Imagine you're the CISO at a regional hospital network. On Tuesday, you receive a classified directive: remove all equipment from Vendor X within 90 days. You can't tell your board why, ask Vendor X for help, or even confirm the directive exists. Your legal team needs government approval before hiring outside counsel to interpret the order.
This isn't hypothetical. It's what the UK government's proposed amendments to the Cyber Security and Resilience Bill could authorize across energy, water, transport, health, and digital infrastructure sectors.
The issue isn't whether governments need vendor intervention powers, they do. The real question is whether those powers should operate in secrecy.
The Case for Secret Powers
National security officials argue that transparency tips off adversaries.
When the UK forced Huawei equipment out of 5G networks under the Telecommunications (Security) Act 2021, the process was public. Huawei knew it was a security risk and had the opportunity to respond. The entire episode unfolded in parliamentary debates and press coverage.
That transparency had costs. Hostile state actors observed how the UK identified risks, what evidence triggered action, and how long removal took. They learned which technical capabilities concerned security services most and adapted.
Under the new proposal, ministers could issue a "vendor-related direction" without publicly naming the supplier. A data center operator might be ordered to stop using certain products, but the market wouldn't know which vendor posed the risk. The direction would be published, the recipient named, but details could be withheld on national security or commercial grounds.
The government's stance: acting before threats materialize requires acting quietly. If you announce you're investigating Vendor Y's supply chain for sabotage risks, Vendor Y sanitizes the evidence. If you declare Vendor Z has ties to hostile intelligence services, those services route their operations through Vendor Z's competitors instead.
Secret powers preserve operational advantage. They let security services protect critical infrastructure without teaching adversaries how to evade detection next time.
The Case Against Opacity
The transparency argument extends beyond open government principles.
Consider vendor risk management. Your third-party risk program likely includes assessing inherent risk, evaluating controls, making a risk-based decision, and documenting rationale. You've built frameworks around NIST SP 800-161 supply chain guidance. You've mapped vendors to NIST Cybersecurity Framework categories. You've got board reporting that shows how you're managing concentration risk across critical suppliers.
A secret government directive disrupts that entire model. You're forced to remove a vendor you've assessed as low-risk. You can't document why or explain the decision to auditors reviewing your ISO 27001 program. If you're SOC 2 Type II certified, your control environment just changed for reasons you can't disclose in your next report.
Worse, you can't warn peers. If Vendor X poses a national security risk to hospitals, it probably poses the same risk to universities, utilities, and local governments. But you're barred from discussing the directive. Other organizations keep buying from Vendor X because the government's concerns remain classified.
The commercial damage compounds quickly. Under the proposal, ministers could withhold vendor names on commercial grounds, not just national security. That means a vendor might be secretly banned not because of espionage risk, but because disclosing the ban would harm UK companies competing with that vendor. You're executing industrial policy disguised as security policy, with no public accountability.
Then there's the precedent problem. If the UK can secretly ban vendors from critical sectors, what stops other governments from demanding the same power? Your global vendor relationships become impossible to manage when any jurisdiction might issue secret removal orders. You can't build resilient supply chains if the rules are classified.
Where Practitioners Actually Land
Most security leaders I talk to accept that some government intervention is necessary. The debate is about the mechanism.
The Telecommunications Act 2021 model, despite its flaws, included procedural safeguards. Vendors had to be publicly designated as high-risk. They received copies of directions. There was a consultation process. The new proposal strips those protections away.
What practitioners want is a middle path: keep the speed and flexibility ministers need, but build in transparency after the fact. Issue the secret directive if you must, but require public disclosure within a defined window unless specific, renewable criteria are met. Let companies discuss directions with vetted legal counsel without needing government approval for each advisor. Publish anonymized case studies so the market learns what triggers intervention.
The current proposal goes further than necessary. Ministers already have emergency powers under existing national security law. The question is whether routine vendor risk decisions should operate in permanent secrecy.
Our Take
Secret government powers should be reserved for genuine emergencies, not normalized as standard vendor management.
The UK government is right that hostile states use commercial technology for espionage and sabotage. It's right that some interventions need to happen quickly. It's wrong that the solution requires permanent opacity.
Here's a workable alternative: issue directions in secret when speed matters, but require public disclosure within 12 months unless the Secretary of State certifies to Parliament that ongoing secrecy remains essential. That certification should be renewable annually but not indefinitely. After three years, either the threat is public knowledge or it wasn't severe enough to justify permanent secrecy.
Require that companies receiving directions can consult with outside counsel and technical specialists without government pre-approval, subject to standard security clearances. If GCHQ wants to maintain a list of approved advisors, fine, but don't make that list a bottleneck.
Most importantly, separate genuine national security decisions from industrial policy. If you're banning a vendor to protect UK companies from foreign competition, own that decision publicly. Don't hide trade policy behind classified security assessments.
For security leaders navigating this environment: document every vendor decision as if you'll need to explain it under oath, because you might. Build redundancy into critical vendor relationships now, before a secret directive forces emergency changes. And push back when government officials ask you to execute classified orders that undermine your ability to run a defensible security program.
National security and transparency aren't opposites. They're both requirements for running critical infrastructure in a hostile threat environment. The UK's proposed powers sacrifice one for the other. That's a tradeoff we shouldn't accept.



