All 13 contributions to the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 (Ministerial Extracts Only)

Read Full Bill Debate Texts

Tue 6th Jan 2026

Cyber Security and Resilience (Network and Information Systems) Bill

(Limited Text - Ministerial Extracts only)

Read Full debate
2nd reading
Tuesday 6th January 2026

(8 months, 3 weeks ago)

Commons Chamber
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 Read Hansard Text Watch Debate

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

Ian Murray Portrait The Minister for Digital Government and Data (Ian Murray)
- View Speech - Hansard - - - Excerpts

I beg to move, That the Bill be now read a Second time.

A happy new year to you, Mr Speaker, and to all the House staff. This is the first opportunity I have had to say that to you.

On 3 June 2024, a busy Monday morning in south-east London, criminals attacked Synnovis, an organisation that processes blood tests on behalf of our national health service. They did not turn up physically, but logged on to computers thousands of miles away and set off ransomware—malicious software that encrypts files from afar, making them unusable. The attack had a ripple effect across London hospitals. It delayed 11,000 appointments, blood transfusions had to be suspended and the company lost tens of millions of pounds.

This was not an isolated case. In the year leading up to September 2025, the National Cyber Security Centre dealt with 204 “nationally significant” incidents, meaning that they seriously disrupted central Government or our critical public services. That is more than double the 89 incidents in 2024. No one disputes that we must do everything we can to protect the UK from these attacks. The UK is the most targeted country by cyber-attacks in Europe, and it was the fifth most targeted nation in 2024 by nation state-affiliated threat actors. In 2024, it is estimated that UK businesses experienced over 8.5 million cyber-crimes in the 12 months preceding the survey, and that in that year more than four in 10, or 43%, of UK businesses were subject to a cyber-attack, affecting more than 600,000 businesses in total.

Significantly, cyber-attacks are estimated to cost UK businesses almost £15 billion each year, equivalent to 0.5% of the UK’s annual GDP, notwithstanding the wider economic effects of intellectual property theft or the experience of patients, as in the first example. The average cost of a significant cyber-attack for an individual business in the United Kingdom is estimated to be just over £190,000. There has been a 200% increase in global cyber-attacks on rail systems in the past five years, increasing the likelihood of severe disruption to the economy and to people’s daily lives.

Chris Vince Portrait Chris Vince (Harlow) (Lab/Co-op)
- Hansard - - - Excerpts

Does the Minister agree that, as we become more and more reliant on IT systems—I am thinking in particular about the new patient registration system at the Princess Alexandra hospital in my constituency—it is more and more important that we combat potential cyber-attacks, particularly from foreign powers and enemies of this country? That is why the Bill is so crucial.

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

I could not agree more. I gave the example of the Synnovis incident that brought blood transfusions in London to a halt, affecting thousands of patients. Our everyday lives are affected by this. As we modernise and digitise our economy and our Government, we have to ensure that our systems are as secure as possible, and cyber-security is right at the heart of that. This is not just a defensive issue; it is very much an economic growth issue as well, as we can see from the impact it has on our economy, our public services and the day-to-day lives of people, as in the example of our train systems that I just mentioned.

Toby Perkins Portrait Mr Toby Perkins (Chesterfield) (Lab)
- Hansard - - - Excerpts

I am grateful to my hon. Friend for giving way, and it is great to see him in his post. On economic growth, how has he sought in the Bill to balance the absolute need for a regulatory framework that businesses can have confidence in alongside the ability to attract continued investment, and to ensure that we do not end up with an over-regulatory framework that stifles investment? How did he find that balance?

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

The Bill builds on the 2018 regulations, which were a hangover from the EU when we adopted them in this country. The Bill expands on those. As my hon. Friend the Member for Harlow (Chris Vince) just suggested, this is about economic growth as well as protecting our systems, so we have to find a balance between ensuring that our regulators have the powers and tools to regulate properly and giving businesses and our public services the confidence to use digital technology knowing that we have the most secure cyber-security in Europe, if not the world. We are very good at this stuff, and that is the balance to be sought. This Bill is about economic growth rather than about the over-regulation of businesses. I do not say this flippantly, but cyber-security is one of those areas where if everything is working, nobody notices, but when it is not working, suddenly everyone notices and it is everyone’s problem. That is why we are bringing the Bill forward and extending the scope of the powers.

Jim Shannon Portrait Jim Shannon (Strangford) (DUP)
- Hansard - - - Excerpts

I thank the Minister very much for what he is saying and bringing forward. There is much in the Bill that we should encourage. I know that he is a regular visitor to Northern Ireland, and Northern Ireland is home to 130 cyber-security companies with some 2,750 employees. It is therefore essential that this legislation protects those jobs and enhances the capacity for more. Does he believe that the Bill both protects us and provides the opportunity for growth in Northern Ireland and, indeed, across the whole of the United Kingdom?

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

Indeed it does. It is one of a number of provisions that the Government are bringing forward to create growth across the country, not just in Northern Ireland. The Secretary of State’s passion is to make sure that those jobs are everywhere, right across the United Kingdom, including in Northern Ireland. The Under-Secretary of State for Science, Innovation and Technology, my hon. Friend the Member for Vale of Glamorgan (Kanishka Narayan), has been in Belfast recently discussing this legislation and wider cyber-security issues with the industry in Northern Ireland, so I can assure the hon. Member for Strangford (Jim Shannon) that that is indeed the case.

Meg Hillier Portrait Dame Meg Hillier (Hackney South and Shoreditch) (Lab/Co-op)
- Hansard - - - Excerpts

Hackney council was the subject of a major cyber-attack in 2020. It did a good job, though it was very slow because of the nature of the challenge of getting things back up and running. The Bill is therefore very welcome but, pursuant to the answer to my hon. Friend the Member for Chesterfield (Mr Perkins), there are challenges for some of the smaller companies. I represent Shoreditch, which has many tech companies that need to maintain a standard on cyber-security but are small. How is the Minister going to balance the regulation for those smaller companies to ensure that they can keep abreast of things but are not so dampened down that they cannot progress and grow?

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

This is about making sure that we extend the scope of the 2018 regulations into other parts of the economy, and I will come on to that later in my contribution. It is about reporting things more quickly to ensure that the attacks can be seen and action can be taken more quickly. It is also about reporting to the regulators to give the regulators confidence and powers across a wider scope of sectors in the economy, and to give businesses the confidence that those sectors have to report to the regulators when things are going wrong so that swifter action can be taken. We can see from the host of recent high-profile issues, including at Hackney council, that it is important to ensure that this legislation goes through quickly and does the job that it is intended to do.

Chris Vince Portrait Chris Vince
- Hansard - - - Excerpts

I thank the Minister for giving way; I apologise for intervening again. Is there a piece of work we need to do on culture? When businesses or the public sector are victims of cyber-crime, there is a danger that employees may feel embarrassed or nervous about reporting their concerns. We need to encourage people if they are victims of cyber-crime to come forward quicker and to recognise the challenges, rather than trying to hide them away and the issue becoming worse.

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

While physical security and national security are issues for all of us, so is cyber-security. The Bill builds on the 2018 regulations to widen the scope into other areas of the economy where such issues have become much more prevalent—for example, data centres. I hope that doing so will give industries and sectors, including their employees, the confidence to report things to the regulators. Giving powers to the regulators will give businesses the confidence that they can report stuff; it is not a regulatory heavy hand dampening businesses. I hope that I can assure my hon. Friend and the rest of the House on that.

Before that significant number of interventions, I was talking about why this issue matters and gave statistics for recent cyber-security activity in the United Kingdom. As a result of all that, one of the very first things we did as a new Government after the election was announce this new cyber-security Bill, just 10 working days in. Since then, the Department has been talking to cyber experts, businesses and regulators to turn these proposals into the comprehensive, serious and proportionate piece of legislation that we present for Second Reading today—one that protects the public and strengthens national security without placing undue burdens on businesses. I appreciate that that is a fine balance, but I think that this Bill finds that balance, so I am confident that the whole House will support it.

Pete Wishart Portrait Pete Wishart (Perth and Kinross-shire) (SNP)
- Hansard - - - Excerpts

We support this Bill and its efforts to tackle cyber-security, but it does not address the mass unauthorised scraping of trusted news content by generative AI systems. That content, as the Minister knows, is often taken without consent or compensation. As the Bill progresses, will he be prepared to look at some measures—maybe something like a bot register where people have to declare their intent when it comes to this type of activity? Will the Government look at this seriously so that news can be protected in this new environment?

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

The hon. Gentleman is ingenious in the way in which he uses interventions on pieces of legislation. I know AI copyright is close to his heart as a former, or perhaps current, professional musician and, indeed, one of the key musicians in MP4—let’s not push that to a Division! AI copyright is, of course, a key issue that the Government are looking at. The Secretary of State for Science, Innovation and Technology and the Secretary of State for Culture, Media and Sport are working closely together on this issue. I think the legislation means that there has to be a report to Parliament in March—I am sure the hon. Gentleman will be very interested in that. We are bringing together the industry and tech companies to try to find a way through that particular issue. We know that it is a huge issue. It is not in the scope of this Bill, which has been kept very tight to deal with these specific and serious cyber-security issues.

As we know, the first duty of Government is to keep people safe. The question is how precisely the Bill will achieve that goal. The answer is simple. The UK’s main cyber-rules—the Network and Information Systems Regulations 2018, or the NIS regime—were first introduced seven years ago and have not been updated since. Those rules require operators of essential services such as energy, water and hospitals, as well as some digital service providers such as online search engines, to take steps to protect the services they provide and the data they hold from cyber-threats.

As Members might expect, a lot has changed in the cyber-landscape in the past eight years. We have had the rise of AI, which cyber-criminals are using to their advantage. Data centres have become a firm fixture of modern life, and we want to see more of them. Since the rules were introduced, criminals tactics have evolved to exploit loopholes in the regulations, as they did in the attack on the NHS supplier that I mentioned, which revealed how hackers can target third parties, such as IT companies, or supply chains as a back-door way to bringing down a wider system. As always, the story is one of technology and cyber-threats moving faster than policymakers can possibly keep up with.

Dave Robertson Portrait Dave Robertson (Lichfield) (Lab)
- Hansard - - - Excerpts

My right hon. Friend is right to mention the impact on supply chains. In the west midlands, we recently had the cyber-attack on Jaguar Land Rover. That had a significant impact not just on that company, but on the supply chain, which has its roots right through the west midlands. That essential part of our economy was brought to a grinding halt by a cyber-attack. Will he confirm that this Bill will help prevent such instances from happening in the future?

--- Later in debate ---
Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

I thank my hon. Friend for all he did on the issues facing Jaguar Land Rover. I know that the matter is close to his heart and, indeed, it was a really big issue across the country, showing how a cyber-attack can affect not just one company, but has a ripple effect throughout the economy. Of course, the Government stepped in to unlock a £1.5 billion bolster to Jaguar Land Rover’s cash reserves to help it through that problem.

I should say to my hon. Friend, and I will come to it later, that Jaguar Land Rover and other private organisations are not in the scope of this Bill. The reason is that individual private companies should take their own cyber-security seriously and ensure that the risks of such incidents and threats are minimised as much as possible. The Bill widens the scope of the existing regulations, which do not include that, but of course the Government are working closely with Jaguar Land Rover, Marks & Spencer and other high-profile cases, because we know the impact they can have on our economy. Indeed, had the Government not stepped in and resolved that issue, the impact on Jaguar Land Rover, and the tens of thousands of employees at the plants and in the supply chain, would have been catastrophic and is not worth thinking about. I thank my hon. Friend for raising that issue.

As I said, as always, the story is one of technology and cyber-threats moving faster than policymakers can possibly keep up with, but today we are fixing that. The first change in the Bill is to widen the scope of the 2018 regulations. To keep up with the changes of the past eight years, we are adding a few new things to that list, starting with large-load controllers. That includes any organisation that manages a significant flow of electricity to or from a smart appliance. It might be a company that supports electric car charging, for example. Bringing these entities into scope will safeguard our power supply and give consumers confidence in using energy-smart appliances, all of which are critical as we advance towards our clean power 2030 mission and net zero.

The second change is that we are adding large data centres in recognition of their growing importance to our day-to-day lives and to the economy. These are vast digital warehouses for the United Kingdom, home to servers that host everything from patient records to their bank details. This is the data that underpins modern life and all our lives and communities, and it must be protected.

We are expanding the scope of the regulations to include managed service providers as well. Those are organisations that provide ongoing functions, such as an IT help desk, to an outside client. Their access makes them an attractive target for cyber-attacks as criminals can find one weak spot and bring countless organisations down. For example, in 2014, an attack on a service provider for the Ministry of Defence compromised the personal data of around 270,000 people—military personnel, reservists and veterans. As organisations rely more and more on outsourced tech, we have to close this gap. In fact, weaknesses in the supply chain have become such a risk that we will go even further by allowing regulators to designate certain organisations as critical suppliers. That includes certain suppliers to essential services that could have a significant impact on the economy or society as a whole—for example, key suppliers to water companies, grid operators or air traffic control. These critical suppliers will be subject to cyber-security duties, which we will set out in secondary legislation.

Meg Hillier Portrait Dame Meg Hillier
- Hansard - - - Excerpts

Last year, the Treasury Committee wrote to the top 10 banks in the UK because there had been a number of outages. There was no suggestion that cyber-security attacks were involved in most cases. A trend in the responses was that third-party software providers are often the source of the issue. What is the Minister’s thinking about how to involve the banking sector in the scope of the Bill?

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

The banking sector is obviously in the regulators’ scope for cyber-security, and there have been a number of outages, as my hon. Friend mentions. The general principle is that cyber-attacks no longer come in through the front door, but through third parties and suppliers. We have seen that, for example, in the recent incidents at Heathrow and in cloud outages with Amazon Web Services and other such companies. They are covered by their own regulations. As I said in answer to my hon. Friend the Member for Lichfield (Dave Robertson) about Jaguar Land Rover, those companies will not be in the scope of the Bill, but we hope that the financial services sector, which is a leader in cyber-security for a whole host of fairly obvious reasons, will take that forward.

The recent attacks on British icons such as Marks & Spencer and Jaguar Land Rover will loom large in people’s minds. Many Members across the Chamber have already mentioned them. Supply chains were thrown into chaos, with small businesses paying the price, which clearly shows the ripple effect across the economy—on other businesses, smaller businesses and patients, such as in the public service examples mentioned earlier—when one part of the system is attacked.

We are clear that all businesses—that covers financial services, Jaguar Land Rover, Marks & Spencer and others—must take immediate steps to protect themselves. That is why, in October, members of the Cabinet wrote to the FTSE 350 companies urging them to strengthen their defences by doing three things: first, to make cyber risk a board priority; secondly, to require suppliers to have a cyber essentials certificate; and thirdly to sign up to the early warning service. That was followed by a similar letter to entrepreneurs and small businesses in November with bespoke advice for smaller teams. We know that those actions work. Organisations with cyber essentials are 92% less likely to claim on cyber insurance than those that do not. Businesses know best how to protect themselves; we are not here to regulate for the sake of regulating.

Government are taking action too. As I announced this morning, the Government cyber action plan sets a radically new model for how Government will strengthen their cyber-resilience and is backed by over £210 million of investment. Government Departments will be held to standards equivalent to those set out in the Bill. That is why the public sector and the Government are not included in the scope of the Bill. The Government should not need to legislate for themselves; we should just get on with making sure that we are leading the charge and that the cyber action plan strengthens the Government’s cyber-resilience. [Interruption.] I do not know if that was an attempt at an intervention from the Opposition Front Bench, but I am happy to take it.

Oliver Dowden Portrait Sir Oliver Dowden (Hertsmere) (Con)
- Hansard - - - Excerpts

I welcome the Minister’s comments about the obligation on the public sector. However, I caution him that, in my experience, cyber-security is one of those things that Ministers talk about, but then other priorities overtake it. The advantage of legislative requirements is that they force Ministers to think about it. I urge the Minister to look at that point again as the Bill passes through Parliament. There is a case for putting more stringent requirements on the public sector in order to force Ministers’ minds on the point.

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

The right hon. Gentleman would have had some involvement in this when he was in government; indeed, the 2018 regulations came from the previous Government. We are all trying to make sure that we are catching up with the technology as quickly as it moves. He makes a very interesting point that I am very conscious of and happy to take away. We are determined to deliver the cyber-security action plan, which is backed by ÂŁ210 million.

The actions that the previous Government took did not come to fruition in terms of their 2030 target, which is why we have refreshed the action plan and brought it forward with some significant cash. It is important for Ministers to take that forward. I hope that the right hon. Gentleman will hold us to account to ensure that we are fulfilling that promise in the cyber-security action plan. Public services, and indeed central Government, must take the leading role to show businesses that the approach to take is to ensure that all our systems are as secure as possible, not just on economic grounds, but for the people that we all seek to represent.

Chi Onwurah Portrait Dame Chi Onwurah (Newcastle upon Tyne Central and West) (Lab)
- Hansard - - - Excerpts

I thank the Minister for the excellent points he is making on the importance of cyber-security and the cyber-security action plan. Can he say a little bit about how the success of the cyber-security action plan will be measured, monitored and communicated to the House? He is probably aware that only 33,000 cyber essentials certificates were issued in 2024, for example, so an increased take-up of cyber essentials and the guidance in the action plan are essential.

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

There are some key dates to monitor progress in the action plan itself. I wrote to my hon. Friend, the Chair of the Science, Innovation and Technology Committee, this morning on the publication of the action plan to lay out some of those issues; the letter will be landing soon. I would be happy to discuss that in front of the Committee in more detail. I hope that the Committee, and indeed the Opposition and our own Labour Members, hold us to account for delivering on this, because it is fundamentally important to Government, whether it be digitisation, modernising Government or winning the case with the public about why digitisation is so important and why Government should be as secure as possible and lead the charge on that across the whole economy. I hope that we and the Committee can take that forward in the weeks and months ahead.

As I said, the Government cyber action plan launched this morning is backed by over £210 million of investment and Government Departments will be held to standards equivalent to those set out in the Bill. I hope that that partially answers the question from my hon. Friend the Chair of the Science, Innovation and Technology Committee. Although the focus of the Bill is on essential services, it will also indirectly help businesses, including those damaged by the recent attacks, and Government. Almost all organisations today rely on data centres, outsourced IT or some kind of external supplier. By extending the Bill’s oversight, we are preventing attacks that could, in theory, reach thousands of organisations.

The Bill also gives new powers to regulators responsible for enforcing the NIS framework. Effective compliance is crucial to the success of any regime. These reforms could be world-leading on paper, but without proper enforcement they are meaningless.

David Reed Portrait David Reed (Exmouth and Exeter East) (Con)
- Hansard - - - Excerpts

We have talked about the regulators having new powers to designate critical national infrastructure in regard to cyber-security threats, but who actually has accountability? The Bill refers to

“regulations made by the Secretary of State.”

Which Secretary of State is that, given that this is a cross-departmental and cross-Government approach?

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

Cyber-security is the responsibility of the Department for Science, Innovation and Technology, but the Cabinet Office has a clear resilience issue as well, as we heard from the right hon. Member for Hertsmere (Sir Oliver Dowden), who was in the Cabinet Office previously. The DSIT Secretary of State will make those regulations, but a plethora of regulators are involved in this process—energy, water and data centres all have different regulators. The regulators that regulate those sectors are being empowered through the expanded number of sectors being brought into the legislation to take the responsibility.

Julian Lewis Portrait Sir Julian Lewis (New Forest East) (Con)
- Hansard - - - Excerpts

I am extremely grateful to the Minister for giving way. On the point about regulators, the industry has issued a brief, which points out, quite sensibly, that these regulators are going to have a lot of extra duties to perform and they will therefore need extra resources to be able to perform those duties, but the extra resources they require will only be unlocked when the Bill has passed. Is there not a danger of a transition period where duties will be laid on regulators to fulfil their role before they have the resources to carry it out?

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

We have to pass the legislation first. It may be amended during its passage through both Houses. Therefore, the regulators will not know what they are regulating until the Bill has passed. However, as I mentioned at the start of my contribution, we have been working with regulators, businesses, organisations and cyber-security experts in the run-up to producing the Bill to make sure that it is in the right place—that it is proportionate on businesses and regulators—and that it is effective, which is the most important thing. I am sure that we will have debates on those kinds of issues as we go through Committee and on to Third Reading, but I very much acknowledge what the right hon. Gentleman said.

The Bill will strengthen the powers of the NIS regulators, ranging from Ofgem to the Civil Aviation Authority, which work together to uphold the UK’s cyber rules across those different sectors—I may have taken the previous intervention 10 seconds too early! We are raising the maximum fine that they can impose, for example, while simplifying the penalty bands to make them clearer. The key driving force for this measure is not to punish rulebreakers or raise revenue, but to incentivise firms to be vigilant. Our goal is 100% compliance and zero fines.

We will also ask regulated organisations to change the way they report attacks and expand both the types of instance they have to report and the timeframe in which they have to report them. This is a small but crucial change. Under the current rules, regulators get notified about a breach only once it has already caused significant disruption—when traffic lights have failed or the heating has shut off. The system does not include cases with the potential to cause a crisis much later, like a hospital’s computer system quietly being spied on as hackers wait for their moment to strike. Under the Bill, if an organisation is within scope, it will have to tell its regulator and the National Cyber Security Centre about these types of breaches within 24 hours and provide a full report within three days. Pace and speed are of the essence. This will not only give us better information, but help agencies to warn others, should they need to, before they become the next targets.

The Bill will also allow the Government to set clear and consistent outcomes for regulations to work towards. One of the virtues of having a regime enforced by different agencies is that each has sector-specific expertise—Ofgem understands the complex digital systems that underpin the national grid, and the Civil Aviation Authority knows the precise threats to air traffic control, for example—but that approach has sometimes led to inconsistencies in how the regime is applied. Some bodies interpret the rules differently from others. The Bill aims to fix that with a single set of objectives issued by central Government and applied across the board. That will send the message that no sector is an easy target in the UK.

We will also improve the way in which regulators, intelligence agencies and law enforcement share information with each other by providing greater clarity on what regulators can share and receive. It is important that regulators have the resources to do their job, as the right hon. Member for New Forest East (Sir Julian Lewis) said. The Bill will also give them new powers to cover the full costs associated with their regulatory duties. To ensure transparency, regulators will consult on how fees are calculated and publish a statement each year to show how the funds are being used. Together, the measures add up to a much more consistent and effective regime with better reporting and much clearer guidance for all involved.

The Bill ensures that the UK’s cyber-security regime is not only fit for today but flexible enough to head off future threats as well. I have mentioned a few things that have changed in the past eight years—shifts in technology and the nature of cyber-attacks, artificial intelligence, data centres and the economy—but one of the biggest changes was, of course, Brexit. Since our exit from the European Union in January 2020, we have been unable to amend the NIS regulations without primary legislation, because the rules were originally part of European Union law. That has slowed the process and made it difficult for us to keep pace with new emerging threats and technology. Meanwhile, Brussels is pressing ahead with NIS2—its forward-looking update—while we lag behind.

That procedural quirk has left essential UK services more exposed, which perhaps tells us something about why the UK has such appalling figures compared with some of our EU counterparts, as hackers and cyber criminals exploit gaps in our dated laws. That is an unacceptable risk, so the Bill includes new powers for the Government to update the NIS regime via secondary legislation, to make it quicker and more agile for dealing with evolving technologies—we might need to respond quickly to a new type of cyber-threat, for example. That is not in order to override Parliament; in almost all cases, the Government will still be required to consult on any changes, and Parliament will have the final say on any legislation made under the power. However, delegated powers are essential for keeping us as responsive as possible. When national security is on the line, we need the ability to act fast and decisively.

In fact, in extreme cases some threats emerge so rapidly that even secondary legislation is too slow; if an ally were to be invaded by a hostile state, for example, the cyber risk to the UK would suddenly escalate. The Government will therefore also be given powers to direct regulators or regulated entities where national security is threatened—to issue specific cyber-security guidance in a crisis, for example. Those powers are intended as a last resort to protect our national security, and safeguards will go into the Bill to ensure that they are used accordingly.

The UK’s cyber sector is the third largest in the world, as we heard from our friend from Northern Ireland, the hon. Member for Strangford (Jim Shannon). It achieves double-digit growth year on year. We have fast-growing clusters of expertise in Cheltenham and Manchester. This legislation will supercharge that success, doubling down on one of our nation’s greatest assets. At its core, the Bill is about protecting the essential services that we all rely on, so that the lights always stay switched on, clean water always runs in our taps, and hospitals are always safe and secure. Those are the real life community issues that we and our constituents all encounter every single day.

This is more than a technical upgrade; it is a bold commitment from the Government to protect one of our biggest economic strengths and keep the UK safe in a rapidly evolving digital world. Together, we are working towards a future in which security is not a hope but a guarantee. I commend the Bill to the House.

Lindsay Hoyle Portrait Mr Speaker
- Hansard - - - Excerpts

I call the shadow Secretary of State.

--- Later in debate ---
Julia Lopez Portrait Julia Lopez
- Hansard - - - Excerpts

As my right hon. Friend is aware, local government is outside of the scope of the Bill, but it is a very juicy target—much of the public sector remains a very juicy target. In acknowledgment of that, the Government whipped out a strategy very quickly this morning that is meant to give us assurances about the public sector’s cyber-resilience. I am not sure that that strategy will provide much reassurance, which is why it is important to understand that this Bill can only be one part of a much wider arsenal to tighten gaps where they exist, in both the private and public sectors.

Ian Murray Portrait Ian Murray
- Hansard - - - Excerpts

It is worth clarifying for the House that we brought forward the Government cyber-security strategy this morning because the 2022 consultation undertaken by the previous Conservative Government was not acted upon. This Government are acting on those threats, bringing forward a plan that we will subsequently see through, and I think the hon. Lady should acknowledge that.

Julia Lopez Portrait Julia Lopez
- Hansard - - - Excerpts

I welcome the strategy, but I have not yet had a chance to have a good look at it, because the Government always seem to publish these sorts of documents right at the last minute. The only way to get any information out of this Government is to apply some pressure in this House, and then, remarkably, things come flying out of the cupboard.

I will be very interested to see what the strategy looks like and whether it is up to the challenge we now face. The problems and risks of cyber have increased markedly since we were in Government because of the advent of AI technology—that technology is changing the picture very rapidly, just as the defence picture is changing very rapidly. My concern is that this Government are not taking seriously enough the various defence and security challenges that this House faces; they are prioritising spending on welfare payments, union payments and all manner of other things. It is one thing to get a strategy out of the door; it is another to put in place the measures that will implement that strategy. Basically, all we have seen over the past 18 months is strategy documents, without a great deal of delivery. That is one of the reasons why the Government are so rapidly losing public confidence.

In conclusion, we support this cyber Bill in principle—the threat is real and growing, and it demands action. However, it is only a tool, not a cure-all. A Government who are trying to close down gaps in one place while wilfully opening up huge new risks in a different corner are being negligent in their approach. Furthermore, if this legislation is to command confidence, it must be practical, proportionate and genuinely effective. Without meaningful improvements, the Bill risks placing new burdens on business while delivering only marginal gains for our national resilience. Cyber-security is a shared responsibility between Government, regulators, industry and the public, but leadership must come from the top, and that is where this Bill currently falls short.

With the private sector taking the lion’s share of the load while gaping holes remain in public sector cyber-defences, the Bill begs obvious questions about the confidence that citizens should have in flagship Government projects such as the Prime Minister’s mandatory digital identity system. As it stands, the Bill would not have prevented high-profile cyber-shutdowns such as Jaguar Land Rover’s, it does little to address the chronic vulnerabilities in the public sector, and it certainly will not make Labour’s dodgy ID database any more secure. That is why, as the Bill progresses through Parliament, we will be pressing this Government to ensure that it delivers genuine security, proper accountability and raised cyber-defences across the board, while taking them to task on major mistakes such as mandatory ID. Cyber-security is no longer a niche compliance exercise; it is about protecting the fundamental economic and defence interests of our nation.

--- Later in debate ---
Anneliese Dodds Portrait Anneliese Dodds (Oxford East) (Lab/Co-op)
- View Speech - Hansard - - - Excerpts

I wish you, Madam Deputy Speaker, all parliamentary staff and all Members in this Chamber a very happy new year.

It is a real pleasure to rise to speak in favour of this crucial Bill, which I am pleased to see having its Second Reading. It is also a pleasure to follow the hon. Member for Exmouth and Exeter East (David Reed), who set out many of the stakes that are so critical here. We also heard that in the opening speech by my right hon. Friend the Minister for Digital Government and Data, who described a number of disturbing cases, as others have done during the debate. He also set out the scale of the impact of cyber-attacks with some concerning figures, as did my hon. Friend the Member for Warwick and Leamington (Matt Western). I was particularly struck by the 0.5% hit to GDP from cyber-attacks and the fact that our country has been the third most severely impacted worldwide by cyber-attacks. It is therefore welcome that the Bill focuses on a faster and more joined-up approach to deter and deal with cyber-attacks.

I believe that that approach has gone alongside a really strong grip from the new Government on the need for a sectoral approach to dealing with cyber-attacks. Of course, we unfortunately had to see that, given the attack on JLR. I was pleased to see the previous Secretary of State really engaging with the automotive sector—work that has been continued by the current Secretary of State—on the challenges and lessons that need to come out of that attack, which has been particularly important in my constituency given the significance of BMW Cowley for employment in Oxford East.

I believe it is critical that we assess cyber-security alongside other forms of cyber-criminality, as the head of MI5 has argued for us to do. Cyber-attacks are increasingly being carried out by quasi-non-state actors that operate in the grey zone that the right hon. Member for Hertsmere (Sir Oliver Dowden) talked about, often implicitly backed by Russia or other adversaries. Those attacks are taking place at the same time as a rise in cryptocurrency laundering and disinformation operations.

I am sadly forced to share the assessment of GLOBSEC, the security-focused think-tank, that the pattern of Russia’s hybrid war

“has persisted without an effective Western response”.

There has been an escalation in cyber-attacks, sabotage, disinformation and political interference, but we have not seen the kind of joined-up approach across like-minded democracies that is needed. I was assured recently by my right hon. Friend the Paymaster General that the Government are working with the EU on combating foreign interference. That work clearly needs to be intensified, especially when we see what is happening to other democracies not so very far away from us.

I saw the threat for myself directly in Moldova, where cyber-criminals’ methods are often being used in combination: a cyber-attack on the election regulator coincided with a disinformation campaign sponsored by Russia and disruptions like bomb hoaxes in real life. So while I welcome this legislation, it must be co-ordinated with broader work to protect our country’s resilience and digital sovereignty, and to secure transparency on foreign interference.

In that regard, I will end by mentioning a concerning development: the sanctioning of two British citizens by the United States over the Christmas period, both of whom have worked to deliver transparency, including on foreign interference—clearly relevant to this Bill. Imran Ahmed is from the Centre for Countering Digital Hate, whose dispassionate, evidence-based analysis has uncovered the spread of disinformation, violent racism and material that poses harms to children. Clare Melford is from the Global Disinformation Index, which provides information about the extent of polarisation and disinformation so that companies can make informed choices about where to advertise—a free market approach to providing transparency.

The Minister stated at the beginning of this debate that when national security is on the line, we must be ready to act, and I strongly agree. A number of Members in the Chamber have said how important it is that we have a cross-economy and cross-society approach to these issues. I believe that the sanctioning of these individuals risks chilling transparency, including potentially transparency that can uncover foreign interference. I hope the Government will resist all attempts to reduce transparency. The welcome efforts in this Bill on cyber-resilience must be accompanied by work to counter other cyber and information-related threats to our national digital sovereignty and, more broadly, threats to our national security and interest.

--- Later in debate ---
Mike Reader Portrait Mike Reader (Northampton South) (Lab)
- View Speech - Hansard - - - Excerpts

I start with a story; it is a real story, but I have changed the names for obvious reasons. It was a Tuesday afternoon and I had a call from our CEO, David, who said to me, “Mike, I am jumping on a plane, but I need you to speak to a law firm we have been working with. This lady called Sandra will ring you from A&A law firm. I want you to speak to her. She will talk to you about a project we have been working on. Sorry I have not been able to read you in until now.” I think, “This is a bit strange. David’s a very busy man, but why would he ring me jumping on a plane?”

Sandra rang me, and it seemed pretty legit. We had a chat and it turns out we may know someone in common. I looked her up on LinkedIn: her firm is legit, she is there, and she has connections similar to mine. She tells me, “I need you to sign a non-disclosure agreement so we can talk to you about the opportunity we are working on with David.” I said that was fine and signed the NDA. I was sent a Teams link and joined a call with Sandra and some of her colleagues. Also on the call was David, my chief exec, whose signal was not good. He said, “Mike, I’m on a plane, but I’ve tried to join just to say thanks so much for being a part of this. We’re looking at an acquisition in your business area. I want you to work with A&A legal partners to ensure they have got the information they need. This is a real opportunity for us to grow. You know that we have been looking to grow the business.” Then his signal dropped off.

I carried on the conversation with Sandra and her partners. They started asking for information that perhaps they did not need—for example, about operational matters and how the business worked. They followed up with another call, in which they started asking for financial information about some of our clients. They followed up with another call in which they asked for financial information about the business. At that point, I thought, “I had better ring David and just make sure this is legit.” When I rang David, I found that he had no idea this was going on. Our business was being attacked through a deepfake intrusion. They had mirrored our chief exec, and used his voice for a call and his image for a Teams call. Had I—this story is actually about a friend of mine—not called my boss to say, “Is this legit?” they could have got away with goodness knows what. That seems quite far-fetched, but Arup, another big British firm, got done by a very similar deepfake scam; it lost £20 million to scammers.

I start with that real story about something that happened to one of my colleagues, because this Bill is really important. It is a framework Bill that will set out how we put in place better standards, procedures and controls, but actually where many businesses—be they data centre providers, managed service providers or those already covered by legislation—fall down is at the point when a human is in the loop. We heard from my hon. Friend the Member for Harlow (Chris Vince) about how to get the culture right, and how to ensure that people are considered in future legislation and guidance that will come off the back of the Bill. I wanted to open up and make that point, because through the Bill, we can do all we can on technical processes and procedures, but it is really important that we focus on the human in the loop and the human aspect, as that is often where these major attacks start.

I am really pleased to support the Bill. Cyber-security and cyber-crime impact our daily lives. I will not repeat the stats, which we have heard from many hon. Members on both sides of the House. They impact the businesses that support our economy, our public services and our banking sector—things that we use every day. It is therefore right that the Bill has been brought forward, although there was a considerable delay following the work done in 2022 by the previous Government. I am pleased that the Bill seems to have cross-party support.

The Bill recognises that attacks involve a wide range of methods, and may involve data centres, outsourced IT providers and complex supply chains working in the sector. That is critical for my constituents in Northampton, who are on the northbound data super-highway from London. In the last six months, we have heard announcements of over ÂŁ1 billion of investment in new data centres, in both the public and private sectors. I thank the Minister and his Department for all their hard work in securing that investment, which will create new jobs in my constituency. Without improved regulation and clarity, that investment remains slightly uncertain. The Bill will definitely improve that clarity and certainty for the sector, as well as for the many businesses in my constituency that rely on a managed service provider for their IT or provide data centres. That is particularly important for all hon. Members, because the control centre that looks after our security is in my constituency. That data security is therefore particularly important for our personal wellbeing.

I have also looked at this issue from the perspective of the many businesses in my constituency who use managed service providers for their IT. They include large businesses. In my previous business—a business of 7,000 or 8,000 people—an MSP provided our help desk; when I had a problem, I would ring it up. The inclusion of managed service providers is critical to give us better protection and improve standards and resilience, and therefore reduce burdens on the businesses that use them, particularly their cyber insurance costs. I have two asks of Government on this. First, as other Members have done, I ask that we do this proportionately, as change in this area may have a considerable impact on small businesses—both on their MSP costs and their direct costs. I also ask that we work hard to consider how the legislation works with international law, particularly as my experience is that a lot of MSPs, such as HelpDesk, use overseas workforces.

I welcome the stronger reporting requirements. I recognise the point made by the hon. Member for Bromsgrove (Bradley Thomas) about his ten-minute rule Bill on regulation and reporting. From a business perspective, as long as there is clarity—the Bill sets out that there will be greater clarity for business—we get honesty, trust and a business environment in which people understand what they have to do and when they have to do it. The Bill moves us towards that.

I also welcome the much stronger enforcement powers in the Bill. That sends a real message to criminals that there are significant risks to them. To businesses, I say that money talks, and when there are stronger enforcement risks to someone’s business, all of a sudden cyber-security ends up higher up the corporate risk register.

As the Bill is implemented, I ask for genuine consultation with industry. It is particularly important to note that this is a framework Bill.

Kit Malthouse Portrait Kit Malthouse (North West Hampshire) (Con)
- Hansard - - - Excerpts

The hon. Gentleman is making a very interesting and pertinent speech. I hope he will welcome the fact that the Bill strengthens the requirement on companies to not only look at prevention but have an adequate recovery plan. Does he think that there is adequate sanction in the Bill for those companies that are deemed not to have an adequate recovery plan? My reading is that regulators cannot necessarily fine for a negligent recovery. As the hon. Gentleman said, the human factor so often matters, but surely that matters as much in recovery as it does in prevention.

Mike Reader Portrait Mike Reader
- Hansard - - - Excerpts

I think the Bill goes some way on that, and it is clear that future legislation and guidance will start to frame those issues. There are other ways that we can drive businesses to improve their business resilience planning. It is part of the standard Government procurement process to require business continuity planning to be demonstrated, and many large businesses in our constituencies will be trying to transact with Government, whether local or national, with the NHS or others. Business resilience is also required at other times when the state interacts with business; I think of procurement particularly. My background is in one of those key areas.

I was just saying to the Minister that one concern I have is that this is a framework Bill. There is to be a lot of future guidance, so we need continued consultation—this message has been made by others as well—so that the standards are really clear. The legislation was getting quite messy. We want to make it a lot clearer. We want to be really clear with business, and we want to give organisations early notice, so that they can adjust, rather than springing this on business as we push to address a real threat that has been recognised right across industry.

I come back to my original point: we should consider the human in the loop. When we set guidance and requirements, we should look at how businesses think about the human aspect, as well as the technocratic solutions that would be in a business continuity plan or similar. This is a necessary Bill. I support its aims and focus. It signals real confidence to the market—to those already operating in it, and to those who are coming to invest in great places like Northampton, to build the data centres and other infrastructure that we need.

--- Later in debate ---
Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- View Speech - Hansard - - - Excerpts

First and foremost, I thank all Members for their contributions to the debate. I am glad that the House has welcomed the Bill, with deep expertise shown by Members on both sides of the House. Of course, Members have asked questions and I will try to share the Government’s approach. Before that, let me set out what is at stake.

The UK is the most cyber-attacked country in Europe. In 2024, more than 600,000 businesses were subject to a cyber-attack, the average cost of which was just over £190,000. The cost of cyber-attacks to UK businesses in aggregate is estimated to be £14.7 billion a year. The personal experience of my hon. Friend the Member for Northampton South (Mike Reader) is on my mind, as well the facts that my hon. Friend the Member for Warwick and Leamington (Matt Western) shared, such as the most common password in this country being “password”, and, indeed, the comments of my hon. Friend the Member for Mid Cheshire (Andrew Cooper) about Buffy the Vampire Slayer being an effective name deployed in some contexts. The combination of aggregate impacts and such personal experiences is the motivation for the Bill.

National security is the first responsibility of any Government. Cyber-threats have grown and the previous Government failed to move fast enough in the light of that. This Government are acting robustly to ensure that the British public are secure. The big message is, “Let’s ditch legacy systems and platforms and move to a more secure future.” We have done that by ditching the Conservative party; it is time to do it across our economy.

Let me deal with some of the themes that hon. Members raised, especially threats from AI that will emerge in future. The right hon. Member for Hertsmere (Sir Oliver Dowden) and my hon. Friend the Member for Congleton (Sarah Russell) mentioned those threats. AI will almost certainly continue to make elements of cyber-intrusion operations more effective and efficient, and cyber-threats more frequent and intense. That is why it is important that organisations take steps to bolster their cyber-defences. Under the Bill, organisations must have regard to the state of the art when maintaining the security of their network and information systems. That applies not only to cyber-defences, but to cyber-threats.

The right hon. Member for Hertsmere mentioned agentic AI, and I am conscious that it will be a particular risk. A significant source of mitigation must be the quality of our capability in the private sector, but also in the public sector. I pay tribute to the work of the AI Security Institute, which is right at the frontier of understanding the risk of agentic AI.

Several Members asked questions about scope. Of course, there is a significant risk across our economy, but we have chosen to focus, as NIS regulations have historically done, on essential services, the failure of whose network and information systems poses imminent threat to life to the British public. For that reason, the scope of the Bill is tight. That is not to say that other businesses should not do a great deal to protect themselves against cyber-attacks. However, the Government need assurances that the resilience to cyber-attack of essential services, the disruption of which would have the most profound consequences for public safety, national security and economic stability, is prioritised. Of course, businesses outside the scope of the Bill should make it a critical business priority to gain the same assurance without the need for as much Government intervention.

I am aware of the points made by my hon. Friends the Members for Lichfield (Dave Robertson) and for Warwick and Leamington, the Chair of the Joint Committee on the National Security Strategy, as well as by my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), the Chair of the Science, Innovation and Technology Committee, on Jaguar Land Rover. In that instance, the Government acted swiftly in exceptional circumstances by providing a ÂŁ1.5 billion loan guarantee to protect jobs, support businesses in the supply chain, and preserve this vital part of British industry. However, as the hon. Member for Exmouth and Exeter East (David Reed) noted, that should not be the expectation on Government; businesses must look to their own defences as a matter of corporate responsibility.

David Reed Portrait David Reed
- Hansard - - - Excerpts

Will the Minister give way on that point?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I might just make a bit of progress.

My hon. Friend the Member for Warwick and Leamington mentioned the food sector and food retailers, given recent attacks. Following the attacks on Marks & Spencer and Harrods, my hon. Friend the Minister for Food Security and Rural Affairs has written to and engaged deeply with the chief executive officers of major food retailers to advise on how the food sector can best protect itself from cyber-threats.

There is a broader question about sectors that are not regulated by this Bill, which has been raised by numerous Members from across the House. The fact that a sector is not regulated under the Bill does not mean that organisations in it cannot protect themselves against cyber-attacks. As I said, the Bill is not designed to cover every sector. Where sectors are covered by existing regulations, and where the Government do not consider it essential to regulate a sector through the Bill, we have taken a proportionate approach. Introducing blanket coverage for whole new sectors would create extensive regulatory burdens for more of our economy, stifling economic growth. At the same time, this Bill will enable the Government to bring more sectors into scope in the future, and to take swift action if national security is at risk.

The Bill sits alongside a series of actions that the Government have taken. I highlight in particular the fact that the Government have written to UK businesses and trade bodies across sectors to make sure that they are embedding cyber essentials across their supply chains, that they are making cyber-resilience a board-level priority, and that the NCSC’s early warning system and advice is heeded.

Both Conservative Front Benchers, the Liberal Democrat spokesperson, the hon. Member for Harpenden and Berkhamsted (Victoria Collins), and my hon. Friend the Member for Congleton spoke about coverage of the public sector. The public sector requires a significant step change in cyber and digital resilience. As has been mentioned numerous times, today we have published the Government’s cyber action plan, backed by £210 million of investment. The plan takes decisive action and holds Government Departments accountable for their cyber-security and resilience, as well as providing them with more direct support and services, and co-ordinating responses to fast-moving incidents.

I will take up the point made by the right hon. Member for New Forest East (Sir Julian Lewis) about the juiciness of local government digital provision. I share his enthusiasm. The Government’s cyber action plan takes into account wider Government and public sector coverage. In fact, it strengthens, clarifies and joins up how lead Government Departments hold the wider public sector, including local government, to account for improved and equivalent cyber-resilience.

I will make an observation about the points raised about not just reporting and assessment, but recovery and resilience. I flag to hon. Members from right across the House that our proposals for security and resilience requirements are being prepared for secondary legislation. They will align with the NCSC’s cyber assessment framework, which relates to effective response and recovery. A consultation is likely in the year ahead.

There were a series of questions and comments about regulators, and proportionate and effective regulation. The Bill allows regulators to make sure that they are well resourced to carry out their duties, and can charge reasonable fees to cover more of the cost of their activities under the regime. It will enhance the regulators’ impact by ensuring clearer information gateways and increased incident reporting, and establishes a unified set of objectives. The shadow Secretary of State talked about regulators not finding enough incidents, and about them finding too many, but I will let her work out the obvious contradiction in her position.

I say in response to the right hon. Member for Hertsmere that there is clear scope for AI capability to be used in triage. I very much hope that the reviews that the Secretary of State must undertake—they are embedded in the Bill’s requirements—will ensure that we look at efficient ways that regulators can do that.

The Chair of the Science, Innovation and Technology Committee, my hon. Friend the Member for Newcastle upon Tyne Central and West, made a point about the frequency and quality of the reviews of the regime in this Bill. The Department for Science, Innovation and Technology will monitor and evaluate the new framework in reviewing the effectiveness of the regime. The Bill requires the Secretary of State to lay before Parliament a report on the operation of certain NIS legislation, and to publish one at least every five years. It will be an extensive review, so we want to make sure that it is proportionate, rather than overly frequent. The commitments made by the Secretary of State to the Chair relate primarily to the Bill.

In response to the points made by my hon. Friends the Members for Warwick and Leamington, and for Mid Cheshire, about the possibility of a cross-sectoral cyber regulation approach, I flag that 12 regulators are responsible for enforcing this regime, because different sectors rely on different technologies, and have very different risk attitudes and responses to vulnerabilities. It is right that we use sector expertise to address sector-specific issues.

The hon. Member for Bognor Regis and Littlehampton (Alison Griffiths) made an appropriate point about enterprise IT and operational technology being differentiated. That is why we have used a sectoral lens; it is a very tractable way of differentiating the risk factors. We have set out a sectoral approach, but that does not preclude the Secretary of State from setting out, in a statement of strategic priorities, the possibility of co-ordination and information sharing across regulators.

In response to the points made by the Liberal Democrat spokesperson, the hon. Member for Harpenden and Berkhamsted, as well as the hon. Member for Exmouth and Exeter East, about making sure that incident thresholds are clear and proportionate, the 24-hour light-touch notification requirement is proportionate. All that is needed is information alerting the regulator and the National Cyber Security Centre to the nature of the incident; the system does not rely on over-regulation. With the exception of data centres, reportable incidents that affect operators of essential services would need to have affected the operation of significant network and information systems right across the entity, and to have a significant national security impact. That is extremely unlikely to include minor matters, such as the receipt of a phishing email.

The Chair of the Treasury Committee, my hon. Friend the Member for Hackney South and Shoreditch (Dame Meg Hillier), made a point about financial services organisations, and I respond simply by flagging that UK financial services are resilient against cyber-threats. The threats are of course growing, but the regulatory approach taken by the Financial Conduct Authority, the Prudential Regulation Authority and the Bank of England were some of the sources for the approach we have taken in this Bill. Regulatory overlap was mentioned; this Government will make sure that businesses that have to navigate multiple regulatory frameworks with multiple services will face minimal burdens. We will work with our regulators and international authorities, including those in the EU, on the implementation of the Bill.

Turning to the impact on business, and the Bill ensuring a proportional approach to security, the Government will regulate only when that is necessary to protect our economy and our country from serious harm. A single attack can disrupt hospitals, transport and vital services, putting lives at risk, and we will not gamble with our economy or our people’s safety. The cost of doing nothing is, of course, too great. As I have mentioned, cyber-attacks drain almost £15 billion a year from UK businesses. At the same time, this Bill takes a proportionate approach to ensuring the safety of British people.

Board-level responsibility was brought up by a number of Members from across the House. I simply say that all business leaders need to take responsibility for their organisation’s cyber-resilience. On 13 October last year, the Government wrote to chief executives, requesting that they make cyber-security a board-level responsibility. The Government’s new cyber governance code of practice focuses on the governance of cyber risk specifically, and we will consider using secondary legislation to require companies to clarify their cyber-security responsibilities at board level.

