UK Police Chiefs Cite TfL Prosecution to Push for New Cybercrime Risk Orders
UK police chiefs are citing the Transport for London prosecution and the Scattered Spider sentencing to press for Cybercrime Risk Orders — a proposed civil tool to restrain suspected cyber offenders. Post-TfL policy analysis this week.
UK police chiefs are turning the country's largest cybercrime prosecution into an argument for new civil powers to restrain suspected offenders before charges are brought.
LONDON — Senior UK law enforcement officials have seized on the country's largest cybercrime prosecution to press for new legal powers, arguing that the Transport for London (TfL) case exposes an enforcement gap a proposed tool — Cybercrime Risk Orders — is meant to close. Speaking around the July 16 sentencing of two men tied to the 2024 TfL intrusion, officials framed the orders as a way to restrain high-risk suspects mid-investigation.
The case, reported by Infosecurity Magazine, turns a landmark conviction into a policy lever. Owen Flowers, 19, and Thalha Jubair, 20, were each sentenced to five and a half years for unauthorised acts against TfL; both are believed to be part of Scattered Spider. The CyberSignal covered the sentencing and the attribution of roughly 120 attacks to Jubair.
What the Police Chiefs Advocated
Paul Foster, deputy director of the NCA and head of its National Cyber Crime Unit, described the TfL case as “the largest cybercrime prosecution ever brought before the UK courts” and Scattered Spider as “the most significant cybercrime threat to the UK in recent years.” His argument for new powers rested on two features of the investigation: Flowers was 17 when arrested, and he breached bail twice, in October 2024 and May 2025.
Existing tools, Foster argued, do not fit these cases. Serious crime prevention orders do not apply to underage offenders, and some computer misuse offences fall below the serious-crime threshold those orders require, “which leaves a gap.” CCROs, he said, would “have allowed us to arrest Flowers sooner,” potentially by acting on information from US or Australian partners. City of London Police Commander Ollie Shaw separately said he “welcomes” the orders and advocated for “digital prisons” to constrain offenders.
Continuation Context: The TfL Sentencing and Jubair Attribution
The advocacy builds directly on the sentencing The CyberSignal has tracked across this series. Flowers and Jubair were sentenced on July 16 at London's Woolwich Crown Court under Section 3ZA of the Computer Misuse Act 1990 — only the second conviction under that section, which Foster called the Act's “most serious” provision. (The first, per the Crown Prosecution Service, involved a former GCHQ intern.) The road to sentencing ran through Jubair's earlier guilty plea in the TfL case.
The scale is what makes the case a policy anchor. The intrusion is thought to have cost TfL an estimated £29m in damages and £10m in lost income, with disruption affecting between seven and 10 million people. The nearly two-year investigation drew in the Crown Prosecution Service, City of London Police, the FBI, Europol, and the Australian Federal Police — the international dimension underpinning Foster's claim that CCROs would have let UK authorities act sooner.
The Proposed Cybercrime Risk Orders Framework
Proposed by the government in May 2026 as part of a planned Computer Misuse Act reform, CCROs are civil preventive measures intended to manage the behaviour of people suspected or convicted of cybercrime. Per the officials' account, they could restrict individuals judged to pose an ongoing threat “even before prosecution thresholds are met,” framed as “similar in principle to sexual risk orders.” Conditions would be actively monitored, and any breach could carry criminal sanctions, including imprisonment, regardless of whether the underlying investigation has concluded.
Shaw's “digital prison” framing sketched how such conditions might work: restricting access to the tools and platforms an offender needs to reoffend, enforced with technology providers, with account monitoring and device limits — though he conceded practical hurdles, notably keeping devices out of prisons. The orders were trailed in the May 2026 King's Speech; officials indicated reform legislation could be introduced later this year as part of a broader national security package, with CCROs slated for late 2027 or early 2028.
Policy-Analysis Implications for UK Cybercrime Enforcement
The pitch fits a run of UK signalling about the seriousness of the threat environment, including the NCSC's assessment that hostile states drive a large share of the most severe risks to critical infrastructure and its leadership's framing of Iran, Russia, and China as primary drivers of UK cyber threats. CCROs are a proposed answer to a problem the state has spent the past year defining in stark terms.
The counter-case came from within the security community. Adam Pilton, a UK-based cybersecurity consultant, told Infosecurity he would welcome reforms that “lower the barriers to prosecution,” but cautioned that CCROs may not work as advertised: subjects are “highly skilled and capable of tricking most officers,” so unless those checking compliance have genuine technical capability, “these orders won't be able to achieve what they promise.” He dismissed the “digital prison” label as “headline-grabbing marketing.” That tension between preventive ambition and enforceability is the live question for defenders and policymakers alike.
Open Questions
Several core details remain unsettled. The orders were proposed by “the government,” but whether the Home Office has formally endorsed a specific statutory design was not established in the reporting reviewed here. The thresholds for imposing an order, the standard of evidence, and the oversight and appeal mechanisms were not detailed, and it is not confirmed the reform will pass on the signalled timeline. The proposal also arrives amid wider debate over allied approaches to cyber and AI governance, from Five Eyes coordination on frontier AI to civil-liberties scrutiny that any pre-charge restraint power will attract.
For now, UK policing has made a public, case-anchored argument for a new civil tool, and the government has signalled intent to legislate. The statutory substance that would let observers judge the orders' scope, proportionality, and enforceability is still ahead.
The CyberSignal Analysis
The facts above are drawn from UK law enforcement statements and Infosecurity Magazine's reporting; what follows is The CyberSignal's editorial reading for policy and security audiences. None of the judgments below are new reported facts.
Signal 01 — A Conviction Becomes a Legislative Lever
The durable takeaway is procedural, not technical: a landmark sentencing is being used, in public and by name, to make the case for a specific new power. That is how enforcement gaps get legislated — a concrete failure mode (a teenage suspect who breached bail twice during a two-year investigation) is offered as proof that existing orders fall short. The TfL case will now be the reference example whenever CCROs are debated.
For security and policy audiences, the signal is to watch how tightly the power is scoped to the problem it invokes. Powers justified by an exceptional case can be drafted narrowly or broadly, and the gap between the two is where the debate will sit.
Signal 02 — The Enforcement Gap Is Real; the Fix Is Unproven
Two things can be true at once. The gap the officials describe is genuine: serious crime prevention orders do not reach underage suspects, and some computer misuse offences fall below the serious-crime bar, leaving a real management problem during long investigations. But the proposed remedy is unproven, and the sharpest doubt — raised from inside the field — is about enforceability against technically capable subjects.
The actionable interpretation is to separate the diagnosis from the prescription: endorsing that a gap exists does not require endorsing CCROs as designed. The questions that will decide whether the orders work — who monitors compliance, with what capability, and under what oversight — are precisely the ones not yet answered.
Signal 03 — Watch the Timeline and the Oversight Detail
The most consequential uncertainty is the distance between advocacy and enacted law. CCROs are a trailed proposal on a soft timeline: reform legislation signalled for later in 2026, the orders slated for late 2027 or early 2028. Between now and then, the statutory text, evidentiary thresholds, and oversight machinery all remain to be written.
The forward-looking watch items are specific: a published bill, the pre-charge evidentiary standard, the named oversight body, and any independent effectiveness review. Until those appear, the UK has a well-argued proposal backed by a landmark case, not yet a law defenders can plan around.