The UK government’s call for evidence on sections 1–13 of the Telecommunications (Security) Act 2021 is scheduled to close on 12 October 2026. Its stated subject is the impact and effectiveness of the legislation. For businesses, this is a concrete reminder that public affairs is most useful when it turns operational experience into information a public authority can assess. A response should make a policy question easier to decide, rather than merely make the respondent’s preferences more visible. [1]
The NCSC’s exercise guidance provides a practical model for involving leadership, security and communications in testing response processes. Evidence from such exercises can improve an internal assessment, although it is not itself an official evaluation of the legislation. [2]
Start with the question being asked
A consultation response can fail before the first sentence if it addresses a different problem from the one under review. Read the scope, questions, submission instructions and treatment of confidential information. Identify which experience the company can genuinely evidence. A technology supplier may understand one implementation interface particularly well without being able to judge the entire security framework. Stating that boundary strengthens the response. It also prevents a communications team from making broad claims on behalf of customers whose circumstances it has not verified. The aim is a contribution proportionate to the organisation’s actual knowledge.
Convert a complaint into an observable process
Saying that a requirement is complex provides little basis for policy judgment. Describe the sequence that creates difficulty: the information requested, the teams involved, the time required and the point at which duplication occurs. Use an anonymised example where commercial confidentiality requires it, while retaining enough detail for scrutiny. Separate one-off transition costs from recurring costs and distinguish measured time from estimates. If the company has no reliable measurement, acknowledge that and propose a way to collect it. A precise description of an implementation problem is more persuasive than a large but unexplained financial number.
Explain the security consequence as well as the cost
A company arguing for a simpler process should show how the proposed change preserves or improves the policy objective. Otherwise simplification can sound like a request for weaker safeguards. For example, a shared reporting vocabulary might reduce repeated work while making important incidents easier to compare. The response should state the conditions under which that benefit would arise and any risks the change could introduce. This is a hypothetical policy illustration, not a finding about the Act. Public affairs teams should involve operational security specialists early enough that the recommendation remains technically credible when challenged.
Keep UK and EU frameworks distinct
International companies often reuse a global policy paper for several consultations. That can save drafting time but obscure material differences in legal scope, institutions and implementation. A submission about UK telecom security should not automatically borrow an EU product-security argument or assume the same authority is responsible. Use a comparative appendix if cross-border friction is relevant, identifying the actual processes being compared. For a business operating in Britain and France, the strongest contribution may be a specific interoperability issue. The company should demonstrate the issue rather than use international complexity as a general reason to resist regulation.
Make representation transparent
State whose experience the document reflects: the company alone, a set of consenting customers, or a trade association with an agreed position. Do not present a coalition view if members have not approved it. Where research is commissioned, explain the method and limitations. A public affairs adviser can help structure the argument, but should not obscure the commercial interest behind it. Transparency gives officials a fair basis for weighing the evidence and reduces reputational risk if the submission becomes public. It also helps internal teams recognise the difference between a corporate position and a neutral assessment.
Plan the public explanation before submitting
A company may later be asked why it supported a particular regulatory change. Prepare a concise account that links the recommendation to security outcomes and implementation evidence. Avoid a public slogan that contradicts the more careful submission. Employees and customers may read excerpts without the full context, so the main argument should remain intelligible on its own. Where confidential annexes are necessary, check that the public version still explains the substance of the request. Confidentiality should protect legitimate information, not become a reason for publishing an unsupported assertion that readers cannot evaluate.
What can still be done responsibly
A deadline is not a reason to invent missing evidence. If an organisation has limited time, a narrow and well-supported contribution is preferable to a comprehensive-looking paper built on assumptions. Confirm the live deadline and submission route before acting; this article records the timetable available on 11 October. Keep an internal record of the final version, approvers and evidence sources so later engagement remains coherent. Belief System supports evidence-led public affairs and the translation of technical experience into accessible institutional arguments. The work starts with a precise question, a verifiable example and a proposed improvement whose consequences can be discussed openly.