A number of Members raised the issue of the effect on small and medium-sized businesses. Growth is the Government’s No. 1 mission, and small businesses are the engine room of that growth. They provide many of our most important services. That is exactly why small and, particularly, micro-sized managed or digital services are exempt from regulation under this Bill. They can be regulated only if they are designated as critical suppliers, and there will be an extremely high bar for designation. That should answer the question from my hon. Friend the Member for Mid Cheshire about companies meeting the bar for designation. A point was made about the ability of small businesses to tell quickly whether they are in scope. The regulator will complete an investigation process, which will include giving notices and having consultations with relevant businesses, prior to confirming whether an organisation meets the criteria for being in scope. That process needs to be robust, but we hope to make sure that those regulatory processes are proportionate, too.

I turn to a critical question from my hon. Friend the Member for Milton Keynes Central (Emily Darlington), my right hon. Friend the Member for Oxford East (Anneliese Dodds) and the hon. Member for Ceredigion Preseli (Ben Lake) on long-term sovereignty and capability in this country. Over the last decade and a half, the Conservative party in government sold this country’s strategic leverage over the primary sector, software and digital infrastructure. We will not repeat that mistake. We have already committed, right across the board, to extremely robust digital sovereignty measures. We have committed £500 million to a sovereign AI fund. We have made sure that there are tens of billions of pounds pouring into this country as capital infrastructure for AI, and British firms like Nscale are right at the heart of that. There is an advanced market commitment to cloud compute, to make sure that British companies are right at the heart of the provision of core infrastructure in future. Through the British Business Bank, we are committing tens of billions.

David Reed Portrait David Reed
- Hansard - - - Excerpts

We talk about sovereign capability, but how can we have fully sovereign capability when we do not own the means of production of most advanced chips?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I point the hon. Member to a thriving compound semiconductor cluster in south Wales, as well as chip manufacturing companies. If he doubts how advanced Arm is—the primary chip design company in the world—I would advise him to read a primer on the chip company supply chain.

The Government are pursuing a clear sense of digital sovereignty. On China, I flag that we are taking stronger action to protect our national security, including our critical national infrastructure, as well as making sure that, where appropriate, we look for opportunities for co-operation. The national security strategy, the independent review of state threat legislation and our new powers on counter-terrorism will make sure that we do that.

I am conscious that I am testing your patience, Madam Deputy Speaker, so I will simply flag a final point. The “whole society” approach was mentioned by a number of right hon. and hon. Members. We are making a series of investments in skills to ensure that young people are inspired to pursue careers in cyber-security. On the points made by my hon. Friends the Members for South East Cornwall (Anna Gelderd), and for Portsmouth North (Amanda Martin), I am deeply passionate about ensuring that young people—young women and girls, in particular—in their areas, Wales and across the country pursue thriving careers in cyber-security.

National security is the first responsibility of this Government. The Bill could not be more necessary for confronting developments in global cyber-threat. I thank all right hon. and hon. Members for their engagement with the Bill as it progresses. I encourage them to engage deeply. To all rogue organisations with hackers at the helm—I do not just mean the Conservative party—I say this: your time is up. With this Bill, we will make sure that the British public are secure.

Question put and agreed to.

Bill accordingly read a Second time.

Cyber Security and Resilience (Network and Information Systems) Bill: Programme

Motion made, and Question put forthwith (Standing Order No. 83A(7)),

That the following provisions shall apply to the Cyber Security and Resilience (Network and Information Systems) Bill:

Committal

(1) The Bill shall be committed to a Public Bill Committee.

Proceedings in Public Bill Committee

(2) Proceedings in the Public Bill Committee shall (so far as not previously concluded) be brought to a conclusion on Thursday 5 March 2026.

(3) The Public Bill Committee shall have leave to sit twice on the first day on which it meets.

Consideration and Third Reading

(4) Proceedings on Consideration shall (so far as not previously concluded) be brought to a conclusion one hour before the moment of interruption on the day on which those proceedings are commenced.

(5) Proceedings on Third Reading shall (so far as not previously concluded) be brought to a conclusion at the moment of interruption on that day.

(6) Standing Order No. 83B (Programming committees) shall not apply to proceedings on Consideration and Third Reading.

Other proceedings

(7) Any other proceedings on the Bill may be programmed.—(Jade Botterill.)

Question agreed to.

Cyber Security and Resilience (Network and Information Systems) Bill (Money)

King’s recommendation signified.

Motion made, and Question put forthwith (Standing Order No. 52(1)(a)),

That, for the purposes of any Act resulting from the Cyber Security and Resilience (Network and Information Systems) Bill, it is expedient to authorise the payment out of money provided by Parliament of:

(1) any expenditure incurred under or by virtue of the Act by the Secretary of State or another public authority, and

2) any increase attributable to the Act in the sums payable under or by virtue of any other Act out of money so provided.—(Jade Botterill.)

Question agreed to.

Cyber Security and Resilience (Network and Information Systems) Bill (Ways and Means)

Motion made, and Question put forthwith (Standing Order No. 52(1)(a)),

That, for the purposes of any Act resulting from the Cyber Security and Resilience (Network and Information Systems) Bill, it is expedient to authorise:

(1) the imposition of charges under or by virtue of the Act; and

(2) the payment of sums into the Consolidated Fund.—(Jade Botterill.)

Question agreed to.

Cyber Security and Resilience (Network and Information Systems) Bill (Carry-over)

Motion made, and Question put forthwith (Standing Order No. 80A(1)(a)),

That if, at the conclusion of this Session of Parliament, proceedings on the Cyber Security and Resilience (Network and Information Systems) Bill have not been completed, they shall be resumed in the next Session.—(Jade Botterill.)

Question agreed to.

Cyber Security and Resilience (Network and Information Systems) Bill (First sitting)

(Limited Text - Ministerial Extracts only)

Read Full debate
Committee stage
Tuesday 3rd February 2026

(7 months, 4 weeks ago)

Public Bill Committees
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 Read Hansard Text Amendment Paper: Public Bill Committee Amendments as at 3 February 2026 - (3 Feb 2026)

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

Tim Roca Portrait Tim Roca (Macclesfield) (Lab)
- Hansard - - - Excerpts

Q This question is mainly for Jen. Your colleague Jamie MacColl has made a series of forthright comments about the Bill and compared it to NIS2. How does the Bill compare to legislation worldwide?

Jen Ellis: As a starting point, I will clarify that I am a fellow at RUSI. I work closely with Jamie, but I do not work for RUSI. I also take no responsibility for Jamie’s comments.

On the comparisons, David alluded to the fact that Europe is a little bit ahead of us. NIS2, its update to NIS1, came into force three years ago with a dangling timeline: nations had until October 2024 to implement it. My understanding is that not everybody has implemented it amazingly effectively as yet. There is some lag across the member states. I do not think we are too out of scope of what NIS2 includes. However, we are talking about primary legislation now; a lot of the detail will be in the secondary legislation. We do not necessarily know exactly how those two things will line up against each other.

The UK seems to be taking a bit of a different approach. The EU has very specifically tried to make the detail as clearly mandated as possible, because it wants all the member states to adopt the same basis of requirements, which is different from NIS1, whereas it seems as though the UK wants to provide a little bit of flexibility for the regulators to “choose their own adventure”. I am not sure that is the best approach. We might end up with a pretty disparate set of experiences. That might be really confusing for organisations that are covered by more than one competent authority.

The main things that NIS2 and CSRB are looking at are pretty aligned. There is a lot of focus on the same things. It is about expanding scope to make sure that we keep up with what we believe “essential” now looks at, and there is a lot of focus on increased incident reporting and information sharing. Again, the devil will be in the detail in the secondary legislation.

The other thing I would say goes back to the earlier question about what is happening internationally. The nations that David mentioned, like Australia or the jurisdiction around the EU, are really proactive on cyber policy—as is the UK. They are taking a really holistic view, which David alluded to in his introduction, and are really looking at how all the pieces fit together. I am not sure that it is always super clear that the UK is doing the same. I think there is an effort to do so, and UK policymakers are very proactive on cyber policy and are looking at different areas to work on, but the view of how it all goes together may not be as clear. One area where we are definitely behind is legislating around vendor behaviour and what we expect from the people who are making and selling technology.

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- Hansard - - - Excerpts

Q Thank you very much to both of you for your insights today. The question on my mind is related, in part, to the point that Jen raised. There are a range of levers at the Government’s disposal in thinking about and acting on cyber-security. I am interested in your thoughts on which parts of the economy ought to be in the scope of regulation and legislative measures, and where effective measures that sit outside of regulation and legislation—guidance being one from a range of non-regulatory measures—would be better suited.

Jen Ellis: Again, that is a hugely complex question to cover in a short amount of the time. One of the challenges that we face in UK is that we are a 99% small and mediums economy. It is hard to think about how to place more burdens on small and medium businesses, what they can reasonably get done and what resources are available. That said, that is the problem that we have to deal with; we have to figure out how to make progress.

There is also a challenge here, in that we tend to focus a lot on the behaviour of the victim. It is understandable why—that is the side that we can control—but we are missing the middle piece. There are the bad guys, who we cannot control but who we can try to prosecute and bring to task; and there are the victims, who we can control, and we focus a lot on that—CSRB focuses on that side. Then there is the middle ground of enablers. They are not intending to be enablers, but they are the people who are creating the platforms, mediums and technology. I am not sure that we are where we could be in thinking about how to set a baseline for them. We have a lot of voluntary codes, which is fantastic—that is a really good starting point—but it is about the value of the voluntary and how much it requires behavioural change. What you see is that the organisations that are already doing well and taking security seriously are following the voluntary codes because they were already investing, but there is a really long tail of organisations that are not.

Any policy approach, legislation or otherwise, comes down to the fact that you can build the best thing in the world, but you need a plan for adoption or the engagement piece—what it looks like to go into communities and see how people are wrestling with this stuff and the challenges that are blocking adoption. You also need to think about how to address and remove those challenges, and, where necessary, how to ensure appropriate enforcement, accountability and transparency. That is critical, and I am not sure that we see a huge amount of that at the moment. That is an area where there is potential for growth.

With CSRB, the piece around enforcement is going to be critical, and not just for the covered entities. We are also giving new authorities to the regulators, so what are we doing to say to them, “We expect you to use them, to be accountable for using them and to demonstrate that your sector is improving”? There needs to be stronger conversations about what it looks like to not meet the requirements. We should be looking more broadly, beyond just telling small companies to do more. If we are going to tell small companies to do more, how do we make it something that they can prioritise, care about and take seriously, in the same way that health and safety is taken seriously?

David Cook: To achieve the outcome in question, which is about the practicalities of a supply chain where smaller entities are relying on it, I can see the benefit of bringing those small entities in scope, but there could be something rather more forthright in the legislation on how the supply chain is dealt with on a contractual basis. In reality, we see that when a smaller entity tries to contract with a much larger entity—an IT outsourced provider, for example—it may find pushback if the contractual terms that it asks for would help it but are not required under legislation.

Where an organisation can rely on the GDPR, which has very specific requirements as to what contracts should contain, or the Digital Operational Resilience Act, which is a European financial services law and is very prescriptive as to what a contract must contain, any kind of entity doing deals and entering into a contract cannot really push back, because the requirements are set out in stone. The Bill does not have a similar requirement as to what a contract with providers might look like.

Pushing that requirement into the negotiation between, for example, a massive global IT outsourced provider and a much smaller entity means either that we will see piecemeal clauses that do not always achieve the outcomes you are after, or that we will not see those clauses in place at all because of the commercial reality. Having a similarly prescriptive set of requirements for what that contract would contain means that anybody negotiating could point to the law and say, “We have to have this in place, and there’s no wriggle room.” That would achieve the outcome you are after: those small entities would all have identical contracts, at least as a baseline.

Emily Darlington Portrait Emily Darlington (Milton Keynes Central) (Lab)
- Hansard - - - Excerpts

Q I want to go back to basics and get a bit of insight from you. What cyber risks are businesses currently facing, and how do you feel the Bill addresses those risks?

David Cook: The original NIS regulations came out of a directive from 2016, so this is 10 years old now, and the world changes quickly, especially when it comes to technology. Not only is this supply chain vulnerability systemic, but it causes a significant risk to UK and global businesses. Ransomware groups, threat actors or cyber-criminals—however you want to badge that—are looking for a one-to-many model. Rather than going after each organisation piecemeal, if they can find a route through one organisation that leads to millions, they will always follow it. At the moment, they are out of scope.

The reality is that those organisations, which are global in nature, often do not pay due regard to UK law because they are acting all over the world and we are one of many jurisdictions. They are the threat vector that is allowing an attack into an organisation, but it then sits with the organisations that are attacked to deal with the fallout. Often, although they do not get away scot-free, they are outside legislative scrutiny and can carry on operating as they did before. That causes a vulnerability. The one-to-many attack route is a vulnerability, and at the moment the law is lacking in how it is equipped to deal with the fallout.

Jen Ellis: In terms of what the landscape looks like, our dialogue often has a huge focus on cyber-crime and we look a lot at data protection and that kind of thing. Last year, we saw the impact of disruptive attacks, but in the past few years we have also heard a lot more about state-sponsored attacks.

I do not know how familiar everyone in the room is with Volt Typhoon and Salt Typhoon; they were widespread nation-state attacks that were uncovered in the US. We are not immune to such attacks; we could just as easily fall victim to them. We should take the discovery of Volt Typhoon as a massive wake-up call to the fact that although we are aware of the challenge, we are not moving fast enough to address it. Volt Typhoon particularly targeted US critical infrastructure, with a view to being able to massively disrupt it at scale should a reason to do so arise. We cannot have that level of disruption across our society; the impacts would be catastrophic.

Part of what NIS is doing and what the CSRB is looking to do is to take NIS and update it to make sure that it is covering the relevant things, but I also hope that we will see a new level of urgency and an understanding that the risks are very prevalent and are coming from different sources with all sorts of different motivations. There is huge complexity, which David has spoken to, around the supply chain. We really need to see the critical infrastructure and the core service providers becoming hugely more vigilant and taking their role as providers of a critical service very seriously when it comes to security. They need to think about what they are doing to be part of the solution and to harden and protect the UK against outside interference.

David Cook: By way of example, NIS1 talks about reporting to the regulator if there is a significant impact. What we are seeing with some of the attacks that Jen has spoken about is pre-positioning, whereby a criminal or a threat actor sits on the network and the environment and waits for the day when they are going to push the big red button and cause an attack. That is outside NIS1: if that sort of issue were identified, it would not be reportable to the regulator. The regulator would therefore not have any visibility of it.

NIS2 and the Bill talk about something being identified that is caused by or is capable of causing severe operational disruption. It widens the ambit of visibility and allows the UK state, as well as regulators, to understand what is going in the environment more broadly, because if there are trends—if a number of organisations report to a regulator that they have found that pre-positioning—they know that a malicious actor is planning something. The footprints are there.

--- Later in debate ---
None Portrait The Chair
- Hansard -

The witnesses need not feel obliged to answer every question; if colleagues could direct their questions to individual witnesses, we will get through quicker.

Stuart McKean: I think that the MSP definition is quite broad at the moment, so adding some clarity to it will help. At the moment, the key definition of an MSP is based on size, and whether you are a small, medium, large or even microenterprise. The reality is that only11%, I think, of MSPs are the large and medium-sized enterprises that are going to fall in scope of the Bill as a managed service provider. Although the definition might be quite broad, the clarity on the size of MSP is actually quite particular, and you will lose a lot of MSPs that will not be in scope.

Jill Broom: Although some of our members are content with the definition of managed service provider, others feel that, as Stuart said, it is too broad. It continues to cause a little bit of confusion, since it is likely to encompass virtually any IT service. Probably some further work needs to be done and further consultation. There will be some further detail in the secondary legislation around that definition. I wanted to highlight that a lot of detail is coming in secondary legislation, which can make it quite difficult to scrutinise the primary legislation. A broad call-out for ensuring mandatory and meaningful consultation on that secondary legislation and associated guidance would be really welcome.

We are already working with the Bill team to put some of the pre-consultation engagement sessions in place, but we would call for the consultation to be brought forward to help us to understand some of the detail. The consultation period on the secondary legislation is currently estimated to happen towards the end of the summer, but we would like that to be brought forward, where possible. That consultation is going to cover a lot of detail, so it needs to be a substantial amount of time to allow us to comment. We are keen to be involved in that process as much as possible.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Q Thank you all very much for making time. I have an implementation-focused question, perhaps directed at Stuart, but open to all. In practice, it would be helpful to understand how frequent is the case that a single company might provide multiple of the possible services in scope: MSP services, cloud hosting, data centre support and cyber-security services. What ability might we have to identify parts of an organisation that are in scope for particular bits and those that are not?

Stuart McKean: You are going to hear the word “complex” a lot in this session. It is hugely complex. I would almost say that everyone likes to dabble. Everyone has little bits of expertise. Certain companies might be cloud-focused, or focused on toolsets; there are a whole range of skillsets. Of course, the larger organisations have multiple teams, multiple scopes and much more credibility in operating in different areas. As that flows down the supply chain, in many cases it becomes more difficult to really unpick the supply chain.

For example, if I am a managed service provider delivering a cloud service from a US hyperscaler, who is responsible? Am I, as the managed service provider, ultimately on the hook, even though I might be using a US-based hyperscaler? That is not just to pick on the hyperscalers, by the way—it could be a US software-based system or a set of tools that I am using. There are a whole range of parts that need to become clearer, because otherwise the managed service community will be saying, “Well, is that my responsibility? Do I have to deliver that?”.

You are then into the legislation side with procurement, because procurement will flow down. Although I might not be in scope directly as a small business, the reality is that the primes and Government Departments that are funding work will flow those requirements down on to the smaller MSPs. Although we might not be in scope directly, when it comes to implementing and meeting the legislation, we will have to follow those rules.

Allison Gardner Portrait Dr Gardner
- Hansard - - - Excerpts

Q It is interesting that you mentioned the complexity and skilled teams. Sanjana, you talked about the need for more skill and responsibility, and how distributed responsibility across supply chains is a big deal. That comes down to a duty of care on people who are procuring these things. The annual cyber security breaches survey found that board-level responsibility for cyber has declined in recent years. What explains that, and how could it be improved? As a quick supplementary question, do you think there should be a statutory duty for companies to have a board member responsible for cyber risk? Jill, I will go to you first.

Jill Broom: With the board, historically, cyber has not been viewed as a business risk, but as a technical problem to be addressed by the technical teams, instead of being a valuable, fundamental enabler of your business and a commercial advantage as well, because you are secure and resilient. That has been a problem, historically. It is about changing that culture and thinking about how we get the boards to think about this.

I think a fair amount of work is happening; I know the Government have written to the FTSE 350 companies to ask them to put the cyber governance code of practice into play. That is just to make cyber a board-level responsibility, and also to take account of things such as what they need to do in their supply chain.

--- Later in debate ---
None Portrait The Chair
- Hansard -

I should say to the witnesses: do not feel obliged to answer each question if you do not feel that you have anything material to add.

Matt Houlihan: It is very tempting to answer the question on AI, but thank you for the question on managed service providers. It is right that managed service providers are looked at in this Bill. An increasing amount of the work of managing IT services is clearly now outsourced to managed service providers. There needs to be some scrutiny and some baseline of cyber-security with those. I would say a couple of things on what guidance is needed. We broadly support the definition in the Bill. I appreciate the comments in the previous session that suggested that the definition was a little too broad and could be refined, which I think is fair, but when you compare the definition in the CSRB with the definition of managed service providers used in the NIS2 legislation, a couple of bits of clarity are provided in the CSRB. First, the managed service provider needs to provide an

“ongoing management of information technology systems”.

We feel that word “ongoing” is quite important. Secondly, it has to involve

“connecting to or…obtaining access to network and information systems relied on by the customer”.

We feel that

“connecting to or…obtaining access to”

the network is an important part of the definition that should be put forward. One area where more tightness can be provided is where, in the Bill, there is a non-exhaustive list of activities that an MSP could be involved in, such as

“support and maintenance, monitoring, active administration”.

The Bill then says, “or other activities”, which adds quite a bit of uncertainty on what is and is not an MSP.

The other area I would like to highlight and link to Ben’s answer on AI is that the “active administration” activity raises a question about the extent to which AI-enabled managed services would come under that definition. I am sure that lots of managed service providers will use AI more and more in the services that they provide to their end customers; to what extent does “active administration” involve an AI-related service?

To end on that specific question, the Information Commissioner’s Office will, I believe, issue guidance for managed service providers once the Bill is passed. That guidance will be the critical thing to get right, so there should be consultation on it, as my colleague from techUK suggested earlier. I would also suggest that that guidance cannot be a simple check-box list of things that have to be done. We should shift our thinking to have more of an ongoing appreciation of what cyber-security involves in practice for MSP or other regulated entities under the Bill. Making sure there is an ongoing process and that there is effective enforcement will be important.

Chris Anley: On the NAO report , the cyber action plan and public sector cyber-security, you are absolutely right to point out that the NAO report identifies serious issues. The Government recently acknowledged that they are likely to miss their 2030 cyber-resilience targets. It is also important to point out that the cyber action plan lays out an approach with many very positive elements such as an additional ÂŁ210 million in central funding. There are many benefits to that, including a centralised provision of services at scale, a concentration of expertise and a reduction of costs.

Then there are other broader initiatives in the cyber action plan. The UK software security code of practice, which has been mentioned several times in these sessions, is a voluntary code that organisations can use as a tool to secure their supply chain. Cisco and NCC Group are ambassadors for that scheme and voluntarily comply with it, and it improves our own resilience.

Whether the cyber action plan goes far enough is a very difficult question. The NAO report also points out the extreme complexity of the situation. Within the budgetary constraints, I think it is fair to say that the steps in the plan seem reasonable, but there is a broader budgetary conversation to be had in this area. Two of the most significant issues identified in the report are the skills shortage, which has come up in these sessions—almost a third of cyber-security posts in Government are presently unfilled, which is dangerous—and the fact that Departments rely on vulnerable, outdated legacy IT systems, which may be the cause of an incident in their own right and would certainly make an incident much more severe were one to occur. The problem is that those are both largely budgetary issues. Successive Governments have obviously focused on delivering taxpayer value, as they should—we are all taxpayers—but over a period of a decade or more, that has led to a position where Departments find it difficult to replace legacy IT systems and fill these high-skill, high-cost cyber-security positions. There is very much a broader discussion to be had, as has been raised in these sessions, about where we should be in terms of the budget. You are absolutely right to raise the public sector issues. Although the Bill focuses on the private sector, the public sector obviously must lead by example.

Dr Ian Levy: We think the current definitions of critical suppliers are probably overly broad and risk bringing in SMEs, when you really do not want to do that. That said, we need to think about the transitive nature of supply chains. With previous regulations that talk about cyber-security, we have seen a flow-down of requirements through contracting chains. There is a question about how far it is reasonable to go down those contracting chains. In my experience, the value of the contract and the potential impact are not necessarily correlated. We certainly saw that when we were giving evidence for the Telecommunications (Security) Act 2021.

There is a real question about how you define what supply chain you mean. You mentioned that AWS has a complex supply chain. We certainly do—it is astoundingly complex—but the important thing is that we control the really important parts of that. For example, we build our own central processing units, graphics processing units, servers, data centres and so on. The question then becomes: how does that translate out to customers? If a customer is using a partner’s service running on AWS, where does the liability accrue? I do not think that is adequately covered in the Bill.

In terms of certainty and foreseeability, the Bill as it stands admits a single entity being regulated multiple times in multiple different ways. We are subject today to at least four different sets of regulations and regulators. Some of them conflict, and some of them are ambiguous. As this expands out, a single reporting regime—a lead regulator model—would take some of that ambiguity away so that you have more foreseeability and certainty about what you are trying to do.

There are things in the current drafting of the Bill that we think need some consultation. There are things in primary legislation, such as the Secretary of State’s powers, that seem to be unbounded—that is probably the best way to describe it—and that seems dangerous. We understand the necessity for powers around national security, but we think there need to be some sort of safeguards and consultation about how they are used in practice. For any multinational company, something that is effected in the UK is likely to affect all our customers, so some real constraint is needed around that.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Q One of the themes already emerging in the conversation and in the wider public debate is that, on one line of thought, the right framework is that the law should focus on outcomes, principles and responsibilities, and then delegate specificity to both agile definition over time and specific expertise in sectors. An alternative view says that in looseness there is uncertainty, and we in Parliament should prescribe activity and impact thresholds and what companies should be doing. I am interested in areas across the board where you think prescription is a helpful way to go, as well as in your general experience of the core way and framework through which we have regulated a number of these activities, which is to rely on the agility and expertise in particular sectors, rather than the prescription of activity in primary legislation.

Chris Anley: By our calculation, as you say, the number of organisations that fall under the scope of the Bill in terms of the Government’s impact assessment is 0.1% of the private sector, which is one one-hundredth of the tip of the iceberg. We are going to have to adopt a whole-of-economy approach if we are going to secure the UK—we have already talked about the public sector issues.

On the Bill itself, we have three main comments. First, the secondary legislation forms the bulk of the technical measures, so we are calling for early consultation on that. Secondly, the Bill imposes additional reporting obligations, adding to an already complicated situation for reporting cyber-incidents in the UK. The reporting obligations trigger at a time of great complexity for an organisation, so we are calling for a single point of contact for reporting all cyber-security incidents in the UK and a single timeline. That may sound like a big ask—an impossible dream. Australia has already done it, and the EU is in the process of doing it in its digital omnibus streamlining package.

Finally, in terms of cyber professionals, the passage of a cyber-security Bill through Parliament is a golden opportunity to address the serious problems with the Computer Misuse Act 1990. Cyber professionals who are defending the UK cannot currently do so without risking criminal prosecution. We cannot carry out basic identification and verification actions without potentially committing the offence of unauthorised access to computer material, because a ransomware gang, for example, is unlikely to give us authorisation to identify the command and control system they are using to attack the UK.

We support the CyberUp campaign, which is proposing an amendment to the Computer Misuse Act to provide a statutory defence, resting on four strong safeguarding principles. We believe that that would help to protect our defenders while maintaining the integrity of the law. Based on the campaign’s research into the size of the cyber-security industry in the UK, the amendment would not only help to prevent incidents and mitigate incidents in progress, but add 9,500 highly skilled jobs and over £2.5 billion in revenue to the UK economy. Other nations are already benefiting from this type of safeguard, including our oldest ally, Portugal, which has implemented them in its recent amendments to NIS2, which is the exact legislative equivalent of the process we are in today. In summary, please help us to defend the UK by protecting our defenders.

Dr Ian Levy: To follow up on what Chris says, we strongly agree on early consultation on the technical detail of the secondary legislation. Somebody said in the previous session that, in security, the devil is always in the detail. Well-meaning text can be massively misinterpreted. We need to be very careful about that, so wide, early consultation is key.

On incident reporting, I will make two points. Chris made the point that when you are being asked to report, you are at your most desperate, because you have just found out that you have been attacked and you do not know what is going to happen. A lot of legislation accidentally ignores the victim. When we set up the NCSC, one of the primary things was that we were there to support the victims. I urge you not to lose sight of that. Absolutely, go after and find the culprits later, but in the moment, the victims are absolutely key to this.

The second part of that, about a single reporting timeline and a single reporting route, is that it is not just good for the victims but the only way that we generate strategic intelligence. That is one of the things that is missing in the UK—and has been for decades. We have five, six or seven different reporting portals that all characterise things differently and take different types of information, and bringing them together to have a single picture about the actual threat to the UK is incredibly difficult. A single reporting forum could fix that.

Ben Lyons: I might distinguish between what organisations need to do and whether organisations are in scope. In terms of what they need to do, the outcomes-based approach is sensible. If you think about when the Johnson Government were consulting on the measures that would go on to form this Bill, that was a time when ChatGPT had not been invented and the geopolitical environment was very different. The world is moving fast, and I think that the cyber assessment framework is a good starting place for what a code of practice could look like, because it is already understood by industry and is outcomes-driven.

I agree with the previous comments about incident reporting. I think that there is a lot of merit in the suggestion around a shared portal so that it is easier to report incidents in that moment of dealing with a cyber-attack. Within the regime as envisaged, probably the most important bit with reference to reporting is about improving that early clarity and visibility for the NCSC so that they can help. That is probably where I would place the emphasis, more than on regulators having that information within 24 hours. In that context, an approach that recognises best efforts in that first 24 hours but is focused on tackling the problem will be important for dealing with the issue.

On the supply chain, I would say—and we have heard about this before—that there could be more clarity there in terms of who would be in scope for designated suppliers. Thinking a bit around both systemic dependency and the potential for wider disruption would be important factors to give it more clarity.

Matt Houlihan: To round off the responses, on the question about finding the balance between specificity and agility, the Bill does a reasonable job at that. We can totally see the need to keep some of the doors open, because not only is the nature of the threat changing rapidly but the nature of technology—and of our capabilities to defend—is changing as well. We have already talked about AI, and we have lots of quantum research taking place as well that will have a big bearing on cyber-security.

It is right that the Bill has some agility in it, but it is clear from the responses today that there is a need to tighten it up in certain places. We talked about incident reporting, and having a simpler, more co-ordinated system for regulated entities to work with so that that reporting process is easier. The definition of “incident” itself needs to be looked at, we believe. The idea of an instance not only having, but being capable of having, an adverse effect on information systems opens the door very widely to lots of potential incidents that may need to be reported on. Having a tighter definition there would be very useful.

To touch on the point about Secretary of State powers, we feel that the door is a little bit too wide. If you look at legislation such as Australia’s cyber-security legislation from 2018, the Security of Critical Infrastructure Act, that also has some good Secretary of State powers, but there are lots of guardrails contained in it that make it clear that it is a power of last resort, where the entity is unwilling or unable to carry out the remedial action itself. There are also other guardrails contained in that legislation. We urge the Committee and the Government to look at that Act and take inspiration from it to think about where those guardrails could be worked into the UK law.

None Portrait The Chair
- Hansard -

Four colleagues wish to ask questions, and they have only 20 minutes in which to ask them, so I appeal for brevity, both in the questions and, if you do not mind, in the answers.

Cyber Security and Resilience (Network and Information Systems) Bill (Second sitting)

(Limited Text - Ministerial Extracts only)

Read Full debate
Committee stage
Tuesday 3rd February 2026

(7 months, 4 weeks ago)

Public Bill Committees
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 Read Hansard Text Amendment Paper: Public Bill Committee Amendments as at 3 February 2026 - (3 Feb 2026)

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

David Chadwick Portrait David Chadwick
- Hansard - - - Excerpts

Q Thank you for joining us. You mentioned frauds. It is a fact that criminals across the world are targeting British citizens every day. In Dyfed-Powys, over ÂŁ500,000 was lost to online fraud in 2023-24, and elderly victims are losing ÂŁ7,900 a day to fraud. Clearly, these attacks are coming from all over the world. Interpol recently arrested over 800 members of a global criminal network based in Nigeria. From your perspective, how effectively are UK police forces currently able to work with international partners to investigate and prosecute overseas criminals? What additional support from the Government would most improve your ability to mitigate online fraud from overseas?

DCS Andrew Gould: That is a really good question. The international jurisdiction challenge for us is huge. We know that is where most of the volumes are driven from, and obviously we do not have the powers to just go over and get hold of the people we would necessarily want to. You will not be surprised to hear that it really varies between jurisdictions. Some are a lot more keen to address some of the threats emanating from their countries than others. More countries are starting to treat this as more of a priority, but it can take years to investigate an organised crime group or a network, and it takes them seconds to commit the crime. It is a huge challenge.

There are two things that we could do more of better—these are things that are in train already. If you think about the wealth of cyber-crime, online fraud and so on, all the data, and a lot of the skills and expertise to tackle that sit within the private sector, whereas in law enforcement, we have the law enforcement powers to take action to address some of it.

With a recent pilot in the City funded by the Home Office, we have started to move beyond our traditional private sector partnerships. We are working with key existing partners—blockchain analytic companies or open-source intelligence companies—and we are effectively in an openly commercial relationship; we are paying them to undertake operational activity on our behalf. We are saying, “Company a, b or c, we want you to identify UK-based cyber-criminals, online fraudsters, money-laundering and opportunities for crypto-seizure under the Proceeds of Crime Act 2002”. They have the global datasets and the bigger picture; we have only a small piece of the puzzle. By working with them jointly on operations, they might bring a number of targets for us, and we can then develop that into operational activity using some of the other tools and techniques that we have.

It is quite early days with that pilot, but the first investigation we did down in the south-east resulted in a seizure of about ÂŁ40 million-worth of cryptocurrency. That is off a commercial contract that cost us a couple of hundred grand. There is potential for return on investment and impact as we scale it up. It is a capability that you can point at any area of online threat, not just cyber-crime and fraud, so there are some huge opportunities for it to really start to impact at scale.

One of the other things we do in a much more automated and technical way—again funded by the Home Office—is the replacement of the Action Fraud system with the new Report Fraud system. That will, over the next year or so, start to ingest a lot of private sector datasets from financial institutions, open-source intelligence companies and the like, so we will have a much broader understanding of all those threats and we will also be able to engage in takedowns and disruptions in an automated way at scale, working with a lot of the communication service providers, banks and others.

Instead of the traditional manual way we have always been doing a lot of that protection, we can, through partnerships, start doing it in a much more automated and effective way at scale. Over time, we will be able to design out and remove a lot of the volume you see impacting the UK public now. That is certainly the plan.

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- Hansard - - - Excerpts

Q One of the things that we have heard over the course of the day is that the Bill is just one of a range of different ways in which public authorities engage with companies on cyber-security and resilience. I am interested in hearing about the impact the Police CyberAlarm programme has had on the cyber-security and resilience of organisations. What would you like to see going forward?

DCS Andrew Gould: I love the fact that you have heard of it. One of the things that we struggle with is promoting a lot of these initiatives. Successive Governments actually deserve a lot of credit for the range of services that are provided. We aspire to be a global cyber-power, and in many ways we are. When you look at the range of services, tools, advice and guidance that organisations or the public can get, there is quite a positive story to tell there. I think we struggle to bring that into one single narrative and promote it, which is a real challenge. People just do not know that those services are there.

For those who are not familiar with Police CyberAlarm, it is a Home Office-funded policing tool focused on small and medium-sized organisations that probably do not have the skills or understanding to protect themselves as effectively. They can download that piece of software, and it will sit on their external networks and monitor for attacks. For the first time, it helps us in policing to build a domestic threat picture for small and medium-sized organisations, because everybody has a different piece of the puzzle. GCHQ has great insight into what is coming into the UK infrastructure, but it obviously cannot monitor domestically. Big organisations that provide cyber-security services and monitoring know what is impacting their clients or their organisation, but not everybody else. At policing, we get what is reported, which is a tiny piece of the puzzle. So everyone has a different bit of the jigsaw, and none of it fits together, and, even if it did, there would still be gaps. For SMEs, that is a particular gap.

For us, we get the threat intelligence to drive our operational activity, which has been quite successful for us. The benefit for member organisations—we are up to about 12,000 organisations at the moment, which are mostly schools, because we know that they are the most vulnerable to attack for a variety of reasons—is that, having the free tool available, it can do the monthly vulnerability scans and assessments. So they are getting a report from the police that tells them what they need to fix and what they need to patch.

We do not publicly offer a lifetime monitoring service, because we would not want the liability and responsibility, and we do not have the infrastructure to run that scale of security operation centre. But, in effect, that is actually what we have been doing for a long time—maybe not 24/7, but most of the time—because we have been able to identify precursor activity to ransomware attacks on schools or other organisations, and have been able to step in and prevent it from happening. There have been instances where officers have literally got in cars and gone on a blue light to organisations to say, “You need to shut some stuff off now, because you are about to lose control of your whole organisation.”

To that extent, it has been really impactful, but the challenge for us is how to scale. How do you scale so that people understand that it is there? How do you make it easier for organisations to install? That is one of the things that we are working on at the moment, so that everybody can benefit from the scans and the threat reporting, and we can benefit from a bigger understanding of what is going on.

The flip side of the SME offer from our point of view is our cyber-resilience centres. By working with some of the top student talent in the country, we can scale to offer our member organisations across the country the latest advice and guidance, help them understand what the NCSC advice and guidance is, and then help them to get the right level of security policies, patch their systems and all that kind of thing. It helps them to take the first steps on their cyber-resilience journey, and hopefully be more mature consumers of cyber-security industry services going forward. We are helping to create a market for growth, but also helping those organisations to understand their specific vulnerabilities and improve from a very base level.

Bradley Thomas Portrait Bradley Thomas
- Hansard - - - Excerpts

Q With regard to ransom payments and extortion attempts, what do you typically see? Is it for monetary gain or intellectual property data—what is the split?

DCS Andrew Gould: That is another really good question. Generally, it is financial, but you will often get what is called the double dip, so there is the extraction of data as well as the encryption of it, so that you no longer have access to it. They might take that data as well, primarily personal data, because of the regulatory pressures and challenges that that brings. There is a sense among a lot of criminal groups that, if they have personal data, you are more likely to pay, because you do not want that reputation, embarrassment and all the rest of it, as opposed to if they take intellectual property, for example. But it is not that that does not happen as well. Primarily, it is financial gain.

Cyber Security and Resilience (Network and Information Systems) Bill (Third sitting)

(Limited Text - Ministerial Extracts only)

Read Full debate
Committee stage
Thursday 5th February 2026

(7 months, 3 weeks ago)

Public Bill Committees
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 Read Hansard Text Amendment Paper: Public Bill Committee Amendments as at 5 February 2026 - (5 Feb 2026)

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- Hansard - - - Excerpts

It is a pleasure to see you in the Chair, Mr Stringer. The Bill will make crucial updates that build on the NIS regulations, which are the UK’s only cross-sector cyber-security regulations. As clause 1 sets out, “NIS regulations” refers to the Network and Information Systems Regulations 2018 (S.I., 2018, No. 506).

Clause 2 gives an overview of the Bill’s parts and what they include. It sets out that part 2 amends the NIS regulations by expanding the scope of the regulations to cover data centres, large load controllers and managed service providers. It also introduces powers for regulators to designate suppliers as being critical for their sector. Part 2 also updates the existing incident-reporting regime and includes provisions relating to the recovery of regulators’ costs, information-gathering and sharing powers, and enforcement powers. Part 3 gives new powers to the Secretary of State to specify other sectors as in scope of the regulations in future, to create new regulations relating to the security and resilience of regulated services, and to issue a code of practice and a statement of strategic priorities. It also requires the Secretary of State to report on this legislation and its implementation. Finally, part 4 gives new national security powers for the Secretary of State to issue directions. I commend the clauses to the Committee.

Ben Spencer Portrait Dr Ben Spencer (Runnymede and Weybridge) (Con)
- Hansard - - - Excerpts

It is a pleasure to serve under your chairmanship, Mr Stringer. I thank all hon. Members on both sides of the Committee for taking part, and the officials for their work on the Committee stage of this important Bill.

The Bill will significantly update and expand the Network and Information Systems Regulations 2018 by bringing new services within scope of regulation, giving sector regulators the power to designate critical suppliers, updating and expanding the reporting regime for cyber-security incidents and making significant changes to the regulatory funding model and regulators’ information-gathering and sharing powers. The Bill will also grant extensive powers to the Secretary of State to respond to emerging cyber-threats, including the power to bring further sectors within the scope of regulation, giving directions to regulated entities and issuing a code of practice that sets out measures for compliance with duties under the NIS regulations. Recognising the increasing role of malicious cyber-activity as a threat to our national security, part 4 will give the Secretary of State far-reaching powers to issue directions to regulated entities for reasons of national security.

Covid turbocharged the digitalisation of all aspects of the economy and our daily lives, bringing new opportunities but at the same time heightening the exposure of digital systems to exploitation by malicious actors. The previous Government recognised that in their post-implementation reviews of the NIS regulations and in a subsequent series of consultations on proposals to improve the cyber-resilience of the entities that are most important to the UK economy. Those consultations included a review of information security risks relating to outsourced IT provision, data centres and organisations controlling large amounts of electrical load. The last Government’s work assessing those threats has informed this Government’s decision to bring data centres, managed service providers and large load controllers within the scope of the NIS regulations.

Industry stakeholders have welcomed the Bill as essential for bringing the cyber rules governing critical infrastructure in line with modern threats, economic realities and technological developments, and for moving our cyber-security regulatory framework into closer alignment with international partners to ease cross-border operations for businesses that provide services overseas.

In some respects, at least, the Bill identifies the right problems, but, crucially, it falls short of providing workable solutions. In embarking on our scrutiny of the Bill, the Committee should be acutely aware of the raft of digital legislation with which businesses and regulators have been asked to grapple in recent years. Many of those new regulations are necessary, but as lawmakers we should be conscious of the burden that we are placing on industries and particularly on small and medium-sized enterprises, which are the lifeblood of the UK economy and which have fewer resources to navigate complex layers of regulation. It is therefore incumbent on all of us to enact laws that are clear and capable of practical implementation.

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I thank the hon. Member for his point about balance. I am confident that this is an area to which the Committee will return quite a few times in our line-by-line scrutiny of the Bill, particularly clause 12, which relates to the designation of critical suppliers. Clearly the regulations need to be proportionate, but to make that judgment we will need to know exactly what the regulations are. A lot of the detail is not in the Bill and has instead been left to secondary legislation. As we heard from the experts, it is very difficult to scrutinise legislation that is mostly being left to future regulations rather than being set out in the Bill.

These definitions will be critical if businesses are to have clarity as to whether they will fall within scope. I do not want to go too deeply into clause 12 now, but I see it as an exemplar. How are businesses that could fall within the critical supplier designation to know what they need to do? How is the operator of an essential service to know what information it needs to pass to the regulator on businesses that it may end up regulating? It would be very helpful if the Minister could comment, even at this introductory stage, on how he envisages that balance playing out in the Bill, particularly given that so much of the detail has been left to secondary legislation. Anyway, I digress—I will get back on topic.

Businesses are struggling with legal uncertainty and the increased costs of regulatory burden. Regulators in the sector lack the resources, the teeth and sometimes even the will to carry out effective oversight and enforcement of existing cyber regulation. Uncertainty about which incidents should be reported will dramatically increase the burden on regulated entities and on regulators. All the while, institutional barriers to effective oversight and enforcement remain.

The Bill fails to give the legal certainty and the proportionate framework that businesses need if we are to achieve widespread adoption and hardened cyber-resilience across the sectors that are most critical to the economy and our society. Perhaps most critically, there is little point in granting the Secretary of State extensive powers to make directions to regulated entities for national security purposes if the Government remain wilfully blind to the greatest threats to our national security. In the past few weeks, reports have circulated that a Chinese state-affiliated group hacked the communications of top Downing Street officials between 2021 and 2024, yet the vital organs of our state, central Government Departments and agencies carrying out the most critical functions, are left unprotected and unaccountable for their cyber-resilience under the Bill.

If we do not address these problems, we risk the Bill becoming yet another missed opportunity for the Government. These are opportunities that we can ill afford to miss if we are to safeguard our economy and our national security.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I welcome some of the Opposition spokesperson’s comments. Let me briefly address his questions about definitions and public sector inclusion. It is customary for the Opposition to oppose for the sake of opposition, at times, and I am afraid that this is one of those times; I have so far set out only two clauses, which are effectively an index to the Bill. Notwithstanding that, I will address his two particular points.

I was delighted that in our evidence sessions we heard from witness after witness who appreciated the flexibility of the Bill. For the Government to prescribe activities or incident thresholds in the finest detail in primary legislation is not how businesses, Government and regulators ought to engage. I hope that the Opposition will come to appreciate that in due course.

On critical suppliers, which no doubt we will come on to, I thought that in response to Opposition comments at our second sitting, I set out a very clear, precise set of tests. I found no opposition to that claim, but I look forward to hearing any original thoughts on that question.

On incident reporting, I was delighted that there was a witness who noticed that the extension of the definition of incident reporting, to include incidents capable of having an impact, was appropriate and exactly in the right place.

On the question about the public sector’s inclusion, we are here not to prescribe and wait for a law to tell us what we ought to do in the public sector, but instead to move fast and fix things. In that spirit, the Bill focuses on essential services.

Question put and agreed to.

Clause 1 accordingly ordered to stand part of the Bill.

Clause 2 ordered to stand part of the Bill.

Clause 3

Identification of Operators of Essential Services

Question proposed, That the clause stand part of the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 3 makes important distinctions as to which organisations can and cannot be considered operators of essential services for the purposes of the NIS regulations. It clarifies that a person—in practice, an organisation or business—can be an operator of an essential service regardless of whether that person is established in the UK, as long as they are providing essential services in the UK. That means that organisations established outside the UK can be regulated under the NIS regulations.

Clause 3 also makes it clear that the NIS regulations do not apply to public electronic communications networks or to public electronic communications services. Those are telecoms operators, which are regulated separately under the Communications Act 2003. The amendments in clause 3 will prevent telecoms companies from being subject to duplicate regulations; they will also ensure that all essential services in the UK are protected, even if the company operating them is based outside the UK. I commend the clause to the Committee.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 3 will amend the relevant provisions of the NIS regulations, stipulating that operators of essential services are within scope of the regulations whether or not they are operating an essential service in the UK, and regardless of jurisdiction in which they are established. Providers of public electronic communications networks and public electronic communications services are excluded from characterisation as operators of essential services, as the Minister says, to avoid duplication with their sector-specific cyber-security regime.

The clause is an important provision to ensure that entities providing essential services in the UK are compliant with domestic standards. Perhaps the most important aspect of the change is ensuring that serious cyber-security risks that appear within the systems of those entities are reported to the UK authorities for action. That is vital for the National Cyber Security Centre to keep abreast of emerging risks and be able to respond to them.

Nevertheless, the complex maze of compliance and regulatory standards across jurisdictions is a growing challenge for businesses of all sizes and particularly for small and medium-sized enterprises. This is also a complicating factor facing UK companies when providing services abroad, particularly in the digital domain. Will the Minister lay out what discussions he has had with industry representatives about easing the complexity of cross-border digital service provision to ensure that the UK is a competitive and attractive place to do business?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

On the question about cross-border compliance and making sure that we have a proportionate and effective regime, we have had a series of engagements at ministerial and official level with representatives of techUK, the industry body. The NCSC has convened a series of organisations—not least managed service providers, but others as well—and there has been a pretty extensive period of consultation on that and every other matter in the Bill.

I feel satisfied that the Bill strikes a good balance in ensuring proportionality in what businesses experience. Critically, as supply chains in this context become increasingly cross-border, it is vital that bodies that may not be resident in the UK but which provide essential services here are included in the scope of the Bill.

Question put and agreed to.

Clause 3 accordingly ordered to stand part of the Bill.

Clause 4

Data centres to be regulated as essential services

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I beg to move amendment 11, in clause 4, page 3, line 5, column 3, leave out from beginning to “the” in line 6.

This amendment and Amendment 12 would remove the Secretary of State for Science, Innovation and Technology as a joint regulator for the data infrastructure subsector, leaving the Office of Communications acting as the sole regulator for that subsector.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss the following:

Government amendment 12.

Clause stand part.

Clauses 5 and 6 stand part.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 4 of the Bill amends the NIS regulations by creating a new regulated sector, data infrastructure, and designating the Secretary of State for Science, Innovation and Technology and Ofcom as joint regulators. We have received clear feedback from the data infrastructure sector expressing concerns that a dual regulator model could create unnecessary complexity and limit accountability. Amendments 11 and 12 will remove the Secretary of State for Science, Innovation and Technology as a regulator, leaving Ofcom as the sole regulator, which will streamline the regulatory model for data infrastructure and resolve the concerns raised by stakeholders.

Ofcom already has proven regulatory expertise and is well placed to oversee the new data infrastructure sector effectively. By adopting a single regulator for data infrastructure, the amendments will reduce administrative burden, simplify engagement, and strengthen accountability. This will ensure a clearer, more effective regulatory framework for this rapidly growing sector. 

Clause 4 brings qualifying data centre services into the scope of the NIS regulations, recognising both their vital role in underpinning our economy and public services, and that disruption to them can significantly impact productivity, service delivery, and revenue.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

Clause 4 relies heavily on capacity as the trigger for regulation. I understand why that is attractive: it is measurable. But capacity is not the same as criticality, and a high-capacity facility used for redundancy can present less systemic risk than a smaller, highly concentrated one. I simply put on record that the way this threshold is applied in practice will matter more than the number itself.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for that thoughtful point. One assurance I will offer her is that the direct definition of data centres in scope here rely on capacity as a proxy for their essential independent nature, but when data centres below the capacity threshold but high on the criticality threshold are suppliers to essential services, they would be covered in part by the critical suppliers framework in the Bill. I take her point into account.

