Ofcom opens investigations into Zayo and Tata Communications over security data failures
Julian Glover
Ofcom has opened two separate investigations into whether fibre network operator Zayo Group UK and digital communications provider Tata Communications (UK) failed to comply with a statutory information request tied to their network security duties.
Both companies were issued with a notice on 23rd June 2026 under section 135 of the Communications Act 2003. The notice required them to provide information to help Ofcom assess compliance with the security duties set out in sections 105A to 105D of the Act and the Electronic Communications (Security Measures) Regulations 2022.
The notice asked the operators to detail the measures they were taking to meet their network security duties. Ofcom says it has found evidence to suggest that neither operator may have provided complete or accurate information in response. Zayo alone also faces an added allegation that it may not have supplied the information within the required time-frame.
What the regulator is examining
Ofcom holds a range of information-gathering powers to help it assess, monitor and govern the UK market. Communications providers are generally required to respond to such requests within a reasonable period, and to make sure the information they supply is accurate so as not to mislead the regulator.
The two investigations will now look at whether Zayo and Tata failed to comply with their statutory duties in relation to these requests. Cases of this kind can take anywhere from a few months to well over a year to complete, depending on how complex they are, so an outcome is likely by the end of 2026 or at some point in 2027.
Where Ofcom does find a breach, the outcome often attracts relatively small to modest fines, frequently paired with a requirement to improve internal processes and systems.
Enforcement backdrop
The investigations come as Ofcom steps up its oversight under the Telecommunications Security Act 2021, which moved the UK from an operator-led security model to a more prescriptive regime. That framework requires public electronic communications providers to meet set standards for network architecture and supply chain risk management.
A May 2026 Ofcom consultation proposed updates to the regulator's resilience guidance to reflect emerging threats, including risks linked to AI and geopolitical instability. The updates aim to standardise incident reporting thresholds, such as requiring mobile operators to report security compromises affecting at least 100,000 customers.
Ofcom has treated accurate data submission as a central regulatory pillar in earlier cases. In July 2024 it fined TikTok £1.875 million for failing to provide accurate information about its parental control features, one of the first major penalties under similar information-gathering powers. Smaller fines have also been common, including a £150,000 penalty against O2 in December 2021 for incomplete responses during a billing investigation. The pattern suggests initial fines for administrative failures tend to be modest, while repeat offences or evidence of systemic negligence can lead to much higher penalties.
Further regulatory pressure is expected as the government prepares the Cyber Security and Resilience Bill, noted in the May 2026 King's Speech, which could extend Ofcom's remit to cover data centres and other digital infrastructure.
For Zayo, which announced a $4.25 billion acquisition of Crown Castle's fibre business in March 2025, keeping to UK-specific security rules is becoming a central operational requirement for a cross-border provider.

Julian Glover
Julian Glover covers UK home and business broadband, comparing providers, explaining new tech, and helping readers find the right deal for their household.



