Ofcom has opened an investigation into Zayo Group UK over whether the telecommunications infrastructure provider complied with a statutory information request connected to the UK’s telecoms-security regime.
The regulator issued Zayo with a notice under section 135 of the Communications Act 2003 on 23 June 2025. The notice sought information to help Ofcom assess the company’s compliance with security duties under sections 105A to 105D of the Act and the Electronic Communications (Security Measures) Regulations 2022.
Ofcom said the available evidence suggests some information supplied in response to the notice may not have been provided within the required timeframe and may not have been complete or accurate.
The regulator has not made a finding that Zayo breached its obligations. The investigation will determine whether a failure occurred in relation to the statutory information request.
Statutory requests are one of the mechanisms regulators use to establish whether companies are meeting legal requirements. In telecommunications, information supplied by network operators can inform Ofcom’s assessment of security measures and determine whether further supervisory or enforcement action is required.
Ofcom said it is “essential that stakeholders provide accurate and complete information in a timely fashion.” Where the regulator has reasonable grounds to believe a requirement imposed under section 135 has been breached, the Communications Act provides an enforcement route under section 138.
The distinction between the information investigation and the underlying security duties is important. The case opened on 10 August concerns Zayo’s compliance with the statutory request itself.
It does not amount to an Ofcom finding that the company has breached the telecoms-security requirements the original request was intended to examine. Any conclusion on the information request will depend on the evidence gathered during the investigation.
Zayo operates network infrastructure and connectivity services across international markets, including fibre and data-transmission infrastructure in Western Europe. Businesses of that type form part of the physical networks used to connect enterprises, data centres, cloud services, and other communications infrastructure.
Security regulation has become more prescriptive as dependence on telecommunications networks has increased. The Electronic Communications (Security Measures) Regulations 2022 sit alongside duties in the Communications Act and require providers within scope to manage risks affecting the security and resilience of networks and services.
Compliance therefore extends beyond installing security technology. Operators need governance structures, evidence, records, risk processes, and reporting arrangements capable of demonstrating to the regulator how duties are being met.
A statutory information request tests part of that capability because Ofcom must be able to obtain reliable material before assessing the underlying controls. The quality and timeliness of regulatory information can consequently become a compliance matter in its own right.
The same principle applies across other regulated sectors. Incomplete, inaccurate, or late information can trigger enforcement separately from the conduct that prompted the original request.
Businesses responding to formal notices therefore need processes that bring together legal, compliance, technical, and operational teams, particularly where requested material spans complex infrastructure or several business units.
Telecommunications security can involve large volumes of technical information distributed across networks, suppliers, operational teams, and management systems. Producing a complete response may require evidence from several parts of an organisation.
Those internal complexities do not remove the statutory obligation to respond within the terms set by the regulator. Companies need to identify where relevant data sits, who owns it, how it will be verified, and which executives are responsible for approving the final submission.
That evidential layer is becoming more important as network infrastructure supports a larger share of economic activity. Fibre connectivity underpins cloud computing, data centres, business applications, remote working, and increasingly data-intensive artificial-intelligence systems.
Weaknesses in network resilience can therefore have consequences far beyond an individual telecommunications provider. The regulatory regime reflects that dependency by placing formal security duties on operators and giving Ofcom powers to gather the information needed to supervise them.
The Zayo case remains at its opening stage. Ofcom has said it will update the investigation as work progresses, and no timetable for a conclusion has been published.
No enforcement outcome can be inferred from the decision to investigate. The case will nevertheless test an important part of telecoms-security governance: whether regulated infrastructure providers can demonstrate compliance through complete, accurate, and timely evidence when formally required to do so.




You must be logged in to post a comment.