Bradley Thomas Portrait Bradley Thomas (Bromsgrove) (Con)
- Hansard - - - Excerpts

What consideration has been given to the potential conflict between data centres’ contractual obligation regarding customer confidentiality and mandatory rapid reporting? What assurance can the Minister give us that data centres will ensure that the conflict does not impact their future business?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

In the course of engaging with firms we have considered what the timeline for reporting ought to be. It is critical that the initial notification requirement, which is a much lower requirement than the full notification requirement, at least gives the NCSC and other enforcement authorities the ability to counter national security and wider-impact risks. I believe that specification to be proportionate in the Bill, but it is of course a matter for implementation that we will keep a close eye on.

An attack on a data centre can have significant impacts beyond the facility itself. As data centres underpin digital services across multiple sectors, disruption or compromise can cascade through essential services, businesses and public services. Incidents may also pose national security and economic risks, given the concentration of sensitive and critical data. Bringing qualifying data centre services into scope of the NIS framework helps ensure these risks are managed proportionately and incidents are reported promptly. 

As per Government amendments 11 and 12, we propose that Ofcom is the regulator.   Medium and large third party data centres and very large enterprise centres will be required to manage risks and report to Ofcom. Their thresholds have been carefully calibrated to capture data centres whose disruption could have the greatest impact, while avoiding unnecessary burdens on smaller operators. This will strengthen the cyber-security and resilience of data centres, align with international regulations, and introduce structured oversight, notification, and incident reporting to strengthen national security and economic stability.

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

As I risk getting into trouble with Mr Stringer, I will not respond to the hon. Member for Lichfield. I look forward to the opportunity to debate this issue again, perhaps in the emergency Budget in the next couple of weeks.

Clause 6 brings large load controllers, which provide the flow of electricity in and out of smart appliances, within scope of the NIS regulations if the load is above 300 MW. I understand that the threshold has been decided through consultation, given that that pressure could have a substantial impact on the grid. There is a challenge in managing peak demand and supply in the grid and big changes in it, so I entirely understand why the Government are introducing this provision. Smart EV devices—I have a smart charging electric vehicle device myself—used system-wide could cause big grid disruptions, particularly as we integrate infrastructure into our homes such as solar panels, batteries and other energy-related smart devices.

In fact, we need the grid to become more smart device-integrated over the next 10, 15 or 20 years. When we look at projections of energy consumption, we see that we will need to enable people to use the grid by expanding technology such as vehicle-to-grid energy supply, so that we can manage peak load. That is part of expanding our energy, reducing energy costs and supporting renewable energy and the transition to net zero. If anything, this issue will become more important and expansive over the years.

On that basis, I have some questions for the Minister about the clause. Why are data centres and large load controllers the two sectors that he has decided to put on the face of the Bill? I say that with particular reference to the NIS2 regulations, which are expanded a bit more. How does he envisage this area expanding in the future? Is he confident that the scope of the clause is sufficient to cover future technologies that are coming down the track? I am thinking of EV charging apps. The list is prescriptive, but does it have sufficient flexibility? Is the Minister able to come back with secondary legislation if he needs to expand the list in the future, given that it is in the Bill in that form? Would it not be better to put that on the face of the Bill and to use secondary legislation to lay it out, in order to have flexibility? The Minister has been trying to ensure flexibility elsewhere, and understandably so—let us not go back into those debates. I just want to understand his reasoning behind that a bit better. That is certainly not a criticism, but I want to know why those particular sectors have been pulled out, and why it has not been left for secondary legislation.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

With your permission, Mr Stringer, I will restrict my comments to clauses in question—in particular, clauses 5 and 6—and the relevant Government amendments. The shadow Minister has auditioned for roles at the Department for Business and Trade in talking about the philosophy of regulation, at the Department of Health and Social Care in talking about his medical background, and at the Treasury in talking about taxation. I will try to restrict myself to none of those and simply speak to the clauses and address three points in response to his comments.

The first relates to the skills and resourcing of our regulators. On that, I welcome the shadow Minister’s prior engagement with me directly and his questions now. The last Government completely gutted our regulators. Having done so, they achieved neither growth nor regulatory quality, which Opposition Members now talk about. As a consequence, it falls to us to make sure that our regulators are fit for purpose and resourced in the way they need to be. This Bill gives them the powers to secure initial and full notifications in a timely way, the powers to share information in an appropriate way and, fundamentally, the ability of cost recovery, to resource themselves in an appropriate way. Alongside that, our wider initiatives on skills in the cyber-sector and technology more broadly are fundamental to achieving our aspirations, not least through the CyberFirst programme, which I mentioned in a witness session.

Bradley Thomas Portrait Bradley Thomas
- Hansard - - - Excerpts

Will the Minister give way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I might just make a slight bit of progress. As I mentioned in a previous session, the programme reached 415,000 students, and it has now been evolved into the wider TechFirst scheme as well.

The shadow Minister, as well as the hon. Member for Bromsgrove, made a very important point about resilience in particular and sovereign capability. Particularly for those reasons, I am really proud of two things. One is that the Bill includes suppliers that may not be resident in the UK but provide essential services in the UK. This is a critical means through which we can secure our capabilities here. The second, which is close to my particular interests in the data centre and compute world, is that, through our initiatives on sovereign AI, and having launched a very innovative advance market commitment in the chips part of the stack, which ends up crowding in wider demand—not least through companies such as Nscale, a fundamental part of our AI growth zone in the north-east—this Government are finally rectifying the errors and omissions of the last Government, in making sure that Britain does not do what it did in the last commercial cloud context, but instead, in this AI compute world, has some actual chips on the table.

Thirdly, I will not try to settle the thrilling debate between the shadow Minister and my hon. Friend the Member for Lichfield on the philosophy of regulation. I will simply make the humble suggestion that in this context we have arrived at, not a full-fat compendium, as the shadow Minister described it, but a very targeted Bill, which has been the result of extensive industry engagement—indeed, some of it was carried out by the prior Government—that aligned on the sectors in question and the inclusion of critical suppliers in scope.

On the shadow Minister’s question about the thresholds and definitional specificity of large load controllers in the Bill, I will of course remain very open to ensuring that the secondary powers, which are intended precisely to enable us to move flexibly as the clean power industry moves, give us the flexibility to move with it. At the same time, the threshold of 300 MW reflected the point at which a large load controller could pose an unacceptable risk to the electricity system and our CNI. This threshold was set very clearly in partnership with technical experts, including the National Energy System Operator. Of course, as the market grows, the potential for cyber-incidents will grow, and we will keep that under close review.

Chris Vince Portrait Chris Vince
- Hansard - - - Excerpts

On the point about flexibility, I think we would recognise that the legislative process in this House does not always move as quickly as we might want it to, but there are reasons for that, because scrutiny is really important. Does the Minister agree that the changing nature of the cyber-threats we face and the changing nature of technology, which he understands far more than me, are the reasons why it is so important to have flexibility in the Bill?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank my hon. Friend for that point. The reality is that neither he nor I am placed to judge exactly where the thresholds should be set on a permanent basis. That is exactly why we have secured the flexibilities that we have in the Bill.

Clause 5 brings Crown-operated data centres into scope of the NIS regulations, ensuring that Government data centres meet robust standards comparable to those in the private sector.  Bringing Crown data centres within scope closes a critical gap and guarantees that public sector infrastructure is protected against evolving threats.  Exemptions will apply only in defined cases in which a data centre service is provided by an intelligence agency or a facility handling highly classified—“Secret” or “Top Secret”—information. These data centre services are already governed separately, and applying the NIS regime could cause conflict. I urge that clause 5 stand part of the Bill. 

Finally, clause 6, on large load controllers, introduces the essential new service of load control under the energy subsector of the NIS regulations. This will capture organisations—

None Portrait The Chair
- Hansard -

Order. I am sorry to interrupt the Minister, but can he speak a little more loudly and slowly for the benefit of all Members?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Loudly and slowly: this will capture organisations remotely managing significant amounts of electrical load via energy-smart appliances, both in a domestic and non-domestic setting. These organisations play an increasingly important role in the management of the electricity system, but are not currently regulated for cyber-security. A cyber-attack could therefore create major disruptions to the national grid, shutting down public services and critical national infrastructure. Capturing load control as an essential service will safeguard the public from these disruptions. It will also reflect the need to bring in new safeguards to manage a more digitalised and dynamic energy landscape in the transition towards net zero.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Before the Minister moves on—I was a bit nervous that he was going to finish—I have an additional question about the Crown data centre. What happens if a data centre is providing services commercially to both the public and the Crown? How is that operated within the scope of the Bill?

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am happy to write to the shadow Minister on that point. My understanding is that a Crown data centre will be in scope if it is providing, as in that particular example, to both the public and the private sector, but I am happy to write to him to clarify that point.

The load control market is growing exponentially and we need to make it cyber-secure. For that reason, I propose that clause 6 stands part of the Bill.

Amendment 11 agreed to.

Amendment made: 12, in clause 4, page 3, line 7, leave out “(acting jointly)”.—(Kanishka Narayan.)

See the explanatory statement for Amendment 11.

Clause 4, as amended, ordered to stand part of the Bill.

Clauses 5 and 6 ordered to stand part of the Bill.

Clause 7

Digital services

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I beg to move amendment 13, in clause 7, page 7, line 7, leave out paragraph (b) and insert—

“(b) a pool of computing resources is ‘scalable’ if the resources are flexibly allocated by the provider of the service, irrespective of the geographical location of the resources, in order to handle fluctuations in demand;

(c) a pool of computing resources is ‘elastic’ if the resources are provided and released according to demand, in order to rapidly increase and decrease available resources depending on workload;

(d) computing resources are ‘shareable’ if—

(i) multiple users share a common access to the service, which is provided from the same electronic equipment, and

(ii) processing is carried out separately for each user.”

This amendment would refine and make further provision about certain aspects of the definition of “cloud computing service”.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss clause 7 stand part.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 7 amends the definitions of “relevant digital service provider” and “cloud computing service” in the existing NIS regulations. As in the original NIS regulations, an RDSP is a cloud computing service, online search engine or online marketplace. To be in scope, they must provide a service in the UK and not be a small or microbusiness. That prevents disproportionate business burden, focusing on those larger businesses whose compromise could have a significant impact on the UK’s economy or society. The changes to the definition in the clause clarify that to be in scope, providers cannot be designated as a critical supplier or be subject to public authority oversight, as defined by clause 11. That maintains consistency with the approach to managed services, and minimises dual regulation and unnecessary burden.

Government amendment 13 strengthens the definition of a cloud computing service in clause 7. It introduces precise, clarified and separate definitions of the three core characteristics of cloud computing resources, which is that they are scalable, elastic and shareable.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

Clause 7 is definition-heavy, and rightly so; these terms decide who is regulated and who is not. My only observation is that cloud models are, as the Minister knows, evolving quickly because of the AI revolution. Definitions that track architecture too closely will age fast, so the Committee should be alert to whether these terms will still make sense in five years’ time and not just today.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I very much welcome that point. In talking about broad architecture characteristics—being able to scale compute and to be elastic to multi-tenants by being shareable—rather than setting out the specific nature of resources, we capture both commercial cloud and AI deployments. However, I am keen to ensure that we keep this under review and, where possible, use the flexibilities provided by the Bill to adapt it to changes in technology.

Although the policy intention behind the definition has not changed, amendment 13 will provide certainty for industry, support effective regulatory oversight and ensure that services whose disruption could significantly impact the UK economy and society are properly captured. In addition, the drafting is more aligned with that of our international partners, which will improve efficiency for providers operating across borders.

This targeted, technical improvement will bring greater clarity, consistency and fairness to the NIS regulations. I urge Members to support both the clause and this important amendment.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 7 amends the definition of cloud services, which have been within the scope of regulation since the NIS regulations came into force. The expanded definition emphasises remote accessibility and the “on demand” nature of cloud services, and that services may be delivered from multiple locations. It also excludes managed services from the scope of cloud services to avoid duplication of regulatory requirements and oversight.

The Minister proposes changes to this provision in Government amendment 13, which sets out further details regarding the features of in-scope cloud service provision, including common access by multiple users, with each having access to separate processing functions. My question to the Minister builds on the one raised by my hon. Friend the Member for Bognor Regis and Littlehampton. It is obviously difficult—if it is possible at all—to predict how the tech sector will evolve, but what powers will the Government have to adjust these provisions as the cloud ecosystem changes, and what consultation has the Minister done on that within the scope of the Bill?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

On that important point, which the hon. Member for Bognor Regis and Littlehampton also raised, the changes to the definition came about in part through extensive engagement, and in particular by ensuring that the attributes of “elastic” and “scalable” were treated individually rather than jointly and that “shareable”—the ability to have multi-tenants and therefore be a genuine cloud computing service for multiple clients—was considered in scope. As I mentioned to the hon. Member for Bognor Regis and Littlehampton, it is important that we keep this under review, and part of the reason for the secondary powers in the Bill is to make sure it remains both specific, giving clarity and certainty, and flexible at the same time.

David Chadwick Portrait David Chadwick (Brecon, Radnor and Cwm Tawe) (LD)
- Hansard - - - Excerpts

Currently, the law requires regulated persons to manage risks to the security of their systems. Amendment 28, tabled by the Liberal Democrats, explicitly inserts “risks arising from fraud” into that duty. It would make it clear that a system cannot be considered secure if it is easily exploited by scammers.

Fraud should be considered a national security issue, and there is clearly a relationship between fraud and cyber-security. Scammers across the world are targeting British citizens. Elderly fraud victims in Dyfed-Powys lose £7,900 a day to a tidal wave of scams perpetrated by scammers from many countries across the world, notably Nigeria. UK-wide, in the first half of 2025 alone, criminals stole over £600 million through scams. Surely, we cannot pass a cyber-security and resilience Bill—

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I broadly agree. This is one of those difficult areas where there can be overlap. I have sympathy with the argument that it is important to use any opportunity, and in particular this Bill, to raise fraud.

We focus on financial fraud, but this area is not limited to that, especially when we think about other malicious operators, and about ransomware and hacktivism, where the boundaries are particularly blurred. In a situation where a fraudulent operator, service, provider or organisation has material, whether on social media or subject to search engines, and the police or other competent authorities have flagged it to the provider as fraudulent—as illegal criminal activity—what duties does that provider have to remove it or take it down? Is that something that the Minister is aware of? Has he looked into it, and what is the Government’s plan to crack down on that activity?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for Brecon, Radnor and Cwm Tawe for tabling amendment 25, which would amend the duties for RDSPs in the NIS regulations. I empathise with the source of his concern about fraud; I think many of us in the House know and feel that concern, through either our personal experience or that of our constituents.

That said, the security duties within NIS require RDSPs to identify and take steps to manage the full spectrum of risks posed to the security of their systems. They must prevent and mitigate relevant incidents, regardless of what the threats are or where they emanate from. That includes taking an all-hazards risk-based approach. Entities must manage risks to cyber-security, physical security and broader operational resilience. “Security” includes the ability to resist any action that may compromise the availability, authenticity, integrity or confidentiality of those systems, including risks that may arise from fraud. I caution against highlighting only one particular vector of risk in the clause; that is unnecessary and would not reflect the full range of risks each RDSP faces.

Further, while the Bill clarifies the high-level duty to manage risks, secondary legislation will give further detail on the security and resilience requirements. Guidance and the code of practice will give further detail still on the types of risks to consider. For that reason, I kindly ask the hon. Gentleman to consider withdrawing the amendment.

The shadow Minister asked about the Government’s treatment of fraud, particularly when it has been found on a platform and the authorities have asked that platform to take it down. The Government made a clear commitment in our manifesto to introduce a new fraud strategy, and the Home Office, as the lead Department, has been working at pace to engage deeply in making that an effective reality.

Alongside that, in my wider role in online safety, I am conscious that fraud is a fundamental area of content in which platforms have to look at where it crosses the border into illegality, as it may well do in the instance the shadow Minister described. That has been a central focus since the illegal content duties came into play last year. I believe that such instances are well covered by the pieces of legislation that I have just mentioned. The Bill is clearly more focused on critical national infrastructure and its exposure to network and information systems.

Lincoln Jopp Portrait Lincoln Jopp (Spelthorne) (Con)
- Hansard - - - Excerpts

Members on both sides of the Committee have referred frequently to the fact that the incident that took Jaguar Land Rover down would not have been covered by the Bill. JLR employs a digital service provider, in the form of Tata Consultancy Services. Would that provider not be covered, meaning that JLR is in scope?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Although I will not rule a particular provider in or out of scope, if the provider in question met the threshold for RDSP coverage, it would be covered, but the locus of that coverage would be limited to the provider rather than to the end-customer entity. I hope that clarifies that sufficiently.

Let me explain how clause 8 was designed to tackle the risks that Committee members have set out. The clause updates the existing duties for RDSPs in the NIS regulations to ensure that they remain resilient against evolving cyber-threats. It clarifies the requirement for those services, making it clearer that they must secure themselves not just to keep the services they provide running and available but to contribute to wider systems security as a whole.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

Given the scenario we just discussed, it is possible that a digital service provider would have an obligation to report under the Bill, but the parent company employing its services would not. Given the requirements for confidentiality that a client company may put upon a digital managed service provider, how can that conflict be managed?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I appreciate the hon. Gentleman’s question, and I have two comments to make on that front. First, the relevant digital service provider will have a range of different customers, and my expectation would be that the regulators and the NCSC would seek a deep understanding of the risk exposure across the full breadth of that portfolio, rather than for each particular customer. Of course, that would form part of some analysis.

Secondly—the shadow Minister asked a related question —I am happy to write about the interaction between prompt notification responsibilities and commercial confidentiality duties, on the basis of the engagement we have conducted so far. Especially when questions of major risk exposure are concerned, I would hope there are provisions that allow the relevant digital service provider to notify the NCSC, but I am happy to write to the hon. Member for Spelthorne and the shadow Minister to clarify that point.

Clause 8 also removes a reference to the RDSP’s own network and information system to clarify that the duty is intended to cover all network and information systems that the relevant digital service relies on.

The cyber-risk landscape is diffuse and multifaceted. Hostile actors can use a range of routes and techniques to attempt to take services offline, as well as to extort, steal and surveil. These changes to the NIS regulations support a holistic approach to tackling cyber-risk. They ensure that important dependencies are covered and that facets of security such as the confidentiality of data and integrity of systems are not set aside.

The clause also requires RDSPs to have regard to any relevant guidance issued by the Information Commission when carrying out its duties. Finally, it removes a requirement for relevant digital service providers to consider specific duties referenced in EU regulations. I urge the Committee to support the clause unamended.

Question put, That the amendment be made.

Division 1

Question accordingly negatived.

Ayes: 1

Noes: 9

Clause 8 ordered to stand part of the Bill.

Cyber Security and Resilience (Network and Information Systems) Bill (Fourth sitting)

(Limited Text - Ministerial Extracts only)

Read Full debate
Committee stage
Thursday 5th February 2026

(7 months, 3 weeks ago)

Public Bill Committees
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 Read Hansard Text Amendment Paper: Public Bill Committee Amendments as at 5 February 2026 - (5 Feb 2026)

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss the following:

Amendment 10, in clause 10, page 9, line 29, at end insert—

“(2A) The measures taken by an RMSP under paragraph (1) must ensure that the number of customers to whom the RMSP provides services does not exceed the critical risk threshold.

(2B) In paragraph (2A), the ‘critical risk threshold’ is the number of customers within a sector or subsector where an incident affecting the provision of services to those customers by the RMSP would result in disruption that is likely to have a significant impact on the economy or the day-to-day functioning of society in the whole or any part of the United Kingdom.

(2C) Paragraph (2D) applies where the number of customers to whom an RMSP provides services exceeds the critical risk threshold by virtue of contracts entered into before the coming into force of section 10 of the Cyber Security and Resilience (Network and Information Systems) Act 2026.

(2D) The RMSP must take steps to reduce the number of customers to below the critical risk threshold, including exercising any right to terminate a contract or vary the terms of a contract.”

This amendment would place a duty on relevant managed service providers (“RMSPs”) to ensure that they do not provide services to manage the technology systems for a number of customers that exceeds a critical risk threshold, such that an incident affecting those services would be likely to result in significant disruption in the United Kingdom. This would prevent an RMSP managing the technology systems for a whole sector or subsector. Provision is also made for a situation where an RMSP is in breach of the critical risk threshold because of contracts entered into before the enactment of the Bill.

Clauses 10 and 11 stand part.

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- Hansard - - - Excerpts

I welcome you, Ms McVey, to the most exciting event in Parliament this week.

None Portrait The Chair
- Hansard -

I question that, but carry on.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

What a pleasure it is to serve with you in the Chair. Clause 9 brings large and medium-sized managed service providers—MSPs—into the scope of the Network and Information Systems Regulations 2018. MSPs are organisations that provide an ongoing IT function, such as an IT help desk or cyber-security support, to an outside client. In doing so, MSPs often have widespread and trusted access to clients’ networks and systems. A single targeted attack can ripple outward, disrupting thousands of other systems. That makes MSPs attractive targets for cyber-attacks. Last year an attack on Collins Aerospace halted check-in and boarding systems at major European airports, causing international disruption. Such attacks highlight what can happen if a single point of failure is compromised, and the importance of managed service providers implementing robust cyber-protections. Despite that, MSPs are not currently regulated for their cyber-security in the UK. As organisations rely more and more on outsourced technology, we must close that gap. The clause provides essential definitions of a “managed service” and of a “relevant managed service provider” to clearly set out which organisations are in scope of the regulations.

Clause 10 imposes new duties on MSPs that have been brought into scope by clause 9. For the first time, such businesses must identify and manage risks posed to the network and information systems that they rely on to provide their managed services. As part of that duty, MSPs must have

“regard to the start of the art”,

meaning that they must consider new tools, technologies, techniques and methods that threat actors may employ. That includes artificial intelligence, and means that providers must deploy the right tools to mitigate the risks and take action to minimise the impact of incidents if they occur. By bringing MSPs into scope of the regulations and imposing such security duties on them, we will strengthen cyber-security and resilience across supply chains, reduce vulnerabilities in outsourced IT services and better protect businesses and services across the UK.

Alison Griffiths Portrait Alison Griffiths (Bognor Regis and Littlehampton) (Con)
- Hansard - - - Excerpts

Bringing MSPs into scope is the right direction of travel, and MSPs sit at points of concentrated risk, but they are not all the same and the real risk is not size alone but the level of privileged access and cross-customer dependency. Proportionality will be critical under these provisions if we want better security, not just box-ticking.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I agree very much with the hon. Member’s point, and a similar sentiment is expressed elsewhere in the Bill, in that it ensures that the focus is primarily on large and medium-sized MSPs, and that small businesses and microbusinesses are dealt with in a deeply proportionate way. That is an important point to take into account.

Clause 11 defines what it means for a digital or managed service provider to be

“subject to public authority oversight”

under the NIS regulations. Public authority oversight is defined as “management or control” by “UK public authorities” or by a board where the majority of members are appointed by those authorities. Such MSPs are already subject to requirements in the Government cyber-security strategy, which is mandatory for Government organisations. That ensures that cyber-resilience standards remain strong for services linked to public functions, while preventing disproportionate burdens on providers already subject to public authority governance.

In response to points raised by hon. Members in prior Committee sittings, I flag the engagement that we have conducted in coming to the definition of MSPs in question. In particular, beyond the provisions of the 2022 consultation, prior to the introduction of the Bill, we conducted a range of bilateral meetings. We have had multiple conversations with the industry body techUK, roundtables with digital firms, and we engaged through the National Cyber Security Centre-led MSP information exchange with 40 providers in this context, and undertook market research mapping the MSP market. As a consequence, adjustments to the definitions at the heart of this provision have been agreed with incredibly deep and broad engagement across the industry to arrive at a widely-welcomed definition.

Lincoln Jopp Portrait Lincoln Jopp (Spelthorne) (Con)
- Hansard - - - Excerpts

It is a pleasure to serve with you in the Chair, Ms McVey. Small and medium-sized enterprises are defined by the headcount of full-time employees, yet in the world of IT, particularly for managed service providers, data centres and digital service providers, that is not a helpful metric to understand size and scale. Did the Department consider reevaluating the size of digital and managed service providers based on the through-flow of transactions or data rather than headcount? When I worked in the world of tech, there was a ratio for headcount that was totally different from other sorts of businesses.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The hon. Member raises an important point about the operating leverage of technology businesses. The Bill directly focuses on size as one proxy for risk, but it is not a complete or perfect proxy. That is why, through the critical supplier provisions, it ensures that any smaller providers can be caught in scope as essential services.

Ben Spencer Portrait Dr Ben Spencer (Runnymede and Weybridge) (Con)
- Hansard - - - Excerpts

It is a pleasure to serve under your chairmanship, Ms McVey.

Clause 9 brings within scope of the NIS regulations a new category of technology service providers, known as relevant managed service providers. MSPs play a critical role in the UK economy. Research conducted by the Department for Science, Innovation and Technology under the last Government suggests that 11,000 MSPs were active in the UK in 2023, of which 1,500 to 1,700 were medium or large organisations that would be in scope of the Bill. Micro and small enterprises that offer managed services are excluded from the scope of regulation but have the potential to be designated as critical suppliers under other provisions, which we will come to shortly.

MSPs are critical to the functioning of the multiple businesses that they serve, offering contracted IT services such as helpdesk and technical support, server and network maintenance, and data back-up. In many cases, they also provide managed cyber-security solutions to their customer bases. Consequently, these businesses often have significant access to their clients’ IT networks, infrastructure and data, which makes them attractive and valuable targets.

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

The cloud providers I have spoken to talk about several things. They talk about the crippling cost of energy in the UK, something that we need to drive down—

None Portrait The Chair
- Hansard -

Order. You are telling me that you do not think it is in scope, but we consider that it is.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Once again, the shadow Minister is auditioning for roles in the Treasury, by talking about general taxation, and in the Department for Business and Trade, by talking about general philosophies of regulatory reform. I will focus on matters within the scope of our debate, and on four aspects in particular.

First, Opposition Members have raised questions about definition. They have been answered frequently, but I am happy to repeat the answer. The scope of MSP coverage, which focuses on large and medium-sized MSPs, means that something in the order of 11% of MSPs are covered, by number, but 97.6% of the UK’s MSP revenue is covered. I hope that that gives sufficient assurance as to the coverage of the Bill. Of course, the critical supplier provisions cover any others.

--- Later in debate ---
Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

Will the Minister give way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am happy to proceed and to focus on Crown ownership of data centre provision to others. For those reasons, I continue to commend clauses 9 to 11 to the Committee.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

Will the Minister please clarify whether he thinks that, as page 102 of the impact assessment states, the hourly rate for a lawyer changing a contract is ÂŁ34?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I simply point out to the hon. Member that the pricing for law varies materially. I hope that, with the benefit of technology, it continues to be very accessible to all relevant providers.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

I am sorry, but that is nonsense. The footnote on the page that cites £34 an hour for a contract lawyer directs us back to the Office for National Statistics. I hope that the Minister lives in the real world—he has clearly worked in the business world—so he knows that that is nonsense. Does he agree that that pretty well undermines that section of the impact assessment?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Having closed the debate, I am happy to conclude.

Question put and agreed to.

Clause 9 accordingly ordered to stand part of the Bill.

--- Later in debate ---
None Portrait The Chair
- Hansard -

The point has been made clearly on the record. We can take it beyond this room, and perhaps you can write to the Minister afterwards for clarification.

Clauses 10 and 11 ordered to stand part of the Bill.

Clause 12

Critical suppliers

Question put, That the clause stand part of the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 12 will introduce a new power for regulators to designate critical suppliers to organisations as in scope of the NIS regulations. These are suppliers that are so pivotal to the provision of essential digital or managed services that a compromise or outage in their systems can cause a disruption that would have serious cascading impacts for our society and economy; I am thinking in particular of the Synnovis incident in 2024, when 11,000 medical appointments were cancelled across London hospitals as a result of an attack on a pathology service provider.

The clause will ensure that the power to designate can be exercised only where suppliers pose a credible risk of systemic disruption and when the regulator has considered whether the risks to the supplier cannot be managed via other means. In other words, it is a very high bar indeed. 

The clause provides safeguards for suppliers, which must be consulted and notified during the designation process. It also requires regulators to consult other relevant NIS regulators when they are considering whether to designate, or decide to do so, ensuring that they have an accurate understanding of how suppliers are already regulated. 

Finally, the clause provides for designations to be revoked when risks no longer apply or when a supplier has met the thresholds for regulation as a relevant digital service provider or relevant managed service provider. It should be noted that the clause does not set out the security duties on critical suppliers; these will be defined in secondary legislation following an appropriate period of consultation.

By addressing supply chain vulnerabilities, this measure will strengthen the resilience of the UK’s essential and digital services on which the public rely every day. I commend the clause to the Committee.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

The clause merits close scrutiny, because it is the point in the Bill where risk is supposed to be addressed beyond the individual operator and into the supply chain. In plain terms, clause 12 will allow the regulator to designate a supplier as critical where disruption to that supplier would have a significant impact on the delivery of an essential or digital service. The trigger is impact, not size or sector. That approach is sensible, but I want to stress-test how it works in the context of operational technology.

Across power, telecoms, transport, water and industry, many essential services rely on the same family of industrial control equipment. Substations, signalling systems and industrial plants may look different, but they often run on identical controlled devices and firmware supplied by a very small number of manufacturers.

The risk is not hypothetical. A single vulnerability in widely deployed OT equipment can create a common mode failure across multiple sectors at the same time, even where each operator is individually compliant with its duties. At the moment, the Bill places obligations squarely on operators of essential services, but in OT environments, operators do not control the design of equipment, the firmware, the vulnerability disclosure process or the remote access arrangements that vendors often require as a condition of support.

As Rik Ferguson highlighted in written evidence to this Committee, uncertainty about how and when suppliers might be brought into scope can lead to defensive behaviour and late engagement. The risk is amplified in OT, where suppliers may discover vulnerabilities before operators do, and where one operator may report an issue, while others in different sectors, using identical equipment, remain unaware.

There is also a traceability problem. OT equipment is frequently sold through integrators and distributors. Manufacturers may not have a clear picture of where the equipment is ultimately deployed. Without that visibility, national-scale vulnerability notification and co-ordinated response become very difficult.

UK Finance has also drawn attention to the complexity of multi-tier supply chains and the need for clear accountability when regulatory reach extends upstream. The clause recognises that reality, but its effectiveness will depend on how consistently and predictably designation decisions are made across sectors.

My concern is not about the existence of the power. It is about whether, in practice, the power will be used early enough and clearly enough to address shared OT risks before they become cross-sector incidents. Operational resilience today depends less on individual sites and more on the security practices of a relatively small— I would say very small—number of OT suppliers that sit behind them. The clause has the potential to address that, but only if its application is focused on genuine systemic risk and supported by clear signals to suppliers and operators alike. For those reasons, the clause warrants careful consideration as the Bill progresses.

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I really appreciate my hon. Friend’s intervention. It goes incisively to the heart of the concern about how these provisions are currently drafted. I really struggle to see how an OES that is providing a service to another OES could effectively argue that it is not within the full scope of these regulations. We have a lot of OESs in this country. It may be the Minister’s and the Government’s intention to essentially have a proxy regulatory framework for suppliers to OESs going forward—it is being kept very loose, because there is some flexibility in that, but that in itself will be a problem.

I worry that a lot of providers are going to think to themselves, “Why should we provide to an OES when we might be at risk of being designated as a national critical supplier?” Surely that is a concern that will have a chilling effect on organisations supplying to OESs, because of the risk of being found within the scope of this additional regulatory burden.

Don’t get me wrong; as I have said, companies should be taking cyber-security seriously, as should everyone. However, not everyone should be subject to the various regulations and data-sharing requirements that this Bill provides for. I suspect that many organisations will be very concerned. If there is a risk of designation as a critical supplier, companies will already be instructing lawyers and other organisations to manage that corporate risk.

If an organisation starts supplying to a hospital trust, or to whoever it may be, it might think, “Actually, we’re likely at risk of being designated, so we need to start doing some work and investment, either to challenge that designation or begin doing the preparatory work.” Maybe that is the intention: to effectively regulate the entire sector providing to OESs without actually lifting a finger in terms of regulation through this Bill. If that is the case, I am sort of sad, because I think it is better to be clear-cut about it. I would be grateful if the Minister answered that point directly.

Finally, in terms of OESs, we have already mentioned the fact that Government and local authority IT infrastructure and services are among the biggest risks in our system. I was really struck by the evidence from the NHS on Tuesday, in which our witnesses described data-sharing operations with adult social care, which is of course provided by local authorities.

It seems quite perverse, if I may say so, that a GP surgery, which is a private organisation, could be deemed a critical supplier to a hospital in terms of patient information sharing. Quite frankly, I would like the Minister to answer the question specifically: does he envisage primary care GPs being in scope because of data sharing of hospital records with NHS trusts? GPs could fall within scope as critical suppliers, while social care records, which are provided by local authorities, would not. There are all these weird situations that could emerge because of the scope and the looseness of these provisions, with all the consequent harms and problems. I look forward to hearing the Minister’s responses to my points.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

First, I will respond to the apt and thoughtful points from the hon. Member for Bognor Regis and Littlehampton on operational technology. I can confirm to her that both vendors and providers of operational technologies will be covered by the provision of the five-step test for critical supplier designation. That is an important aspect when thinking about supply chains and the presence of operational technology where it is of critical interest.

The hon. Member for Spelthorne raised a very accurate point about proportionality in the provisions of the Bill, and in particular the impact assessments, statements, or limited statements on critical supplier impacts. As he will know very well, the Bill takes a very nuanced position on proportionality. When a sector is designated, there will be total clarity on the number of suppliers affected and on the ultimate impact. We will have sight of that.

The provision on critical suppliers was asked for by industry. The reason why the Bill does not specify critical suppliers is that it is simply not for the Government to specify how a business can or cannot continue. It is for businesses and regulators to work that through by understanding the depth of expertise that businesses have. We have started to do that, but that is precisely why the critical suppliers provisions have been delegated to secondary legislation and subsequent guidance.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

Will the Minister give way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I commit to giving way to the hon. Gentleman at the end of my speech. He asked about schools. I am happy to confirm that schools are not in the scope of the Bill.

In response to the shadow Minister, I highlight that the five-step test is cumulative: a business must meet all the conditions to be designated as critical, not just one. I think that answers the series of logical puzzles that he tied himself up in.

I am very happy to confirm to the Committee that it is expected that regulators will use information gathered from their oversight of operators of essential services, relevant managed service providers and relevant digital service providers to identify potential critical suppliers for designation. They can also ask organisations for more information to support their assessments. Future supply chain duties will also require organisations to share supply chain risk assessments with regulators. A supplier can be designated only after the regulator has completed an investigation process, including serving notices and holding a consultation, and confirmed that the criteria are met. Designated suppliers will also have the right to challenge decisions through an independent appeals process.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Will the Minister give way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I commit to giving way at the end of my speech to the shadow Minister and the hon. Member for Spelthorne.

On the question of consultation, I am happy to confirm that the team in question has set up an implementation-focused effort. We have started to engage with regulators already, and there will be an extensive process of engagement on the Bill with business, as has been conducted historically.

The shadow Minister highlighted a number of logical puzzles. I have worked in a range of businesses and public sector organisations, and most have business continuity services. His hypothetical idea that businesses do not understand alternative provision, and whether they are or are not in a position of exposure, is well solved in the real world. I would give more credit to our expert witnesses from NHS Scotland than he did in recognising that they said that they frequently deal with the question of critical suppliers in co-ordination with competent authorities.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

The Minister came back with an answer on proportionality, saying that it is not for Government to decide what is essential. He missed out the next bit, which is, “We’re just going to regulate critical suppliers and pass laws about them, but we don’t know how many there are, and we don’t know how much the policy is going to cost.” Would he accept that characterisation as the logical conclusion of what he said?

The Minister also said that schools were not covered by the Bill. As far as I am aware, patient data and children’s data are two of the most precious things that we have, so I would like to know why schools are not covered by the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

On the first point, I am afraid that I do not think that was an appropriate characterisation, because where the sectoral scope is clear and where there is a clear risk of critical national infrastructure and essential services being directly exposed, we have specified that in the Bill. We have looked at the impacts set out in the impact assessment. For the critical suppliers in those sectors—I would expect them to be very limited in number—we have made sure that regulators and businesses have the flexibility to set the requirements directly, rather than them being set here in Parliament.

Chris Vince Portrait Chris Vince
- Hansard - - - Excerpts

I was going to intervene on the hon. and gallant Member for Spelthorne, but he is bigger than me. I recognise the points he made about the number of critical suppliers, but I come at the question from the other angle: doing nothing may leave critical suppliers at risk. Although we might not know the exact number, as he correctly asserted, it is important that we do something and introduce the regulations as soon as we can to protect our critical infrastructure.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank my hon. Friend for that point. This issue has not come out of nowhere. Industry and a number of organisations asked that we introduce the measures in the clause.

Beyond the very clear five-step test for critical supplier designation, the Bill provides that the requirements on critical suppliers are proportionate. The reason why we have both the five-step test and the provisions in the Bill is that, in most cases, if the risk assessment suggests so, the security requirements set out in the Bill will be less onerous in most cases. They will be specified in secondary legislation and guidance.

On the question of schools, and more broadly the question of public sector authorities, I entirely accept that the handling of pupil data in schools is a critical aspect of our public service operations. The reason why public service authorities have largely been left out of the Bill’s scope is because we do not need to wait for the legislative process to act. We have been working, not least closely with the Government’s cyber-security strategy and the cyber action plan, to ensure that pupil data is kept securely and robustly.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

The Minister is, of course, within his rights to snarkily dismiss the questions that I have raised, but I should point out that the stuff that is debated in Parliament, whether in Committee or on the Floor of the Chamber, is relevant when it comes to future legal disputes after a Bill is passed. The questions I have asked about the application of the Bill’s provisions will be important parts of the legal disputes that I expect will arise after its implementation. When people look back through the Minister’s dismissive comments, I hope they have other resources that they can go to for settling legal arguments. However, he may choose to respond fully now, or in writing if he cannot provide me with an answer.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I believe that where the shadow Minister laid out any specific concerns, I was able to set out answers, not least on the process for the designation of critical suppliers and the availability of an appeals process. Where his points were more in the realm of specific hypothetical puzzles, I have stayed clear for precisely the reasons that he highlights. This is serious stuff that can form the basis of how businesses and others plan, rather than specific judgments that we ought not to speculate about in this House.

Question put and agreed to.

Clause 12 accordingly ordered to stand part of the Bill.

Clause 13

Provision of information by operators of data centre services

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss clause 14 stand part.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 13 ensures that operators of data centres provide essential information to regulators, enabling them to properly monitor their sector and its cyber-resilience. The clause requires operators to submit key details, such as names, addresses and contact information, within three months of designation, and to update regulators within seven days if anything changes. Regulators are required to maintain a list of designated entities. By keeping regulatory records current, the clause strengthens our ability to monitor and protect essential services and respond to incidents that could affect businesses, public services and national security. The clause plays a key foundational role in the Bill’s wider framework for cyber-security and resilience.

Like clause 13, clause 14 places legal duties on digital and managed services providers to provide essential information to their regulator—in this case, the information commission. Like operators of data centre services, RDSPs and MSPs will be required to register with the information commission within three months, submitting key details, such as names and contact information, and to update regulators within seven days if anything changes. Organisations based outside the UK will be required to nominate a UK representative and provide contact details. To strengthen cross-agency support and recognise the key role that these businesses play in the UK economy and society, the information commission will be required to share its registers of relevant digital and managed service providers with GCHQ. Those proportionate steps will enable authorities to do their job and respond when it matters.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 13 requires in-scope data centre operators to provide certain information to their designated competent authorities, which—subject to Government amendment 11, which we passed earlier—will now be solely Ofcom, and to keep that information up to date. The information includes the data centre operator’s address and the names of directors. It must be provided within three months of the data centre operator’s designation. For data centres that meet the threshold criteria, that would be three months after clause 4 comes into force. Other OESs are not subject to an equivalent requirement to provide information to their sector regulator. That reflects the fact that the Government currently have limited information about the data centre sector.

RDSPs are already required, under regulation 14 of the NIS regulations 2018, to provide their contact details to the information commission, as their sector regulator. Clause 14(2) amends regulation 14 to require RDSPs to provide more information, including about their directors and the digital services they provide. It would also require the information commission to share a copy of its register of RDSPs with GCHQ. Clause 14(9) requires RMSPs to register with the information commission and to submit the same contact details as RDSPs. RMSPs must nominate a UK representative if they are based outside the UK. The information commission will be required to maintain a register of RMSPs and to share it with GCHQ. Clauses 13 and 14 give Ofcom and the information commission access to more detailed information about regulated entities and facilitate regulatory oversight of the data centre RDSP and RMSP industries in the UK.

Question put and agreed to.

Clause 13 accordingly ordered to stand part of the Bill.

Clause 14 ordered to stand part of the Bill.

Clause 15

Reporting of Incidents by Regulated Persons

--- Later in debate ---
None Portrait The Chair
- Hansard -

Order. That is not relevant now.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I appreciate the intent behind the amendments and the shadow Minister’s position of understanding but not supporting them, which I share. I share his concerns about the potential for emerging risks posed by AI systems, not least in the realm of cyber-security. At the same time, I am conscious that we have not specified any risk factors in the Bill from a reporting point of view for the National Cyber Security Centre or the regulators. To do so in this context would place an undue priority on one category or source of risk.

For those reasons, although I understand the motivation behind the amendments and I am conscious of the risks posed by AI systems, I urge the hon. Member not to press them. The Bill is technology-agnostic rather than focused on particular areas of risk. The Government continue to work on mitigating AI risks, primarily at the point of use, but also through extensive Government capability, not least in the AI Security Institute.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I beg to ask leave to withdraw the amendment.

Amendment, by leave, withdrawn.

Ordered, That further consideration be now adjourned. —(Taiwo Owatemi.)

Cyber Security and Resilience (Network and Information Systems) Bill (Fifth sitting)

(Limited Text - Ministerial Extracts only)

Read Full debate
Committee stage
Tuesday 10th February 2026

(7 months, 3 weeks ago)

Public Bill Committees
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 Read Hansard Text Amendment Paper: Public Bill Committee Amendments as at 10 February 2026 - (10 Feb 2026)

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss:

Clause 16 stand part.

New clause 6—Inclusion of ransomware attacks in the NIS Regulations—

“In regulation 1(2) (interpretation) of the NIS Regulations—

(a) in the definition of ‘incident’, after ‘systems’ insert ‘or a ransomware attack which is targeted at the security of network and information systems’;

(b) after the definition of ‘online search engine’ insert—

‘ransomware attack’ means a cyber-attack involving a type of malicious software that infects a victim's computer systems, can prevent the victim from accessing systems or data, impairs the use of systems or data or facilitate theft of data, and in relation to which a ransom is demanded for access to be restored or for data not to be published.”

This new clause would include ransomware attacks in the definition of “incident” in the NIS Regulations.

New clause 7—Impact of reporting requirements on relevant bodies—

“(1) The Secretary of State must, within 12 months of the passing of this Act, publish and lay before Parliament—

(a) a review of the impact, on relevant bodies, of—

(i) the requirements relating to the notification of incidents in Parts 3 and 4 of the NIS Regulations (as amended by this Act); and

(ii) any additional incident notification requirements made by regulations under this Act; and

(b) proposals for the creation of a single cyber incident reporting channel for relevant bodies.

(2) A review under this section must consider –

(a) the costs of requirements on relevant bodies; and

(b) interactions with other incident reporting regimes.

(3) In this section, ‘relevant bodies’ means operators of essential services, critical suppliers or digital service providers, as defined by the NIS Regulations.”

This new clause would require the Secretary of State to review the impact of incident reporting requirements on relevant bodies, and to set out proposals for a single incident reporting channel.

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- Hansard - - - Excerpts

I will begin by discussing clauses 15 and 16. Clause 15 updates the incident reporting provisions in the Network and Information Systems Regulations 2018. Under the current regulations, organisations are required to report incidents only once they have had a significant impact on service continuity. It is widely recognised that this is too narrow, and results in a range of concerning incidents going unreported and a distorted picture of how secure and resilient the UK’s essential services actually are.

To take two examples: a ransomware attack where confidential data has been exfiltrated from an organisation without an immediate impact on service would not be reportable; nor would a pre-positioning attack, where a hostile actor has hacked into a network and is in a position to cause significant disruption down the line, such as to the provision of drinking water. That cannot be right, and does not reflect the cyber-threats that critical services face.

To ensure such incidents are caught, the clause sets a new, wider definition of incidents that must be reported. The focus is now on incidents that have successfully affected the security or operation of an organisation’s network and are likely to have a significant UK impact, which will ensure that regulators and the National Cyber Security Centre are fully aware of the range of cyber-threats affecting the UK’s essential services.

The Bill sets out the factors that should be considered when assessing whether an incident has had, or is likely to have, a significant impact in the UK—including, crucially, whether the confidentiality, authenticity, integrity and availability of data has been compromised. The Government will provide further clarity in secondary legislation, setting out thresholds for each sector for when an incident is considered to have had, or be likely to have, a significant impact. That will be consulted on before it is introduced. Taken together, it means that only meaningful incidents are reported. Over-reporting has been a concern raised by hon. Members throughout the Bill’s progress, so I stress this point: things such as unsuccessful phishing emails will clearly not be reportable, as they would not be likely to have a significant impact.

Given our economy’s systemic dependence on data centre facilities, for that sector alone we will also ensure that Ofcom and the NCSC receive reports on a wider range of potential incidents and near misses. That ensures that not only immediate disruptions but incidents posing future risks are reported.

Clause 15 also streamlines the reporting process for all NIS sectors. It ensures that incident notifications and reports go to the NCSC at the same time as the regulator. It also sets out what those organisations can do with the information they receive, including how the information can be shared to manage the wider impacts of an incident or prevent future incidents. Finally, the clause introduces faster reporting, so that the NCSC and regulators are informed within 24 hours of entities becoming aware that a reportable incident is taking place.

The 24-hour notification will be light touch, but will enable the NCSC and regulators to offer faster support to minimise the negative impacts of the incident. Fuller details will need to be reported within 72 hours of the entity becoming aware that a reportable incident is happening. The changes will protect the UK’s essential services, ensuring that the NCSC and regulators are able to provide the best support that they can.

Clause 16 sets out requirements for managed service providers, relevant digital service providers, and operators of data centres to inform customers who are likely to have been adversely affected by a reportable incident. Under the current regulations, there is no requirement for any regulated entity to inform its customers if it has been impacted by a reportable incident. That may have made sense when the NIS regulations were more heavily focused on operators of essential services and the primary concern was service disruption, but it would be an inexcusable omission now that the Bill is expanding to include managed service providers and operators of data centres, in addition to the digital service providers already in scope.

These are organisations that, if compromised, could leave their customers’ systems, data or services exposed or inaccessible. In such circumstances, it is vital that their customers are notified, so that they can take whatever steps they need to in order to mitigate those risks.

Bradley Thomas Portrait Bradley Thomas (Bromsgrove) (Con)
- Hansard - - - Excerpts

I have two points for the Minister to address. First, could he clarify whether an organisation would face repercussions if a regulator believed in retrospect that notification should have been provided sooner? Secondly, on customer notification, can the Minister address the concern around striking the right balance between informing the customer and ensuring that the update that they receive is meaningful and not so vague that it causes further distress or worry?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for those two thoughtful points. On the first, in terms of retrospective regulatory action on the adequacy of notification, I expect that the regulators will set out—in their guidance and by working closely with the entities in scope—their expectations about the nature and timeliness of the notification. That will be one input into a regulator’s broader assessment of entities’ compliance with the regime. I expect that timely notification will be assessed on an ongoing basis by the regulator, but I would not expect it to be an exclusive or primary aspect.

On the question of customer notifications being proportionate, I share the hon. Member’s concern about ensuring that it is timely and efficient and at the same time meaningful for the relevant customers. I hope that exactly those principles are embodied in the guidance that regulators share about notification requirements.

Customers being notified is all the more important given that in many cases, those customers will themselves be operators of essential services and other critical national infrastructure. The Bill therefore places new transparency requirements on managed service providers, relevant digital service providers and operators of data centres. Similar requirements were introduced under the NIS2 regulations in the European Union.

Clause 16 requires those regulated entities to take steps to establish which of their customers, if any, are likely to be adversely affected by a reported incident. It then sets out the information that the entity must share with those identified customers. These new requirements will support the overall resilience of the UK’s essential services and economy, which depend so heavily on these services, and reduce the overall impact of disruptive cyber-attacks.

