UK published the National Cyber Security Strategy to address cyber threats from rogue nations like Iran, Russia, China, terrorists, states sponsored hackers and cyber menaces like ransomware against the national infrastructure. There are some uncertainties if essential services providers can accomplish the implementation requirements of the NIS Directive until May 2018. The penalty will only be applied once the operator of essential service fails to comply with the directive tacking into account these following criteria listed in article 14, Security requirements and incident notification. The fine will be judged and decided upon the accordance with the proper measures that were not taken and implemented, with a maximum value of 17 million.”]
Source: https://securityaffairs.co/wordpress/68637/laws-and-regulations/uk-government-security-measures.html

