- Jersey Cyber Security Centre Newsletter
- Posts
- JCSC News: Home stretch for the Cyber Law, Guernsey launch
JCSC News: Home stretch for the Cyber Law, Guernsey launch

Contents
Dear reader,
It’s been a longer period since your last newsletter, partly due to Jersey’s general election, which took place on the 7 June, and the election of Ministers. (This means a period of reduced communications for all of Government so that the focus is kept - rightly- on the candidates). Deputy Gerald Voisin has been elected Minister for Sustainable Economic Development, and we look forward to working with him and Assistant Minister Phil Romeril over the coming years.
With the new Government in place, the commencement order for the Cyber Security (Jersey) Law 2026 has been signed by the Minister, which means the Law will come into effect later this year. (For more information on the timelines, and what you’ll need to do, see below). This marks the culmination of years of work, both within JCSC and with our stakeholders, so I am pleased that it is finally within reach.
Behind the scenes, we’ve been working closely with our newly-appointed colleagues at Guernsey Cyber Security Centre (GCSC) as they settle into their roles. Together, we held a formal launch event in early June which was well-attended. As well as being a chance to hear from excellent speakers, it allowed us to showcase the good work already happening in Guernsey with key stakeholders.
And speaking of good work, I heard about a lot of it when I attended the FIRST Conference in Denver, Colorado back in mid-June. These conference always provide an insight into how other cyber defenders are responding to the same threats that impact us, and there’s always something we can learn from them and apply here in Jersey.
Until next time,

Guernsey Cyber Security Centre launch
In June, GCSC held its launch event at Old Government House. The event brought together members of the States of Guernsey, regulators, and cyber security practitioners to set out some of the challenges facing the Bailiwick and how GCSC can play a part in addressing them.
Speakers at the event included Lynne Capie from Soteria Communications, investigative journalist and author Geoff White, and email prankster James Linton.
Watch the full video from the event, or visit the GCSC website: gcsc.gg
Reflections from FIRST: Can we do more to stop cyber scams?

JCSC is a member of an international body (the Forum of Incident Response and Security Teams) that represents cyber defenders around the world. Most national teams, as well as many large corporates, are represented. The UK and Japan sponsored Jersey’s membership. FIRST runs a number of regional events the team attend each year as well as an annual conference that gives us the opportunity to build relationships with, share with, and learn from with others from around the world.
It’s an intensive week with seven days of back-to-back sessions in multiple streams, from technical how-tos to policy discussions and consideration of emerging threats such as quantum computing and Artificial Intelligence. Normally we would send more than one team member to try to cover this (it’s a big event!) but this year it was just me.
Of the many stand-out sessions this year, the one that resonated most was ThaiCERT’s presentation on how they are responding to scams.
Cyber scams and frauds are known to cost Islanders about £5m a year, but as nearly 90% of these are not reported, the true cost could be nearer £40-£50m. Cyber scams also cut across multiple remits - in Jersey that’s JCSC, States of Jersey Police, the JFSC and FIU, plus others. They are hard to solve because it’s not just a technical problem, or just a local one.
At JCSC we’re already working to improve scam reporting. You can already report phishing to us, and we do takedowns of malicious websites with our international partners such as FIRST and UK NCSC. However addressing this fully takes collaboration, something the Jersey Fraud Prevention Forum is increasingly leading on.
ThaiCERT shared their multi-agency approach that stretched from law changes to technical measures. They found that many cyber scams are on social media sites, and simple changes like requiring social media sites to do KYC (verification) on advertisers cut many of the scams out at source. Requiring actions by telecoms providers helped as well. That’s the sort of thing we should be looking at here, too.
What next for the Cyber Law?
With the new Cyber Security (Jersey) Law 2026 being due to come into effect later this year, if you are an designated as an Operator of Essential Service (OES), the countdown to prepare is now on.
The Law will be enacted in two stages.
In September, Parts 2 and 3 of the Law will come into effect. These Parts set out the role and powers of JCSC, so have a limited impact on other organisations.
In December, Parts 4 and 5 of the Law will come into effect. These Parts set out the thresholds for Operators of Essential Services (OES) and the requirement for OES to have cyber security measures in place. These Parts also set out reporting requirements for OES.
This means if you believe your organisation is an OES, you should:
Read the Law (via the States Assembly website) and check if your organisation is an OES
Pre-register as an OES using this form
Visit the Cyber Law Information Hub to read our latest Guidance, Standards and Advice
Upcoming events
Channel Islands Cyber Security Conference - Friday 16 October
Booking for the 2026 Channel Islands Cyber Security Conference is open. Join us and the Channel Islands Information Security Forum (CIISF) on Friday 16 October for a new look conference with talks, demonstrations and networking opportunities.
Speakers for the day will include:
Andy Compton, CEO (Cortida)
Ken Munro, Security Researcher and Partner (Pen Test Partners)
Rob Shapland, Director and Ethical Hacker (Cyonic Cyber)
Places at the conference are always in demand, so book your ticket today.
Cyber security in the news
Scale of UK ransomware threat exposed
Figures from Report Fraud suggest that there were 26 successful ransomware attacks each month in 2025, with most reports coming from small or mid-sized companies. The figure is likely to be much higher given issues with under-reporting of cyber incidents.
New study identifies cyber security communications gap
Research from Flinders University in Australia suggests that commonly-used cyber security terminology (think phishing, virus, trojan) can obscure the average user’s ability to understand the risks they’re facing. While it doesn’t provide answers, the paper should make us within the cyber security community consider how we can convey information to non-specialists.
Jobs in Cyber
Are you recruiting for a cyber role locally? Tell us at [email protected] and we’ll share your job listing with the community.
Tool of the Month
Each month, we provide a round up of tools that our team have found useful, and which could be useful to cyber security professionals. If you’ve found a helpful tool you’d like to share, please email us and we’ll include it in a future newsletter.
DangerZoneReceived a document or image that might be risky? This tool will convert potentially dangerous documents into a safe PDF. |
A Periodic Table of DFIRThere are lots of Digital Forensics and Incident Response (DFIR) tools out there and it can a challenge to keep track of them. This simple, interactive tool lists them, including key information. |