Alison Griffiths Portrait Alison Griffiths (Bognor Regis and Littlehampton) (Con)
- Hansard - - - Excerpts

New clauses 6 and 7 sit together and are linked by the same practical concern regarding clarity and workability when an incident is unfolding.

I will start with new clause 6. Ransomware is no longer an occasional or unusual cyber-event; it is now one of the most common and disruptive threats facing essential services, digital providers and their supply chains. Written evidence to this Committee was clear that ransomware incidents are now routine, high-impact events, and that uncertainty at the outset of an attack often makes the consequences worse. The Bill rightly broadens the definition of an incident to capture events that are capable of causing harm, not just those that already have. That is the right direction of travel, but when organisations are under pressure, particularly in the first 24 hours of an incident, uncertainty slows action. Time is lost debating definitions rather than focusing on containment, escalation and reporting.

New clause 6 addresses that problem directly. It makes it explicit that a ransomware attack is an incident for the purposes of the NIS regulations, and sets out clearly what is meant by ransomware attack. It would not create a new duty; it would remove doubt from an existing one. Clear definitions support better behaviour when organisations are operating under real pressure.

New clause 7 follows naturally from that point. If we want faster and clearer reporting, the system into which organisations are reporting has to work in practice, not just on paper. The Bill expands reporting requirements and introduces new notification duties. That is understandable, but UK Finance told the Committee that many firms already support cyber-incidents under multiple regulatory regimes and that additional reporting layers risk duplication rather than resilience. When an incident is live, that duplication causes friction, slows the response and increases costs. It can reduce the quality of information being shared because teams are stretched across parallel processes rather than focused on managing the incident itself.

We do not seek in new clause 7 to reopen the policy intent of the Bill; the new clause would require a review, once these changes are in force, of how the reporting requirements are working in practice. That review would consider costs and interactions with other reporting frameworks. The new clause would also require that proposals for a single cyber-incident reporting channel be published. That is not a bureaucratic exercise; it reflects concerns raised in evidence that resilience is undermined, not strengthened, when reporting becomes fragmented at moments of stress.

Taken together, new clauses 6 and 7 are about making the system clearer at the front end and more usable overall. Clear definitions encourage timely reporting and coherent reporting channels make that reporting effective. I hope that the Committee will give serious consideration to both new clauses.

--- Later in debate ---
Emily Darlington Portrait Emily Darlington (Milton Keynes Central) (Lab)
- Hansard - - - Excerpts

I have a few questions for the Minister. I appreciate the clarity that the Bill brings to many of the services in its scope. I would like to understand how the definition of “incidents” will relate to hardware vulnerabilities that are discovered within a company, as we heard from some of the people who gave evidence to the Committee. It is unclear in the Bill. Perhaps it will be further defined in secondary legislation.

I want to understand how an incident in which someone discovers a vulnerability in hardware—such as in a system-in-package—is reported, and how that information is then delivered by the regulator to other companies in the sector that may have similar technology, and to the other regulators, which may also want to flag that technology as a particular vulnerability. Is that defined as an “incident” or is it defined somewhere else in the Bill? I am a bit confused and am looking for some clarity.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Having been promoted from a position of mere confidence to faith, I will tackle questions from the hon. Member for Runnymede and Weybridge first and foremost. On the question of thresholds of incident, the Bill sets out the severity of the sorts of incidents that we expect reporting obligations to apply to, and at the same time it ensures that it is proportionate in understanding that sector-specific thresholds ought to be precisely that—sector specific, set closely with relevant entities in that sector, and working with the expertise of the relevant regulators. For that reason, it has not been specified more fully on the face of the Bill.

On information sharing, not only is there provision for the specific sets of purposes for which information sharing ought to take place between regulators, but there is a further check on the proportionality of that, through a particular requirement, to ensure that information that is shared in incident contexts is done precisely for the purposes set out in the Bill, and in a way that is proportionate.

My hon. Friend the Member for Milton Keynes Central raised the question of hardware impacts. While the focus of the Bill is primarily on network and information systems, the test, as I think of it, would look at whether any compromise in network and information systems related to a piece of hardware triggers the severity of the impact, or potential impact, to be reportable. In the event that it is reportable, in its severity and potential impact, it will require notification—to the regulator and, when customers are directly impacted in the way that is set out in the Bill, also to the customers. The test is focused on whether network and information systems are engaged, and whether the impact of any incident is likely to be severe enough, in light of the thresholds set out in the Bill.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

My hon. Friend the Member for Bromsgrove raised the case of M&S, which would clearly be out of the scope of the Bill. However, it has a managed service provider, so it is a bit like the JLR case. I am still looking for some certainty as to whether JLR and M&S would come within the scope of the Bill by dint of the fact that they have managed service providers, which are within the scope. I am still not 100% clear on the answer to that question. I would be grateful for greater clarity from the Minister.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I hope this does offer the clarity that the hon. Member seeks. While I will not refer to specific businesses, broadly speaking the sector of food supply is not within the scope of the Bill; the obligations on operators of essential services or direct entities that are within the scope of the Bill will not apply.

However, if—in a hypothetical situation—a managed service provider within the scope of the Bill supplies to that business, the managed service provider would be within the scope of the Bill’s requirements. The customer—in this case, the food supply business—may, if the severity applies, be in receipt of reports from the relevant MSP, in this particular context. They will not be caught up in the full set of obligations in the Bill, but we would expect customers to be notified of incidents where the severity thresholds are met. I hope that gives the hon. Member some clarity.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

I am grateful to the Minister for giving way a second time. I understand his answer, but, to be clear, if an incident that meets the severity threshold is reported to a client who is out of scope, would that bring any obligation to report in the normal way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Under the provisions of this Bill alone, only the entities specified as critical suppliers or operators of essential services—the relevant digital providers and so on—would be caught up in obligations if an event occurred. Assuming neither of those is true of a food supply business, the Bill’s provisions would not apply.

At the same time, in the sort of incident that the hon. Member describes, we would expect the NCSC to be deeply engaged, assuming severity thresholds and wider risks are applied. We would work closely on that operationally and I am sure we would look at how that business could be supported more widely. But the Bill’s provisions are really focused on the sectors, and entities within those sectors, that have an immediate threat to day-to-day operations such as a potential threat to life. There are reasons, which we can get into later, as we have done previously, why we set the sectoral scope in that way.

New clause 6 seeks to clarify that a ransomware attack falls under the definition of “incident” within the NIS regulations. I share the concerns of the shadow Minister and the hon. Member for Bognor Regis and Littlehampton about the significant disruption that ransomware attacks can cause. Indeed, last year we saw the impact of the ransomware attack on Synnovis, a supplier to the NHS, which resulted in the delay of 11,000 out-patient and elective procedure appointments. The hon. Member for Bognor Regis and Littlehampton and the shadow Minister are quite right that this kind of attack should be considered an incident under the NIS regime. Because of the changes to incident reporting introduced by the Bill, I can confirm to the Committee that ransomware attacks will be in scope.

The Bill updates the definition of “incident” so that it applies to any event that has, or is capable of having, an adverse effect on the operation or security of network and information systems. Ransomware attacks already fall well within that definition. Although I welcome the principle and intent behind the new clause, its content is already addressed by the Bill. I hope that assures hon. Members across the Committee.

New clause 7 would require the Government to publish a review of the new incident reporting regime within a year of the Bill’s receiving Royal Assent. It is important that the effectiveness of the NIS regulations, including the reforms to incident reporting introduced by the Bill, should be reviewed periodically. That is why the Bill requires the Government to conduct a review and lay it before Parliament once every five years. That timeframe will enable the new regime to bed in and allow a meaningful period of time to measure change before the Government report on its effectiveness. As my hon. Friend the Member for Stoke-on-Trent South said, notwithstanding her and the shadow Minister’s confidence in me and the Government, to publish a review after only one year would risk giving an incomplete picture, as regulators and regulated entities may still be transitioning to the new processes.

The new clause would also require the Government to publish proposals for a single reporting platform for cyber-incidents, again within a year of the Bill’s passing. We have heard the clear ask from businesses to minimise the time they spend filling in different reporting templates following an attack, to ensure they can prioritise the technical response. I share the concerns of the hon. Member for Bognor Regis and Littlehampton, and we are exploring all options to enable a proportionate and efficient reporting system. That said, setting a fixed time limit of one year to develop proposals does not reflect the inherent complexity of the task and the need to get it absolutely right for the businesses in scope of the Bill, not least because the proposals will need to be rigorously evidenced, consulted on and tested. For those reasons, I am unable to accept the new clause.

Question put and agreed to.

Clause 15 accordingly ordered to stand part of the Bill.

Clause 16 ordered to stand part of the Bill.

Clause 17

Powers to impose charges

Question proposed, That the clause stand part of the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 17 introduces new charging powers for NIS regulators, enabling them to recover the full costs of their regulatory functions under the NIS regime. This is an important reform that will help to ensure that regulators are effectively funded as they take on their expanded responsibilities under the Bill. It will allow them to move away from a funding model that relies on ad hoc invoicing or Government grants, and to approach their duties with greater confidence and certainty.

The clause sets out detailed procedural requirements that determine how and when the charging powers can be used. These will ensure that regulated organisations know what to expect from regulators; fees will be set proportionately and regulators will provide satisfactory accounting for the sums they have charged.

The first requirement is that regulators consult and publish a charging scheme. It must specify what functions the fees are covering, the amount of fees being charged or how those fees will be calculated, and the charging period they cover. Crucially, regulators will be able to set different levels of fee for different types of organisations—for example, varying charges according to size or turnover, or excluding organisations from the charging scheme if it would be disproportionate or counter-productive to include them.

Bradley Thomas Portrait Bradley Thomas
- Hansard - - - Excerpts

I have two points for the Minister to address. First, can he address concerns around whether funds raised will be directly reinvested into improving cyber-security, rather than covering administrative overheads? Secondly, there is no specific reference to turnover thresholds, so how can the Minister be sure that a one-size-fits-all approach will not be used, causing many similar organisations to suffer financially?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for those thoughtful points. On the first question, the charging scheme applies to relevant costs, which are costs that regulators incur precisely when they carry out functions under the NIS regulations relating to cyber-security specifically. Those can include the cost of audits, inspections, handling incident reports or enforcement action, as well as other aspects, such as assessments of cyber-security and the provision of advice. It is important to acknowledge that regulators can decide to recover costs in relation to specific functions or their costs relating in particular to the Bill’s provisions. I hope to have assured the hon. Member that the charging scheme has a clear, tight scope that is related to cyber-security functions.

On the second question, regulators probably ought to look at turnover in a way that is sector-specific, in part because there are already a range of ways in which other regulatory regimes define turnover in particular sectors, so the appropriate definitions for their sectors will be familiar to both regulators and regulated entities. At a later date, secondary legislation may be used if it is found necessary to set out factors that regulators ought to consider in setting up charging schemes, including the possibility of nuanced definitions of turnover. Any future regulations for this purpose will be subject to consultation requirements and the affirmative procedure. I would very much expect, at a sector level, a clear and proportionate definition and charging structure in relation to turnover.

The second requirement is to set out, transparently and clearly, what fees have been paid, what fees are still due, and what costs have been incurred in a given charging period. On Second Reading, many hon. Members discussed the need for properly resourced regulators to successfully implement the Bill. I share that concern, and this clause seeks to achieve exactly that, in a way that is fair and proportionate to regulated organisations.

I commend the clause to the Committee.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 17 will amend the NIS regulations to provide a framework for regulators to impose charges on regulated entities to recover the costs incurred by them in carrying out their supervision and enforcement functions. The Government’s explanatory factsheet supporting the Bill suggests that those changes are needed to ensure that regulators are

“better resourced to carry out their responsibilities.”

We have heard at length from witnesses in oral evidence sessions that resourcing is a key consideration for regulators in meeting their new and expanded obligations under the Bill. The concept of our regulators’ being better funded is good. However, as with much of the Bill, the lack of detail around the regulator charging model is causing uncertainty among regulated entities that would be liable to meet the associated costs.

--- Later in debate ---
Another concern is that a regulator funded by organisations within the remit of its oversight may have reduced incentives to prioritise efficiency in the exercise of its duties. Which comparable regulatory regimes have the Government looked at for inspiration in planning this funding model? Which regulators are regarded as successful in their approach to oversight and enforcement and is there any correlation between that and their funding models?
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The shadow Minister raised two main points that I am keen to address. The first was about ensuring that I committed to next steps on potential guidance for the charging scheme. I can confirm that the Government will issue guidance for competent authorities. That will include general directions on how the fee regime ought to be implemented. At the same time, we do not intend to be prescriptive as to how competent authorities should recover costs to benefit from their experience and practice in setting up these regimes. It is important that each regulator is able to tailor their fee regime in a way that is consistent with and complementary to the state of their sector.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

On the subject of charging and money, has the Minister had the opportunity to revisit his own impact assessment on the basis that there might be a glitch in the matrix? It says on multiple occasions that the hourly salary for a contract lawyer is ÂŁ34 an hour. When we discussed it last week, I contended that this was totally unrealistic, probably to a factor of 10.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am reminded of the hon. Member’s point last week. I am happy to write to him on the basis of the precise figure in the impact assessment, which I understand to be based on not just an extensive survey but the application of subsequent uplifts. I am more than happy to continue that conversation in correspondence.

On factors that ought to be considered in setting up charging schemes, I mentioned some, such as size and turnover, but I will flag that those are suggestive and indicative rather than exhaustive factors that regulators may consider. Regulators ought to be able to set different levels of fee for different types of organisations. There is also provision to exclude organisations from a charging scheme altogether if it would be disproportionate or counterproductive to include them. It is appropriate that regulators and competent authorities can vary their charging schemes in the light of that.

On current regulatory performance and its correlation with charging schemes, I have not observed any direct correlation. What I have seen, simply, is that some regulators are clearly doing well. We heard in evidence from a range of participants that in some cases things are working particularly well and that, in others, there is more scope for improvement. That is precisely why the Bill sets no fundamental lowest common denominator for how regulators ought to approach either charging or their enforcement duties; instead, it ensures that we are conducting oversight of each regulator as robustly as possible. I assure hon. Members that the question of regulatory enforcement is central and that the motivation behind the charging scheme is precisely to ensure that regulators are well resourced to implement the Bill.

Question put and agreed to.

Clause 17 accordingly ordered to stand part of the Bill.

Clause 18

Sharing and use of information under the NIS regulations etc

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I beg to move amendment 14, in clause 18, page 38, line 31, at end insert—

“(aa) otherwise in connection with—

(i) the security and resilience of network and information systems, or

(ii) any other matter relating to cyber security and resilience,”.

This amendment would allow NIS enforcement authorities to share information with persons listed in regulation 6(2) (inserted by clause 18), and such persons to share information with NIS enforcement authorities, for purposes relating to the security and resilience of network and information systems or cyber security and resilience.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss the following:

Government amendments 15 to 18

Clause stand part.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The clause introduces vital reforms to how information can be shared in the context of the NIS framework. Right now, as we have heard again and again from both hon. Members across the Committee and witnesses, the NIS regulations have limitations that restrict how and with whom information can be shared. That has serious implications for the effectiveness and efficiency of the regime including business burdens as well as the ability of the UK’s authorities to act on national security or criminal intelligence.

One important limitation in the current regulations is the inability of regulators to share information with many public authorities in the UK and vice versa. For example, NIS regulators currently cannot share information to support the evaluation of the NIS framework or policy development relating to cyber-resilience and national security. The clause addresses those concerns by enabling information to be shared between NIS regulators and UK public authorities, including the Government. That will be done for the purposes of supporting the NIS regulations as well as wider objectives alike, reducing business burdens and for national security and crime purposes.

The clause also imposes strict requirements and safeguards on how the information can be further shared. The net effect of the changes will be fewer burdens on business, better and more informed regulatory decision making, joined-up incident response and improved security for the United Kingdom.

Government amendment 14 makes targeted but important changes to the clause. It proposes a further ground for sharing information focused on wider cyber-security and resilience outside the context of the NIS regulations and NIS sectors. In practice, it means that NIS regulators will be able to share information with regulators who are responsible for overseeing the cyber-security and resilience of other vital sectors under different regulatory frameworks and vice versa.

The amendment is a crucial addition to the Bill. It means that the UK’s regulators can think holistically about the risks that their sectors are facing, the interventions they propose to take and the obligations they are placing on business. That in turn will mean better outcomes, more effective and informed incident response, more co-ordinated oversight and lower business burdens.

The amendment will be particularly important in supporting co-ordination with the financial regulators responsible for the critical third parties regime, which could be used to designate organisations already in scope of the NIS regulations such as cloud service providers. It also anticipates the need for co-ordination for other sectors, such as civil nuclear and space, in the future. In short, the amendment is necessary to ensure that UK regulators can take a more co-ordinated approach to protecting the UK’s most essential services.

Government amendments 15 to 18 are consequential on amendment 14. I urge the Committee to support the amendments, and I commend clause 18 to the Committee.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 18, which the Government seek to modify through amendments 14 to 18, creates new pathways for information sharing between regulators, public authorities and Government Departments. It also creates a power for NIS enforcement authorities to share information with relevant overseas authorities for specified purposes. The new regime is intended to remove gaps and ambiguities in the existing framework governing the sharing of information obtained in the course of competent authorities and the oversight role of NCSC, and to create legal certainty in this domain.

In turn, it is anticipated that greater information sharing will assist with the detection of crime, enforcement activity and awareness of emerging cyber-risks and with ascertaining the effectiveness of the NIS regulations in building UK cyber-resilience. In particular, the Bill creates a new gateway to ensure that NIS regulators can share information with UK public authorities, and vice versa, as well as sharing and receiving information from organisations outside of the NIS framework, for example other regulators or bodies such as Companies House.

The Bill strengthens safeguards on how information can be used once it has been shared under the NIS regulations by restricting onward disclosure. More effective information sharing will be vital for competent authorities to keep up to date with emerging risks and building resilience in their sectors, and the new measures were broadly welcomed by regulators in our oral evidence session.

However, industry bodies such as techUK have called for further detail on the new information-sharing regime. What steps are the Government taking to ensure that regulators share responsibility for protecting sensitive data, and that information-sharing processes are coherent, proportionate and secure? Could the Minister elaborate on the discussions he has had with regulators on those matters, and on how secure information sharing will work in practice?

Finally, on the detail of the text in Government amendment 14, proposed new paragraph (aa)(ii) refers to persons

“otherwise in connection with…any other matter relating to cyber security and resilience,”.

Given that this is an information-sharing power, that seems a remarkably broad “any other matter” provision. What disclosures that are not already covered in the Bill does the Minister conceive will come up in that scope? What guidance or consultation will the Minister produce to make sure that such powers are proportionate and not at risk of abuse?

Emily Darlington Portrait Emily Darlington
- Hansard - - - Excerpts

Again, I welcome the Government amendments and clause 18; they are important to enabling us to share our vulnerabilities in an appropriate way with those people who may be involved. However, some of the aspects of those vulnerabilities that security services—GCHQ, His Majesty’s Government Communications Centre and others—raised with us relate particularly to not only foreign interference, but the potential for interference through technology embedded in our networks. How does the Minister see the measures working within our co-operation with different foreign nations, particularly during these volatile times?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

In response to the shadow Minister’s first question about ensuring sensitive handling of shared information and proportionality, all information handled by regulators ought to be treated carefully and with awareness of its importance. The regulators have to act reasonably, and the NIS regulations specifically require information obtained from inspections to be held securely. Of course, data protection laws apply to regulators as well. Alongside that, regulators will be required to consider the relevance and proportionality of sharing their information to the purposes set out in the Bill; as I have mentioned, the Bill includes specific purposes for why information might be shared.

--- Later in debate ---
Question proposed, That the clause stand part of the Bill.
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 19 sets out that regulators must provide guidance on specific issues, including security requirements and incident reporting notifications. Guidance already plays an important role in supporting the implementation of the NIS regime. We have, however, identified some areas where regulated entities would benefit from additional clarity. The clause ensures that every regulated sector has the guidance they need from their sectoral regulators to help them to comply. To ensure consistency across regulators, the clause also requires regulators to co-ordinate with each other when preparing guidance relating to designating critical suppliers. The clause also requires regulators to consider guidance published by the Secretary of State such as the code of practice when preparing guidance on the security and resilience requirements. That will ensure that regulators consider good practice recommendations and take more consistent approaches to preparing guidance.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 19 amends the NIS regulations and will require regulators to publish guidance on the security and instant reporting requirements of regulated sectors. In formulating their guidance, regulators are under a duty to co-ordinate and consult with other regulators to ensure consistency as far as is reasonably possible. Relevant provisions in the code of practice, to be issued by the Secretary of State under clause 36, must also be taken into account. Newly regulated entities will, no doubt, welcome proportionate guidance on meeting obligations, and existing regulated entities will appreciate any streamlining that comes from consultation between regulators and their approach. Can the Minister provide further details about whether consultation between regulators and the Secretary of State is under way on a consistent approach to regulation?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

As I have mentioned to the shadow Minister, the Minister for Digital Economy, the Secretary of State and I have engaged with a number of the regulators in scope here. Both those conversations, and the broader framework of this Bill, are intended to drive consistency across sectors through common security requirements, clear guidance and a statement of strategic priorities, which will set objectives that regulators must seek to achieve. I hope that is sufficient assurance not only that those conversations have started, but that they will be a fundamental focus as we ensure consistent regulation across the board.

Question put and agreed to.

Clause 19 accordingly ordered to stand part of the Bill.

Clause 20

Powers to require information

Question proposed, That the clause stand part of the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 20 introduces important updates to the information-gathering powers that regulators have under the NIS regime. It ensures that regulators are able to collect any information that they might reasonably require to exercise, or to decide whether to exercise, their functions under the regulations.

While the clause sets out some of the purposes for which a regulator might particularly wish to collect information—for example, to determine whether an organisation should be designated as a critical supplier—this is an explicitly non-exhaustive list. The clause also allows regulators to collect information through the issuing of an information notice. It sets out the details that must be included in such a notice, and the form that it may take. An information notice must, for example, explain why the information is being sought and the form in which it must be provided.

New regulation 15A, as introduced by the clause, makes clear that an information notice can be given to an organisation based outside the UK and can apply to information held outside the UK. An information notice may require the obtaining, generating, collecting or retaining of information or documents. Those changes are critical in ensuring that regulators can access the information they need properly to enforce the NIS regulations. I commend this clause to the Committee.

Bradley Thomas Portrait Bradley Thomas
- Hansard - - - Excerpts

Can the Minister elaborate on how he will ensure that regulators have the capacity to cope with large-scale data reports?

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

In terms of scope, could the Minister give us some sense, when it comes to managed service providers, whether the purpose behind this clause is to enable regulators to find out their entire client list? I would be grateful for some clarity on that point.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I will take each of those three questions in order. The hon. Member for Bromsgrove raised a very important point—shared, I think, in sentiment across the House—about ensuring that regulators have the capacity to deal with the volume and quality of information they might receive under the provisions of this clause. Precisely for that reason, we have set out a charging scheme possibility here that allows regulators to equip themselves. Of course, that is initially a question of resourcing, rather than the quality or capability of that resourcing. We will therefore continue to ensure, through our oversight of regulators in appropriate ways, that we are pressing home the importance of enforcement quality and regulatory capability.

To the shadow Minister’s point on proportionality, I share the focus on ensuring that designation and information requirements are proportionate, not least for critical suppliers. Like him, I will avoid repeating the previous debate, but the five-step test for the designation of critical suppliers, combined with the fact that the Bill allows for secondary legislation and guidance to specify more proportionate burdens on them, rather than on key regulated entities, alongside the fact that information notices ought to be proportionate and focus primarily on the purposes of the Bill, gives me—and, I hope, him—assurance about the proportionality embedded in the Bill.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Will the Minister talk through what the data exchange flow chart will look like? How will it work in practice? Will the OES proactively contact the regulator and say, “We have all these suppliers—go play”? Will the regulator contact the OES and say, “Give us a list of all your suppliers, and then we are going to start an investigation programme and decide what data we need”? What is the direction of communication in practice? Or—perhaps even worse—will the burden be on suppliers to an OES to contact the regulator and say, “Could we possibly be in scope?” How will it shake out in practice?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Although I will not specify prescriptively what the activity and flow ought to be, I can share from my experience that many large-scale businesses—and indeed many medium and small-sized businesses—have a very clear business continuity plan mapping their critical suppliers. In this case, I would expect the regulator and the regulated entities to engage. Who sends the email first is an open question, and I would not want to specify it in the Bill, but I would expect each regulator and their regulated entities to work very closely to understand the critical suppliers that meet the tests specified in the Bill, and to engage with those critical suppliers as a consequence.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

The Minister has mentioned business continuity plans a second time as a justification for not going into detail on this, but the whole reason for the Government bringing in the powers in clause 12, and the designation of critical suppliers, is that there was no business continuity plan in place in the example of Synnovis. I do not see how that argument gets away from the need for clarity, for organisations that could be at risk of being in scope of being assessed and designated as a critical supplier, about what actions they have to take in response to regulation, proactively or otherwise, and the burdens on them. We have just discussed the cost of enforcement, which risks essentially becoming a cyber-security tax.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I would not want to imply that every organisation has a business continuity plan, but the simple point is that the framework for assessing critical third-party suppliers is established in business and other regulatory regimes, as I have mentioned. The novelty or ambiguity that the shadow Minister suggests simply does not apply. That is not to say that there will not be cases in which new critical third-party suppliers will be designated—that is the point of the provisions of the Bill. The practice will of course need rigour, efficiency and proportionality, but it will be grounded in existing, widely understood frameworks.

I need the hon. Member for Spelthorne to remind me of his question, if I might ask him to do that.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

I might have to remind myself. I asked the Minister whether the purpose of this clause is for a regulator to be able to ask a managed service provider what their entire client list is, in order to make various assessments.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for asking and repeating the question. The purposes of the provisions on information requirements are focused on ensuring that regulators can conduct their duties as provided by the Bill. I would not expect information notices to require an exhaustive list in every instance, but instead to primarily focus on a more proportionate set of asks relating to risk vectors to the security of the regulated entities and to wider national security and cyber-security.

Question put and agreed to.

Clause 20 accordingly ordered to stand part of the Bill.

Clause 21

Financial penalties

Question proposed, That the clause stand part of the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 21 reforms the enforcement regime for the NIS regulations. It seeks to ensure that providers of the UK’s most essential services are complying with their obligations under those regulations. Where they are not, it will allow for more meaningful penalties that reflect the risks they introduce to our society and economy as a whole. To do that, the clause makes a number of critical changes.

First, the clause introduces a new penalty maximum based on turnover. The current maximum penalty is £17 million, which can appear disproportionately large for smaller organisations, but could also easily be absorbed by larger ones as the “cost of doing business.” The clause therefore increases the penalty limits from £17 million to a maximum of £17 million or 4% of annual turnover, whichever is higher. I am confident that that strikes the right balance within the UK regulatory context. It brings the regime in line with other UK legislation that regulates cyber-security, such as part 1 of the Product Security and Telecommunications Infrastructure Act 2022, without rushing uncritically to the more severe penalties we see in other CNI regulation.

The second change is to create a simple two-band penalty structure that will provide much-needed clarity to regulators and industry about the penalty tiers for specific acts of non-compliance.

Bradley Thomas Portrait Bradley Thomas
- Hansard - - - Excerpts

On the point about banding, can the Minister assure us that there will be consistency applied across regulators so that different events are not differentially penalised depending on the regulatory body? On the question of turnover and the financial penalty, can the Minister elaborate on how the figure was derived?

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member on both fronts. On the penalty bands, clearly defined parameters are set out in the Bill, and my hope is that that increases the effectiveness, the clarity and—at the heart of it, to his question—the consistency of application we expect across regulatory regimes.

As I mentioned, the 4% figure for the maximum penalty in part referenced existing UK regulatory regimes and legislation that were felt to be the most comparable. In part, it was judged to be an appropriate, proportionate maximum, based on relevant concerns around the appropriate level of deterrent effect, the proportionate level of fine, the regulatory precedent and the broader impact on investment and the economy as a whole, notwithstanding the significant cyber-security costs businesses already experience.

The second change in the clause is intended to eliminate the confusion surrounding the definition of a “material contravention” in the current regulations. Finally, the clause ensures that regulators can consider a wider range of factors when determining what constitutes an appropriate penalty. Where mitigating steps have been taken to address a breach, that should be acknowledged, but so too should the impacts of the breach and any history of compliance or non-compliance.

To conclude, an effective regulatory regime must be backed by fair but effective penalties to ensure that it is followed.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

This is really where the regulatory rubber hits the road. Earlier, we described cases involving a client who is not in the Bill’s scope but who employs a managed service provider that is, and that is therefore vulnerable to these charges. What happens when there is an interface between a client employee operating an IT system and what the managed service provider does? For example, someone could bring in a data stick, shove it in the side of a computer and break the rules, eliciting some form of ransomware. How will it work when the regulator goes to the managed service provider and says, “Here’s your £10 million fine,” and the client says, “That is down to you”? It is going to be a lawyer-fest, isn’t it? Even lawyers who get paid more than £34 an hour are going to make quite a lot of money.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Just so that I am clear, not least for future records, I think the case described is one where the client is not in the Bill’s scope but is provided to by an MSP that is in the Bill’s scope, and where the relevant responsible individual is in the client business as an employee or agent of that business. The hon. Gentleman raises an important point. Both the obligations and the defined focus of the Bill are on regulated entities. In this instance, if the individual is not in the regulated entity and the regulated entity has complied with the entirety of the wider cyber-security reporting obligations in the Bill, we would look to other venues of legal action against the individual in question. It would be challenging for a Bill that does not regulate the entire economy to ensure that every individual and firm unregulated by it are brought into its scope as well. But that is not to diminish the significance of requiring other pieces of law to act on individuals elsewhere.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I will come to my speech, but as we are having a debate on this point, but does the Minister’s answer not risk a gilded defensive posture being set up by MSPs? If they list terms and conditions for the use of their services that essentially bar everything, they can say that any liability—if there is ransomware or they get hacked—is completely on the client, as opposed to themselves. Does the Minister’s explanation not risk MSPs taking a very defensive posture to ensure that the client is liable for any problem? Given that the clients are usually not regulated entities, this provision effectively becomes meaningless.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I can see the shadow Minister’s hypothetical point, but I assure him that if there is some universal, consistent practice on the part of an MSP to avoid liability, where liability should reside with them, that should be in scope of how the regulator assesses the performance of that MSP. Secondly, I assure him that there remains a degree of competition in the MSP market, given the attractiveness of the UK customer and end user market for MSPs. I would therefore very much expect any MSP that adopts a falsely defensive posture of the sort that the shadow Minister describes not only to be assessed as doing so by the regulator, but to fall foul of the competitive market context that we have and want in the UK.

To conclude, an effective regulatory regime must be backed by fair but effective penalties to ensure that it is followed. The clause ensures that that is the case for NIS regulations, and for that reason I commend it to the Bill.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I think I will follow up in writing on my intervention to try to dig down into the explanation of how liability will be laid down when the client is not a regulated entity but is receiving services from regulated entities. That is an important point, because these are quite hefty fines. As my hon. Friend the Member for Spelthorne pointed out, even with ÂŁ34 an hour lawyers, there will be a lot of industry activity to try to avoid liability in the context of a substantial cyber breach, which can be significant.

More generally, the clause makes significant changes to enforcement practices under the NIS regulations, including to increase the financial penalties regulators can impose for infringement of the regulations, and to set out a clearer system of tiered penalties, based on the severity of infringements. The Government’s impact assessment states that these changes have been made because of concerns reported by regulators that

“enforcement under the NIS Regulations has been constrained by unclear band structures and a maximum penalty which is insufficient to deter non-compliance across all NIS sectors”,

which goes back to my previous point. Enforcement activity under the NIS regulations has been sparse, inconsistent and insufficiently effective to increase cyber-resilience to the levels necessary to meet the proliferating cyber-security risks to our most critical sectors.

Fundamentally, the existing approach to enforcement has not achieved the necessary change in attitude to cyber-risk at the highest levels of regulated entities. It is concerning that board level responsibility for cyber-security has steadily declined among businesses since 2021, with 38% of businesses having a board member responsible for cyber-security in 2021, compared with 27% in 2025.

The enforcement model clearly needs to be more effective, and increasing fines is only one part of that. Regulatory capacity to undertake supervision and enforcement remains a concern, as does perceived reticence on the part of regulators to impose fines on critical infrastructure providers, due to the risk of destabilising essential services and increasing costs for consumers. In our oral evidence sessions, many witnesses, including Richard Starnes of the Worshipful Company of Information Technologists, raised the issue of greater responsibility at the highest levels of management for cyber-resilience. What assessment has the Secretary of State undertaken of whether changes to the penalty regime are likely to influence board-level attitudes towards cyber-security?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The shadow Minister makes a really important point: cyber-security must be taken seriously at the highest level—at board level. It is part of the cyber assessment framework, which the Government have put at the heart of how we think about assessing cyber-security in firms as well as public sector organisations. It is also part of the guidance we are looking at in the cyber action plan and our wider cyber-security strategy. I take those very seriously. In terms of making sure that businesses have a razor sharp focus, the intent of the fine regime is to ensure that there is a deterrent effect and that it is felt at decision-making levels, which must include boards.

Question put and agreed to.

Clause 21 accordingly ordered to stand part of the Bill.

Clause 22

Enforcement and appeals

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss the following:

Government amendment 19.

Schedule 1.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 22 sets out, through schedule 1, consequential changes to the regulations in relation to enforcement and appeals. That is to ensure that the regulations work effectively in relation to the new entities brought into scope, such as managed service providers, data centres and large load controllers, so that the enforcement and appeal systems work as intended. Government amendment 19 makes a minor drafting correction. I commend clause 22 and schedule 1 to the Committee.

Question put and agreed to.

Clause 22 accordingly ordered to stand part of the Bill.

Schedule 1

Enforcement and appeals

Amendment made: 19, in schedule 1, page 86, line 33, at end insert—

“(ea) in sub-paragraph (da), after ‘14A;’ insert ‘or’;”.—(Kanishka Narayan.)

This amendment would make a minor drafting correction.

Schedule 1, as amended, agreed to.

Clause 23

Minor and consequential amendments etc

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss the following:

Government amendments 20 to 22.

Schedule 2.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 23, through schedule 2, introduces a number of minor and consequential amendments to the NIS regulations, necessitated by the more substantive changes introduced by the Bill. Among other technical changes, the schedule revokes assimilated EU legislation, removes the requirement for an NIS national strategy to be published once a statement of strategic priorities has been designed in its place, and updates references in the regulations to reflect the new clause numbering. Government amendments 20 and 21 make minor drafting corrections.

Government amendment 22 aligns the process for issuing documents, notices and directions under the NIS regulations with the Bill. As it stands, regulators will be required to follow two different procedures for issuing documents, notices and directions under the NIS regulations and under the national security powers in part 4 of the Bill, which is unnecessarily confusing for regulators and regulated entities. Amendment 22 resolves the issue by aligning regulation 24 with clause 57, as amended by Government amendments 23 and 24. I commend amendments 20 to 22, clause 23 and schedule 2 to the Committee.

Question put and agreed to.

Clause 23 accordingly ordered to stand part of the Bill.

Schedule 2

Minor and consequential amendments etc

Amendments made: 20, in schedule 2, page 89, line 35, at end insert—

“(ia) omit the ‘and’ at the end of the definition of ‘relevant law-enforcement authority’;”.

This amendment would make a minor drafting correction to regulation 1(2) of the Network and Information Systems Regulations 2018.

Amendment 21, in schedule 2, page 89, line 37, at end insert—

“(iia) omit the ‘and’ at the end of the definition of ‘representative’;”.

This amendment would make a minor drafting correction to regulation 1(2) of the Network and Information Systems Regulations 2018.

Amendment 22, in schedule 2, page 91, line 4, at end insert—

“11A (1) Regulation 24 (service of documents) is amended as follows.

(2) In paragraph (1)—

(a) in the words before sub-paragraph (a)—

(i) for ‘or notice’ substitute ‘, notice or direction’;

(ii) after ‘served on’ insert ‘or given to’;

(iii) after ‘served’, in the second place it occurs, insert ‘or given’;

(b) omit the ‘or’ at the end of sub-paragraph (b);

(c) for sub-paragraph (c) substitute—

‘(c) sending it by post to the person’s proper address or by email to the person’s email address.’

(3) In each of paragraphs (2) and (3)—

(a) after ‘document’ insert ‘, notice or direction’;

(b) after ‘served on’ insert ‘or given to’.

(4) In paragraph (4), for ‘service’ substitute ‘documents, notices and directions’.

(5) For paragraph (5) substitute—

‘(5) For the purposes of this regulation, a person’s “proper address” is—

(a) in a case where the person is a body corporate with a registered office in the United Kingdom, that office;

(b) in a case where paragraph (a) does not apply and the person is a body corporate, partnership or unincorporated body with a principal office in the United Kingdom, that office;

(c) in any other case, an address in the United Kingdom at which the person serving or giving the document, notice or direction believes, on reasonable grounds, that it will come to the attention of the person on whom it is to be served or to whom it is to be given.

(5A) For the purposes of this regulation, a person’s email address is—

(a) an email address provided to a NIS enforcement authority as an address for contacting that person,

(b) an email address published for the time being by that person as an address for contacting that person, or

(c) if no email address has been so provided or published, an email address by means of which the person serving or giving the document, notice or direction believes, on reasonable grounds, that it will come to the attention of that person.’

(6) After paragraph (5A) (inserted by sub-paragraph (5)) insert—

‘(5B) A document, notice or direction sent to a person by email is, unless the contrary is proved, to be treated as having been served or given at 9am on the working day immediately following the day on which it was sent.

(5C) In paragraph (5B) “working day” means a day other than a Saturday, a Sunday, Christmas Day, Good Friday or a bank holiday under the Banking and Financial Dealings Act 1971 in any part of the United Kingdom.’”—(Kanishka Narayan.)

This amendment would align regulation 24 of the NIS Regulations with the provisions about giving of directions and notices in clause 57 of the Bill, as amended by Amendments 23 and 24.

Schedule 2, as amended, agreed to.

Clause 24

Key definitions in Part 3

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss the following:

New clause 1—Food supply chain to be regulated as an essential service—

“(1) The NIS Regulations are amended as follows.

(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

‘Food supply

Food supply chain

The Secretary of State for Environment, Food and Rural Affairs (United Kingdom)’



(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—

‘The food supply chain subsector

11 — (1) This paragraph describes the threshold requirements which apply to essential services in the food supply chain subsector.

(2) For the essential service of the food supply chain in the United Kingdom the threshold requirement is that the person is in the food supply chain and does not qualify as small or a micro-entity (or is excluded) within the meaning of Part 15 of the Companies Act 2006.

(3) after paragraph 10 insert—

(a) a “food supply chain” is a supply chain for providing individuals with items of food or drink for personal consumption, where the items consist of or include, or have been produced to any extent using—

(i) anything grown or otherwise produced in carrying on agriculture, or

(ii) anything taken, grown or otherwise produced in carrying on fishing or aquaculture;

(b) a person is “in” a food supply chain if that person is a producer or an intermediary in a food supply chain.

(4) In paragraph (3)(b)—

(a) “producer” means a person who is carrying on agriculture, fishing or aquaculture;

(b) “intermediary” means a person in the food supply chain between a producer and the individuals referred to in paragraph (3)(a).

(5) In this paragraph—

“agriculture” includes any growing of plants, and any keeping of animals, for the production of food or drink;

“aquaculture” means the breeding, rearing, growing or cultivation of—

(a) any fish or other aquatic animal,

(b) seaweed or any other aquatic plant, or

(c) any other aquatic organism;

“plants” include fungi.

(6) In regulation 8A of the NIS Regulations (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—

(c) provides an essential service of a kind referred to in paragraph 12 of Schedule 2 (food supply chain sector) within the United Kingdom.’”

This new clause would designate those in the food supply chain that rely on network and information systems as “operators of essential services” within the meaning of the Network and Information Systems Regulations 2018, thereby placing them under duties to manage risks to those systems and to provide notification regarding any incidents that have an impact on the food supply chain.

New clause 8—Local authorities to be regulated as essential services—

“(1) The NIS Regulations are amended as follows.

(2) In table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert—

‘Local Government

Local Government

The Secretary of State for Housing, Communities and Local Government’



(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—

‘The Local Government Sector

11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector.

(2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register.

(3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records.

(4) In this paragraph “local authority means”—

(a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly;

(b) in Wales, a county council or a county borough council;

(c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994;

(d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.’”

This new clause would bring local authorities within the scope of the NIS Regulations as operators of essential services in relation to their functions managing electoral rolls and social care records. This ensures that public sector bodies holding sensitive data such as electoral rolls and social care records are subject to the same statutory protections as other critical infrastructure.

New clause 9—Critical manufacturing and retail sectors—

“(1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities—

(a) the manufacture of critical transport equipment;

(b) the industrial production and processing of food products; and

(c) the retail sale of food and essential goods via large-scale distribution chains.

(2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors.”

This new clause would require the Secretary of State to designate the manufacturing of critical transport equipment and retail of food and essential goods (when part of a large-scale distribution chain) as essential activities, bringing them within the scope of Part 3 of the Bill.

New clause 11—Electoral infrastructure to be regulated as an essential service—

“(1) The NIS Regulations are amended as follows.

(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

‘Elections

Electoral infrastructure

The Electoral Commission’



(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—

‘The electoral infrastructure subsector

11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector.

(2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to—

(a) maintain a register of electors containing more than 50,000 entries;

(b) issue, receive, or process postal ballots for a parliamentary or local government election; or

(c) count or aggregate votes cast in a parliamentary, mayoral or local government election.

(3) In this paragraph—

“parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom;

“network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026.

(4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—

“(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.”’”

This new clause would designate the administration of elections and maintenance of voter registers as an “essential service” within the meaning of the NIS Regulations.

New clause 12—Political parties to be regulated as an essential service—

“(1) The NIS Regulations are amended as follows.

(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—

‘Government

Political parties

The Secretary of State for Housing, Communities and Local Government’



(3) In Schedule 2 (essential services and threshold requirements), after paragraph 10 insert—

‘The political parties subsector

11 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector.

(2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons

(3) In this paragraph—

“registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.’”

This new clause would designate political parties as providing essential services for the purposes of cyber security.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 24 defines key terms for this part of the Bill, and in doing so introduces two delegated powers. Those powers enable the Government to bring new sectors into the scope of the NIS regime and to designate regulators to oversee them. The power will be used only in relation to activities that are truly essential to our society and economy—in other words, where disruption could pose risks to life or the economic stability of the UK.

The powers are essential in the rapidly changing world we occupy. As we have seen with data centres and managed service providers, our society and economy can quickly become reliant on new services that are acutely vulnerable to cyber-attacks and system outages. Our legislation must be able to keep up with those changes and protect the services that matter most to our country.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

I want to use new clause 1 as a lens to view a wider question that sits underneath clause 24, rather than as a verdict on the clause itself. That question is how we decide, in a disciplined and credible way, which activities are sufficiently critical to be brought into the scope of the regime, and how that judgment is applied consistently over time.

New clause 1 would bring much of the food supply chain directly into scope through primary legislation. I understand the instinct behind that. Food supply is fundamental to public confidence, and disruption would be felt very quickly. However, if the underlying test for inclusion is systemic impact, food is not the only sector that raises these questions. I am vice-Chair of the Business and Trade Committee, and over the past year we have taken evidence on economic security from major UK firms that have experienced serious cyber-incidents. One example everyone here will be familiar with is Jaguar Land Rover. Evidence to our Committee indicated that the cyber-incident there contributed to UK GDP being around 0.1% lower than expected in the third quarter last year, which was not a marginal effect. That reflected disruption to tightly integrated manufacturing systems, with production lines brought to a halt and knock-on impacts across just-in-time supply chains and regional economies.

I make that point to underline something simple: cyber-risk presents simultaneously as operational, financial and reputational risk, and in combination those effects can be felt economy-wide. If that is the rationale for bringing food into scope early, it inevitably raises questions about other high-value sectors where a single incident can have national economic consequences.

That brings us back to clause 24 and the role of the Secretary of State. The Bill is clearly designed to allow scope for provisions to evolve through secondary legislation as risks change. That flexibility is sensible, but flexibility works only if the criteria for widening scope are clear, predictable and capable of being explained to industry, regulators and Parliament. If decisions appear to be reactive or driven by the most recent or most visible incident, confidence in the regime will suffer rather than strengthen.

That concern is reflected in the written evidence we have received. The Association of British Insurers, for example, supports higher standards of cyber-resilience, but it also emphasises the importance of clear definitions and coherence between regimes, particularly where firms are already subject to overlapping regulatory requirements. Its point is not about resisting regulation, but about avoiding uncertainty and duplication, which do not improve resilience.

My questions are ones of principle rather than position. First, what is the settled test that the Secretary of State will apply when deciding to bring a sector into scope under the clause 24 powers, and how will that judgment be made transparent to Parliament? Secondly, if Parliament were to require rapid expansion of scope, how confident are the Government that regulators would have the capacity to supervise a much larger and more diverse population without diluting oversight elsewhere?

I am not seeking to land a conclusion on new clause 1 today—I understand why it has been tabled and I recognise the seriousness of the issues that it highlights—but if we are going to widen scope, to food or otherwise, the Committee is entitled to press the Government on the discipline and guardrails that will sit behind those decisions. This needs to remain a targeted and credible regime, rather than one that expands without a clear and consistent logic.

Cyber Security and Resilience (Network and Information Systems) Bill (Sixth sitting)

(Limited Text - Ministerial Extracts only)

Read Full debate
Committee stage
Tuesday 10th February 2026

(7 months, 3 weeks ago)

Public Bill Committees
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 Read Hansard Text Amendment Paper: Public Bill Committee Amendments as at 10 February 2026 - (10 Feb 2026)

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

Lincoln Jopp Portrait Lincoln Jopp (Spelthorne) (Con)
- Hansard - - - Excerpts

It is a pleasure to serve under your chairship, Mr Stringer. When we left off, we were considering the powers of the Secretary of State to bring new organisations within scope. I am a Conservative, and my view is that the best form of regulation is usually competition, so I am not actually volunteering these sectors for the guards. However, I want to understand the underlying logic as to why certain things have been included and certain things have not.

We have a fairly good guide as to what is essential. The reason we do is that we went through a global pandemic, and the following groups and organisations were designated as absolutely essential for the running of the state: health and social care, which is included; education and childcare, which is not; anything to do with the justice system; religious staff; public service broadcasters; local and national Government, which again is not in the Bill; food and other goods, which, as we discussed, are also not in the Bill, although they are in the new clauses; public safety and national security; transport; utilities; communications; financial services; and postal services.

That is the analogue I am putting to the Minister: we found out which things we really needed, we designated them as essential and we allowed them to continue during the covid pandemic. None of us particularly relishes being reminded of that time, but we owe it to the people who will be subject to the Bill to ask the Minister exactly what has been argued in and what has been argued out of scope, to understand how vulnerable the blank cheque we are issuing to the Secretary of State is to their including more and more in it, come the day of the races.

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- Hansard - - - Excerpts

I will start by addressing the questions raised by hon. Members, including the hon. Member for Spelthorne, who concluded by setting out a general philosophy of how we thought about what is in and out of scope, and then I will address some of the more specific concerns in the new clauses.

The overarching philosophy has not at all been to deny, as the hon. Members for Spelthorne and for Brecon, Radnor and Cwm Tawe argued, that there are a series of services that are absolutely essential. There is a category of critical national infrastructure, and there is a category of essential sectors and services that we identified in the pandemic. Although there is some overlap, a distinct segment for the Bill is operators of essential services such as digital services and managed service providers. The assessment there has been more about the immediacy and severity of the impact, and the availability of alternative provision in a very short time, which has meant that those sectors have been ruled in. I will lay out the logic of our position on the new clauses, which might help clarify this question, although I would be happy to engage further with hon. Members on it.

I am conscious that the hon. Member for Bognor Regis and Littlehampton and the shadow Minister raised very appropriate points about robustness and proportionality in relation to the Secretary of State exercising the powers in the Bill, so I will lay out the process and the role of Parliament.

