the JCSC will be significantly impacted by the Law's implementation.[15]

Cyber Security Policy Framework:

The Panel explored how the draft Law aligns with the Draft Cyber Security Policy Framework which went out for consultation on  22 July 2025 and closed on 2nd September 2025 with a response published in October 2025.

Deputy M. Tadier : We are aware that there is a Cyber Security Jersey Law which is lodged and how does it align with the cyber security policy framework from now and for the next 15 years, and the broader sustainable economic development strategy, please?

Assistant Minister for Sustainable Economic Development:  It is an important framework in terms of supporting cyber security in our Island as envisaged by the cyber security policy framework which sets out policy ambition. The framework itself is a continuance of a previous cyber security policy that anticipated the establishment of the Jersey Cyber Security Centre and the bringing in of the law. So, the cyber security policy framework has, if you like, a broader reach than the law because it is setting out areas of work outside the law as well as within the law. Within the law it starts with a focus on these operators of essential services setting out the statutory framework for them to ensure that they implement certain security measures and report cyber instances so that our essential critical infrastructure is not so vulnerable that we can try and protect it in that way. It contemplates that the nature of these duties could potentially be extended through further regulations made under the law as the cyber security culture that we hope to evolve in this Island becomes more established.[16]

The Panel acknowledges that the draft Law cannot be successful in protecting the Island from cyber-attacks on its own and welcomes the update of the 2017 Cyber Security Strategy.

Ministerial responsibility:

The Panel questioned why responsibility for national cyber security sits with the Minister for Sustainable Economic Development rather than the Minister for Home Affairs:

Deputy M. Tadier : Could you explain maybe why you think it has fallen to this Ministry rather than necessarily perhaps to Home Affairs? There is an element, of course, about security and defence and criminality in it. Do you think you are the natural home for it and how does that compare.

The Minister for Sustainable Economic Development: It is a good question. I have never actually thought about it. It is one of those that this was on my desk when I took over. It has a business-enabling element. It is an economic-enabling piece of legislation and protecting, so in that sense I think it is quite happy with us. As a department, we also have things like the Telecoms Law as part of our department and obviously the whole digital economy side, which Mark represents. So I think in that sense it does sit easily with us but I think it is incumbent on us to speak to the Home Affairs Department and Minister to make sure that they are sighted and understand as well. Given the rest of the remit around telecoms and digital, this fits easily within our department.28

The Panel notes this rationale and the intention for cross-departmental awareness. Conclusion

The Panel has scrutinised the draft Law throughout its development, including through briefings and hearings. The Panel is therefore supportive of the principles of the draft Law and believes that the proposed articles will achieve their desired goal towards improving Jersey's cyber resilience and protecting essential services.

28 Transcript - Quarterly Public Hearing with the Minister for Sustainable Economic Development - 03 October 2024