In terms of the process for bringing new sectors or activities in scope, something must meet a specific, rigorous test to be defined as a new essential activity for the purposes of the Bill. The Secretary of State must be satisfied that the activity is essential to our economy or society. As I have mentioned, that is reserved for the most vital activities to our nation and acts as a high bar for inclusion, on the terms I mentioned to the hon. Member for Spelthorne.

In reaching a decision, the relevant Departments will need to carry out risk assessments and impact assessments and consider whether inclusion of those sectors and activities is proportionate. That is part of the normal policy development process. After that, the proposals will be subject to consultations and the affirmative procedure, ensuring the necessary scrutiny. Parliament will have the final say on the use of any expansive powers, as the vast majority of the changes I mentioned will be made through delegated powers and subject to the affirmative procedure. If a new sector is then brought into scope, we will undertake a phased implementation wherever possible, and organisations will be given adequate time to comply. Alongside that, regulations will be made in a controlled way and include consultations with relevant stakeholders before secondary legislation is laid before Parliament.

I make one final observation on the points that have been made, not least about Jaguar Land Rover. The UK Export Finance export development guarantee is not a bailout. UKEF receives payments for providing its guarantees, ensuring that the Government are appropriately compensated for the risk taken. In that context, a different assessment was made, as I hope to come to shortly.

More broadly, the Committee heard from expert witnesses that although the purpose of the Bill is clear, and its impact is a significant help for our national cyber-security and essential services, it or any other singular move is no silver bullet when it comes to our cyber-security. Different levers are effective in different parts of the economy and must be applied appropriately.

The most stringent lever the Government have at their disposal is legislation. As we have discussed in this and prior sittings, proportionality is key to the exercise of that lever. Regulation creates obligations and requires resources, so the pros of regulating must outweigh the costs. In the context of the Bill, that means protecting our society and economy from unacceptable risks with an immediacy of threat to our day-to-day life, not least our national security. That means things like keeping the lights on, the taps running and the NHS going, where there is little or no alterative provision of such services. We must also avoid creating unnecessary burdens where other measures are available.

In that context, I turn first to new clauses 1 and 9. The Government and the National Cyber Security Centre are clear that all organisations, whether a food supplier, an automotive giant, a supermarket or any other business operating in the UK, should take steps to protect their cyber-security and increase their resilience. That is why in October the Government wrote to FTSE 350 companies urging them to take three actions to strengthen their defences. First, they should make cyber-risk a board-level priority, and I know that that sentiment is shared across the Committee. Secondly, they should require suppliers to have baseline cyber-security through Cyber Essentials. Thirdly, they should sign up to the NCSC’s early-warning service.

The response has been encouraging already. A significant proportion of organisations have responded, with many of those responses coming directly from chief executive officers and chairs, showing the seriousness accorded to this by boards. Following the letter, we have seen increased interest in the Cyber Essentials website, uptake in early-warning registrations, and uptake in registrations for the IASME supplier check tool, which organisations can use to identify suppliers with Cyber Essentials certificates.

Beyond that, Departments and the NCSC deliver sector-specific support for key parts of the economy. On food specifically, the Department for Environment, Food and Rural Affairs and the wider Government have worked with the food and retail sector on cyber-resilience for many years, and we always stand ready to protect the UK food supply chain. During last year’s incidents involving Marks & Spencer and the Co-op, the NCSC and DEFRA worked closely with the affected retailers to support their response, to communicate advice and guidance and to assess the risk to food security. Following the attack, DEFRA Ministers wrote to major retailers to invite further collaboration on cyber-matters. Officials from both the NCSC and DEFRA are working with retailers to understand how we can best support them and the resilience of our food supply chain in the future.

Crucially, the food sector is unique among critical sectors for its high levels of industrial and geographic diversity. There are approximately 20,000 small and medium-sized food manufacturers alone spread across the UK, and many more farms, distribution centres, retailers and other types of businesses that form the UK’s food supply chain. As a result, it is a sector with few single points of failure. Its resilience is further strengthened by the steps that individual operators and suppliers are taking.

Finally, it is worth mentioning that the cyber-attack on Marks & Spencer last year, which hon. Members have raised, specifically involved the social engineering of a third party managed service provider. As the Committee is aware, the Bill brings large and medium-sized managed service providers into scope. That important change delivers downstream benefits across the wider economy, including for food retailers.

I will move on to new clause 8. The Government recognise that a step change in cyber and digital resilience is required across the public sector, including in local authorities. The Government’s cyber action plan is the overarching strategy to improve the cyber-resilience of Government. It will hold the public sector, including local government, to equivalent requirements to organisations regulated by the Bill. At the outset, the hon. Member for Spelthorne raised a question about schools and pupil data; where local authorities are the lead affected departments in that context, they would be expected to maintain very close oversight and compliance with the requirements and asks of the cyber plan, including in schools and the maintenance of pupil data.

Local authorities in England are accountable for their own cyber-security and resilience. The Ministry of Housing, Communities and Local Government, as the lead Government Department, is accountable for the sector-wide resilience of English local government, and is already taking a range of steps to support the sector, strengthen its cyber-resilience and manage its risks more effectively. For example, MHCLG has already provided £23 million of cyber grant funding and technical support to local government. That includes the delivery of clear cyber-security standards through the adoption of the cyber assessment framework—CAF—for local government. It is also aligned with the wider approach taken by organisations already in scope of the network and information systems regulations.

On social care specifically, as the lead Government Department for adult social care, the Department of Health and Social Care is working to ensure that the standards applied by adult social care providers are consistent with those used across Government and the wider public sector. The DHSC is investing a further ÂŁ21 million over this Parliament to give care providers the support and guidance they need to improve their cyber-resilience and to enhance cyber-security standards to align with the cyber assessment framework. The MHCLG has also launched a local government cyber-incident response service to support English local authorities to respond to severe cyber-incidents, helping to limit the impact these have on data and services.

I now move on to new clauses 11 and 12, tabled by the hon. Member for Brecon, Radnor and Cwm Tawe. The joint election security and preparedness unit—JESP—sits jointly between the MHCLG and the Cabinet Office. It was created by the defending democracy taskforce, a cross-Government unit, and works to protect UK elections and referendums by co-ordinating work across Government to respond to threats, including on cyber-security.

I know that the shadow Minister takes a keen interest in these questions on the run-up to elections, and he raised some important points. JESP works closely with the NCSC, which produces guidance for organisations involved in delivering elections, including local authorities. That includes advice to help IT practitioners implement security measures that will help prevent common cyber-attacks, as well as offers for direct NCSC support, including the NCSC’s active cyber-defence services.

The MHCLG as a whole is responsible for centrally managed digital electoral services covering voter registration, a postal or proxy vote, or a voter authority certificate. All systems and suppliers involved in developing and maintaining digital electoral services must meet strict cyber-security requirements, not least the MHCLG cyber-security assurance framework.

I will move on to political parties. JESP and the NCSC regularly engage with political party representatives to understand their requirements, monitor any cyber-infrastructure vulnerabilities and raise awareness about Government cyber-defence services. The NCSC’s active cyber-defence programme provides free security tools to help UK organisations, including political parties and local authorities, reduce exposure to common cyber- threats. The NCSC encourages all political parties to sign up to these, and offers individual candidate briefings to parties that wish to take them up.

Everything I have said reflects the Government’s current assessment of where regulation is needed to protect the core of our society and economy. Of course, we have seen that what is considered an essential service can change, and we also know that cyber-threats are constantly evolving. That is why the Bill will enable the Government to bring more essential activities and services into scope in future, and to take swift action if UK national security is at risk, in scenarios where the evidence suggests the pros outweigh the costs. However, at this stage we do not think that that is the case for new sectors. I therefore ask hon. Members not to press their new clauses.

Question put and agreed to.

Clause 24 accordingly ordered to stand part of the Bill.

Clause 25

Statement of strategic priorities etc

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss clauses 26 to 28 stand part.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 25 introduces a power for the Secretary of State to designate a statement of strategic priorities for the implementation of the NIS regulations. The NIS regulations are enforced by 12 different sectoral regulators. Although that allows each regulator to apply its sectoral expertise, it also means that at times they have taken divergent approaches to their regulatory responsibilities. Clause 25 addresses that by allowing the Secretary of State to set overarching objectives for regulators in the wider context of a statement of strategic priorities. The statement will replace the NIS national strategy, which the Government were previously required to produce under the NIS regulations. It will set out the Government’s priorities for the security and resilience of essential services.

To ensure that the objectives remain stable enough to enable regulators to plan their work, the clause will prevent a statement from being withdrawn or amended within three years of its designation. However, that three-year rule will not apply if there has been a general election, or a significant change in the threat landscape or in Government policy. That will allow for flexibility where appropriate. In sum, clause 25 empowers the Government to drive a more effective and consistent application of the NIS regulations.

Clause 26 establishes the process through which a statement of strategic priorities can be designated. It requires that there must be consultation with regulators, and that the statement be laid before Parliament, where it will be subject to the negative procedure. It establishes that the Government must share a draft of a proposed statement with the NIS regulators, and that the regulators must be given at least 40 days to provide comments to the Government on that draft statement. The Government must consider whether it is appropriate to make any changes to the draft statement in the light of that consultation. Once any changes have been made, they must lay the statement before Parliament, where it will be subject to the negative procedure. Following that, the Secretary of State may designate the statement.

Clause 27 establishes the legal duties that regulators will have in relation to a statement of strategic priorities. It sets out that regulators must

“have regard to the statement”

when carrying out their NIS functions, as introduced by parts 3 and 4 of the Bill. It also introduces a requirement for regulators to “seek to achieve” the objectives included in the statement.

Alison Griffiths Portrait Alison Griffiths (Bognor Regis and Littlehampton) (Con)
- Hansard - - - Excerpts

As we heard in written evidence from the ABI, clarity about roles really matters. Can the Minister confirm that the statement of strategic priorities is not intended to operate as indirect instruction, and that regulators will retain clear discretion where sector evidence points in a different direction?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for her point. Perhaps I can give a flavour of the objectives I might expect in a statement and assure her of the independence of sector regulators. Subject to consultation, which we would expect in the build-up to any such statement, a statement might include objectives such as encouraging regulators to seek to ensure that their sectors have plans in place to increase security, or focusing on regulatory activity in areas of greatest horizontal risk. To the hon. Member’s point about sector-specific expertise and the independence of regulators, the statement is intended to set objectives to be achieved within the parameters of regulators’ existing statutory duties, and what the overarching risks are. Of course, regulators will be free to do that in the ways they think most appropriate for their sectors, in the light of their own expertise and experience. I hope that gives the hon. Member some assurance.

Clause 28 requires the Secretary of State to publish an annual report setting out, in general terms, how NIS regulators have complied with their duties in relation to a statement of strategic priorities over the previous 12 months, and how they intend to meet their duties in the following 12 months.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

As the Minister is saying, clause 28 is meant to help Parliament understand how regulators are responding to the statement of strategic priorities. Can he say a little about how substantive that reporting will be, and whether it will genuinely allow Parliament to assess how those duties are being exercised in practice?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The hon. Member raises a very important point. We want Parliament to play an important role in the scrutiny of the overarching regime as a whole, but particularly in the operation of the statement. Perhaps I can break it into two parts: scrutiny of the statement in the first instance, and scrutiny of regulators’ compliance with the statement. Once a draft statement has been consulted on, the Government will be required to lay it before Parliament, and that will be subject to the negative procedure. Parliament will have 40 days to scrutinise the proposed statement and express disagreement with it, which is very similar to the procedure for statements of strategic priorities in other areas—not least online safety. In terms of confidence in Parliament about actions that regulators have taken, the Secretary of State will be required to publish an annual report setting out, in general terms, the activity undertaken by regulators in the prior 12 months, alongside activity planned for the following 12 months. My expectation is that, very similarly, Parliament will have sight of that, and have the ability to scrutinise it and ask questions of the Secretary of State in the usual way.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am grateful to my hon. Friend the Member for Harlow for his affirmation of that important point of parliamentary scrutiny.

As I mentioned, the report in question will set out how NIS regulators have sought and will seek to achieve the objectives in the statement through the exercise of their regulatory functions. The clause requires the Secretary of State to lay the annual report before Parliament, as well as to publish it in an appropriate manner. Clause 28 also introduces information-gathering powers for the Secretary of State so that they can collect the necessary information from regulators to draft the report. I commend the clauses to the Committee.

Ben Spencer Portrait Dr Ben Spencer (Runnymede and Weybridge) (Con)
- Hansard - - - Excerpts

It is a pleasure to serve under your chairmanship, Mr Stringer.

Clause 25 introduces a power for the Secretary of State to issue a statement of the Government’s strategic priorities in relation to the security and resilience of network and information systems with regard to essential activities. The statement will set out the responsibilities of regulators and specify objectives to secure the Government’s priorities. Competent authorities must be consulted in the drafting of the statement, and the Secretary of State must issue a report in every 12-month period on regulators’ compliance with meeting the objectives within it.

The changes aim to address important challenges around consistency in the approach to regulation that were identified by the previous Government’s second post-implementation review of the NIS regulations. Importantly, the measures also provide for a regular review of competent authorities’ approach to discharging their regulatory obligations. That measure is necessary given the inconsistent approach to oversight and enforcement of the NIS regulations so far.

We know that there are existing challenges relating to the capacity of competent authorities and there is the ongoing issue of securing sufficient cyber-security professionals to staff the teams. It is all well and good making statements, but they need to be followed. What strategies does the Minister anticipate will be needed and used to support—and, where necessary, drive up—standards of regulatory oversight when competent authorities fall short of the aims set out in the statement?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the shadow Minister for raising an important point. His broader question is one of the most important in this context: Bills are only as good as the ultimate enforcement capability, capacity and framework in which regulators enforce them. Particular aspects of the Bill are focused on that question. One ensures that regulators have not just the resource through the cost recovery and charging schemes that the Bill allows for, but the information through the information-gathering powers—and not just the information, but a statement of strategic priorities as new horizontal risks emerge across sectors. So regulators are armed with resource, information and strategic priorities that emerge from time to time.

Alongside all those resources, data and information powers, regulators need also to have accountability, of course. In that context, the statement of strategic priorities is intended to be one vehicle through which regulators’ compliance with overarching objectives of the Bill will be looked at as well, alongside ongoing oversight of each of the regulators through the usual departmental channels.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

Having worked in business, I know that the words we use to ensure that the capabilities are there are easy to say but not always easy to deliver. How will the Minister ensure that when we have a multi-sector issue, which could easily come up—particularly, as we have already discussed, around OT and the use of IEDs across multiple sectors—the National Cyber Security Centre and other regulators will have access to the skills, people and resources necessary to manage what could be a catastrophic incident? We already know that cyber-skills are in short supply as it is, even in the commercial sector.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The hon. Member raises an important point. Two or three things are really important channels of impact when it comes to skills. First, the NCSC as a convening body across regulatory areas will be able to make sure that different regulators come together and learn by being able to share information not just between themselves, but through the NCSC itself as the convening body for sharing good and prompt understanding of emerging risks.

Secondly, on broader skills, the cost recovery schemes allowed under the Bill create a way for regulators to ensure they are resourced up and have the ultimate financial firepower to be able to enforce the requirements of the Bill.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

I thank the Minister for his patience. He mentions a specific example of where he will ensure that the NCSC is resourced up. Do we have specific examples that have happened already of those powers having been put in place successfully? From conversations with the NCSC, I understand that it is reliant on its accredited bodies across the country, but we have not yet—I am touching the wood of my desk, as I speak—had to respond to a complex multi-sector issue. I challenge the Minister on whether he is confident about our capability to respond to one.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I share the hon. Member’s recognition and her gratitude that we have not experienced the sort of incident that she described. The NCSC has told her, me and other Committee members that it brings regulators together and has done so on a number of occasions in the past to share cross-sectorally an understanding of emerging risks as well as incident-specific impacts. I take no sense of complacency from that precedent, but I do take some confidence from it. As the Minister in charge, I will ensure that the Department keeps a close eye on the ongoing implementation of the co-ordination powers under the Bill.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

The Minister is being generous with his time during this important debate. I was just thinking through his earlier response to the point made by my hon. Friend the Member for Bognor Regis and Littlehampton about using the cost reclaims to employ cyber-security professionals. That goes to the heart of the concerns about the Bill and its approach to regulation.

We have heard that the industry, including regulators, is struggling to recruit cyber-security professionals. What gives the Minister confidence that, just because some money will be sloshing around in the regulators, there will be the ability to recruit cyber-security professionals, who are going to be essential to the implementation of the Bill?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

First, I will provide some context for agreement. We want more people to be trained in cyber-security so that they can serve in the public and private sectors. Through the Bill, as well as a range of other initiatives, we are making sure that at every stage of the pipeline, there is resourcing, confidence and a demand signal that so more people can benefit from cyber-skills and serve in the industry.

There is a clear financing path for regulators to at least start to hire. Earlier in the pipeline, we are looking at a series of cyber-skills programmes all the way from schools through CyberFirst—I think about 415,000 students have gone through that programme. Ultimately, we want to create a long-term pipeline so that regulators and private companies can make the most of those skills.

Chris Vince Portrait Chris Vince
- Hansard - - - Excerpts

I am going to mention Harlow, because Harlow has young people with amazing potential. The point that the shadow Minister and other Opposition Members have made is really important. We need to make sure that this and the next generation of young people are trained up in these skills, because this is an emerging threat. I encourage the Minister to promote the Bill and what the Government are doing in cyber-security, because it is important that the wider public know that these important skills and jobs are available.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am, of course, very happy to take on my hon. Friend’s recommendation that I be the promoter and ambassador for the Bill across the country. I am only sad not to have been invited to visit his constituency in the act of promoting said Bill, but I take his point seriously.

On the broader point about skills, I entirely agree with both my hon. Friend and the Opposition in recognising that skills are central to the enforcement of the programme. I hope that the funding and the earlier focus on skills across the life cycle give some assurance that the Government are committed to that.

Question put and agreed to.

Clause 25 accordingly ordered to stand part of the Bill.

Clauses 26 to 28 ordered to stand part of the Bill.

Clause 29

Regulations relating to security and resilience of network and information systems

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss clauses 30 to 35 stand part.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 29 is the key pillar of the Bill’s future-proofing powers. It allows the Secretary of State to update, amend or replace the NIS regulatory framework by creating new regulations. This is a critical provision. Due to the way in which the NIS regulations were transposed into UK law, the Government lack a way of updating the framework other than through primary legislation. As a result, our regulations have remained static amid a rapidly evolving threat landscape, leaving our essential and digital services vulnerable to attack and our resilience falling behind the EU. The clause is an important response to that problem. It will ensure that the Government can take swift action so that our cyber regulations remain relevant. It is a more proportionate and effective approach than always relying on primary legislation.

I know the use of delegated powers can be a source of concern, so I will be clear that the clause is not a carte blanche—or a blank cheque, which the hon. Member for Spelthorne might be worried about—to smuggle in anything and everything under the guise of cyber-security. It is tightly constrained to ensure that any new regulations align with the original purposes of the NIS regulations. New regulations can be made only for the purposes of strengthening the cyber-security and resilience of the UK’s most critical activities, and only where they are genuinely essential to the functioning of the UK’s society and economy. Cyber-criminals will always find ways around regulations, but with this power we can stop them in their tracks.

I have already explained the critical role that clause 29 plays in enabling new regulations to be made for the purposes of cyber-security and resilience. However, I want to be clear about how those regulations will be used and reassure the Committee of their checks and balances. Clauses 30 to 35 set out what the regulations can do.

Clause 30 enables the Secretary of State to use the regulation-making powers to impose requirements on regulated persons. It clarifies who can be made subject to requirements and the types of requirement that can be imposed on them.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

My question relates to clause 29 but also clause 30. As the Minister says, the powers are deliberately wide. The Institution of Engineering and Technology noted in evidence that predictability matters more than compliance. Will the Minister explain exactly how the Government will judge when risks require new statutory duties rather than updated guidance, so that businesses are not left guessing?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Any legislation made under clause 29 will need to align with the Bill’s clearly specified purposes to protect the systems that underpin our vital services. In any case, secondary legislation will require deep consultation to ensure that businesses have the sense of clarity that they require. There is a specific bar to pass for the scope of any further provisions, and it is a high bar given the definition of the sectors and the activities covered in the Bill.

Clause 30 has been designed with some clear use cases in mind. It will enable the security duties on regulated organisations to be updated with appropriate technical details. It will also ensure that more detailed thresholds for incident reporting can be set, and it is the mechanism through which we will set out the regulatory requirements for designated critical suppliers. In other words, the clause will help us to operationalise the provisions of the Bill and update the technical details of regulatory requirements in response to new risks or technology.

Clause 31 enables the Secretary of State to confer functions on regulators through the Bill’s regulation-making powers. These may be existing NIS regulators or newly appointed regulators. The types of functions that can be conferred are those concerned with compliance: monitoring and securing compliance, and investigating and managing non-compliance. To carry out such functions effectively, regulators must be able to impose penalties. Clause 31 also provides for that while putting in place important safeguards so that regulated organisations have a means of appealing penalties. The clause is essential for future-proofing the regulatory regime. It ensures that regulators can be equipped with the functions and powers they need to ensure the compliance and security of the UK’s most essential services.

Clause 32 sets out details and safeguards for how the regulation-making powers can be used when they impose or amend financial penalties. Crucially, it establishes upper limits on what the penalties can be—the greater of £17 million or 10% of turnover for an undertaking, or £17 million for a non-undertaking, or £17 million for an undertaking adjusted as needed to account for inflation. The 10% threshold has been chosen as a defensible outer limit for a regulatory regime concerned with national resilience and security. It aligns with penalties for non-compliance in legislation regulating critical national infrastructure and with the Bill’s own national security powers.

The clause further clarifies that regulations can define “turnover” and “undertaking”, where needed, to calculate a penalty. Together, these provisions create important safeguards and flexibility. They establish proportionate and transparent parameters within which penalty amounts can be set. They also enable the Secretary of State to define and consult on terms that are essential for operationalising the Bill’s new turnover-based penalties.

Like clause 31, clause 33 enables the Secretary of State to make regulations conferring functions on regulators. The functions specified in clause 33 complement the core compliance functions outlined in clause 31. They relate to the disclosure of information, issuing of guidance, record-keeping, preparation of reports, undertaking of reviews, and co-operation. The clause also enables the Secretary of State to impose functions on organisations that are not regulators but that play a public role related to the cyber-security and resilience of essential services. GCHQ, in its capacity as the UK’s computer security incident response team and technical authority, is the most important. Like clause 31, this clause is essential for future-proofing NIS regulations. It allows organisations that oversee and facilitate the cyber-security and resilience of essential services to be equipped with the tools and functions they need.

Clause 34 enables the Secretary of State to make provisions for regulators to recover relevant costs using the powers under clause 29(1). These are the costs incurred through their functions under the NIS regulations or other obligations imposed through parts 3 and 4 of the Bill. 

In practice, the clause ensures that the Secretary of State can make changes and updates to the way that regulators carry out their cost recovery function under the NIS regime. It could, for example, be used to specify further factors that regulators need to consider when establishing approaches for charging fees in the charging schemes, in addition to those already set out in clause 17. That might be needed to deliver greater consistency in how the cost recovery measures are being applied and is something that the Government will keep under review.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

As the Association of British Insurers has highlighted in its written evidence, the way cost recovery operates will shape behaviour on the ground. Can the Minister reassure the Committee that changes made under clause 34 will be transparent and proportionate and will not inadvertently discourage investment in cyber-resilience, particularly for smaller firms in supply chains?

On a personal point, could I ask him to speak more slowly? I am really struggling to hear him.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I apologise for the pace of my speech; I will try to make sure I am speaking more slowly.

On the particular point on transparency and ensuring that any amendments to cost recovery are both transparent and grounded in specific provisions, I can set out the sorts of expectations we have had for circumstances in which amendments might be made. In particular, the Bill’s powers will enable regulators to set up charging schemes, but it is not prescriptive—

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

Could the Minister repeat that?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The Bill’s new powers enable regulators to set up charging schemes, but it is not prescriptive about how it should do that beyond certain baseline requirements. More specific requirements, as provided for in the Bill, could become clear, such as if cost recovery mechanisms are not working effectively or if regulators are diverging unhelpfully.

All regulators must consult on charging schemes. In doing so, the industry should have ample opportunity to scrutinise the approach that regulators are taking and, importantly, Parliament should be able to add to that scrutiny as well. Like clause 31, clause 34 is essential for the future-proofing of NIS regulations.

Clause 34 enables the Secretary of State to make provisions for regulators to recover relevant costs; I have mentioned examples of the sorts of factors we might specify in that context. Together with clauses 29 to 33, 35 and 41, clause 34 is necessary to ensure that the Secretary of State can update and amend the functions of regulators as needed in the future, and is an integral part of the Bill’s future-proofing powers.

Clause 35 is the final clause that clarifies the limits and prospective uses of the regulation-making power in clause 29. It confirms that the regulations may confer functions and allow certain functions to be delegated to others—for example, it could enable a regulator to delegate functions to inspectors. It also clarifies that regulations can be made to require a person to have regard to guidance or codes of practice, or that make provision by reference to another document or piece of guidance. In short, the clause provides helpful clarity about how the regulations could be applied.

Sarah Russell Portrait Sarah Russell (Congleton) (Lab)
- Hansard - - - Excerpts

On a point of order, Mr Stringer. I am not sure whether this strictly meets the criteria for a point of order, but it is clear that some people in the room cannot hear what is happening. I know the convention is that only the Whips and Ministers sit on the front row, but if those who are struggling to hear wish to sit closer, could we abandon that convention? It would be a reasonable adjustment so that everyone can participate properly, because this is discriminatory.

--- Later in debate ---
None Portrait The Chair
- Hansard -

Does the Minister wish to respond?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

No.

Question put and agreed to.

Clause 29 accordingly ordered to stand part of the Bill.

Clauses 30 to 35 ordered to stand part of the Bill.

Clause 36

Code of practice

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss clauses 37 to 39.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 36 sets out that the Secretary of State may issue a code of practice for regulated entities. The code will describe recommended steps to help these entities to comply with their duties and requirements under the NIS regulations and any new regulations made under the Bill. This will make it simpler for regulated persons to understand what is expected of them, thereby driving consistency and complementing sector-specific guidance from regulators.

The clause will also make enforcement clearer and more effective, as regulators must take the code into account when they assess compliance. The code is designed to be flexible: it can be updated as threats and technology change, and can be tailored to different types of organisations, ensuring that guidance is current, relevant and practical for all.

Given the importance of the measure in providing practical recommendations to regulated entities, it must be consulted on before it is prepared or revised, and this process is set out in clause 37. Before the code can be brought into force, a draft must be laid before Parliament, providing ample opportunity to scrutinise and, if necessary, reject it within a 40 day period. If either House objects, the Secretary of State cannot proceed with that version and may prepare a new draft. If the draft is approved by Parliament, the Secretary of State may issue it and must publish it, and it then comes into effect immediately, unless otherwise specified. The clause also clarifies how the 40-day period is calculated, to ensure consistency and transparency in the process.

As we know too well, cyber-threats continue to evolve as new tactics and technologies are deployed, which is why the clause includes a power for the Secretary of State to amend the procedure for issuing the code. The Secretary of State may, for example, wish to add or amend consultation requirements or extend the 40-day period.

Clause 38 establishes how the code of practice will be used and treated in legal and regulatory settings, to ensure it has the intended effect. For regulated persons, the code of practice is intended to be formal guidance, with recommendations on how to comply with their duties, but not to be legally binding itself.

As we know, there can be more than one way for businesses to meet their obligations and ensure that they have in place appropriate and proportionate security and resilience measures. It is therefore important that there is a degree of flexibility in how they do this, to accommodate sector-specific nuances and business needs. None the less, it is crucial that the code has sufficient legal status and that the good practice it contains is not simply ignored. That is why the code can be admissible as evidence in court when deciding whether legal obligations have been met, and why the courts and regulators must consider it as evidence when assessing compliance.

Clause 39 establishes a formal process for the withdrawal of the code of practice, in case that is ever needed.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 36 provides that the Secretary of State may issue a code of practice for regulated entities to set out measures that they should take to demonstrate compliance with their duties under the NIS regulations, or any requirements imposed by the Secretary of State under clause 29. If done well, the code could be a repository of best practice, setting proportionate, consistent and effective standards for regulated industries. That will require constructive and open consultation with regulated sectors to identify the challenges facing those sectors and how best to address them.

One issue that came up in oral evidence was the question of the lag between regulation making and industry adoption. David Cook of DLA Piper commented that, after laws come into effect, the process of businesses understanding where they need to get to

“often requires a multi-year programme of reform.”––[Official Report, Cyber Security and Resilience (Network and Information Systems) Public Bill Committee, 3 February 2026; c. 5, Q1.]

The code of practice is not envisaged to be legally binding, in the sense that a failure to comply is not of itself evidence of a failure to meet obligations under the NIS regulations or the Bill. However, clause 38 states that it would be admissible as evidence in legal proceedings so, in that sense, the code is binding in all but name. In view of that, and the fact that codes can be revoked and reissued, can the Minister provide reassurance to regulated industries that a lead-in time will be built into any requirements to allow businesses to prepare to achieve full compliance?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

First, to ensure that the shadow Minister and I are representing the intent behind the code clearly, in legal terms it is not the case that an organisation that fails to follow the code of practice is automatically a regulated organisation that has broken the law. Clause 38 makes it clear that not following the code does not by itself constitute a breach of duty or mean that an organisation is automatically liable to legal action. Organisations can take different approaches to complying with security duties, but if they adopt an approach that is not within the code, they may need to explain why their approach still meets the required standards set out in the regulations, and regulators will be required to take the code into account when preparing guidance.

On the shadow Minister’s question about ensuring appropriate timing and preparation for companies, I would very much expect that the regulators in question would be closely regulated entities to ensure the proportionate implementation of codes.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

We heard from the Information Systems Audit and Control Association that codes work best when they reflect operational reality. Given their evidential status, can the Minister reassure the Committee that codes will remain practical and iterative and not quietly harden into rigid compliance rules?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am very happy to give the broad assurance that we will keep codes under review from time to time, and that any changes to the code will require deep consultation with regulators and businesses to ensure that the codes keep in touch with moving technology.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

For the sake of clarity on the legal status of the codes, I entirely agree with the Minister that it is important to get this right, and my understanding of codes of practice in a different area—statutory codes of practice relating to the Mental Health Act—is that case law says that deviation from the code of practice should be done only for cogent reasons. That is a pretty high bar to pass in terms of deviations. I should declare an interest as a former consultant psychiatrist and someone who operated subject to that particular code of practice.

For absolute certainty, will the Minister write to the Committee and make the status very clear, along with reference to relevant case law in terms of other codes of practice? Does the clause override that jurisprudence or not? That would settle the question as the Bill goes through Parliament.

None Portrait The Chair
- Hansard -

Order. Interventions are getting a bit out of control again. I remind hon. Members that they should be brief.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I agree with the shadow Minister. The Bill’s focus is on the assessment of compliance with ultimate security duties. The codes of practice will set out approaches to do so, but they will not be the only approaches. I would be happy to write to the shadow Minister and the Committee on the particular legal interpretation, and any relevant case law that might apply.

Question put and agreed to.

Clause 36 accordingly ordered to stand part of the Bill.

Clauses 37 to 39 ordered to stand part of the Bill.

Clause 40

Report on network and information systems legislation

David Chadwick Portrait David Chadwick (Brecon, Radnor and Cwm Tawe) (LD)
- Hansard - - - Excerpts

I beg to move amendment 26, in clause 40, page 63, line 7, leave out “5” and insert “3”.

This amendment would increase the frequency of the reports that must be published under Clause 40, from every five years to every three years.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for Brecon, Radnor and Cwm Tawe for moving amendment 26, in the name of the hon. Member for Henley and Thame. It seeks to reduce the period for publishing a report on the operation of the legislation from at least every five years to at least every three. I reassure him that the Government recognise the importance of regular assessments of the regime to ensure that it is as effective as possible. The legislation sets five years as the minimum period. That is an appropriate and proportionate timeframe in which to meaningfully assess the progress, at a regular frequency, of the entire regime set out in the Bill, following the approach set by existing legislation such as the Online Safety Act 2023.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Clause 41 gives further detail on the sorts of provisions that can be included in regulations made under clause 24 and chapter 3 as a whole. It confirms that regulations can make different provisions for different purposes, different categories of person or different areas; can make provisions for how those regulations apply to the Crown or UK territorial waters; and can include consequential, supplementary, incidental, transitional or saving provisions. The clause also defines how certain terms used in regulations should be interpreted, such as “relevant UK waters” or “primary legislation”. In summary, the clause provides important points of clarification about how the regulation-making powers in the Bill can operate. I propose that clause 41 stand part of the Bill.

Clause 42 sets out the consultation requirements and parliamentary procedure that apply where regulations are used to designate new essential services or regulators, to impose regulatory requirements or change regulator functions, or to amend requirements for the five-yearly legislative review.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

These procedures are standard, but the powers they apply to are significant. Where regulations under part 3 would materially expand duties or bring new actors into scope, have the Government considered whether those should receive deeper scrutiny in practice, even if the formal procedure remains the usual one?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for that important point. The expectation is that the powers used here are scrutinised appropriately. If it helps, I can set out which uses of the power, particularly under clause 42, will trigger consultation requirements and the affirmative procedure, which will perhaps give her the assurance she seeks.

In essence, all changes that may have considerable impact on how the NIS regime operates will be subject to consultation and the affirmative procedure. In practice, this means that regulations concerning the designation of essential services, as well as changes to the duties of regulated entities and functions of regulators, will be subject to both consultation and affirmative procedure requirements.

In each of the cases I mentioned, clause 42 requires the Secretary of State to undertake consultation with appropriate persons before any regulations can be made. It also specifies that regulations of this kind can be approved only through the affirmative parliamentary procedure. These provisions ensure that any substantive regulations made through the Bill’s future-proofing powers will be properly tested. They provide the necessary checks and balances that such wide-ranging powers require, and they will ensure the credibility and legitimacy of future regulations made using these powers. For those reasons, I propose that clause 42 stand part of the Bill.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I have two questions for the Minister. Given the impact on devolved legislation, can he confirm that the consultation will extend to devolved authorities should it impact on them? My second question is more generally on the theme of devolved authorities. Can he confirm that, as part of the publicised “reset” negotiations with the European Union, bringing Northern Ireland into scope of NIS2 regulations is totally off the table?

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

On the broader point about application to the devolved Administrations, changes in UK legislation may indeed need to be reflected in devolved legislation, such as where it refers to and references the name of UK legislation. In those contexts, it is important that consequential provision can be made to ensure coherence. We will continue to engage with our devolved colleagues on the implementation. I am very happy to write to the hon. Gentleman and the Committee, particularly on the Northern Ireland point.

Question put and agreed to.

Clause 41 accordingly ordered to stand part of the Bill.

Clause 42 ordered to stand part of the Bill.

Clause 43

Directions to regulated persons

David Chadwick Portrait David Chadwick
- Hansard - - - Excerpts

I beg to move amendment 27, in clause 43, page 66, line 11, at end insert—

“(fa) a requirement to remove, disable or modify hardware, software or other facilities;”

This amendment would enable the Secretary of State to issue directions to remove, disable or modify hardware, software or other facilities for national security purposes.

--- Later in debate ---
Emily Darlington Portrait Emily Darlington (Milton Keynes Central) (Lab)
- Hansard - - - Excerpts

As the Minister will be aware, I have spoken consistently of my concern about our reliance on hardware and tech that comes from potentially non-favourable state actors abroad. That also relates to Government procurement, which I have raised before, as the Minister will know.

The Committee has already discussed how local government and Government Departments are not covered by this legislation, and how there is a separate strategy and document. Can the Minister expand on how protections against a reliance on foreign tech within critical infrastructure, in either the private or the public sector, are being dealt with in the Bill or in the strategy that has been published for the public sector? How will that be continually reviewed as our global geopolitical situation remains unstable?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I will start by addressing amendment 27, moved by the hon. Member for Brecon, Radnor and Cwm Tawe, which would add to the non-exhaustive list of requirements that could be included in a national security direction. It specifies that a direction could include requirements to

“remove, disable or modify hardware, software or other facilities”.

I reassure him that the Bill, as currently drafted, allows the Secretary of State to impose those types of requirements. Clause 43(3)(f) specifies that a direction may include

“a requirement relating to removing, disabling or modifying goods or facilities or modifying services”.

That already encompasses the types of requirements specified in amendment 27.

Furthermore, clause 43(3) lists the requirements that may “in particular” be included in a direction. The list is therefore not exhaustive, and for good reason. It is not possible or desirable to specify every action that might be needed to address a national security risk. That would restrict the Government’s potential avenues to address urgent national security threats, and would risk the legislation being too narrow to address novel threats to the UK’s national security.

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I really do not understand the Minister’s answer. If it has not been published on national security grounds, how will we know that it has been laid? The whole thing could be entirely secret. Surely it has to go to the ISC as an accountability mechanism.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The Bill currently provides for clear parliamentary scrutiny. The Secretary of State is responsible for coming to Parliament, although some information may not be able to be presented in public. I am happy to write to the shadow Minister about the mechanisms that other similar regimes have used to ensure that Parliament’s scrutiny is informed in those cases, whether in Committee or otherwise. The primary mechanism is the one we use for constant parliamentary scrutiny, and it would be unfair for any of us to suggest that most of those channels would not be appropriate for the sort of scrutiny we are looking at.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I think the Minister is saying that there will be a parliamentary scrutiny mechanism under these powers. Is that what he is saying?

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

To repeat, exactly as I said: once a direction is issued, it will be laid before Parliament for scrutiny. If there is any misunderstanding, I am happy for the shadow Minister to write to me so that I can confirm it.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I really think we should be very critical about this. What we are doing now is parliamentary scrutiny. There will be directions in future, which we expect to be laid, and they will also be subject to parliamentary scrutiny. Even where they are redacted because of national security concerns, somebody, or some mechanism of Parliament, will be able to scrutinise them. Can the Minister confirm that?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

To return to the point made by my hon. Friend the Member for Milton Keynes Central about the Bill’s provisions, the Bill looks at particular risks posed by hostile states, related actors and a wide range of other actors. Network and information systems for essential services and the identity of risk sources may be one consideration for organisations and regulators as well as the NCSC. The Bill does not look at specific actors but the outcome of the risk. Of course, hostile actors are an important part of that. I am happy to write to my hon. Friend about wider initiatives outside the Bill, particularly in the public sector, which I know is an important concern for her in relation to hostile state actors. There are a range of initiatives that the Government are taking forward in that context.

Clause 43 grants the Secretary of State the power to direct an NIS-regulated entity to take necessary and proportionate actions in response to national security threats. The power can be used where the entity’s network and information systems have been compromised or there is a threat of such compromise. The clause sets out the sorts of action that a direction could require. A direction could, for example, require an energy provider to take action to remove a hostile actor’s presence from their networks, in response to intelligence that a hostile state actor was pre-positioned for an attack.

Cyber-attacks on NIS sectors represent a serious and growing threat to the UK’s national security. High-capability actors and hostile states can mount increasingly targeted and sophisticated attacks. At present, however, the Government lack powers to require regulated entities to take necessary action in response. That gap could be exploited with increasing frequency and impact. The clause will remedy that, ensuring that the Government have the necessary powers to act quickly to protect our national security.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

To take this a little bit beyond the theoretical, is the Minister suggesting that, where it is discovered that, for example, a major offshore wind power generation facility was fitted with remotely triggerable kill switches, triggerable by a foreign state or sub-state actor, the Secretary of State could require that energy company to remove whatever piece of hardware or software was producing that threat?

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I could not judge a specific situation but, broadly speaking, that is the sort of situation, especially if it is an NIS-regulated entity, and in particular where the exercise of the power is focused on the entity’s network and information systems, that I would expect to come in scope of the powers specified here.

Under clause 44, a direction can be issued only when necessary for national security. It is possible that, in some circumstances, what is needed to protect UK national security could conflict with standard regulatory duties. For example, a direction might relate to a particularly sensitive national security risk, where only those involved in addressing the risk should be aware of it. That is to minimise the risk of hostile actors becoming aware of a vulnerability. A direction could therefore require an entity not to report that national security risk for the period in which the risk was being remedied. They may ordinarily have had to report that national security risk to comply with standard reporting requirements. The clause will resolve that conflict and provide certainty to recipients of directions about what they must do to ensure that the national security risks in a direction are addressed.

David Chadwick Portrait David Chadwick
- Hansard - - - Excerpts

Given the reassurances from the Minister, I beg to ask leave to withdraw the amendment.

Amendment, by leave, withdrawn.

Clause 43 ordered to stand part of the Bill.

Clause 44 ordered to stand part of the Bill.

Clause 45

Monitoring by regulatory authorities

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss clauses 46 and 47 stand part.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

This group of clauses concerns how compliance with national security directions will be monitored. Clause 45 enables the Secretary of State to delegate the task of monitoring compliance with the direction issued under clause 43 to a NIS regulator. Regulators have valuable sectoral expertise and existing relationships with the entities they regulate. As such, it may be effective to delegate monitoring of compliance to the relevant regulator. The Secretary of State will retain the sole ability to make judgments about whether non-compliance has occurred, or if any penalty is appropriate. The regulator would be required to obtain information relating to compliance, to be shared with the Secretary of State. The Secretary of State would then determine how they would like to receive this information—for example, in reports or at regular intervals.

Clause 46 grants information-gathering powers to the Secretary of State and to regulators that are subject to a monitoring direction or request. In order to determine whether an incident or threat meets the bar for issuing a direction, or whether a regulated entity is complying with the direction, the Secretary of State will need information from that entity and potentially other parties. The clause establishes the power for the Secretary of State to request that information. As the monitoring of compliance with the direction may be delegated to NIS regulators, the clause also equips those regulators with the power to request information needed for their monitoring functions.

Clause 47 grants the Secretary of State the power to carry out or delegate inspections needed to assess compliance with a direction, or with a confirmation decision specifying actions to be taken in the event of non-compliance. The Secretary of State is responsible for judging whether a regulated entity is complying with a direction, and therefore needs access to relevant information that the regulated entity holds. In some cases, this may not be possible to verify without physical attendance. To ensure the effective use of time and resources, the Secretary of State will have the power to appoint a person to carry out an inspection on their behalf, or to direct the recipient of a direction to appoint an approved inspector. The clause also grants these powers to regulators, where the regulator has been directed or requested to monitor compliance on behalf of the Secretary of State. This will ensure that they can provide the Secretary of State with the most accurate information. I commend the clauses to the Committee.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 45 gives the Secretary of State powers to require regulatory authorities to monitor and report on regulated entities’ compliance with directions given under clause 43 for reasons of national security. Clause 46 provides the Secretary of State with extensive information-gathering powers through the use of information notices to facilitate the giving of directions and monitoring of compliance with directions under clause 45(4). Clause 47 empowers the Secretary of State to conduct inspections to assess whether a regulated entity is complying with directions issued under clause 45(4). The Secretary of State may appoint a third party to conduct the inspection, and require the regulated entity to meet the costs associated with this.

I reiterate the point that these powers are necessary; however, given the potential for significant cost and administrative burden for businesses, they should be subject to contemporaneous or near-contemporaneous oversight by parliamentary authorities, observing the necessary confidentiality protocols. I also make the point that these information-gathering powers apply extraterritorially and may lead to conflict with regulated entities’ data privacy obligations in other jurisdictions. What discussions has the Secretary of State conducted with industry and law enforcement counterparts in other countries about the approach to information sharing for this purpose, and the implications for companies operating services on a cross-border basis?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am grateful to the hon. Gentleman for his points about proportionality and scrutiny. I want to give him assurances about that, as I did in our earlier conversation.

On cross-border compliance, the hon. Gentleman rightly points out that relevant information can be requested, regardless of whether it is held the UK. I am very happy to write to him with further detail on our ongoing engagement with counterparts elsewhere. During this process, we have engaged more broadly to understand other regulatory regimes and ensure compliance with them.

Question put and agreed to.

Clause 45 accordingly ordered to stand part of the Bill.

Clauses 46 and 47 ordered to stand part of the Bill.

Clause 48

Notification of contravention

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss clauses 49 to 52 stand part.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

This group of clauses concerns the enforcement of directions issued by the Secretary of State. I shall speak to them in turn.

Clause 48 grants the Secretary of State the power to issue a notice of contravention where they believe an entity is failing or has failed to comply with requirements relating to a direction. A regulator that has been tasked with monitoring a regulated entity’s compliance with a direction will also be able to issue a notification of contravention relating to an information notice or inspection issued by the regulator. It would not be appropriate for a regulator to judge compliance with a direction issued under clause 43 or any other requirement imposed by the Secretary of State.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

What happens when the Secretary of State, via his various proxies—the regulator or whomsoever—gives a direction to a company to do something in the interests of national security, and the entity disagrees and says, “That simply won’t work, and it won’t solve the problem that you are seeking to address”?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am reluctant to engage in the specifics of incidents without knowing the full range, but I would expect there to be an initial period of engagement to get to a position of agreement. Where the Secretary of State’s directions are not complied with in the context of a disagreement of the sort that the hon. Gentleman points out, penalties for non-compliance will be available to the Secretary of State. They will have to be justified both in the moment and subsequently, in the light of the particular provisions of the Bill.

The clause sets out the circumstances in which the Secretary of State and relevant regulators can issue a notice of contravention and the details that such a notice should contain, including the steps that an entity should take to rectify or remedy an act of non-compliance and the penalties that are being considered. The ability to issue a notice of contravention is an important procedural mechanism. It gives directed entities the opportunity to address non-compliance before penalties are imposed through a final confirmation decision, and increases the likelihood that the requirements of a direction will be met. That is vital, given the national security risks that a direction is intended to address.

Clause 49 empowers the Secretary of State to determine appropriate and proportionate penalties for non-compliance with a direction. It sets an upper threshold on what the penalties can be. For non-compliance with a direction, penalties are fixed at the greater of ÂŁ17 million or 10% of turnover for undertakings, subject to turnover and undertaking being defined in regulations, and ÂŁ17 million for non-undertakings. For requirements concerning the provision of information or inspections, the maximum penalty for non-compliance is set at ÂŁ10 million.

Clause 49 also provides for daily penalties to be issued. These are set at £100,000 a day for non-compliance with a direction and £50,000 a day for related requirements. They will continue in force until the entity has complied with the relevant requirement. A regulator that has been tasked with monitoring a regulated entity’s compliance with a direction will be able to issue penalties for non-compliance with an information notice or inspection issued by the regulator.

These provisions have been designed to reflect the gravity of non-compliance with a national security direction and the necessity of ensuring that directed entities comply with the requirements that directions impose. It is also why the maximum penalties have been set at a significantly higher level than they have for the updated NIS enforcement regulations in clause 21. The better comparison in that context is the penalty threshold for national security powers in the Telecommunications (Security) Act 2021, which align with the provisions in clause 49.

Clause 50 grants the Secretary of State and, where relevant, regulators the power to issue a final confirmation notice for non-compliance with a direction or related requirements. The clause specifies that the Secretary of State or regulator can issue a confirmation notice where they have previously notified an entity of suspected non-compliance, and where they are now satisfied that non-compliance has occurred. The notice of confirmation is the mechanism through which the Secretary of State or regulator can issue their final determination about the actions an entity needs to undertake to correct or remedy a contravention, and the penalties it will need to pay, in accordance with the provisions in clause 49.

A confirmation decision can be issued only after a directed entity has had the opportunity to make representations about an earlier notice of contravention. Once it has been issued, the directed entity must comply with it, and this duty can be enforced through civil proceedings. In short, clause 50 ensures that a direction can be enforced effectively and appropriate action taken to penalise non-compliance.

Clause 51 sets out how penalties will be recoverable across the nations of the UK in the event of non-payment. Clause 52 grants the Secretary of State the power to enforce non-disclosure requirements imposed in relation to the issuing of a direction, notice of contravention or final confirmation notice. Failure to respect these requirements could harm national security, for example by exposing vulnerabilities in the UK’s essential services or the security mitigations being put in place to protect their network and information systems. As a result, it is crucial that the Secretary of State has adequate powers to enforce non-disclosure requirements. Clause 52 largely replicates the enforcement process for non-compliance with other requirements of directions issued by the Secretary of State. The maximum penalties will be £10 million or £50,000 per day.

I ask the Committee to support the clauses in order to enable the effective enforcement of directions issued by the Secretary of State to protect the UK’s national security.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clauses 48 to 52 deal with notifications and financial penalties where a regulated entity is deemed not to be compliant with directions issued by the Secretary of State under part 4. In particular, clause 48 would grant enforcement authorities powers to issue a contravention notice if they believe a person has failed to comply with a requirement under part 4. The notice must set out details of remedial steps to address the failure, as well as the financial penalty that the enforcement authority intends to impose.

Clause 49 would require penalties to be set at a level that is appropriate and proportionate, with the maximum penalty being ÂŁ17 million or 10% of turnover. A maximum daily penalty of ÂŁ100,000 applies to ongoing breaches. The maximum fines for failing to comply with an information notice or an inspection would be set at ÂŁ10 million.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I have two points to make to the shadow Minister on defining turnover. As he will be well aware, “turnover” is a technical term that is best defined in secondary legislation, to keep up to date with accounting principles that at times vary from sector to sector. He asked for factors that might contribute to definitions. The specific determination of turnover will be set out secondary legislation, but we intend to establish a presumption that only the turnover of the regulated entity that breaches the direction will be considered for determining penalties on this point.

Question put and agreed to.

Clause 48 accordingly ordered to stand part of the Bill.

Clauses 49 to 52 ordered to stand part of the Bill.

Clause 53

Power to direct regulatory authorities

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to consider the following:

Clauses 54 to 56 stand part.

Government amendments 23 and 24.

Clauses 57 and 58 stand part.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

This group concerns the power for the Secretary of State to issue directions to the NIS regulators, as well as general provisions relating to the power and the power to direct regulated entities. That includes the procedure for reviewing, varying or revoking directions, the procedure whereby Parliament can scrutinise these directions, how information concerning directions can be shared, the means by which directions can be issued and the clarifications of key terms concerning part 4 of the Bill. I shall speak to each clause in turn.

Clause 53 grants the Secretary of State the power to direct NIS regulators in the exercise of their NIS functions, where it is necessary and proportionate in the interests of national security. The current system requires regulated entities to undertake “appropriate and proportionate” measures to secure themselves against cyber-threats. Regulators issue guidance to their sectors to help them to interpret that duty. However, geopolitical or technological developments could lead to rapid, unexpected increases in the cyber-threat that quickly leave whole sectors vulnerable and create a national security risk.

In such circumstances, it is essential that the Secretary of State can leverage the expertise and powers of NIS regulators to drive the implementation of enhanced security procedures and practices. For example, they may need to direct a regulator to issue an urgent advisory to its sector regarding new cyber-threats or to update guidance on what measures are “appropriate and proportionate” for them to take. This power will not extend to other Government Departments or devolved Governments, for which any actions to mitigate significant national security threats will be agreed through engagement.

Given the changing nature of national security threats, there may be times at which a national security direction needs to be varied or revoked. Clause 54 introduces powers for the Secretary of State to change the content of a direction, or revoke it altogether, where it is necessary and proportionate to do so in the interests of national security. The Secretary of State will be able to vary a direction to add new requirements, or to simplify directions by removing requirements that are no longer needed. To ensure that regulated entities are able to make representations, the Secretary of State is required to consult them before a direction is varied, where practicable. This requirement does not apply if consultation would be detrimental to the interests of national security.

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

Clause 53 would grant the Secretary of State powers to issue directions to regulators where this is necessary for national security reasons, and to allow a reasonable period for the regulator to comply with that direction. Clause 54 provides that directions may be amended or revoked by the Secretary of State. Under clause 55, directions to regulated entities or regulators must be laid before Parliament unless that

“would be contrary to the interests of national security.”

I repeat my earlier question about the ISC’s role regarding scrutiny. Clause 56 would permit the Secretary of State and regulatory authorities to share any information obtained under part 4 with each other and the NCSC. The provision also allows for the sharing of information with other UK or overseas public authorities with equivalent cyber-security or national security functions. Government amendments 23 and 24 seek to amend that clause to provide for directions and notices issued under this part to be sent by email to relevant persons who provided those contact details to regulatory authorities.

Some reassurance on the extent of information sharing for businesses is delivered through provisions specifying that disclosures of information should be limited to that which is relevant and proportionate. However, those are high-level and subjective terms, open to interpretation by the authority sharing the information. Can the Minister provide any update on the development of protocols between authorities to ensure that information shared is limited to that which is necessary for effective oversight and enforcement in relation to national security risks?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

On the shadow Minister’s first point, I repeat what I said earlier and, of course, acknowledge his concern. I assure him that, while a direction can only be issued out of necessity for national security, it does not follow that public knowledge of that direction or its contents would compromise national security. I would expect a pretty extensive scope of such directions and, therefore, an appropriate channel of scrutiny in Parliament.

On his question of protocols to ensure information shared is not just proportionate in general, but specific to the purpose of national security specified, I am happy to give him the assurance that the Bill contains it and that, in the process of working out implementation, we will make sure that regulators are focused on developing those protocols.

Question put and agreed to.

Clause 53 accordingly ordered to stand part of the Bill.

Clauses 54 to 56 ordered to stand part of the Bill.

Clause 57

Means of giving directions and notices

Amendments made: 23, in clause 57, page 83, line 8, at end insert—

“(za) an email address provided to a regulatory authority as an address for contacting that person,”

This amendment would ensure that a direction or notice can be given to a person using an email address which has been provided to a regulatory authority as a contact email address.

Amendment 24, in clause 57, page 83, line 11, leave out

“there is no such published address”

and insert—

“no email address has been so provided or published”.—(Kanishka Narayan.)

This amendment is consequential on Amendment 23.

Clause 57, as amended, ordered to stand part of the Bill.

Clause 58 ordered to stand part of the Bill.

Clause 59

Extent

Question proposed, That the clause stand part of the Bill.

None Portrait The Chair
- Hansard -

With this it will be convenient to discuss clauses 60 and 61.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I will speak to clauses 59, 60 and 61 in turn. Clause 59 clarifies that the Bill’s provisions apply to England and Wales, Scotland and Northern Ireland. That is consistent with the Network and Information Systems Regulations 2018.

Effective implementation is key to a successful regime. Clause 60 outlines the phased commencement timings of the provisions, ensuring that they commence at an appropriate time. Some of the provisions will commence upon Royal Assent, or two months after Royal Assent, allowing the Government to begin implementing the regime without delay. That includes powers for the Secretary of State to lay important secondary legislation required to operationalise some measures in the Bill upon Royal Assent, and the power to publish a statement of strategic priorities at month two. All remaining measures will be brought into force via regulations, allowing the Secretary of State to sequence implementation in a way that is practical and proportionate, allowing for transitional arrangements and business adjustments. That also allows sufficient time for the implementing regulations to be made and scrutinised, and is required to make operational and implement the new, stronger framework.

Clause 61 clarifies that the Bill can be referred to as the Cyber Security and Resilience (Network and Information Systems) Act 2026 once passed.

Question put and agreed to.

Clause 59 accordingly ordered to stand part of the Bill.

Clauses 60 and 61 ordered to stand part of the Bill.

New Clause 2

Register of foreign powers for the purposes of Part 4

“(1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must, by regulations, establish and maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom’s critical network and information systems within six months of the passing of this Act.

(2) Foreign powers designated by the Secretary of State under subsection (1) must include states –

(a) which have been confirmed by GCHQ as having—

(i) perpetrated, or attempted to perpetrate, a cyber-attack in the UK in the preceding seven years,

(ii) targeted, or intended to target, that attack at the network or information systems of one or more operators of an essential service or critical suppliers, or

(iii) carried out, or intended to carry out, that attack through a state department, agency or affiliate group,

(b) which GCHQ has warned pose a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers.

(3) Regulations under this section are subject to the affirmative resolution procedure.

(4) In this section, “foreign power" means–

(a) the sovereign or other head of a foreign state in their public capacity;

(b) a foreign government, or part of a foreign government;

(c) an agency or authority of a foreign government, or of part of a foreign government;

(d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority; or

(e) a political party which is a governing political party of a foreign government. A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government—

(i) hold those posts as a result of, or in the course of, their membership of the party, or

(ii) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party.”

This new clause would require the Government to maintain a register of state actors posing a threat to UK cyber security for the purposes of exercising the Secretary of State’s powers under Part 4 of the Act, which enable the giving of directions in the interests of national security.—(Dr Spencer.)

Brought up, and read the First time.

Cyber Security and Resilience (Network and Information Systems) Bill (Seventh sitting)

(Limited Text - Ministerial Extracts only)

Read Full debate
Committee stage
Tuesday 24th February 2026

(7 months, 1 week ago)

Public Bill Committees
Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 Read Hansard Text Amendment Paper: Public Bill Committee Amendments as at 24 February 2026 - (24 Feb 2026)

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

None Portrait The Chair
- Hansard -

I thank the shadow Minister for getting those comments on the record. Would the Minister like to address those points?

None Portrait The Chair
- Hansard -

The shadow Minister can keep us updated on whether that has happened.

New Clause 2

Register of foreign powers for the purposes of Part 4

“(1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must, by regulations, establish and maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom’s critical network and information systems within six months of the passing of this Act.

(2) Foreign powers designated by the Secretary of State under subsection (1) must include states –

(a) which have been confirmed by GCHQ as having—

(i) perpetrated, or attempted to perpetrate, a cyber-attack in the UK in the preceding seven years,

(ii) targeted, or intended to target, that attack at the network or information systems of one or more operators of an essential service or critical suppliers, or

(iii) carried out, or intended to carry out, that attack through a state department, agency or affiliate group,

(b) which GCHQ has warned pose a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers.

(3) Regulations under this section are subject to the affirmative resolution procedure.

(4) In this section, ‘foreign power’ means–

(a) the sovereign or other head of a foreign state in their public capacity;

(b) a foreign government, or part of a foreign government;

(c) an agency or authority of a foreign government, or of part of a foreign government;

(d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority; or

(e) a political party which is a governing political party of a foreign government. A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government—

(i) hold those posts as a result of, or in the course of, their membership of the party, or

(ii) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party.”—(Dr Ben Spencer.)

This new clause would require the Government to maintain a register of state actors posing a threat to UK cyber security for the purposes of exercising the Secretary of State’s powers under Part 4 of the Act, which enable the giving of directions in the interests of national security.

Brought up, read the First time, and Question proposed (10 February), That the clause be read a Second time.

Question again proposed.

--- Later in debate ---
David Chadwick Portrait David Chadwick (Brecon, Radnor and Cwm Tawe) (LD)
- Hansard - - - Excerpts

In our previous sitting, the hon. Member for Runnymede and Weybridge set out clearly the cyber-threat posed by China, and argued that, through new clause 2, China should be explicitly recognised as a foreign power presenting a significant risk to the United Kingdom. He rightly highlighted the precedent in UK legislation for maintaining registers of hostile or high-risk state actors to protect national security. I agree that Parliament should be unequivocal in recognising the Chinese Communist party as a strategic cyber-threat, particularly given evidence of state-linked cyber-espionage, infrastructure compromise and the targeting of critical national infrastructure.

We have seen data from the Cabinet Office last week indicating that the Government plan to drastically reduce the integrated security fund spending on domestic cyber and tech to counter cyber-attacks. It will be cut from £113.3 million to £95 million by 2028-29, which is a reduction of 16%. Domestic spending to counter Russian threats in the same period will incur a drop of more than 20%. Those reductions leave us dangerously exposed and are in direct opposition to the Government’s promises to support the UK’s national security priorities. New clause 2 offers the chance to identify and monitor state actors that pose a threat to UK cyber-security.

The register must also reflect the evolving nature of cyber-risk. Threats do not arise solely from formally hostile states, but also from jurisdictions where hostile cyber-actors operate at scale, using digital infrastructure to target UK systems and citizens. We have seen that in countries such as India and Nigeria, where organised cyber-criminal networks have run sophisticated international operations against the UK, exploiting cloud services and telecommunications infrastructure. In India, law enforcement has dismantled major cyber-crime hubs linked to international targeting, including operations specifically affecting large numbers of British victims.

In 2025, the National Crime Agency worked in partnership with India’s Central Bureau of Investigation to raid an organised crime group in Uttar Pradesh, which had targeted more than 100 UK citizens with pop-ups stating that their devices had been compromised, losing them more than £390,000. That is not only an unacceptable financial loss for our citizens, but a significant waste of resources. In Nigeria, long-established cyber-criminal networks continue to conduct large-scale digital fraud campaigns aimed at overseas targets including the United Kingdom. Interpol’s Operation Serengeti in 2025 tackled high-impact cyber-crimes in Nigeria and 17 other nations, arresting 1,209 suspects and recovering nearly $100 million that had been stolen through cyber-fraud.

Although these states might not be hostile in a geopolitical sense, hostile cyber-actors operating within their borders are none the less inflicting sustained harm and placing heavy burdens on our cyber-defence and law enforcement resources. I support the aims of new clause 2, but urge Ministers to ensure that the framework is flexible enough to capture not only hostile states but jurisdictions that consistently serve as bases for large-scale hostile cyber-activity. Data from the Cabinet Office shows that integrated security fund spending on Russia is set to fall over 20% between 2026 and 2029, which shows that the Government are not taking threats from Russia, or other hostile nations, seriously enough.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

It is a pleasure to serve with you in the Chair, Ms McVey.

I thank the shadow Minister, the hon. Member for Runnymede and Weybridge, for the new clauses in his name, which would require the Secretary of State to create a register of foreign powers that pose a threat to UK cyber-security, to review that register, and to lay a report before Parliament. This is intended to inform the use of powers granted under part 4 of the Bill. I empathise with the shadow Minister’s concerns that hostile foreign actors could target the network and information systems of operators of essential services or critical supplies. That is a clear risk, and one that we are addressing through the Bill.

As drafted, the Bill grants the Secretary of State new powers to issue national security directions to regulated entities or regulators where their compromise poses a national security risk. So long as those tests are met, the powers may be used by the Secretary of State irrespective of the actor that is causing the national security incident or threat.

New clause 2 would require the creation of a register of foreign states that pose a risk to the UK based on GCHQ advice. I reassure the shadow Minister that regardless of the proposed new clause, any decision to use the powers in this part of the Bill will be informed by expert national security advice from GCHQ. As a result, it is unclear what additional support the proposed register would provide to the Secretary of State when, for example, deciding whether to issue a direction to a regulated entity.

Additionally, the report required by new clause 3 would effectively be a list of the vulnerabilities of the network and information systems of our essential services, and would therefore be an asset to malicious actors. That would be counterproductive to national security. The new clause would allow the Secretary of State not to publish part or all of the report, if publishing would be contrary to the interests of national security. However, it is unclear how even part of the report could be published without harming national security, given its intended content.

Drafting a report of vulnerabilities that cannot be disclosed to Parliament without harming national security would simply duplicate existing assessments, and run the risk of distracting Government from more effective measures to protect from hostile foreign actors. That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber-security risks where it is appropriate to do so, through things such as the National Cyber Security Centre’s annual report and advisories. I therefore kindly ask that the shadow Minister withdraw the new clause.

I thank the hon. Member for Henley and Thame for the Liberal Democrat new clauses in his name, which would require the Secretary of State to publish a statement of how the Government intend to address risks posed by foreign actors to UK network and information systems, and to assess how many entities regulated by the NIS regime are owned in part or in full by foreign states.

Let me reassure the hon. Member that the Government take the risks posed by foreign interference seriously. The NCSC’s annual reviews continue to highlight cyber-risks to the UK from foreign actors, as well as measures to mitigate those risks. We have robust processes for assessing such threats, drawing on the expertise of the intelligence community, including the National Cyber Security Centre and the National Protective Security Authority.

The measures introduced by the Bill will boost the security and resilience of network and information systems across essential services, managed services and relevant digital services, protecting them from the risks of foreign interference. Where that is not enough, the Bill provides a backstop: the new direction powers in the Bill will enable the Government to protect our critical services from exactly those kinds of national security risks. We will be able to require a regulated entity to undertake any action that is necessary and proportionate for national security in response to the threat of a compromise. Conducting assessments of the ownership structures of the many thousands of in-scope entities within six months would be disproportionately resource intensive, distracting Government from more effective measures to protect our services.

Publishing a review identifying national security risks caused by foreign state ownership, or assessing whether our powers are adequate, as the Opposition’s new clause 3 would require, would provide valuable insight to our adversaries. As I have previously set out, there is a clear pathway for Government to communicate with Parliament and the public about such cyber-risks where it is appropriate to do so, but where we identify specific concerns, it is right that we retain the ability to assess and respond without disclosing our conclusions to those who might exploit them.

Finally, it is worth pointing out that, as drafted, new clause 13 is not aligned with the intended scope of the Bill. The Bill is solely concerned with entities that are currently, or could one day be, regulated under the NIS regulations. This new clause would require a statement on the risks posed to all UK network and information systems, which is a significant broadening of the scope of NIS-regulated entities and sectors. Similarly, the focus on Government procurement seems outside that scope, given that Government network and information systems are not wholly regulated by the Bill. For those reasons, I ask that the hon. Member for Henley and Thame kindly consider not pressing his amendment.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I am grateful to the Minister for his response, but we have seen over the past six months, especially with the alleged spying incidents in Parliament, the Government’s resistance to recognising the Chinese Communist party as a threat. When it comes to our new clause 3 and concerns over transparency, we have also seen, in the last few weeks, that there are mechanisms—for example, the Intelligence and Security Committee—to ensure the disclosure of documents, while preserving national security. I would therefore like to press new clauses 2 and 3 to a vote.

Question put, That the clause be read a Second time.

Division 2

Question accordingly negatived.

Ayes: 6

Noes: 8

--- Later in debate ---

Division 3

Question accordingly negatived.

Ayes: 6

Noes: 9

New Clause 4
--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I thank my hon. Friend for his intervention, which is more for the Minister and the Government Whip’s benefit than mine.

Properly established ISACs will not only increase real-time awareness of cyber-risks and mitigations, but could also alleviate some of the burden on regulators in terms of sector-specific intelligence analysis. Industry feedback and experience from the adoption of the Network and Information Systems Regulations 2018 indicate that sectoral regulators are unlikely to have the capacity to assist with intelligence sharing in relation to real-time cyber-risks.

We know from the sectoral regulators’ oral evidence that building sufficient capacity for effective regulatory oversight is a challenge. Where we have models for sector-led and market-led good practice in hardening cyber-resilience, we should look at how it can be rolled out further. Seeing more of these organisations emerge could even lead to broader adoption beyond NIS-regulated areas to other industries. ISACs have the potential to become integral nodes in improving whole-of-society cyber-resilience, and it is an approach called for by many cyber industry stakeholders. I therefore commend new clause 4.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the shadow Minister for this amendment, which would require the Secretary of State to review how information sharing and analysis centres support the functioning of the NIS regime and what steps the Government can take to improve them.

I recognise the intent of this new clause. These centres play a key role in promoting collaboration and co-ordination in the cyber-security space, allowing organisations to share information, intelligence and best practice. In fact, the UK already benefits from a range of such initiatives, many of which are facilitated by the National Cyber Security Centre. In its latest annual report, the NCSC noted that more than 200 companies now meet regularly in trust groups to exchange intelligence and best practice, and to support each other in incident response. NIS regulators also support organisations to share information with each other in sector-specific groups.

However, while I fully endorse the value of those initiatives, I do not believe it is the Government’s role to review how they operate or to mandate how or where they are established. Such centres are meant to be a forum in which organisations can voluntarily engage in the exchange of information. As such, they operate most effectively where the initiative for participation comes from the organisations themselves or from technical authorities such as the NCSC.

The Government are, of course, committed to ensuring that the information-sharing provisions within the Bill are effective, and that will be assessed through the formal review of the legislation already required under clause 40. I kindly ask the shadow Minister to withdraw the new clause.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

In response to the Minister’s comments, clause 40 is about a review; it does not provide any direction, other than for the Secretary of State to do their job in reviewing this area. I will press new clause 4 to a vote.

Question put, That the clause be read a Second time.

Division 4

Question accordingly negatived.

Ayes: 6

Noes: 9

New Clause 5
--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I agree about the importance of putting things on the record. Since the hon. Member obviously has not been listening to my speech, he can check it out on the record. I acknowledged the challenges in this area—[Interruption.] Does the Government Whip want to intervene, or was she just chuntering? I will continue.

Given that the Bill puts quite a burden on the private sector, as we discussed over several sittings before the parliamentary recess, I think it is important that the Government recognise, as my hon. Friend the Member for Spelthorne said, it would be pretty shameless not to vote for accountability for themselves while putting it on other people. Let us see how the vote goes. I commend new clause 5 to the Committee.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the shadow Minister for moving new clause 5, which seeks to require annual reporting on progress towards meeting the recommendations of the National Audit Office’s report on Government cyber-resilience and meeting the implementation milestones of the Government’s cyber action plan.

We recognise the value of accessing the expertise of Parliament to hold the Government accountable for the changes required for our cyber-resilience. That is why, notwithstanding the hon. Member for Spelthorne acknowledging the embarrassment of the Conservative party owning its hypocrisy, this Government have already strongly welcomed the recent reports from the Public Accounts Committee and the National Audit Office on Government cyber-resilience.

Chris Vince Portrait Chris Vince (Harlow) (Lab/Co-op)
- Hansard - - - Excerpts

I declare an interest as a member of the Public Accounts Commission, which regularly scrutinises the National Audit Office. Can the Minister give some reassurance to Labour Members, who are being accused of hypocrisy, that we do make sure that the highest levels of cyber-security are met?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

My hon. Friend is right. Where the Conservative party did absolutely nothing and continues with its hypocrisy, I am glad to inform hon. Members that this Government have already adopted a duty to provide biannual reporting on progress against the recommendations of these two reports.

Alison Griffiths Portrait Alison Griffiths (Bognor Regis and Littlehampton) (Con)
- Hansard - - - Excerpts

New clause 5 simply asks the Government to commit to reporting back on meeting the milestones they have set themselves for increasing cyber-security standards. Is the Minister confident in the Government’s ability to deliver on their cyber strategy, or is the document not worth the paper it is written on?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I simply repeat my prior sentence: this Government have already adopted a duty to provide biannual reporting on progress against the recommendations of these two reports.

In addition, the Government’s cyber action plan was published in January this year. It sets out how the Government will rapidly improve the cyber-security and resilience of public services to deliver a step change in cyber and digital resilience across the public sector. The plan sets out clear accountability structures to ensure that cyber-risks at all levels of Government are actively owned and effectively managed, with those responsible held to account.

Alison Griffiths Portrait Alison Griffiths
- Hansard - - - Excerpts

The continued use of legacy IT equipment is a particular vulnerability across the Government estate. That will take some time to address entirely, but is there a strategy in place to prioritise the upgrading of this legacy equipment, given that it is one of the greatest areas of exposure?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The hon. Member makes a very important point. We have heard of two major sources of risk from a cyber point of view: legacy technology and technology debt, and frontier AI attacks. The Government’s cyber action plan is not technology-specific, but both those sources of risk are very much on my mind, and I will make sure they are also on the mind of those implementing the Government’s cyber action plan.

I assure Members that we will continue to work with Parliament to support oversight of the plan’s implementation and to explore additional avenues for scrutiny of the Government’s cyber-resilience to guarantee the right level of accountability. I therefore kindly ask the shadow Minister to withdraw his new clause.

Question put, That the clause be read a Second time.

Division 5

Question accordingly negatived.

Ayes: 6

Noes: 9

New Clause 7
--- Later in debate ---

Division 6

Question accordingly negatived.

Ayes: 6

Noes: 9

New Clause 10
--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

This new clause, tabled by the hon. Member for Brecon, Radnor and Cwm Tawe, would require the Secretary of State to consult and report within one year on whether regulatory authorities and regulated persons have sufficient resources and capabilities to meet their statutory obligations. Historical levels of regulatory oversight and enforcement in relation to the NIS regulations 2018 have fallen short of what is necessary to achieve meaningful cyber-resilience across regulated sectors. The second post-implementation review of the NIS regs 2018, conducted in 2022, found that incident reporting on the part of regulated entities was very low, with only 13, 12 and 22 NIS incidents reported in 2019, 2020 and 2021 respectively.

A review conducted by the Worshipful Company of Information Technologists identified a near total absence of formal financial sanctions under the NIS regulations, with zero confirmed major penalties from 2021 to 2024. The model has not been conducive to effective discharge of regulatory responsibilities, with knock-on effects for cyber-resilience and regulated industries, yet regulators will be expected to oversee a far larger pool of regulated bodies and process a far larger number of incident reports under the Bill’s provisions. It is therefore right for us to scrutinise carefully whether regulators are in a position to meet these obligations.

In the evidence sessions, many of my questions to witnesses, including those from Ofgem, Ofcom and the Information Commissioner’s Office, focused on their preparations to meet the demands of their expanded roles. It was clear from feedback that although regulators understand what they need to do to prepare, the practical challenges associated with securing sufficient resource are far from resolved. I would therefore be grateful if the Minister could clarify his plans to review regulators’ progress and what the key milestones will be to ensure that regulators can discharge their new duties alongside their existing ones when these provisions come into effect.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for Brecon, Radnor and Cwm Tawe for his new clause, which seeks to require a consultation on the resourcing and capabilities of regulators and regulated entities, assessment on whether additional Government support is needed, and a report on the findings. I reassure the hon. Gentleman that the Bill was developed in close collaboration with regulators and industry to ensure that regulators have the right information and tools to implement it.

The Bill already requires the Government to produce two regular reports to monitor the effectiveness of the legislation, and those would naturally include reviews of whether resourcing and capability were impacting on the effectiveness of the regime. The first of those is the annual report on regulator activities in relation to the statement of strategic priorities. The second is the report on the operation of the legislation, which must take place at least every five years.

Lincoln Jopp Portrait Lincoln Jopp
- Hansard - - - Excerpts

While we are talking about resources and the application of the Bill, I raise with the Minister that, on page 102 of the impact assessment, it states that the going rate for a contract lawyer is ÂŁ34 an hour. To my mind, that is out by a factor of probably 10. In the 10 days since our last sitting, has the Minister had a chance to re-examine the impact assessment and discover whether that was a genuine error? That number gets multiplied many times in the impact assessment. Has he had a chance to look into that?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The hon. Member has made that point a couple of times before. I am happy to write to him about the calculations, so that he is able to understand the survey and the significant uplift on which the figures are based.

In response to the hon. Member for Brecon, Radnor and Cwm Tawe, given that the two reports can already include the topics addressed by his new clause, adding another report would risk confusing their purposes and increasing administrative burdens on those involved unnecessarily. The Government will not hesitate to adapt our support offering based on the findings of those reports. That will include using our flexible mechanisms—for example, updating our guidance to regulators, the statement of strategic priorities and the code of practice. Beyond that, we will continue to engage with regulators as the Bill is implemented, and consider whether any other means of improving regulators’ and regulated entities’ resourcing and capabilities are necessary and proportionate. For those reasons, I ask the hon. Member to withdraw his new clause.

Question put, That the clause be read a Second time.

Division 7

Question accordingly negatived.

Ayes: 2

Noes: 9

New Clause 13
--- Later in debate ---

Division 8

Question accordingly negatived.

Ayes: 2

Noes: 9

New Clause 14
--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

New clause 14 would require the Government to establish a dedicated support service for small and medium-sized enterprises that are operators of essential services, relevant digital service providers, relevant managed service providers or critical suppliers. That would include provision of advice, technical assistance and recovery guidance following a cyber-incident. It is worth noting that the Bill exempts small and micro enterprises from the regulations as relevant digital service providers or relevant managed service providers. Although regulators can designate a small or micro entity as a critical supplier, very few are expected to meet the threshold for criticality in practice. Similarly, there are limited examples of small or micro operators of essential services.

Improving the cyber-security of our nation’s small and medium-sized businesses is important for the resilience of our wider economy. That is why the Government have developed a wide range of free tools, guidance and training to help those businesses implement cyber-security measures. Such tools include the recently launched cyber action toolkit, which provides small and medium-sized businesses with tailored advice and the offer of free 30-minute consultations with NCSC-certified cyber advisers. Report Fraud, a reporting service for cyber-crime and fraud, runs a 24/7 cyber business incident reporting line, with regional cyber-resilience centres across England and Wales also providing support for small and medium-sized businesses, including incident response and business continuity advice in line with NCSC standards.

I hope that reassures the hon. Member for Henley and Thame that there is already considerable support available for small and medium-sized entities. Considering that, a new dedicated service is unnecessary, and it could divert resources from existing Government and NCSC schemes and impact our efficacy. For those reasons, I hope he will withdraw the new clause.

Question put, That the clause be read a Second time.

Division 9

Question accordingly negatived.

Ayes: 2

Noes: 9

New Clause 15
--- Later in debate ---

Division 10

Question accordingly negatived.

Ayes: 2

Noes: 9

New Clause 16
--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

New clause 16 would require active board oversight of security and resilience measures and accountability for board members where they fail in those oversight duties, whereas new clause 17 would require regulated entities to carry out proportionate, periodic testing of the security and resilience of their network and information systems, and provide the results to regulatory bodies upon request.

On board accountability, as we have already discussed in this Committee, the existing regulatory model under NIS regulations has not been sufficiently effective in driving up cyber-resilience standards to meet emerging threats. Board engagement is a key part of that, but the stat I quoted previously in this Committee indicates that engagement is going in the wrong direction. What assessment has the Minister made of the potential advantages and disadvantages of direct accountability in the adoption of effective cyber-resilience measures, based on a roll-out of the NIS2 regulations?

Proportionate testing of systems may be a useful tool in detecting and managing cyber-security risk. What consideration has the Minister’s Department given to how that topic should be approached in the Secretary of State’s code of practice?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for Brecon, Radnor and Cwm Tawe for his new clauses. I will speak first to new clause 16, which seeks to require boards or equivalent management bodies of operators of essential services, relevant digital service providers, relevant managed service providers and critical suppliers to take specific measures to oversee the security and resilience of their network and information systems.

Board-level engagement is a necessary part of proactively and effectively managing cyber-risks. That is why we published the cyber governance code of practice last spring, as part of a wider package of action to support boards in more effectively governing digital risks to enhance their organisation’s cyber-resilience. More recently, the Secretary of State, together with the Chancellor, the Business Secretary, the Security Minister, and leaders of the NCSC and NSA, wrote to the CEOs and chairs of the UK’s leading organisations, asking them to make cyber-risk a board level priority.

I agree with the hon. Member that going further on board-level responsibility is necessary. That is why we will introduce security and resilience requirements in secondary legislation, following consultation. We will consult on proposals that are consistent with the NCSC’s cyber assessment framework, as we confirmed in our policy statement last year. The cyber assessment framework includes comprehensive measures on good cyber governance, including clear board level responsibility. It is important that industry is consulted on those measures, that they form part of a holistic package on security and resilience, and that they can be updated flexibly over time. We intend to consult on proposals for security and resilience requirements and wider implementation plans later this year.

New clause 17 seeks to require all organisations in scope of the Bill to test the security and resilience of their network and information systems. We agree that proportionate cyber-security testing is critical to identifying and mitigating vulnerabilities in systems and networks. Organisations in scope need to take appropriate and proportionate measures to manage risks to network and information systems on which they rely, and that can include testing of network and information systems. In particular, relevant digital service providers are already required to account for testing as part of their overarching security duty. Additionally, all regulators can use their powers to mandate testing by an inspector, or by the regulated entity, to verify compliance or investigate potential failures.

I reassure the hon. Member that we are going further. We will be updating and providing more detail on the measures that regulated entities need to take, as well as setting strategic objectives for regulators. As I have said before, our proposals for the security and resilience requirements in secondary legislation will be consistent with the NCSC’s cyber assessment framework, which includes measures on appropriate testing.

David Chadwick Portrait David Chadwick
- Hansard - - - Excerpts

Is the Minister aware that the financial services industry is required to conduct regular testing of its systems, and that sectors like aviation and nuclear have designated individuals in their security organisations who are responsible for overseeing those sorts of practices?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the hon. Member for his point. I am also aware that the National Cyber Security Centre’s cyber assessment framework has very specific measures on appropriate testing as well. It already exists, and we want to make sure that it is an important part of specific security and resilience requirements in secondary legislation.

It is crucial that industry is consulted on the nature of any requirements related to testing. As mentioned, we intend to consult on the proposals later in the year. We will also issue a statement of strategic priorities for regulators, and will explore whether that is an appropriate vehicle for driving consistency in the behaviours of regulators in respect of their approach to testing for their sector.

Overall, any approach to going further on proportionate and regular testing must be developed alongside the full set of security and resilience requirements, and co-ordinated and communicated with a wider package of implementing measures. That will allow the impact of options to be assessed, and provide the industry with clarity on the overall approach, including how the components fit together.

The shadow Minister asked about the consideration of NIS2 requirements. We have looked at NIS2 provisions, and variability in member states’ implementation of it, as part of a wider set of considerations on which we will be consulting regarding secondary legislation on governance.

My hon. Friend the Member for Milton Keynes Central made an incredibly important point about security by design, which I very much take into account. The Government Digital Service is already working on a secure by design standard. We want to make sure that it is as robust as possible, and extend it across not just the public sector but parts of the private sector. I will make sure that security by design remains at the heart of the Government’s cyber action plan, as well as that of the private sector.

Emily Darlington Portrait Emily Darlington
- Hansard - - - Excerpts

I thank the Minister for that commitment. Would he consider setting up a meeting between GDS and those MPs who have expertise in this area, so that we can share our expertise and reassure ourselves that this is going in the right direction and at the speed that is necessary?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

My hon. Friend has extensive expertise, from which I benefit extensively. I will be keen to make sure that the Government Digital Service does so too.

In the light of those commitments, I kindly ask the hon. Member for Brecon, Radnor and Cwm Tawe not to press the new clauses.

David Chadwick Portrait David Chadwick
- Hansard - - - Excerpts

During the evidence sessions, numerous very knowledgeable witnesses called for these new clauses, so I will push them both to a vote.

Question put, That the clause be read a Second time.

Division 11

Question accordingly negatived.

Ayes: 2

Noes: 9

New Clause 17
--- Later in debate ---

Division 12

Question accordingly negatived.

Ayes: 2

Noes: 9

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I am a bit unclear about the hon. Gentleman’s intervention. The point I was making was that there is legitimate concern that people doing research into this area and doing threat assessments risk prosecution, so, across the whole of our society, that work is not being done. We have heard quite a lot of evidence from cyber campaigns about the benefits that changes to this law would make to the system, which is why we tabled the new clause. I commend new clause 19 to the Committee. I hope the Minister agrees that now is the time to address the issue.

I suspect that this will be my last, or penultimate, time speaking to the Committee, so I would like to finish by thanking Members on both sides of the Committee for a fun and, at times, robust debate over the past month. I thank the Chairs, the Clerks and all the teams working on the Bill—and Sophie Thorley from my office, who has done incredible research on the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank hon. Members for their new clauses; I recognise the strong feeling and thoughtful contributions about reforming the Computer Misuse Act.

I speak first to new clause 18, which seeks to place a duty on the Secretary of State to review whether amendments to the Computer Misuse Act could support the security and resilience of network and information systems used for carrying out essential activities. I assure the hon. Member for Runnymede and Weybridge that the Government remain committed to ensuring that the Act remains up to date and effective.

The Home Office is already conducting a review of the Computer Misuse Act, and is developing proposals that arise from its findings. That includes careful consideration of proposals to introduce a statutory defence that would allow researchers to spot and share vulnerabilities. It will provide an update as soon as the proposals are finalised. However, limiting a defence to only the sectors covered by the NIS regime would be impractical. Any package of workable defence would need to be broad enough to apply economy-wide.

New clause 19 raises the introduction of a statutory defence to the Computer Misuse Act. I acknowledge the strong sentiment regarding reform of the CMA. There is no doubt that UK cyber-security professionals play a significant role in maintaining the country’s overall security and resilience. Supporting them is vital.

I agree with the principle behind the new clause: that a defence to section 1 of the Computer Misuse Act could strengthen the resilience of network and information systems by allowing researchers to spot and share vulnerabilities. The Government are already conducting a review of the Computer Misuse Act, and we have made significant progress in developing a proposal for a limited defence to the offence provided for in section 1 of the Computer Misuse Act.

Andrew Cooper Portrait Andrew Cooper (Mid Cheshire) (Lab)
- Hansard - - - Excerpts

Many of us, on both sides of the House, are sympathetic to both new clauses. We heard very clearly in evidence sessions that the Computer Misuse Act, as it is today, has a chilling effect on the operation of the cyber-security industry in this country and on whether such companies want to locate here as opposed to other countries.

I absolutely hear what the Minister says about the Home Office developing proposals. I wonder whether he can set out a timescale for when those proposals are likely to be brought forward—whether he expects that to be in this parliamentary Session or the next one. The issue is clearly holding back the cyber-security industry in this country, and we would all like to see it resolved.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

My hon. Friend is absolutely right to recognise the shared sense on the principle of reforming the Computer Misuse Act. Although I am not in a position to give him a specific timeline, I absolutely take into account his recognition that the work needs to proceed at pace. Having held an industry engagement recently on specific proposals, with more than 75 attendees from a range of cyber-security organisations, the Home Office is now reviewing specific feedback as a particular proposal. The question is not whether we will reform the Computer Misuse Act, but simply how.

Freddie van Mierlo Portrait Freddie van Mierlo
- Hansard - - - Excerpts

I am grateful to the Minister for his reassurances on the ongoing review of the Computer Misuse Act. On that basis, I would like to say that I will withdraw the new clause.

David Chadwick Portrait David Chadwick
- Hansard - - - Excerpts

Will the Minister clarify what he thinks ethical vulnerability research actually constitutes?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Sure. I would not wish to define it technically, but my understanding is that it is research aimed at ethical hacking. It is effectively trying to find vulnerabilities through simulated attack systems, which can broaden our understanding of risks and vulnerabilities and allow us to mitigate them accordingly.

I return to new clause 19. Limiting a defence to just the sectors covered by the NIS regime would be impractical; any proposal for a workable defence needs to be broad enough to apply across the economy. That is why we are making sure that, through the Home Office, we are working as promptly as possible to ensure a proposal that is strong in its safeguards to prevent misuse. Engagement, including with the cyber-security industry, is already under way to refine our approach.

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

We are a responsible Opposition and we are pleased to hear about the work that the Minister and his Department have been doing and about the shared purpose in getting this done and getting it right. Would he give us a bit more detail of the timescales and plans for public consultation? I understand that he has been doing some personal consultation in private, but will there be a public consultation? Given that the reform crosses two Departments, which Department will be taking it forward? What I am really looking for from him is a confirmation at the Dispatch Box that he is personally committed to getting this piece of work over the line during this parliamentary term.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I thank the shadow Minister for his recognition of our shared approach on this question. Reform of the Computer Misuse Act is led by the Home Office. I have given my personal commitment to ensuring that reform, but I will also write to him and members of the Committee with as much detail as possible on the timeline to ensure that we are moving fast on it.

In that spirit, I thank hon. Members for their work on this question of the amendment to the Computer Misuse Act and use this opportunity to thank you, Ms McVey, the entire Committee staff and hon. Members for their expertise and perhaps for their sense of fun as well. I thank all staff members, in particular the Bill team in the Department, which has been fabulous throughout the entire process.

Freddie van Mierlo Portrait Freddie van Mierlo
- Hansard - - - Excerpts

I beg to ask leave to withdraw the clause.

Clause, by leave, withdrawn.

Bill, as amended, to be reported.

Cyber Security and Resilience (Network and Information Systems) Bill

(Limited Text - Ministerial Extracts only)

Read Full debate

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I do not want any part of the UK to be subject to the awful AI Act that has been passed by the European Union. Northern Ireland, and particularly Belfast, is a technological powerhouse of which we should be very proud. We need to ensure that it continues to go from strength to strength as part of our fantastic Union.

We on the Conservative Benches will not back new clause 13, because we understand how markets and global supply chains work. We believe in Britain.

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- View Speech - Hansard - - - Excerpts

I start by echoing the thoughts of many Members from across the House, particularly my hon. Friends the Members for Leeds Central and Headingley (Alex Sobel) and for Cowdenbeath and Kirkcaldy (Melanie Ward). I did not know Jo Cox, but I admired her deeply. As we talk about our country’s resilience, her central message—that there is no deeper route to resilience than through the unity of our country and community—is top of our minds for all of us in this House.

It is a pleasure to bring this important Bill back to the House this afternoon. The Bill will increase our cyber-defences and resilience, making the UK an even safer place to live and do business. I thank Members on both sides of the Chamber for their valuable contributions to this debate and for the expertise that they have brought throughout the passage of the Bill. I particularly thank them for their recognition of my core belief: that the central question for our national security and resilience is the question of our technological and AI capabilities.

We tested the Bill’s measures carefully before introduction, but we have since listened to feedback. There are a small number of minor, technical drafting improvements, which I will briefly go through. Government amendments 16 and 17 ensure that regulators can ask for the information they need to fulfil their obligations under the NIS regulations. This does not give regulators any new powers; it simply confirms that the current reasons for requesting information under the NIS regulations will still apply under the updated regulations.

Government amendments 7 and 8 make changes to align with two information-gathering Government amendments made in Committee—amendments 16 and 17. Government amendment 11 makes consequential changes following an amendment made in Committee. That amendment enables information sharing between NIS regulators and other public authorities for cyber-matters outside the scope of the NIS regulations.

Government amendments 14 and 15 clarify the safeguards for information sharing gateways, and amendments 9, 10, 12 and 13 make the necessary changes to ensure that the rest of the clause is consistent with the change made by amendment 14. Government amendments 18 to 26, to clause 57, allow regulators and the Secretary of State to issue notices related to the powers of direction to nominated representatives of regulated entities. I have also tabled Government amendment 27, which corrects minor drafting errors to ensure the Bill works as intended.

Members raised a series of questions, and I will address them thematically. First, the question of scope was raised by new clauses 4, 20, 21, 5, 8 and 9. I thank my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), the Chair of the Science, Innovation and Technology Committee, who brings consistent expertise and experience to these questions; the Chair of the Joint Committee on National Security Strategy, my hon. Friend the Member for Warwick and Leamington (Matt Western); and the hon. Members for Harpenden and Berkhamsted (Victoria Collins) and for Brecon, Radnor and Cwm Tawe (David Chadwick), who tabled amendments on the services and scope of the Bill.

All organisations, from high street shops to manufacturing giants, should take steps to increase their cyber-security and resilience. The Government and the National Cyber Security Centre are making sure that the right tools are available for every part of the economy. I am sympathetic to their intent, and in particular with my hon. Friend the Member for Middlesbrough South and East Cleveland (Luke Myer) when he talks about the impact of cyber-security incidents on local communities.

The Government have committed to reviewing whether new activities need to be brought into the scope of the NIS regulations, but it is essential that any such decision is based on a systematic and specific assessment of carefully considering whether the regulation in these particular parts of statute are the most appropriate response. The NIS regime has been put in place to protect the most essential parts of our economy, often those whose disruption would cause an imminent threat to life. It is focused on a specific set of tests where sectors have little or no alternative service provision in the event of disruption and relates the latest systematic evidence of the threats that each sector faces.

In that context, all Government Departments with sectoral responsibility work with their sectors on broader cyber-resilience. The Department for Environment, Food and Rural Affairs does so with food, and the Department for Business and Trade does so with retail, automotive and so on. The NCSC also has strong relationships across sectors, actively working with them to share best practice and incident insights, and to strengthen overall resilience, such as by engaging with the British Retail Consortium following incidents affecting the sector last year.

The food sector is unique among other critical sectors because of its high levels of diversity. In the analysis underpinning the judgments made in the Bill, there are approximately 20,000 SME food manufacturers in the UK alone, and many more farms, distribution centres, retailers and other types of businesses that form the UK’s food supply chain. Given the lack of a single point of failure, we think there are more proportionate levers to pull, rather than bringing food in scope of the NIS regime. We have made similar judgments about other sectors on the basis of that systematic analysis, as I have shared in Committee and at other stages of the Bill’s consideration.

Matt Western Portrait Matt Western
- Hansard - - - Excerpts

I accept the point about the plethora of businesses in the food supply sector, but my amendment simply seeks commonality with what the European Union has pushed for. Why can it not be the right thing for the UK Government to do as well?

Kanishka Narayan Portrait Kanishka Narayan
- View Speech - Hansard - - - Excerpts

I am happy to the write to the Chair of the Select Committee about comparisons with the EU, but the broad thrust is that we have undertaken a specific analysis of whether the burdens of the Bill should apply in a systematic, proportionate and coherent way to sectors. The analysis suggests that food supply is not in scope for the reasons I mentioned—primarily diversity of supply—but I would be delighted to engage with him on the question of why Europe took a different decision. We have based our decision on our analysis here.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

Will the Minister give way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I am going to make some progress but will try to come back to the Chair of the Select Committee shortly.

The Government’s cyber action plan is the overarching strategy to raise public sector standards across Government, including local government. The Ministry of Housing, Communities and Local Government has taken action to strengthen local authorities’ cyber-resilience, backed by £29 million of cyber grant funding, technical support and the adoption of the cyber assessment framework for local government. In that spirit, I take particularly seriously the point made by my hon. Friend the Member for Oldham West, Chadderton and Royton (Jim McMahon) on supporting capacity even further with centralised capacity support from the Government Digital Service and other parts of cyber-capability in central Government.

The joint election security and preparedness unit, also raised by Members, works to protect UK elections and referendums, co-ordinating across Government on response to threats, including cyber-risks. JESP works closely with the National Cyber Security Centre, producing guidance for organisations involved in delivering elections and electoral infrastructure, particularly local authorities. JESP and NCSC regularly engage with political-party representatives as well.

The question of a register of foreign powers has been raised in relation to new clauses 14 and 15, tabled by the shadow Minister, the hon. Member for Runnymede and Weybridge (Dr Spencer). New clause 14 would require the creation of a register of foreign states that pose a risk to the UK, based on GCHQ advice, for the purpose of exercising powers under part 4 of the Bill. I assure the shadow Minister, as I did in Committee, that the use of those powers will always be underpinned by robust intelligence. That includes, where relevant, information about state actors involved in cyber-threats. As a result, it is unclear what additional support the register would provide to the Secretary of State.

New clause 15 would require the Government to report annually on risks posed by foreign powers. Drafting a report of vulnerabilities would simply duplicate existing assessments and risk distracting the Government from more effective measures to protect the UK from hostile foreign actors. The shadow Minister also proposes that information that cannot be included in the report for national security reasons is sent to the Intelligence and Security Committee. I have made it clear to him, both in Committee and more broadly, that the Government value the independent and robust oversight that the Intelligence and Security Committee provides on behalf of Parliament. However, we do not consider that the report described in the new clause sits within the ISC’s current oversight remit, as outlined in the Justice and Security Act 2013 and the Committee’s memorandum of understanding with the Prime Minister. The Government are actively reviewing the Committee’s existing memorandum of understanding and will update the House in due course.

New clause 3, tabled by the hon. Member for Harpenden and Berkhamsted, would require the Government to assess how many entities regulated by the NIS regime are owned, in part or in full, by foreign states, and the risks that they pose. Publishing a review identifying national security risks caused by foreign state ownership would provide valuable insight for our adversaries. Furthermore, conducting an assessment of the ownership structure of every in-scope entity within six months would be disproportionately resource intensive, and would distract the Government from more effective measures to protect our services.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

Let me take the Minister back to the question of bringing the retail sector into the provisions of the Bill. He seems to be saying that cyber-security and resilience require Government intervention only when there is an immediate threat to life. Will he clarify whether that is what he is saying? My understanding is that we need to keep our economy and citizens secure in all circumstances. On the question of proportionality, my new clause 20 seeks to bring in only very large businesses, so that the requirements of cyber-security on them are proportionate. We know that such businesses are not taking the measures to keep cyber-secure, as we have seen recently with Marks & Spencer, Jaguar Land Rover and others.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

It is rare for me to have a point of divergence with the Chair of the Select Committee, given her experience and expertise. However, on that question I am absolutely not saying that Government support is limited only to the certain number of sectors covered by the Bill. There are a range of other ways in which the Government act to support sectors outside of the scope of the Bill. That is the right thing to do.

The scope of this Bill—the only Bill horizontally applicable to large parts of the economy—is systematically and specifically set to sectors that are significant as essential services, sectors where there is the risk of significant disruption and threat to life, and sectors where alternative supply is limited. For those reasons, we have excluded retail. Consideration of the scale of the business is not currently in that rubric, because there are also businesses that are small in scale but very material in life-threatening impact. I hope that is a satisfactory answer.

I thank my hon. Friends the Members for Dunfermline and Dollar (Graeme Downie) and for Newcastle upon Tyne Central and West for their amendments relating to the risks posed by communications modules made or controlled from outside the UK. Although I am sympathetic to their concerns, the Bill’s approach is intentionally technology and incident-agnostic. Instead of reacting to individual components in isolation, we focus on structural checkpoints and systematic dependencies in this context.

There are a range of other levers—investment screening through the National Security and Investment Act 2021; telecoms and cyber data security requirements to protect data and networks; supply chain measures, such as those in the Procurement Act 2023; diversification requirements to reduce dependency and build resilience—all of which are important to respond to the deeply significant concerns raised.

Graeme Downie Portrait Graeme Downie
- Hansard - - - Excerpts

Will the Minister give way on that point?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I will make some further progress.

I thank my hon. Friend the Member for Leeds Central and Headingley for his amendment relating to AI emergencies. I recognise his concerns, as well as those of my hon. Friend the Member for Cowdenbeath and Kirkcaldy. Technology is evolving rapidly, and Government must be equipped to respond. That is why the Bill grants the Secretary of State the power to direct regulated entities if the compromise of their network and information system, or the threat of it, gives rise to a national security risk. This could, for instance, require an entity to cease using and isolate an AI model.

These powers are a backstop to an effective cyber-security regime, enabling Government to act swiftly in the face of unexpected national security threats. They are also designed to be proportionate, recognising the need for stability among regulated entities and the importance of proper accountability. While I share my hon. Friends’ concerns, I encourage them to work with the Government on a systematic range of ways in which we can mitigate the risks they have rightly highlighted.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I will give way to my hon. Friend the Member for Leeds Central and Headingley in the first instance and then to my hon. Friend the Member for Dunfermline and Dollar.

Alex Sobel Portrait Alex Sobel
- Hansard - - - Excerpts

There is obviously a level of complexity here in relation to the data centre, AI development and the network in the UK and more broadly. Will the Minister therefore commit to a meeting with me and my hon. Friend the Member for Cowdenbeath and Kirkcaldy (Melanie Ward) to discuss this matter further?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I would be delighted to.

Graeme Downie Portrait Graeme Downie
- Hansard - - - Excerpts

I would be more than happy to work with the Government on something that will provide specific protections against cellular internet-of-things modules. What assessment has he made of the specific threat of internet-of-things modules, and what protections are there against that in the legislation?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

Given the specificity of his question, I will suggest that I come back to my hon. Friend. The broad thrust is that through our investment control legislation and procurement legislation, there are a series of responsibilities on Departments to look at it. [Interruption.] Given your encouragement, Madam Deputy Speaker, I shall move on.

Finally, I will respond to the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith), who raised a very important point. The most important thing to say is that I share his diagnosis, although for reasons mostly of technical drafting, I disagree with his prescription—I hope he will take that in the spirit in which it is intended. His amendment risks creating undue uncertainty in law for many other areas where we do not have an explicit requirement. While I share his diagnosis and his objective, I hope that we can work together to consider how best to give it effect, including through the Foreign, Commonwealth and Development Office’s overseas security and justice mechanisms for information sharing.

I thank all hon. Members for their consideration.

Jim Allister Portrait Jim Allister
- Hansard - - - Excerpts

I want to draw the Minister back to a point I raised with him at an earlier stage of the Bill, when he gave me what I would call a holding reply. When this legislation goes through, will the whole United Kingdom be subject to it, or will my part of the United Kingdom—Northern Ireland—be subject to the EU’s AI laws as they affect the digital sector? Businesses in that industry in my constituency want to know whether they will be governed by this Bill or by the EU’s AI Act. In other words, will the EU’s AI Act and Cyber Resilience Act be added to annex 2 to the Windsor framework, which would give them superiority and direct application in Northern Ireland? Can we have an answer—are they going to be added or not?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

The hon. and learned Gentleman will be aware from a response I recently gave him that both the complexity of the EU’s AI Act and its interaction with the Windsor framework are under consideration at the moment. The EU has made a proposal and we are working with it on that. I will be happy to engage with him on that particular question in due course.

Iain Duncan Smith Portrait Sir Iain Duncan Smith
- Hansard - - - Excerpts

I am not quite certain that I understand the Minister’s reasons for why he cannot accept my amendment, tweak it or work with it in the other place. The reality is that with this Bill, we are opening the door in a way that we would not have otherwise done to the use of information that may predicate a failure for some British citizen sitting in a country where the rule of law does not protect them in the courts. The Government are taking a risk of making it worse, not better. While the Minister agrees to some degree with the principle of what I am saying, surely this is the time to put it right in the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

As I say, I agree with much of the right hon. Gentleman’s diagnosis. Let me state in more detail the reasons for objecting on the mechanism. First, the provisions for information sharing are deeply discretionary for UK regulators. Secondly, the subjects in which they can pursue that information sharing are restricted to significant matters of national security and domestic crime prevention in the UK. Thirdly, the way that the amendment is drafted risks creating undue uncertainty in law. If this is the only regime where there is a specific and explicit reference to fair trial in the legislation, it calls into question how other information-sharing regimes are interpreted, such as under section 114 of the Online Safety Act 2023. In other words, drafted as it is, the amendment could invite legal challenge where a regulator exercises its discretion not to disclose this in other regimes, as there is no explicit exclusion. For those reasons, while I totally agree with the right hon. Gentleman’s diagnosis and his objective, I am afraid that the amendment in question risks undermining the objective.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

Will the Minister give way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I will not, because I am testing the patience of Madam Deputy Speaker—[Interruption.] With your permission, Madam Deputy Speaker, I will give way.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

I thank the Minister for generously giving way again. I have no desire to test the House by pushing my amendments to a vote, and I will be happy if I can receive his assurance. I take his points on not having technology-specific regulation where possible, but can I have an assurance that the Minister will work with me, my Committee and other hon. Members to look at the need to safeguard where there are technology-specific risks?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

As ever, I would be delighted to work with the Chair of the Select Committee on a range of technology questions, including this one.

I am delighted with the support that this House has shown for the intention and principles of the Bill, and I am grateful for Members’ consistent, principled scrutiny.

Alex Sobel Portrait Alex Sobel
- Hansard - - - Excerpts

On the amendment from the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith), I think we have made some progress with the Minister, but it is clear that trying to isolate the issues around fair trial from other matters is complex. Repeating my earlier call, will the Minister meet me, the right hon. Member for Chingford and Woodford Green and others who signed his amendment to explore the complexities of this after the debate?

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I can confirm that the Government will be very happy to engage on this question further with my hon. Friend and the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). I commend the Bill to the House.

Victoria Collins Portrait Victoria Collins
- Hansard - - - Excerpts

Before I withdraw new clause 2, I want to draw Members’ attention to my entry in the Register of Members’ Financial Interests in reference to my earlier speech. I beg to ask leave to withdraw the clause.

Clause, by leave, withdrawn.

New Clause 13

Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies

“(1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy (“a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by—

(a) assessing, managing and mitigating risks—

(i) associated with foreign interference,

(ii) arising from reliance on foreign-supplied technologies, and

(b) preventing over-reliance on foreign providers by building domestic capacity.

(2) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to—

(a) an operator of an essential service,

(b) a relevant digital service provider,

(c) a relevant managed service provider, or

(d) a critical supplier, within the meaning of the NIS Regulations.

(3) A Digital Sovereignty Strategy published under this section must—

(a) include risks associated with—

(i) hardware,

(ii) software,

(iii) supply chains, and

(iv) procurement processes;

(b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption;

(c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and

(d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems.”—(Victoria Collins.)

This new clause would require the Government to publish a Digital Sovereignty Strategy setting out how it intends to address risks to relevant network and information systems posed by foreign interference and reliance on foreign technologies, including by supporting the use of domestic technologies.

Brought up, and read the First time.

Question put, That the clause be read a Second time.

--- Later in debate ---
16:07

Division 24

Question accordingly negatived.

Ayes: 77


Liberal Democrat: 55
Green Party: 5
Democratic Unionist Party: 4
Plaid Cymru: 4
Independent: 3
Your Party: 2
Traditional Unionist Voice: 1
Social Democratic & Labour Party: 1
Ulster Unionist Party: 1

Noes: 255


Labour: 252
Independent: 3

New Clause 14
--- Later in debate ---
16:21

Division 25

Question accordingly negatived.

Ayes: 151


Conservative: 80
Liberal Democrat: 56
Democratic Unionist Party: 4
Plaid Cymru: 4
Independent: 3
Reform UK: 2
Traditional Unionist Voice: 1
Ulster Unionist Party: 1

Noes: 258


Labour: 250
Independent: 3
Your Party: 1

Clause 18
--- Later in debate ---
16:34

Division 26

Question accordingly negatived.

Ayes: 162


Conservative: 82
Liberal Democrat: 58
Green Party: 5
Democratic Unionist Party: 4
Plaid Cymru: 4
Independent: 3
Reform UK: 2
Traditional Unionist Voice: 1
Your Party: 1
Ulster Unionist Party: 1

Noes: 246


Labour: 242
Independent: 3

Amendment made: 15, page 41, line 23, at end insert—
--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I beg to move, That the Bill be now read the Third time.

It has been a privilege to take this vital piece of legislation through the House. I thank everyone who has played a role in getting the Bill to this stage, including the noble Baroness Lloyd of Effra, who has been instrumental in driving the policy in this Bill and leading its passage in the other place. I also thank my right hon. Friend the Secretary of State for Science, Innovation and Technology; the officials who have worked tirelessly since the Bill’s inception; the Bill team, led by Shona Lester; the policy teams, led by Nick Dodd and Liam Harkin; the legal team, led by Alicia Swannell; and my private secretary, Ben Holloway. I also thank parliamentary counsel, the Clerks and the Chairs of the Public Bill Committee, and every Member of the House who served on the Committee, as well as Members who have provided important input today and during all previous stages.

This country is subject to daily and unrelenting cyber-attacks. This is no longer the stuff of science fiction, but a daily reality that threatens public services, businesses and even our ways of life. As Dr Richard Horne, the CEO of the National Cyber Security Centre, has said:

“The real-world impacts of cyber attacks have never been more evident than in recent months”.

The Bill delivers on the Government’s commitment to drive secure growth and make the UK more resilient to the threats we face. It recognises how things have moved on since 2018, with data centres playing an increasingly important role in our digital lives and supply chains continuing to diversify. It also recognises that things will continue to change, with a deliberate, technology-agnostic approach and proportionate powers to enable the Government to close regulatory gaps and respond to imminent national security threats.

Since the introduction of the Bill, I have tabled a small number of amendments to refine its drafting and ensure that it achieves its intended purposes. They include designating Ofcom as the sole regulator for data centres, to reduce administrative burdens and strengthen accountability in this key sector. They also include enabling the network and information systems regulators to share vital information with other regulators and public bodies overseeing sectors and vice versa, enabling more co-ordinated and strategic oversight without unnecessary business burdens. They also updated the definition of cloud computing to respond to important feedback from the sector and made several minor and technical corrections to ensure that the Bill can be practically implemented.

The version of the Bill before us is an ambitious, practical and proportionate piece of legislation. It is the result of engagement with industry, important regulator feedback, international dialogue and tireless work from officials. I wish Baroness Lloyd the best in moving the Bill forward in the other place, and I commend it to the House.

Caroline Nokes Portrait Madam Deputy Speaker (Caroline Nokes)
- Hansard - - - Excerpts

I call the shadow Secretary of State.

Cyber Security and Resilience (Network and Information Systems) Bill

(Limited Text - Ministerial Extracts only)

Read Full debate

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

Moved by
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra
- View Speech - Hansard - - - Excerpts

That the Bill be now read a second time.

Northern Ireland, Scottish and Welsh legislative consent sought. Relevant document: 3rd Report from the Constitution Committee

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

My Lords, we are a proudly online nation, embracing interconnectivity in all walks of life. Cloud-based working, the rise of software as a service, the advent of artificial intelligence and more have rocketed the UK forward. They have enabled us to work faster, more efficiently and with more flexibility than ever before.

However, with these advancements come risks. As the technology powering our modern economy has leapt forward, so too have the tools that our adversaries use to extort, disrupt and surveil. Last year, more than 600,000 UK businesses were subject to cyber attacks. This is not only holding businesses back; it is undermining our security. These are criminals and hostile state actors seeking to disrupt the very foundations of our country.

The UK is now the most targeted country in Europe for cyber attacks. It is the duty of this Government to take bold action. We have been clear that all businesses must protect themselves from cyber attacks, but this does not mean regulating every single business. They know their customers and their suppliers, and they are best placed to protect themselves, using the free tools that we have provided.

I commend those who have already signed our Cyber Resilience Pledge, and urge more to do so, committing to take the three simple steps recommended in it: making cyber a board-level responsibility and following the cyber governance code of practice; signing up to the National Cyber Security Centre’s early warning service; and taking a risk-based approach to requiring Cyber Essentials across supply chains. This is our government certification scheme to help organisations improve their cyber resilience. Cyber Essentials works. Organisations with it are 92% less likely to claim on their cyber insurance than those without it. Taking these steps can make a huge difference.

However, where the risks are so great that public safety, the economy or our national security is threatened, it is right that we regulate. The Network and Information Systems—NIS—Regulations 2018 are the UK’s only cross-sector cyber legislation. They apply to operators of essential services in the energy, health, transport, drinking water and digital infrastructure sectors, as well as some digital service providers. The NIS regulations are designed to protect the security and resilience of our most essential services, to keep lights on, to ensure that taps keep running and to protect our NHS. We regulate only where we must, which is why the scope of the NIS regulations is precise. They are a targeted security intervention and the best tool in our arsenal to protect our most essential services. However, the regulations have fallen out of date. If we do not act, the essential services on which we all depend will remain under threat.

That is why we have introduced the Bill. The Cyber Security and Resilience (Network and Information Systems) Bill is a vital opportunity to improve the UK’s defences. In fact, it is the first Bill in British history to have “cyber” in its title. It will update the NIS regulations for the modern age and ensure that the Government can maintain their effectiveness and respond to imminent national security threats.

The objectives behind the Bill are threefold. First, it will safeguard the services on which our people rely most, making our essential and digital services more secure. Secondly, it will deliver a step change in our national security, improving our defences against the cyber attacks that threaten this country. Thirdly, it will better protect our economy. The UK will be a safer and more attractive place for businesses to establish themselves, thrive and grow.

The Bill will achieve these objectives through proportionate and timely measures, which I will speak to in turn. First, the Bill brings more sectors into scope of the NIS regulations. As our economy becomes more interconnected, so do the routes that cyber criminals exploit. For example, data centres in the UK have become critical to nearly all our economic activity and public services. From NHS patient records to financial systems, these vast digital depots are a key part of the modern world. That is why data centres meeting the Bill’s thresholds will be regulated as essential services, ensuring that they take steps to secure their networks.

The Bill also brings large load controllers under regulation. These are organisations that manage significant electricity flows to or from smart appliances. They must be safeguarded to secure our electrical grid and protect consumers using such appliances.

We are also bringing large and medium managed service providers—MSPs—into scope of the NIS regulations. These are organisations offering ongoing services, such as remote IT support or cyber security threat management, to customers. MSPs have deep access into their customers’ systems. As more and more organisations rely on them, MSPs become an increasingly attractive entry point for disruption.

Noble Lords will remember last April’s cyber attack on M&S. It involved a managed service provider being socially engineered, with attackers being able to gain access and compromise systems. We need to close this gap. But these regulations must be proportionate and targeted. Large and medium MSPs comprise fewer than one in 10 of the MSPs active in the UK but account for around 97.6% of the UK’s MSP revenue, so small and micro MSPs will be exempt from this measure. By targeting regulation where the risk and reach are greatest, we will protect almost all MSP customers without burdening small businesses.

In limited circumstances, small and micro-businesses supply critical goods or services to the essential and digital services on which we rely. The Bill therefore enables businesses, including smaller companies, supplying critical goods or services to be designated as “critical suppliers”. This is designed to combat the cyber risks stemming from increasingly complex supply chains.

Members may be aware of the 2024 attack on Synnovis, a pathology provider to some NHS trusts. Criminals thousands of miles away deployed ransomware and made Synnovis’s files unusable, delaying 11,000 appointments. This demonstrates the ripple effect that a compromised supply chain can have on the services at the ends. Duties that critical suppliers will be subject to will be set out in secondary legislation.

I turn to our 12 NIS regulators, whose sectoral expertise is critical to protecting our essential and digital services. These regulators are often operating with one hand tied behind their backs. They do not have the information, resources or levers necessary to properly fulfil their duties. For instance, organisations need only tell their regulator about an incident once it has already caused significant disruption. Under the Bill, they will have to report more types of breaches, to their regulator and the NCSC, within 24 hours and provide a full report within 72 hours. This includes incidents such as pre-positioning and ransomware, where an incident may not cause immediate damage but poses a real threat to the UK economy or society.

This will not only enable the NCSC to support those affected more quickly and warn others but allow the Government to better understand the threat landscape. Furthermore, the Bill requires digital and managed service providers and data centres to inform their customers about reportable incidents that are likely to adversely affect them. This way, customers can take appropriate steps to protect themselves.

However, effective reporting must be matched by consistency. Our 12 regulators cover all NIS sectors and the UK’s four nations. We must utilise their sectoral expertise but ensure that the rules are applied consistently. We cannot allow any sector to become an easy target. This Bill enables government to designate a single set of strategic priorities, as well as objectives tied to them, that regulators must seek to achieve. This will complement the security and resilience requirements, to come in secondary legislation, setting clear, consistent expectations and putting good practice on a firmer footing.

The Secretary of State will be required to consult the regulators on a draft of the statement before designating it. In addition, the Bill gives regulators new powers to recover their full regulatory costs from the organisations that they oversee. This includes enforcement costs, ensuring that this is not conducted to the detriment of a regulator’s books. Regulators must consult on how these fees will be calculated and publish a yearly statement to show how these funds were used.

The Bill also raises the maximum penalty enforceable for regulatory breaches while simplifying the penalty bands for easier, more consistent application. Regulators must consider all circumstances of a case before setting a penalty. This is not designed to punish companies but to incentivise their compliance. The ideal scenario is no penalties at all.

We are also fixing legacy issues concerning information sharing, so regulators can better understand what can and cannot be shared and with whom. All information shared must meet a specified purpose or require permission to be shared and be relevant and proportionate to the purpose for which it is shared. This Bill unties our regulators’ hands, giving them the information, resources and powers that they need to hold the line. That is what effective regulation should look like.

Finally, the Bill contains some important measures to enable future resilience, ensuring that the NIS regulations remain effective into the future. This Bill introduces a targeted, essential set of delegated powers to enable the NIS regulations to keep pace with the ever-changing cyber landscape. These include powers by which the Government can bring new services or sectors into scope of the regulations, so long as they meet the Bill’s strict criteria, or make regulations to further mitigate the risks from security and operational compromises. In the majority of cases, these delegated powers will be subject to consultation and the affirmative procedure will apply. Today’s threats were unimaginable in 2018, so we must not legislate as though today’s threats will stand still. These are carefully targeted, and it would be remiss not to take this opportunity to provide for careful, proportionate delegated powers. In almost all cases of these powers, the Government must consult on any changes. Parliament will still have the final say over legislation made under these powers. Our delegated powers memorandum contains greater detail.

In exceptional cases, even secondary legislation is too slow. Right now, if our intelligence community becomes aware of a NIS incident that threatens our national security, the Government have no emergency power within the NIS regulations to protect our people. This Bill provides powers for the Secretary of State to direct regulators and regulated entities where national security is threatened. This could entail instructing a sector to follow new guidance in response to a crisis or requiring an organisation to take technical steps to remove an intruder from a network. These are essential last-resort levers. The Bill has strong safeguards to ensure that they are used accordingly and only where strictly necessary for national security.

This Bill is about protecting the foundations of a modern economy. Growth cannot flourish where essential services are vulnerable, where businesses are exposed to disruption and where hostile actors can exploit weaknesses. We are not choosing between security and growth; we are recognising that one depends on the other. This will help secure the services that our people rely on, give businesses the confidence to invest and grow and strengthen our national security in an increasingly dangerous world. I beg to move.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

I thank noble Lords for their insightful and wide-ranging content, and I am pleased to hear the broad support for the Bill. I also thank the Minister in the other place and the parliamentarians who engaged with your Lordships and others ahead of the Bill’s introduction. The dialogue has been shaped by pragmatism and a genuine interest in protecting our people and businesses. Should I not be able to respond in the allocated time to all the very many specific points that were raised today, I will make sure that I review Hansard carefully and reply to noble Lords accordingly, placing copies in the Library.

The noble Viscount, Lord Camrose, raised an excellent point about the scope of the Bill and the many other government actions and activities to equip our businesses to tackle cyber threats. I agree that the national cyber action plan is the right place to set out exactly how this is all put together, but today I cannot provide noble Lords a date for the publication of the national cyber action plan.

As other noble Lords did, I started writing down the names of all the noble Lords who raised the question of scope—and I too decided that it was probably better to say “everybody”. This is a very pertinent question. Cyber security and resilience are a shared responsibility. The Government and the NCSC provide a range of tools for all parts of the economy, and it is for all organisations to make use of those to enhance their protections. We have invited all businesses, charities and other organisations to sign the Cyber Resilience Pledge and take the three tangible actions that can help boost their resilience to cyber attacks. For many organisations, this will be a significant step in their defences, and regulation will not be necessary nor proportionate.

Under the Bill, we have chosen to regulate where disruption to services—hospitals, drinking water, and cloud service providers—would mean that people and businesses are left with little or no easy alternatives. The significant steps we are taking in the Bill are reflective of the digital nature of our economy today and the risks we encounter. I recognise and share the sentiment of exploring other parts of the economy that would benefit from being under these regulations in the future, and I assure the House that I have asked my officials to work with other government departments to consider what additional services could be brought into scope in future. At the same time, this work needs to be undertaken with thorough consideration for a range of factors, such as the threats posed to such services by hostile actors and the potential impact they could have on the wider economy, as well as the overall value of the sector. We need to take into account the important points that noble Lords have made about proportionate regulation. I confirm to the noble Baroness, Lady Neville-Jones, that, were we to extend these regulations to further sectors, that would follow consultation.

The noble Baronesses, Lady Northover, Lady Neville-Jones and Lady Ludford, and the noble Lords, Lord Londesborough and Lord Clement-Jones, raised an important point about the government cyber action plan. It is crucial that our Government and public sector are covered. The government cyber action plan, which was published in January, will transform cyber security and resilience across government and the entire public sector by 2030. It will enable us to achieve the same outcomes that we want to achieve for services regulated under the Bill: clear and robust requirements, better incident reporting, and stronger accountability and transparency. The plan sets out accountability structures to ensure that cyber risks at all levels of government are actively owned and effectively managed. I assure your Lordships that we will continue to work with Parliament to ensure proper oversight of the plan’s implementation.

The extension to local government is also covered under the overarching strategy of the Government’s cyber action plan. I say to my noble friend Lady Alexander of Cleveden that MHCLG is taking action to strengthen local authorities’ cyber resilience, backed by £20 million of cyber grant funding and technical support, because it is incredibly important that local authorities are prepared and enhance their cyber action.

On the question about the food and retail sector, raised by the noble Lords, Lord Holmes of Richmond and Lord Taylor of Warwick, and the noble Baronesses, Lady Northover, Lady Ludford and Lady Harding of Winscombe, probably among others, it is very important that the sector enhances its cyber resilience. The food sector is unusual among critical sectors because of its high levels of diversity. There are approximately 20,000 small and medium-sized food manufacturers in the UK alone, and many more farms, distribution services, retailers and other types of businesses that form the UK’s food supply chain. Given the lack of a single point of failure, we think there are more proportionate levers to pull than bringing food into the scope of the NIS regime.

The question of AI was raised by the noble Earl, Lord Effingham, the noble Viscount, Lord Colville of Culross, the noble Baroness, Lady Kidron, and my noble friend Lady Berger. The Government are committed to protecting our national security against the risks posed by advanced AI models, and our AI Security Institute is world leading and one of a small group of organisations with access to Anthropic’s Claude Mythos model before its release. As for addressing the risks of cyber attacks facilitated by AI, it is true that AI capabilities are moving very fast, but strong cyber fundamentals still work. Our advice, and that of the NCSC, is to ensure that organisations get the basics right and that they are managing risks at board level. There is extensive guidance on this from the Government and from the NCSC.

As for whether AI is in scope, the Bill does not specifically bring large language models or AI companies into scope, but where organisations in scope use AI models and systems, those organisations will need to take appropriate and proportionate steps to manage the risks to these from hackers. For example, if an LLM is used as part of the day-to-day software available to staff in a hospital, and is therefore part of the network and information systems, it would be considered in scope.

On the example given by the noble Baroness, Lady Kidron, of how this would happen, the Bill grants the Secretary of State the power to direct entities if the compromise of the relevant NIS or the threat of one gives rise to a national security risk. This could, for example, require an entity to cease using and to isolate an AI model. These powers are a backstop to an effective cyber security regime, enabling the Government to act swiftly in the face of unexpected national security threats, but they are also designed to be proportionate, recognising the need for stability among regulated entities and the importance of proper accountability.

Many noble Lords reflected on the need for effective implementation and the importance of consultation and secondary legislation. There will indeed be secondary legislation and guidance and a business adjustment period for the Bill. To answer the question posed by the noble Baroness, Lady Neville-Jones, this will probably be for the period up to 2028, when we expect the duties to come into force.

On the questions about incident reporting raised by the noble Earl, Lord Effingham, the noble Lord, Lord Ravensdale, and the noble Baronesses, Lady Northover and Lady Harding of Winscombe, we have heard the clear ask from businesses to minimise the time they spend filling in different reporting templates following an attack. We understand the pressure that institutions can be under in the midst of an attack, and we want to make sure that they can prioritise the technical response. We are exploring all options and will look closely at other regimes in the UK and the new template used by EU member states for the NIS2 reporting, reflecting questions posed by noble Lords about where we are looking at the EU regime.

We do not believe that there is a risk of overreporting, but we will provide further clarity by setting out thresholds in secondary legislation following consultation. That will set out when an incident is considered to have had, or to be likely to have had, a significant impact—a question posed by the noble Lords, Lord Holmes of Richmond and Lord Ravensdale.

On the questions raised by the noble Baroness, Lady Bennett of Manor Castle, the ability to share information with like-minded countries is important if we are to make cyber security a global effort. But the Bill does not mandate information sharing across borders, and there are important safeguards around the sharing of information for the purpose of prosecuting a crime. I followed the debate on this topic in the other place, and I would be happy to meet with those interested in this topic to discuss it further.

Noble Lords raised the question of the balance between a single consistent approach and being attuned to sector-specific issues. One of the ways in which we are going to pursue consistency and provide clarity on what is expected is through the new security and resilience requirements for regulated entities, which will be set out in secondary legislation. These will set out the clear and consistent steps that regulated entities will need to take to mitigate their security risks. On the questions posed by the noble Lords, Lord Arbuthnot, Lord Birt and Lord Ravensdale, these will be high-level, outcomes-based requirements that will be consistent with the NCSC’s cyber assessment framework, including requirements on board responsibility and governance, supply chain and incident reporting and recovery, as well as requirements around testing and exercising protective security. These proposals will be technology- and sector-agnostic, and take an all-hazards approach to ensure resilience in the face of an evolving threat landscape and emerging technologies. They reflect the requirement for regulated entities to have regard to state-of-the-art technology when assessing the risks they face.

On the question posed by the noble Lord, Lord Ravensdale, and others on post-quantum cryptography, and that posed by the noble Lord, Lord Birt, on quantum, these would be considered as part of that requirement by regulated entities, but would not necessarily be singled out as a specific technology in the regulation so that we keep these regulations up to date and matched to the cyber risks that individual entities face.

In addition to how the requirements in the Bill will capture board responsibilities, we recognise that board-level governance is essential to effective cyber risk management, which is why the Cyber Resilience Pledge sets out that making cyber a board responsibility is one of the three clear tangible actions that any organisation can make to boost its resilience. The Government’s forthcoming modernising corporate reporting consultation will seek views on whether the existing risk reporting framework produces sufficient reporting on cyber risk management as an additional step that could be considered.

On the questions about the Secretary of State reporting to Parliament at least every five years, this is a minimum baseline. Additional reports can be published if deemed appropriate.

The noble Earl, Lord Effingham, and the noble Lords, Lord Londesborough and Lord Ravensdale, asked about business burden and the definition of small businesses. We believe that this legislation is targeted and proportionate, only regulating where necessary to protect the most essential services on which we rely. That is why small and micro digital service providers are exempt from the regulations, unless designated as a critical supplier. Small businesses are defined as entities that employ up to 50 people and have an annual turnover or balance sheet of less than €10 million. They are exempt from being an RDSP or an RMSP under the Bill. They can be regulated only if they are designated as critical suppliers, for which there will be a high bar for designation.

My noble friend asked how we can support small businesses. This is a very important part of our approach. The NCSC provides support through the Cyber Action Toolkit and Cyber Essentials, which also includes cyber insurance for those who get the certification. For any organisation that experiences an incident, the Government’s Cyber Incident Signposting Service helps point them towards where the issue should be reported and where appropriate support can be sought.

Questions on regulator capacity and consistency were raised by the noble Lord, Lord Vaizey, and my noble friend Lady Alexander. The framework will drive consistency across sectors through these common security requirements and through the statement of strategic priorities, which will set the objectives that regulators must seek to achieve. Sector-specific guidance from regulators will also remain key to address sectoral nuances and risks, building on a common foundation of good practice.

Many noble Lords raised the importance of building out sovereign capability in the UK, and I note that the Government are committed to pursuing that. I am sure that we will have other opportunities to talk further about tech sovereignty in the coming week in Oral Questions and the forthcoming debate on that subject.

My noble friend Lady Paul of Shepherd’s Bush and the noble Lords, Lord Ashcombe and Lord Arbuthnot, discussed cyber insurance. It can absolutely play an important role as part of a wider approach to cyber resilience, particularly in helping organisations to manage the impacts of cyber resilience and to support recovery. We do not believe that cyber insurance is a replacement for cyber security, but it is definitely part of a wider suite of cyber measures.

Many noble Lords made points about skills, which are incredibly important. We are improving industry understanding of cyber security, we are investing in cyber skills through TechFirst, and we are working with the UK Cyber Security Council to develop professional standards to bring cyber security in line with professions such as engineering and accounting. I also heartily endorse the points made by the noble Lords, Lord Ravensdale and Lord Vaizey, about the strength of the cyber security industry and sector in this country. It is not only strong within this country; it is also exporting to many other parts of the world, building on our strengths.

I note that product security, which was mentioned by many today in the sense of building in requirements, is indeed a feature of our product security and telecoms infrastructure—or PSTI—regime, which is an important complement to what is in the Bill.

Finally, the noble Lord, Lord Clement-Jones, led the charge on the Computer Misuse Act. We highlighted in the King’s Speech that a Bill focused on national security will update that Act and provide law enforcement with the updated powers and capabilities, so they can remain effective in the digital age.

I, too, look forward to Committee. This is an incredibly important Bill. I welcome the high level of engagement from across the House tonight on the practicalities and the details.

This Bill is fundamentally about national security. It will deliver stronger protections against those who want to disrupt our way of life. It will do so with growth at the forefront, focusing first on support and partnership and regulating only where it is necessary. I thank noble Lords and look forward to the Bill’s next stages.

Bill read a second time.
Moved by
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra
- Hansard - - - Excerpts

That the bill be committed to a Grand Committee, and that it be an instruction to the Grand Committee that they consider the bill in the following order:

Clauses 1 to 22, Schedule 1, Clause 23, Schedule 2, Clauses 24 to 61, Title.

Motion agreed.

Cyber Security and Resilience (Network and Information Systems) Bill

(Limited Text - Ministerial Extracts only)

Read Full debate

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

Moved by
1: Clause 2, page 2, line 13, leave out “on the Secretary of State”
Member's explanatory statement
This amendment is consequential on my new Clause (Functions under this Part).
Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

My Lords, I will also speak to the other amendments in my name in this group. I thank noble Lords for their constructive engagement on this topic over the Summer Recess. I particularly thank the noble Viscount, Lord Camrose, and his colleagues for sending their questions in advance. I will seek to address those in my opening remarks.

This package of amendments introduces new powers that will enable the UK to address vendor-related cyber risks in our critical infrastructure. The principal new clause introduces a new direction power. It enables the Secretary of State to direct entities in scope of the power where they are using, or may potentially use, vendor-supplied goods, services or facilities in connection with their network and information systems that could create national security risks.

It is becoming increasingly clear that there are axes of cyber risks that the Government need to address. These risks arise from goods or services supplied by another company being harnessed as tools for sabotage, surveillance or espionage. But they also exist where goods or services constitute critical points of failure due to their defective design or vulnerabilities. Noble Lords would have had some sense of these risks from debates during this Bill—in particular, discussions about remote access in embedded products such as cellular modules and the scope for hostile interference and control.

GCHQ has also raised escalating concerns about supply-chain vulnerabilities in the wider geopolitical context. The director of GCHQ explicitly called out those risks in her annual lecture in May this year when discussing the challenges posed by a relationship with China and the threats posed by Russian cyber operations. That is why we have tabled Amendment 102 to tackle decisively these risks and protect our national security. Our intention is to limit the use of this power to operators of essential services in the first instance, although we will review the case for bringing other entities into scope in the future.

Supplementary amendments contain the mechanisms needed to operationalise the power. They enable the Secretary of State to set statutory timeframes for decision-making, to specify and update which entities are in scope of the vendor-related direction power and to introduce mandatory procurement screening should this ever be considered necessary to protect national security. They also introduce a power to bring more entities into scope of the existing direction power in Clause 43.

The powers to bring entities into scope of this framework are rightly restricted. To be brought into scope, the Secretary of State or Chancellor of the Duchy of Lancaster must be satisfied that the entity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is consistent with the Bill’s definition of essential activity in Clause 24. Either Minister can exercise the power. It has been drafted like this to accommodate machinery of government changes.

The decision to introduce the amendments has not been taken lightly. The Bill already includes important national security powers to direct regulated entities whose systems have been compromised, or which are at risk of being compromised, by hostile actors. This new power allows the Government to act before vendors become embedded in supply chains and before taking action becomes costly and disruptive. It will give operators greater confidence in their procurement planning and avoid the need for costly interventions down the line.

Crucially, we are not proposing to introduce these powers in isolation. They will be part of a broader framework which will also include procurement guidance for operators and a voluntary referral route into government where operators have identified potentially risky procurements. The voluntary self-referral route will enable the Government to assist operators with vendor-related concerns, provide them with guidance on how to proceed and, where necessary, inform decisions about the issuing of a direction.

We intend to consult on the implementation of the framework in due course. This will include the criteria for referral and how the mechanism will work in practice. In the event that this Government ever determined a mandatory referral scheme was necessary, we would intend to consult on the definition of a “qualifying transaction” before laying the necessary secondary legislation. However, I emphasise that it is not our current intention to set up a mandatory scheme.

Ultimately, we expect this wider framework will minimise the need for formal interventions using the new powers. However, it is crucial that the power is in place as a backstop to guarantee the Government’s ability to protect the UK’s national security. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I assume that there are no Back-Bench contributions at this point, so I will speak on behalf of the Liberal Democrats to this very significant group of amendments tabled by the Minister as recently as 24 August. I thank her for her introduction today and for her brief meeting shortly after their tabling.

At the outset, from these Benches we express our strong concern about the timing and the sheer scale of the Government’s package of new amendments. To drop 65 amendments of this nature on the eve of Committee, which will completely reshape the architecture of this Bill, after its passage through the Commons, is a major challenge to effective parliamentary scrutiny. The Minister’s letter, also dated 24 August, came alongside these 65 new amendments, so we have had very little time to consider them. As far as I can see, a full Ministerial Statement did not accompany them; we had to rely on the coverage of Computer Weekly to understand the Government’s motives.

The Government have quietly established a major parallel high-risk vendor regime. Under Amendments 102 and 103, the Secretary of State—and now, crucially, under Amendment 101, the Chancellor of the Duchy of Lancaster—are granted unilateral powers to issue vendor-related directions. They can legally order an organisation to prohibit, restrict, remove, disable or modify any software, hardware or digital facility supplied by a designated high-risk vendor. Furthermore, under Amendment 105 they are given the power to establish a mandatory referral scheme, legally forcing companies to submit technology procurement contracts to the Cabinet Office for security clearance before signing.

Let us look closely at the operational mechanism in Amendment 103, which ISC2 has rightly highlighted. The proposed new clause mandates that a company appoints a “skilled person” to oversee compliance and, under subsection (5) of the proposed new clause, permits the Secretary of State to rely on a list of persons published by GCHQ. I ask the Minister: what is this list? Is it public or classified? What objective criteria will govern inclusion? How will conflicts of interest be avoided, and how will independent professional competence be assured? To create statutory compliance roles backed by secret lists is entirely unacceptable.

Under Amendment 108, the Secretary of State can make regulations bringing any specific company into the scope of the Clause 43 directions without bringing them into the NIS regulations as a whole. Under Amendment 127, the Government will insert an emergency “made affirmative” procedure allowing regulations and vendor bans to take effect immediately without prior parliamentary debate. Furthermore, under Amendment 148 the Secretary of State can prohibit a company disclosing that they have received a direction or are in consultation, backed by civil penalties of up to £10 million or £50,000 per day.

There is also a second critical implication—the backdoor regulation of advanced artificial intelligence systems. At Second Reading, the Minister assured the House that advanced AI systems and LLMs were out of scope. These amendments appear to reverse that position. Under Amendment 108, any entity providing essential goods or services can be specified. As our critical infrastructure increasingly integrates agentic AI models, such as GPT-5 or Anthropic’s Mythos, these developers become points of supply chain risk concentration. It seems that, under Amendment 102, the Government can designate AI developers as high-risk vendors and mandate pre-procurement vetting. Is that the case and, if so, why not say so?

The Government will no doubt resist the transparent, legally bounded emergency shutdown power proposed by Amendment 84, with its High Court backstops and seven-day parliamentary reporting, yet here the Government demand sweeping, secretive executive powers to ban software, veto procurement and gag businesses with zero judicial checks. These Benches cannot give these 65 government amendments a free pass. I remind the Minister that, in Grand Committee, unanimity is required for amendments to carry. We insist that the Government come back on Report with strict guardrails and clear limits on executive market intervention without parliamentary consent before these new powers can be exercised.

Quite apart from that, both the Constitution Committee and the Delegated Powers and Regulatory Reform Committee had something to say about the existing powers in the Bill, but neither committee has had a chance to look at these amendments. I am sure that they will have comments to make in due course.

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.

That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.

However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.

Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.

I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.

I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.

Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their comments, views and questions, and I will endeavour to respond to them.

In respect of why the power is being granted to the Secretary of State or the Chancellor of the Duchy of Lancaster, it is to anticipate any unforeseen machinery of government changes. It is nothing more than that—to avoid future changes that would be needed when government departments change. On the skilled persons list, I am advised that that is currently available on the NCSC website, so it is accessible to all.

I come back to the heart of the questions: why is this power needed? It is needed because, even though we are taking powers on critical suppliers, it can be the case that vendors have the capability and intent to cause harm, particularly where they have a link to a third country. That is the element I would highlight today. It is through such vendors that a third country can gain access to or control of critical systems, enabling disruption to UK national infrastructure, surveillance through access to data at scale or espionage through access to sensitive information. The risk landscape is evolving quickly, which is why we are taking action now. On the questions posed by the noble Viscount, Lord Camrose, this is very much in the context of all the other things we are doing—all the other powers in the Bill, the scope of the Bill and the Government’s cyber action plan. This is an additional power focused in particular on being able to act earlier in a preventive manner.

On the definition of “qualifying transactions”, the amendment contains a power to create a statutory referral system. This system would need to state which procurements or transactions were in its scope, but, as the noble Viscount mentioned, we do not anticipate needing to do that now. The process of the Bill is such that we will enact both the mechanisms in the Bill and the voluntary referral mechanism. We will then be able, in the period of assessing the effectiveness of the Bill, to look at the effectiveness of the voluntary referral route. Should we need to introduce a mandatory route—obviously, we have done this in different areas of national security—we will be able to do so.

On scrutiny by Parliament, I appreciate that the fact that we tabled these amendments over the summer has meant that not everybody has been able to familiarise themselves with them and we have not been able to have as many in-depth discussions as we would normally when Parliament is sitting. I would be extremely happy to meet noble Lords with officials so that, after Committee, we can go through all the questions and points of detail that have been raised in this session on how these powers will be enacted, parliamentary scrutiny, the consultation process and all the elements that we have set out in our amendments.

A few noble Lords focused on AI. The power could be extended to high-risk AI models that are procured by operators of essential services. The test for using the vendor power direction does not specify or distinguish particular types of goods or services, in keeping with the technology-agnostic approach of the Bill. If an operator of an essential service were using a vendor-supplied AI model in connection with its network and information services, and this would give rise to a national security risk, it could be in scope of the power. That is very much in keeping with what I believe I said at Second Reading about other areas of connection with network and information services in the rest of the Bill and where that may apply to AI.

With that, I beg leave to withdraw—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

Before the Minister sits down, I note that there are a lot of “just in case” elements of the Bill; to me, it feels that there are rather too many. For example, I refer the Minister back to the Chancellor of the Duchy of Lancaster v the Secretary of State. Any department is, at any time, subject to machinery of government changes, but never in any Bill that I have seen—admittedly, I have not seen that many—have both been specified, so why is it so in this Bill? Why do this now? Why not simply make a choice and amend later if necessary?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am very happy to look at the points that noble Lords have raised in the course of this discussion. I believe that elements such as the consultation and the process of scrutiny are well thought out. I believe that in terms of the elements of subsequent parliamentary scrutiny—the reports that will be made both on the application or when the direction is affected—this is very much in keeping with other national security legislation which has been agreed by this and previous Governments. Many of these elements are very akin to processes that are operational in other areas of government. However, I am very happy to look at, and indeed will look at, all the points that noble Lords have raised. We will discuss them in subsequent meetings, and we will revert to them on Report.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

Can the Minister explain why GCHQ is not the right home to exercise these powers? I am sure we will all agree that national security is a significant issue, but it is being lodged in departments that have no prior experience of it. What is wrong with existing GCHQ procedures, which are respected and trusted?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I will need to write to the noble Lord on that specific question of how GCHQ’s powers are executed in respect of operational decisions such as this. I am aware that in other areas they are within Secretary of State responsibility, whether they are exercised by a Secretary of State, advised by GCHQ or whether, as the noble Lord suggests, they are actually undertaken by GCHQ.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I thank the Minister for her gracious, intended withdrawal of Amendment 1, and I am sure we will have a much better debate on Report as a result, particularly once we have had a chance to read her remarks on both interventions today. However, I hope she will agree with me, especially in terms of what she said about being technology agnostic through the Bill, that we will have a much better debate as we come to talk about specific AI issues as a result of not having already incorporated those in the Bill. So, all the way around we will have a much better debate about the proper shape of the Bill as a result of those amendments being withdrawn.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

With that, I believe now is the time where I beg to leave to withdraw Amendment 1.

Amendment 1 withdrawn.
--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness, Lady Kidron, for her introduction and my noble friend Lady Harding for setting out the motivation for ensuring that we have the right balance of risk and regulation here. The amendments from the noble Baroness, Lady Kidron, seek to allow for the designation of systemically important data centres, RDSPs and RMSPs which do not already meet the threshold. The Government have considered this issue in the development of the regime and have taken an approach which reflects the markets of the various digital services in scope of the regime.

In respect of data centres, the Government agree that a data centre’s significance is not determined solely by size and recognise that smaller facilities may play an important role in supporting the economy and wider society. For that reason, the Bill already provides a route for such operators to be brought into scope outside the standard threshold requirements. The competent authority, Ofcom, has powers to gather information from operators and assess whether designation is appropriate in individual cases.

However, with respect to the RDSP and RMSP measures, the existing small and micro-enterprise exclusions have been designed to be proportionate and avoid imposing undue burden on entities with limited resources and market coverage, while focusing on providers whose disruption would have significant societal impact or economic risk to the UK. Although many small and micro-enterprises operate in the digital and managed services market, large MSPs hold a disproportionate share of market value. The largest MSPs account for 86% of revenue in the UK, despite representing just 4% of all MSPs. It is the disruption of these services that is most likely to cause significant harm to the UK.

The Bill also has measures in place to bring small or micro digital or managed service providers into the scope of the Bill if they are considered to provide a critical service to a regulated entity. If these entities meet the designation criteria, they can be designated as a critical supplier and be subject to mandatory cyber security and resilience requirements. I assure the noble Baroness that I recognise the discrepancy between these two regimes and her concerns, and I am content to explore this, and the points made by the noble Lord, Lord Markham, further, and to provide a more detailed response on Report.

On the issue raised by the noble Lord, Lord Clement-Jones, for his amendment which would amend the relevant managed services definition by excluding specific services, I take seriously the importance of providing clear definitions in the Bill. That is why the definition in the Bill is designed to capture services posing a risk to the UK economy and society, both today and beyond. I reassure the noble Lord that the relevant managed services that would be excluded by this amendment are already likely to be excluded by virtue of them not meeting the definition in the Bill. However, we cannot and should not list every service not in scope or we risk providing a definition that quickly becomes outdated and fails to accommodate new trends in both technology and services—a point frequently made by noble Lords in respect of the development of technology and online services. The Bill requires a delicate balance to ensure that the definition includes the right level of detail. The regulator, the Information Commission, will provide guidance on the application of the regulations prior to commencement of the RMSP provisions, including elements of the RMSP definitions.

On the point raised by the noble Lord, Lord Clement-Jones, on privileged access, MSPs pose risks because they provide ongoing management of customers’ IT services and often have deep and broad access to the networks, infrastructure and data those customers rely on, so the Bill focuses on any connection or access to network and information systems relied on by the customer rather than only access whether privileged or administrative. That is because requiring privileged access would narrow the definition and include some firms we intend to regulate as providers composed of cyber risks through non-privileged access without holding elevated administrative rights. For that reason, I caution against adding these exclusions to the definition of a managed service.

Finally, Amendments 4 and 5 are tabled in my name. They are targeted and technical amendments that improve the clarity and consistency of the Bill by strengthening the definition of load control in Clause 6. They clarify that the relevant activity must be carried out for system balancing purposes. System balancing purposes are defined as purposes which contribute to the,

“balancing, flexibility, security or stability of the electricity system”.

The policy intention has not changed. This amendment simply provides greater clarity about the activities the regime is intended to capture. It will reduce the risk of misinterpretation, provide greater certainty for industry and regulators and support effective regulatory oversight. This will ensure that the regime captures the activities intended to fall within scope and reduces the risk of inadvertently capturing activities that are not relevant to the operation and resilience of the electricity system.

Regarding the questions about the further scope of the Bill in respect of local government and the Government’s cyber action plan, I believe we will return to that in later groups.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

I am very grateful to the Minister for suggesting that there will be some consideration of the gap, as she put it, and I look forward to that. I want to raise one thing, which is that I was very struck by her reference to a small number of companies having 86% of the market. In a sector that is dominated by the concentration of power in very small numbers of companies owning many pieces of the stack, is she not worried that making those companies protected and safe and the smaller ones not may further serve to increase the concentration of power and market concentration? Is that not a problem for the future?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The purpose of the Cyber Security and Resilience (Network and information Systems) Bill is to further enhance the scope and powers we have to protect essential services connected through network and information services. The market as it exists today is as I described. What is within the scope is not the totality of our approach to supporting the further cyber resilience of the UK economy. That is why, for example, we have CRCs locally to support SMEs so that whatever size they are, they can get assistance on the best cyber protection they can take. It is why we have Cyber Essentials and why the NCSC provides advice—all that the economy needs to take appropriate action to be secure. That is one aspect. The second aspect is that small and micro digital managed service providers are in scope of the Bill if they are considered to provide a critical service to a regulated entity, so even very small entities could possibly be in scope if they are so designated.

The last point I shall make—and I am sure we will come on to this further when we come to talk about AI—is that the Government are doing a huge amount in regulation and funding through public finance institutions to support the development of UK technology companies and UK innovators and to ensure that they have the right procurement contracts with the public sector so that they can grow and so that the entirety of our companies can benefit from the best global managed service providers and the best UK managed service providers.

Amendment 3 withdrawn.
--- Later in debate ---
Moved by
4: Clause 6, page 4, line 31, after “controller” insert “—
(a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and”Member’s explanatory statement
This amendment would ensure that the threshold requirement relating to the essential service of load control, inserted by Clause 6 of the Bill, applies only to organisations which carry out activities for system-balancing purposes.
--- Later in debate ---
I finish by returning to the broader point. The reason for this group—the debate around AI in the context of cyber security—is that I am afraid we are still unclear about the Government’s wider approach to cyber security and AI. We need to see the bigger picture in the form of a national action plan or White Paper that explains to us overall how the Government see the evolving world enabled by these extremely powerful technologies. We can go sector by sector and debate the best way to regulate and protect them against cyber attacks, but what matters is the Government’s applied philosophy. Until we see that, we are debating ideas in the dark.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments, and I recognise the concerns that have been expressed. Technology is evolving at a rapid pace, and it is important that we harness the benefits and, equally, protect against the risks it may pose.

The noble Lord, Lord Holmes of Richmond, asked about the approach that we take. We understand how quickly technology is evolving, and it is important that we have a flexible and future-proof approach. If we limit ourselves to specific technologies, we will not capture new developments. For instance, when the NIS regulations were introduced in 2018, we could not have predicted the role that AI and quantum would play in cyber. That is why the Bill takes an “all hazards, all threats, all technologies” approach. This requires regulated entities to manage all the risks relevant to their network and information systems. For example, if AI forms a part of the system that the essential service relies on—for example, in the provision of drinking water—that entity must assess and mitigate the risks it poses.

More generally, the Government take the concerns very seriously. The UK is taking a leading role with our approach to AI security. I will set out my response to each amendment in turn, but while we do not consider the amendments proposed to be the right approach, I reassure noble Lords that the Government are exploring whether additional targeted interventions may be needed in future to address the most significant AI-related national security risks. As the Government’s thinking is at an early stage, I would be open to future engagement with noble Lords on potential options. Any future approach would need to have carefully designed measures, with the evidence base proportionate to and targeted at the risks in question, while minimising unintended impacts on growth, innovation and the operation of critical services.

I turn to the amendments. The intention of the NIS regime is to require organisations to protect themselves from risks that could compromise their network and information systems, which could include a cyber attack, a natural disaster or even human error. That protection would be appropriate and proportionate to the risks faced by those organisations, including state-of-the-art technology such as AI. I reassure noble Lords that this would include relevant risks from AI embedded within the systems of regulated organisations. To take one example, healthcare providers in scope of the regime would be required to manage risks associated with the AI products they use to provide their services. This is because essential services in scope must look at, and work to mitigate, risks posed to their network and information systems.

As AI is increasingly becoming embedded across the economy, we will keep its impact on the regulatory landscape under review. The Bill is focused on the cyber security and resilience of network and information systems; broader questions about the regulation of AI systems are more appropriately addressed through separate discussions, for example on online safety.

Bringing providers of AI services—those companies at the cutting edge of frontier AI development—and their products into the scope of the NIS regime, which Amendment 6 seeks to do, would not address the harms that can be posed by some AI products and services. Specifically, it would not prevent their misuse by hostile actors. Instead, the Government are already taking firm action in more appropriate ways, which also speaks to the concerns that Amendment 75 would aim to address and which the noble Baroness, Lady Foster, asked about.

First, the UK AI Security Institute, as noble Lords are well aware, is world leading in its research on advanced AI capabilities. AISI was set up to build a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose. It works with developers to strengthen security before models are released and ground policy decisions in evidence rather than speculation, especially as they relate to national security matters.

Secondly, the UK Government are taking a leading role in addressing these risks in both the domestic and international setting. As the noble Lord, Lord Tarassenko, and others have set out, including the noble Viscount, Lord Camrose, it is critical that this approach has global impact. Our AI cyber security code of practice has formed the basis of the world’s first global standard, EN 304 223, which sets baseline security requirements for developers and deployers across the AI life cycle. This demonstrates our global leadership and commitment to shaping international technical standards, which go wider than some of the issues raised in this Bill.

Underpinning all this is a simple but powerful message, which was set out in a joint Five Eyes statement in June. It recommended that as AI capabilities evolve all industry, including vendors, should seek to step up their cyber defences. This is a clear call to action for all organisations, including the Government, and a reminder that the key tenets of cyber hygiene still stand strong. That is also why we are committed to building a national-scale AI-enabled cyber defence for the UK, Cyber Shield. It will scan UK systems continuously to discover vulnerabilities and apply national-level mitigations.

The noble Baroness, Lady Kidron, tabled Amendment 75, which sets out several red lines on AI capabilities that would enable an AI system to facilitate significant risks to the UK. The noble Baroness will recognise that AI is one of many technologies that can be used for beneficial and harmful purposes, as she has mentioned on previous occasions. In addition to the example of chemistry questions, banking services can be used to connect families but might also be used to finance illegal terrorist activities. Equally, while powerful AI capabilities can be used by malicious actors to cause harm to the UK, they might also be used by the national security community to defend the UK and by UK organisations and companies to protect themselves from harm. It is therefore not in the UK’s national interest to restrict UK organisations and the public sector accessing powerful AI capabilities, especially given the global nature of AI risks. It is also unlikely that AISI would be able to give conclusive assurances regarding AI models in the way envisaged in this amendment. Testing shows what a model can do, but not conclusively what it cannot, as the noble Viscount, Lord Camrose, pointed out.

The noble Lord, Lord Tarassenko, tabled Amendment 12, which would require RDSPs to follow guidance issued by the AI Security Institute. For the reasons I set out on Amendment 6 and because it is not AISI’s role to provide guidance of this nature, I do not think it would be appropriate. I will set out more detail on AISI’s role later in my response.

On Amendment 84, tabled by the noble Lord, Lord Clement-Jones, we have chosen to go further than our EU counterparts and the NIS2 regime to respond to these risks by bringing forward powers in the Bill to direct regulated entities if there is a national security risk in relation to their network and information system. This may be used, for instance, to require a regulated entity to cease using and isolate an AI model.

We believe this is a more proportionate and effective response, as data centres operate in highly complex ecosystems and AI systems are often distributed across different data centres and jurisdictions. It is much less desirable to direct multiple data centres to shut down, with the impact this could have on services that rely on them, than to direct them to cease using an AI model. This is important, as our economic security will grow as UK companies grow as they increase AI adoption as we develop our domestic capabilities and attract global talent, underpinned by our data centre and digital infrastructure.

I refer to my introductory remarks on exploring further targeted interventions. This includes examining whether proportionate containment powers could provide a more effective and targeted response, including powers to restrict access to specific AI systems where necessary to prevent or mitigate serious harm. The amendment tabled by the noble Lord, Lord Clement-Jones, also seeks a regular report on AI security. In December 2025, the AI Security Institute published Frontier Al Trends Report, which sets out high-level trends on AI progress based on two years of government-led testing of leading models.

Amendments 85, 86, 92 and 98, tabled by the noble Lords, Lord Tarassenko and Lord Clement-Jones, are a testament to AISI’s leading role and expertise. They seek to provide AISI with powers to address potential risks arising from frontier AI models. I have already set out the important role that AISI plays building a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose, working with developers to strengthen security before models are released and grounding policy decisions in evidence rather than speculation. These amendments would give AISI a role that it was not designed to fulfil. AISI’s focus on frontier technology and trusted relationships with the world’s leading AI labs allow it to keep pace with the fast-moving technology, thereby providing critical awareness of the most novel and serious AI risks. This amendment would undermine the voluntary collaboration on which AISI operates. A regulatory role for AISI is therefore the wrong answer, but the Government remain committed to ensuring that AISI is equipped to fulfil its vital role and will continue to keep the House updated on its work as appropriate.

As I have just set out, such amendments raise a real risk of placing barriers on AI adoption and deployment in the UK. Due to the scope of the Bill, the amendments cannot address wider AI harms or cyber security in the wider economy. I share concerns about the potential of hostile actors using frontier AI models against our essential services. Placing these restrictions on their deployment in the UK, as amended, would not be effective.

I shall respond to the direct question asked by the noble Baroness, Lady Kidron, on large language models. Large language models are not typically considered online search engines in respect of the CSRB. While some LLMs can be seen to share similar characteristics and may utilise online search engines, their functions tend to be much broader.

I hope that I have addressed the points raised—well, I hope that I have at least touched on all the points raised today. On the points made on changes to the Government, I very well recall the numerous discussions that we have had on AI over the past few months and continue to be the point of continuity on them. As I have said, the Government will be happy to engage with noble Lords as options are being considered. We always stand ready to protect our national and economic security.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

If I have understood what the Minister said, the NHS must protect itself, but the AI that is attacking it has no duties or obligations under the Bill to check itself before it is used in those ways. That is what I think is the Government’s position, and I would be grateful, when she responds, if she could answer that.

I also want to say two other things. One is that I think these issues will come back on Report, so I would be grateful for some proper discussion before then, so that we can see whether we come to a certain place. I do not have it at my fingertips—I may be helped by one of my colleagues—the amount of search that now happens through AI, but it is almost ludicrous to suggest that LLMs are not search. It is deliberate that I got that answer.

--- Later in debate ---
Finally, on the AISI point—we will probably come back to it a little bit in the next group—a few months ago AISI dropped the societal harms piece of its remit. That was largely due to pressures within government. As much as I recognise that it was set up to do one thing, it is very much at the behest of whoever is immediately pulling the strings. I think that there was a very deep understanding among those who were concerned about this issue that the frontier companies were much more comfortable talking about future security risks, which are a little way ahead and about which we can say we do not know what is going to happen, than the societal risks, which are happening right now. So I think that on both of these things we will be back, but I am grateful for the offer of a discussion.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

To respond to the question about how the Bill approaches certain AI products and services, as I mentioned in respect of Amendment 6, were AI services to be brought into the ambit of the Bill as proposed in Amendment 6, that would not address some of the harms that the noble Baroness, Lady Kidron, and other noble Lords, have set out. The way the Bill works is that it is about risks that are relevant to the systems of the affected organisations. As in the healthcare example I gave, it is about risks associated with products that might be used to provide those services. That is the way the Bill is set up. Obviously, as I also said, we are very well aware about the increasingly embedded nature of AI in the economy, and we will keep its impact on the regulatory landscape under review.

Amendment 6 withdrawn.
--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Birt, for introducing this debate and all noble Lords who have spoken. I appreciate the rigorous strategic thinking that the noble Lords, Lord Birt and Lord Londesborough, have put into the proposal for an office for cyber resilience, but I will try to keep my remarks to the principle of a single regulator.

As others have set out very powerfully, I see the appeal of having a single regulator: it is easy to issue directives, to store data and information centrally, to take a systemic approach overall and to better manage the hiring of scarce, skilled resources. That said, as my noble friend Lady Neville-Jones pointed out, it is important to see the value of sectoral regulators supported by a centre-of-excellence model. More sector-specific expertise, more direct communication with the industry and more flexible approaches are all easier to achieve with smaller, more specific regulators. At a sufficient level of abstraction, it almost does not matter which of those models you go for; it is about having resourced, skilled and empowered people performing monitoring and enforcement activities, regardless of the body under which they sit.

More broadly, the point is that, while differences between a more centralised or more sectoral approach are worthy of debate—I do not think we would ever hit the extremes of either of those—what actually matters is ensuring that, whichever route the Government choose to take us, they make certain that the regulators are adequately resourced and that they exist within a wider strategy.

I am not sure, and look forward to finding out, whether the first of those is the case. The Government have chosen the more sectoral approach, but we do not yet know how the regulators are going to be resourced and what additional resourcing needs will be needed to cope with the increased responsibilities that will be laid at their door. I look forward to hearing from the Minister on how the regulators are going to be funded, how the funding needs will be calculated and how they are going to be supported in this significant expansion of their role.

The second point is that the regulators should exist as a part of a wider strategy, which is not currently the case. I apologise to noble Lords for banging on about this, but it is very difficult to get the past the hole in the Bill in the shape of a wider national cyber strategy. Whether the regulators are many or one matters little without the bigger picture into which they fit. In an ideal world, we would review the overall cyber strategy and then debate what regulatory structures might be appropriate to deliver it but, for now, sadly, that is not the world that we are in.

The Secretary of State—or, indeed, the Chancellor of the Duchy of Lancaster; it is not reassuring that we still do not know which one—must commit to publishing the national plan, after which we can assess the efficacy of its many parts.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lords, Lord Birt and Lord Clement-Jones, for their introduction to this section and for setting out the motivation behind a single cyber regulator.

As others have pointed out, this is a question of sectoral expertise and cyber expertise. It is my view that, given the complex cyber landscape, establishing a single regulator would not be as effective as the approach that we are pursuing. Different sectors have different risks, technologies, operational environments, market structures and resilience challenges within their industries. To take an example, the energy sector has a greater reliance on operational technology—such as turbines, substations and gas pipes—as compared to the digital services sector, which is predominantly information technology-based. Noble Lords will see that the guidance on quantum, for example, differs in that respect. This is why expert regulators are needed to ensure compliance in a manner that reflects the realities of their sectors.

I do not recognise the assertion that there is a single internationally recognised model of best practice. There are very near neighbours who have the model that we are pursuing, which keeps the sectoral expertise. Additionally, I do not believe that it would be an effective use of resources to establish a new regulator, and the proposed 12-month establishment period would delay the implementation of this regime.

Finally, cyber would continue to exist within a multi-regulator landscape as there are separate regulatory approaches for telecommunications and financial services. I agree with the point made by many noble Lords—highlighted in particular by the noble Lord, Lord Holmes, both at Second Reading and now—that a consistent approach to implementing and enforcing the regime is crucial. The Bill will drive this through by establishing common security and resilience requirements and secondary legislation for all regulated entities, clear guidance for regulators, and a statement of strategic priorities setting common objectives that regulators must seek to achieve. These will cover issues such as governance, skills, risk management, business continuity, supply chains, incident response, and appropriate testing and exercising. They will be consulted on, and any relevant secondary legislation will be subject to the affirmative procedure.

Regulators will supervise and enforce the common requirements while providing guidance that is tailored to the risks and operational realities of their sectors. Crucially, information-sharing gateways and cost-recovery mechanisms will bolster the well-resourced, experienced regulators who stand ready to collaborate while best supporting their respective sectors. I believe that the Bill’s approach gets the right balance between sectoral expertise and a common approach.

On Amendment 91, which would require specific organisations to conduct an annual independent audit, I agree that independent assessments play an important role in providing assurance and leveraging external expertise; that is why the current framework already enables regulators to require independent audits or inspections. However, it is for the sectoral regulators to set the frequency and nature of audits, bearing in mind proportionality and their expertise in the risks and operational realities of their sectors. We will continue to drive uptake of assured independent audits across sectors, using the range of levers that the Bill provides. That is what the current framework provides for and what the implementation of the Bill will ensure.

I turn to Amendment 90, which would require the proposed OCR to work with the UK Cyber Security Council in order to ensure sufficiently qualified cyber security professionals among regulated entities; I note that the amendment laid by the noble Baroness, Lady Northover, on this topic will be debated later. The Government strongly support the need for the professionalisation of the cyber sector. We already work with the UK Cyber Security Council and regulators to encourage cyber professionalisation across NIS sectors. We also intend to set further expectations for regulators to encourage cyber professionalism through the Bill’s security and resilience requirements, which, as I just mentioned, will be set out in secondary legislation. They will address relevant training, skills and professional standards, and the Bill’s regulators must publish guidance on these requirements.

--- Later in debate ---
Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

In this recovery regime, will whatever organisations that are to be regulated be levied for the service of regulation that will be provided, or will the revenue come as a result of fines? If that is the case, I hope they will not raise the revenue by finding fault. What is the basis of the cost recovery? It needs to be perceived to be fair, not onerous and not directed at encouraging regulators to regulate for the sake of increasing their income.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The intent behind the cost recovery model is to provide a fair approach so that regulators, when regulating on cyber, can recover the costs associated with that. Further guidance will be put out on this. I cannot recall the Bill’s exact provisions on fines. I will come back to the noble Baroness on that.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

My Lords, I confess to a real disappointment listening to the Minister’s response. We have sat here all afternoon and heard many strong contributions on many matters, but so far, the Government do not appear to have moved an inch on any of them.

I have a few quick points. The Minister just referred to the regulators. There are 12 regulators of 12 sectors, which is a tiny fraction of the economy. We have had this very profound discussion about AI today. Is she really asking us to believe that Ofwat is capable of mastering the complexity and continuing challenge that AI poses? To me, the answer is all too obvious.

Secondly, I say to the noble Baroness, Lady Neville-Jones, in particular, that I have sat on many boards over recent decades at different levels in the UK, in Europe and globally. An awful lot of expertise comes to the table, but it is absolutely out of the question that every board in the land will have a real cyber expert on it—hence the notion. A financial audit is a really powerful thing these days. It gets into the bowels of a company, and if anything is going wrong anywhere then it will find out about it. That is why I propose that we have a cyber resilience audit—not for every company in the land but for those that fall under the heading of essential services.

Finally, we are at war, and I completely agree with the noble Lord, Lord Londesborough, that the scale of the damage to our economy is almost certainly vastly underestimated. The framework imposed in this Bill is for fighting a war, but we see around the world at the moment that—guess what—wars change. Different weapons are used and different tactics come up. It is as if we have split the MoD and said that the Army will be with DCMS, the Navy will be with another department and the Air Force with another. The idea that you cannot have effective co-ordination within government and outside government honestly does not carry any weight. I beg leave to withdraw my amendment.

--- Later in debate ---
Lastly, I am grateful to the noble Lord, Lord Clement-Jones, for his amendments, in particular, Amendment 95, which would reduce the maximum interval between legislation and operational reports from five years to three years. That is welcome. The world of cyber security is ever changing and it will do so with increased speed as our AI continues to develop. A five-year maximum timeframe is simply too long for any Government to reflect on the effectiveness of existing legislation. I hope that the Minister will take that point, along with the others I have made.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments in this group, which I will endeavour to cover in my response, starting with the lead amendment from the noble Baroness, Lady Ludford. Fraud risks and fraud are indeed important to address. The Bill requires relevant digital service providers to prevent or mitigate risks through an all-hazards approach. We already expect RDSPs to address risks posed by fraud as part of their security duties. The reason why we do not single out risk posed by fraud is that this may not reflect the full range of risks faced. It is important that regulators in their guidance, for example, in respect of the ICO, respond to the risks that their sectors are experiencing, which could include fraud. I heard clearly the facts that the noble Baroness set out, but that will be something that will come in due course.

On the important points made by the noble Lord, Lord Ravensdale, on the risks posed by quantum computing, the “all hazards, all threats, all technologies” approach enables a flexible and future-proof regime. It is important that each version of the statement of strategic priorities is not bound by the risks posed by specific technologies because they could become outdated; it cannot necessarily prefigure what will be a particular risk in 10 years’ time. Post-quantum cryptography is incredibly important. The department is working on guidance documents that will support organisations to manage their transition, in line with the NCSC guidance and deadlines. On the question specifically about the next statement of strategic priorities, we will encourage regulators through the statement to understand the evolving threat landscape and adapt their regulatory response accordingly, which could include risks from quantum or fraud, if those are the most pressing ones at that time.

On the approach suggested in Amendment 94 by the noble Lord, Lord Clement-Jones, we appreciate good practice standards, and we continue to promote their adoption across the wider economy. However, a more advanced cyber security framework is required to ensure adequate protection and assurance for the services in scope of the Bill. I am confident that the Bill’s outcomes-based approach is the right one. It allows existing good practice to contribute to demonstrations of compliance with existing and future requirements. We will introduce security and resilience requirements in secondary legislation. These requirements will be linked to the security duties and will provide clearer outcomes that organisations in scope must meet. We are engaging with regulators and industry throughout this development, and we intend to consult on these proposals later this year.

I turn to the question of how regulated entities demonstrate their compliance with their duties. Amendment 92B seeks to require large businesses in scope to report on their cyber security and resilience plans. Our proposed security and resilience requirements under the Bill will require regulated entities to maintain overarching security policies, implement a continuous risk management framework, maintain incident response and recovery plans, and ensure appropriate board-level oversight of these. This will be supported by guidance from regulators which must be regarded. Entities would be expected to maintain evidence demonstrating compliance with these requirements. The information provided to regulators and the NCSC will enable effective regulatory supervision, which holds organisations to account, and will enhance wider threat and resilience analysis and support. This will feed into government monitoring and evaluation, where public post-implementation reports will provide insights and assess the effectiveness of the regime. I will come on to the timing of those later.

The UK’s corporate reporting framework is currently undergoing wider modernisation efforts. Future consultation will seek views on whether the existing risk reporting framework produces sufficient reporting on cyber risk management, so it is best dealt with as part of that work.

On funding and information sharing in Amendment 169, ISACs can play an important role; there are many initiatives under way, many of which are supported by the NCSC. They have a voluntary approach which builds trust and brings about positive cultural changes. We believe that there is a real risk that the Government could undermine these benefits and complicate the regulatory landscape by intervening and recasting these initiatives as mechanisms of regulatory oversight and enforcement. However, I agree that more can be done to understand their impact, and how the Government can support them. That is why the Bill’s formal review mechanism was included, which will consider the entirety of the regime’s impact, including for information sharing.

Coming back to the question of regulator funding, and to expand a little on the new cost recovery powers to ensure that regulators are able to recover the full costs relating to their NIS duties, this will enable regulators to be autonomously funded and sufficiently resourced to carry out their responsibilities. We will also enable regulators to better focus their resources through establishing a unified set of objectives through the statement of strategic priorities. The current framework therefore already ensures sufficiently and independently funded regulators, without a delayed commencement of the regime. To respond to the question posed earlier by the noble Baroness, Lady Neville-Jones, it is anticipated that fines levied under the regime would go to the Treasury.

On the absolute criticality of skills in the sector and Amendments 15, 174C and 174D from the noble Lord, Lord Arbuthnot, and to all those who spoke on skills and cyber capability, the Government absolutely agree that workforce is crucial for effective implementation of the regime. I have previously set out how we intend to introduce security and resilience requirements, which will be consistent with the CAF. We propose that the SRRs will address organisational capability and personnel skills and training, driven from board level. These requirements will be developed in collaboration with industry, experts and regulators and formally consulted on before they are mandated. The SRRs will be supported by regulator guidance, tailored by sector, as well as government implementation guidance for regulators. We do not believe that additional guidance and a separate strategy would be proportionate, and it could be duplicative given the existing guidance published under the Bill.

Cyber skills obviously go much broader than the Bill. That is why we are working closely with the UK Cyber Security Council and regulators to encourage cyber training and professional standards. Additionally, we have TechFirst, the Government’s flagship tech skills programme, which goes to the point made by the noble Baroness, Lady Ludford, everywhere from school children through to professionals and the university sector.

Briefly, we talked earlier about skilled persons and Amendment 114. I mentioned earlier that a skilled person is a person with expertise. However, we do not think that we should tie the Government’s hands to specific skills requirements, which would reduce the Secretary of State’s flexibility in this space and could impede the regulated entity’s ability to take the necessary action required by the direction.

On the question of reporting, we recognise the pace of cyber developments alongside the importance of regular assessments of the regime. We must be as effective as possible and agile in the face of new developments. Amendments 95 and 95A, tabled by the noble Lords, Lord Arbuthnot and Lord Clement-Jones, would reduce the period that the report on the operation of the legislation should be published to every three or even two years. As raised in the other place, the five-year period set out in the Bill is a minimum baseline and the Government will consider more frequent reports if deemed necessary. This framing follows the precedent set by the Telecommunications (Security) Act and the existing NIS regulations. This will provide the Government with the time they need to meaningfully review the cross-sectoral regime, analyse the information received from regulators and understand how it has evolved, and identify what improvements can be made.

However, I stress that the Bill will also require the Secretary of State to provide Parliament with an annual report setting out how regulators have sought to achieve their objectives set out in the statement of strategic priorities. This annual report will enable more frequent monitoring of the regime and how it is working in practice by reporting on the regulators who implement it. The first report will be published one year after the publication of the SSP, which is targeting 2027. As a result, we anticipate that the first report would be published under two years after Royal Assent.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The content of the statement of strategic priorities will be subject to consultation and we will be working with regulators on that. It could include specific risks, whether from quantum or from fraud. What I do not want to do right now is to commit that it will include that, because we are going through a process.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - - - Excerpts

My Lords, I thank the Minister for her reply. Her last words gave me a little bit more hope than the rest of her response, to be honest, when she said that the statement of strategic priorities could include specific risks, because it seemed to me that she was otherwise being a bit generic and unspecific—almost above the fray. When I came in on a previous group—and other noble Lords are much more knowledgeable and expert in this field than I am—I picked up some frustration that the feedback from the Government and from the Minister today was a bit vague and not very responsive. All this is happening out there; there are huge cyber threats and there is a feeling that the Government are not really getting to grips with the actualité quite as much as they might.

I understand that the Minister might not be able to say now what will be in the statement of strategic priorities, but what we are searching for is that it will grapple with real problems out there in the economy, in society. I must admit that Amendment 82 from the noble Lord, Lord Ravensdale, on post-quantum cryptography, is somewhat above my pay grade. I wish I was more knowledgeable, but I ain’t. But I understand what he is saying, how real this is: the threat is out there. You just have to read newspapers to get the drift of what is happening. I mentioned that fraud is nearly half of all crime, so these are big issues. I think that what we want from the Government is a feeling that they get it, that there is going to be specificity in the way that they are going to implement this Bill and that they are really going to be on the case of these big threats. The Minister’s last words were a bit more encouraging than some of the rest of what she has been saying. That said, I am sure we will come back to some of these issues on Report, but I beg leave to withdraw my amendment.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend for introducing this group; as it is the final group of the day, I will keep my remarks brief.

Amendments 15A and 15B in the names of my noble friend Lord Arbuthnot and the noble Lord, Lord Clement-Jones, seek to allow regulatory oversight of critical suppliers on whom operators of essential services and relevant service providers depend, be it directly or indirectly. We believe that this must be a reasonable approach. The aim of Clause 12 is to ensure the continued functioning of the central suppliers and providers by providing support for their critical suppliers. Surely whether they are supplied directly or indirectly is of little importance.

Amendment 16 from the noble Lord, Lord Ravensdale, would restrict the designation of critical suppliers to those who present systemic risk rather than a simple single-entity risk. We should seek to minimise government oversight wherever possible, and suppliers should not be designated unless they pose a genuine risk. I am also supportive of the noble Lord’s focus on cross-sectoral consistency and general macroeconomic risks, which is too often something that the Government neglect.

However, I am hesitant to endorse the amendment in its entirety. Having to assess every supplier of every OES, RDSP or RMSP and having to decide whether it meets the systemic threshold have the potential to place an unrealistic administrative burden on designated competent authorities. We are already concerned about the resources that they will need to undertake the changes that the Bill introduces; I am unsure whether we need to ask more of them.

To wrap up, I return to a more general point: the risk to the economy or to national security is a scale, and the legislation that we pass should reflect this. Perhaps the noble Lord, Lord Ravensdale, is correct that the designation of critical suppliers based solely on whom they serve is too permissive, but it is equally as likely that restricting designation to systemic risks would be too restrictive. This highlights—it goes back to earlier groups—that the binary distinction about which we are talking now does not cover the gradation of different types of risk. That is why I come back to the original point that my noble friend Lord Camrose made on adopting, perhaps, the Cyber Monitoring Centre’s severity scale, which offers a template for a more nuanced approach to definitions. I hope that the Minister can commit to reviewing the Bill’s definitions ahead of Report.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords, in particular the noble Lords, Lord Arbuthnot and Lord Ravensdale, for engaging with the incredibly important question of drawing the right scope in the Bill for the designation of those in the supply chain. It is incredibly important that we get this right and take into account the economic and security impact. To begin, let me explain our reading of the amendments and the practical impact they would have.

Amendments 15A and 15B would enable regulators to designate suppliers as critical beyond those which directly supply to regulated entities, if they are materially dependent on that supplier to provide the regulated service. This would extend the scope of the measure to include suppliers further down the chain, even where they have no direct relationship with the regulated entity. In addition, the amendments would introduce an additional assessment of whether a regulated entity is materially dependent on a supplier, which would form part of the designation process. This could create a higher bar for designation of a direct supplier than currently exists in the Bill and could limit designation by excluding suppliers whom it would be reasonable and prudent to include.

The Bill recognises the importance of supply chain security, has considered the risks that supply chains pose and has developed targeted and proportionate measures to address those risks. First, regulated entities are subject to an overarching duty to identify and manage the risks posed to the systems they rely on to provide their services. A core part of this is to consider the risks arising from their supply chains. Secondly, as will be set out in the forthcoming security and resilience requirements, we will require regulated entities to take specific steps to manage their supply chains through an analysis of the risks they could pose, and to include a requirement to put in place contractual obligations on those suppliers to manage the immediate risks and the risks posed further down the supply chain, which may not be in the immediate view of the primary regulated entity. Thirdly, it is recognised that some suppliers in the market are critical to certain sectors and therefore the most proportionate step is to regulate them in their own right and to subject their security posture to the scrutiny of regulators.

This clause is already designed to be a proportionate and targeted measure and is aimed at bringing into scope only those suppliers who are genuinely critical to the regulated entities they supply directly. Finally, as we discussed at the beginning of this Committee, some suppliers may present additional risk and are potentially the vector of attack from hostile actors. That is why we believe that we need to take measured but decisive steps to manage that risk before it crystallises and before those vendors are embedded in critical systems. The amendments would significantly increase the number of potential suppliers that regulators may need to consider for designation and could risk imposing additional burdens on smaller suppliers that may be several layers removed from the regulated service.

On Amendment 16 in the name of the noble Lord, Lord Ravensdale, I agree that a supplier should be designated only where they are genuinely critical to the provision of a regulated service. That is why the Bill includes strict designation criteria that must be met before a supplier can be designated. Importantly, an incident affecting the systems relied on by the supplier could disrupt regulated services in a way that significantly impacts the economy or the functioning of society. The Bill maximises the proportionality of the measure so that only the most critical suppliers to regulated entities are designated. It will also limit the number of small and micro enterprises that are likely to be designated.

The noble Lord’s amendment intends to limit that further. Its intention is to focus on suppliers whose activities being disrupted would cause systemic risk to the UK’s digital ecosystem, economy or essential services, and to prohibit designation if a supplier provides goods or services only to a single operator of essential services, a critical national infrastructure entity or a public authority.

We discussed a little earlier in Committee the risk of small but risky suppliers. Amending the designation criteria to focus on systemic risk to a wider number of entities could potentially leave many of the UK’s most essential services vulnerable to disruption. In fact, the compromise of just one of these providers could still have a significant impact on the economy or functioning of society in the UK or any part of it. Under the noble Lord’s amendments, a supplier that is essential to a single energy provider responsible for a county’s power, an NHS hospital looking after a whole city or a single cloud service provider used nationwide may not be judged as posing a systemic risk if it were disrupted. This would leave these essential end services vulnerable to severe disruption if that supply were compromised, with significant impacts for the huge number of citizens relying on them.

The amendment would also require the Government to issue statutory guidance for regulators on designating critical suppliers. I agree that consistency in the decisions taken by regulators will be crucial to the success of this regime. That is why my department will work with regulators to develop guidance to drive this consistency, and regulators will be required to consult with other regulators before designating suppliers where there is a relevant connection to multiple sectors. As we have discussed before, the statement of strategic priorities will also provide common objectives for regulators, which will further increase alignment between their approaches.

I heard very clearly what noble Lords said in introducing their amendments and the important other contributions during this discussion, which highlight how important it is to strike the right balance for this measure. I believe that the Bill establishes a proportionate and targeted framework that captures genuinely critical suppliers without extending regulation or excluding risks within the supply chain.

Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - - - Excerpts

My Lords, I listened carefully to what the Minister said. She made some very reasonable points and she may even be right, but I will need to take it away and think about it. In the meantime, I beg leave to withdraw my amendment.

Cyber Security and Resilience (Network and Information Systems) Bill

(Limited Text - Ministerial Extracts only)

Read Full debate

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I start by thanking my noble friend Lady Neville-Jones for introducing this group and setting out her stall so clearly and compellingly. I apologise that some of the amendments that have been looked at here I had in my record as being part of the next group. So, if I do not cover them all now, they will be covered by my noble friend Lord Markham as we get into the next group.

Let me begin by outlining the amendments in my name and those of my noble friends Lord Markham and Lord Holmes of Richmond. The need for action on ransomware has never been higher. The NCSC handled 204 nationally significant ransomware attacks in the year to September 2025 that we know about—up by 130% on the year prior, leading the NCSC to name ransomware as the most pressing threat to the country in its annual report. Of course, one of the challenges we face with ransomware attacks is not knowing when they happen, to whom and how often. The victims too often have strong reasons, generally associated with legal liability, not to report them. This makes it challenging, if not impossible, for any government agency seeking to identify commonalities across attacks to pursue repeat offenders and warn vulnerable organisations.

We could seek to make reporting of such attacks mandatory, but at the risk of placing hacked organisations in an impossible position where public reporting creates a legal bind that worsens the damage already done by the attack. I take on board the cogent concerns expressed by the noble Lord, Lord Clement-Jones, but the moral hazard occurs today where companies do not report ransomware attacks, thereby damaging our collective ability to defend others yet to be attacked.

Our amendment therefore seeks to find a channel that reports the facts of the hack and the metadata around it in a way that is not disclosed beyond the agency charged with cyber protection and does not become public knowledge. I do not pretend that this will be straightforward. For instance, we would have to understand how to deal with FoI requests and so on. That is why we propose a consultation. But if we were able to achieve something on this basis, we would greatly enhance our ability to protect UK PLCs from these hugely damaging attacks.

Amendment 172 seeks to require a review on the impact of the new reporting requirements introduced by the Bill. Again, this is fairly straightforward. The strengthened incident reporting requirements are being introduced to allow the regulators and the Government to help with providers and suppliers who have been attacked. Whether these requirements actually serve that purpose, and whether they do so at the expense of providers, cannot yet be known, but we must be able to form an assessment and adjust if necessary. Everyone in this Room would accept that we need statutory agility in the face of fast-moving technology, and a review on these lines could and would enable just that.

For a similar reason, I support the desire for transparency in Amendment 165 in the name of the noble Lord, Lord Clement-Jones. This may even overlap with our own amendment; we could probably think about merging the two in some way. It seems clear that both Houses of Parliament should be informed as to what the reporting regime is being used for and whether it is fulfilling its function. I hope that the Minister agrees.

I very much support Amendment 17 in the name of my noble friend Lady Neville-Jones. We are going from an incident constituting an actual adverse event on the security of network and information systems to it being capable of having such an effect. Arguably—the noble Lord, Lord Clement-Jones, made this point very well—almost any incident would meet this condition. We need language that expresses genuine risk to avoid all incidents being caught in the net. This seems wholly pragmatic to me and I commend it to the Minister, to whose response I look forward.

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments in this group; in fact, subsequent groups also speak to this question of the nature, scope and timeliness of incident reporting. What we are all trying to do, I think, is to get the right balance in reporting actionable information that can be used by regulators and the NCSC to improve the security of the United Kingdom and the entities that operate essential services within it. That is obviously what the Government have put forward. I have heard clearly the arguments made by noble Lords, some of which probe the intention and the detail, and I will attempt to clarify those as I speak.

First, I shall speak to Amendments 19, 36 and 44 in my name. Improving incident reporting under the NIS framework is a key pillar of the Bill. Without an understanding of incidents, our regulators and the NCSC cannot assist in recovery, assess risk and bolster resilience. The amendments that I have tabled will ensure that the incident reporting measures for regulated entities reflect what we are trying to achieve.

The Bill already requires relevant regulated entities to consider a list of factors when determining whether an incident is likely to have a significant impact and be reportable. This includes whether data relating to users is, or is likely to be, compromised. Government Amendments 19, 36 and 44 remove the reference to “users”, meaning that all data compromises relating to the relevant network and information system are in scope of incident reporting. This will enable key incidents to be reported, including the compromise of commercially sensitive information or the exposure of access details or usernames of the regulated service.

These incidents will need to be reported to the NCSC and the relevant regulator. I say in response to the noble Lord, Lord Clement-Jones, that that is the motivation behind the change to that categorisation. This will ensure that the regulators have full oversight of significant security compromises, supporting them to keep the UK safe and secure. We will shortly consult on what constitutes a significant impact and put further detail in secondary legislation and guidance.

I turn now to the amendments tabled by—

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

May I interrupt the Minister before she moves on to the next set of amendments? I do not intend to ambush her as regards her amendments this time around, but I seek an assurance, given that there seems to be quite a philosophical difference between her amendments today and those put forward by the noble Baroness, Lady Neville-Jones. There is considerable industry concern about the disproportionality involved. I seek an assurance from the Minister that, between Committee and Report, she will actively consult on the impact of this part of the Bill—Clause 15—and not just when it is in black-letter form. There is quite a lot of concern from many industry voices. It is incumbent on the Government to listen to those voices on the impact of this reporting structure and these duties before they go ahead in a way that many of us believe will not be helpful for the running of these businesses.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

We have already undertaken some consultation and I am happy to commit to contact affected businesses and business organisations and have further conversations between now and Report. Perhaps if I progress a little more, I may be able to answer some of the questions that may have given rise to some of this but, equally, there are different rationales for some different thresholds in the Bill, which, again, I am just about to come on to. I will set out the rationale for those because I think that they are well motivated and are linked to the risk profile that we see in the country and the connectedness of certain regulated entities in the country.

I turn to the amendments tabled by the noble Baroness, Lady Neville-Jones, and her questions to me on the link between the definitions and whether they apply beyond incident reporting. They apply to the security duties within the Bill, which means that regulated entities have a duty to prevent or minimise the impact of incidents. The amendments from the noble Baroness would limit this and reduce their security and resilience. We think that not every incident should be reportable but that organisations need to take appropriate and proportionate steps to mitigate the risks before, during and after a broader set of incidents.

On the second part of the noble Baroness’s amendments and her second question, the Government have recognised that the reporting threshold for data centres is broader than that for other regulated entities under the Bill. This reflects the distinctive role and risk profile of data centres. They are the physical infrastructure underpinning digital services across the economy and the public sector. Unlike the virtual cloud layer, for instance, they combine cyber, physical, personal and operational technology risks. This is particularly important in collocation facilities where infrastructure belonging to numerous customers is concentrated in one location. Then they need physical access to the premises and information about facilities or operational systems. A single incident could therefore exploit both physical and digital vulnerabilities, potentially affecting the confidentiality, integrity or availability of services belonging to multiple customers and sectors. The consequences may also extend beyond the facility’s immediate geographic location, because the hosted service can support users and central services elsewhere. That is the rationale for having this threshold applying to data centres.

To come on to the questions raised, including by the noble Lord, Lord Clement-Jones, on the use of the phrase “capable of”, and the points made in the amendment from the noble Baroness, Lady Neville-Jones, replacing “could have had” or “capable of having” with “likely to have” would exclude some incidents because their eventual impact was uncertain or successfully contained. It would also constrain the security duties, as I mentioned. In reference to the incident reporting definitions introduced by Clause 15, the subsequent detail sets out how the notification of incidents applies in each regulated sector, except for data centres. That is how the definition is made for regulated sectors other than data centres.

There are a lot of safeguards in the Bill to ensure that reporting remains proportionate. It is intended to capture significant near misses, not routine scanning, unsuccessful low-level attacks or ordinary operational events, and clear guidance will ensure that the industry understands this threshold. As the noble Baroness, Lady Neville-Jones, pointed out, we will set this out in secondary legislation and that will allow the consultation to take place that the noble Lord, Lord Clement-Jones, emphasised is so important—we agree with that. We have undertaken extensive engagement to date and will continue to do so.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

As per the points made by other noble Lords, this is a prime example of when you realise how valuable it is to have in this House and, in particular, in this Committee people who have lived experience. Because of that, this is a well thought out set of proposals; I thank my noble friend Lady Harding for bringing them before us, and I thank my noble friend Lord Holmes and the noble Baroness, Lady Kidron, for supporting them.

These amendments mirror a lot of what I saw from the other side when I was the Health Minister and we had the problems with Synnovis and testing. That is where I am coming from: you realise that you need some real teeth because, even though you have public bodies such as the NHS, which you think would listen to the Minister on certain requirements, that that does not always follow. The point made by my noble friend Lady Harding about everyone telling you to keep quiet applies to state organisations just as much as it does to private companies. Having teeth is an important part of all this and of making things happen.

The staged approach has been mentioned. In your first 72 hours, it is all about wanting just to get the information out there. One of my questions—I will come on to the rest in a minute—is: what are we doing on our side with that information? We must make sure that it is being used valuably and used to alert others. Only later on, around the 30-day mark, do you get into the “lessons learned” stage. So staged reporting would be a very sensible and well thought out approach.

That brings me on to another point; I would be grateful if the Minister could address it. If we are requiring businesses to provide such information to the Government very quickly, what will they get back? The strong justification for rapid incident reporting is surely that the NCSC can aggregate the intelligence, identify common attack vectors and vulnerabilities, and rapidly warn other organisations before they, too, are attacked. Obviously, that is the difference between regulatory reporting and genuine national cyber defence. I would be grateful if the Minister could explain the planning and what will happen operationally when one of these early notifications is received. How quickly will the information be assessed? How quickly will actionable intelligence be disseminated to other potentially vulnerable organisations? What obligations will there be on the Government and the regulators to ensure that the information provided by one organisation improves the resilience of everyone else?

Of course, there is a wider point here. Throughout our consideration of the Bill, we need to guard against measuring success by the number of organisations regulated or the number of reports submitted. Rather, the real test is whether fewer attacks succeed, whether we identify attacks faster, whether organisations can recover more quickly and whether intelligence from one attack prevents the next one. That is the outcomes we want this regime to achieve.

I hope that the Minister will look seriously at the principles behind these amendments, and in particular at whether we can achieve a reporting structure that gives the Government the information they genuinely need quickly while allowing organisations to concentrate their scarce cyber expertise on the thing that matters most: defeating the attack.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments in this group. We have spoken previously about the importance of effectiveness, proportionality and clarity. I absolutely hear the experience of the noble Baroness, Lady Harding, in leading a telecommunications company and the experience it had.

We have learned from experiences across all sectors in introducing the new regime that is in the Bill, which puts in, as others have said, a staged approach that includes an early alert to regulators and the NCSC within 24 hours. That will provide awareness and enable the NCSC and regulator to provide early support, as well as potentially understand whether it is impacting multiple regulated entities.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, before the noble Baroness, Lady Harding, stands up, I heard what the Minister had to say about consulting across sectors. I was reminded that, at Second Reading, I mentioned the fact that the law firm with which I am associated, DLA Piper, was subjected to a NotPetya ransomware attack back in 2017. What the Minister said is completely at odds with not only what the noble Baroness, Lady Harding, said, but the experience that we had in the way that we needed to understand how these events unfold. It would be really helpful to know from the Minister, or for her to publish, the sectors where the Government have had those discussions and which parts of industry have agreed that this is an appropriate form of incident reporting.

What we are trying to do, throughout the Bill, is to ground it in what is practical. At the moment, despite the fact that we are letting through some government amendments, it seems that we are heading in the wrong direction with this clause. It is going to be disproportionate in the way that it impacts on business and is not even going to be fit for purpose, despite the disproportionality. It is just not going to work.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I think we all agree that we want a proportionate and clear regime. The noble Lord supports further incident reporting here—additional stages of incident reporting. In our impact assessment, we clearly set out the implications of that in its cost to business and so on. We will come on shortly to discuss potentially broadening the scope of incidents that would be reported. We have not been able to quantify that potential impact, as a sort of counterfactual, because we are only just discussing that.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I have listened really carefully to the Minister and thank her for her response, but I feel that we just had a completely black and white no, which is extremely disappointing. We have had something almost worse than a black and white no, because if I heard her correctly—I will need to go back and read it again—I think she has added uncertainty, because suggesting that it is okay because regulators have the ability to ask for extra reporting is a company’s worst nightmare. What you want is really clear black and white guardrails, as we have been trying to introduce in these amendments.

I had hoped that we could have follow-up discussions between now and Report, but I feel like the door has been rather slammed in my face. I would be very keen to understand, as the noble Lord, Lord Clement-Jones, has just said, what consultation has really happened and to have a recognition that you need to consult organisations that have experienced a substantial cyber attack. If an organisation has not, then I am afraid it will want to keep quiet and will not want to report anything. It is easy to ask broad groups of organisations, “Would you like more reporting?” We all know what the answer to that would be. That is an easy consultation.

I would really value more detailed discussions with the Minister and her officials between now and Report, because I feel that we will come back to this, particularly given the support that my amendments have received from across the Committee, for which I am extremely grateful. I beg leave to withdraw the amendment.

--- Later in debate ---
Moved by
19: Clause 15, page 22, line 14, leave out “users of”
Member’s explanatory statement
This amendment would require an operator of an essential service to consider whether any data relating to the essential service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.
--- Later in debate ---
Moved by
36: Clause 15, page 26, line 31, leave out “users of”
Member’s explanatory statement
This amendment would require a relevant digital service provider to consider whether any data relating to the relevant digital service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.
--- Later in debate ---
Moved by
44: Clause 15, page 30, line 4, leave out “users of”
Member’s explanatory statement
This amendment would require a relevant managed service provider to consider whether any data relating to the relevant managed service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.
--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I, too, thank my noble friend Lady Harding of Winscombe for tabling this important set of amendments, which we welcome, and for clarifying the refinements of the grouping process, which had slightly eluded me up to that point. As with the previous group, this would amend four key areas of, on this occasion, customer reporting. It would tighten the timing to notify customers; widen the incidents expected to be reported by removing the adverse impact criterion; add extra reporting triggers; and add an “advice on remedies” duty.

Of course, businesses should be supported in the case of cyber attacks and our priority must be preventing, containing and controlling such incidents, but this cannot come at the expense of the customers that businesses serve and depend on. Customers deserve to know when a firm they depend on is targeted, even if such an attack does not necessarily directly adversely affect them. They deserve to be informed promptly and they deserve to be informed of potential remedies.

It is worth saying that there is a welcome side effect to doing so, based on the premise that behaviours are the best guard against cyber attack. Constantly being aware that cyber attacks are going on will improve behaviours. As was said earlier, the goal is not to create panic but, on a continuum between insouciance and panic, we must imbue a point closer to concern more widely in the population to keep people aware that we are constantly at risk of being hacked. On these Benches we feel these are wise, pragmatic and helpful changes. I certainly hope the Minister agrees.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness for raising important points around customer communication. As set out in the Bill, it takes forward the current duties to notify customers that the Bill places on data centres, OESs, RDSPs and RMSPs. That duty was designed to ensure that providers of key digital and data infrastructure services consider whether their customers are likely to have been adversely affected by a reported incident—whether through disruption of service, compromise of their data or exposure of their systems to cyber threats—and to notify them.

I will explain the logic in response to the point of the noble Lord, Lord Clement-Jones, about the importance of meaningful communication with customers. The reason we have drafted the Bill so that customer notification follows the 72-hour incident report is to ensure that regulated entities can focus on understanding the nature of the incident and contact customers when they are more likely to understand its potential impacts.

We have discussed the question of what an organisation might reasonably be expected to know within 24 hours of identifying an incident. The point is that customers should be communicated with in a timely manner, with sufficient information, so that they can take the necessary action. On that point, the rationale for 72 hours was to time it, for simplicity, with the 72-hour report. I am happy to consult further with the noble Baroness to explain the logic of the 72-hour and 42-hour requirement to communicate with customers, because the motivation is exactly the same: to have actionable and meaningful communication with customers.

I turn to the degree of depth of communication, the advice that can reasonably be put on regulated entities on technical measures, and what technical mitigations customers should take on their own. It is reasonable that the regulated entity should share what they know about the nature of the incident. The question about whether the regulated entity is in the right position to provide advice to customers on what mitigations they should take is both practical and technical. Would they have enough insight to have an effective understanding of the situation of the customers and a detailed understanding of the customers and their businesses in order to give effective meaningful advice in that way—or would that just be a requirement on the entities that would not have the intended impact? On that point, I am not quite persuaded that the line is drawn in the right position.

On keeping in touch, mentioned by the noble Baronesses, Lady Kidron and Lady Harding, I am happy to come back to that on Report to make sure that we have the right balance between the initial notification and the right type of customer communication.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

I thank all the noble Lords who, again, have supported my long list of amendments and I thank them for their excellent contributions. It feels as if we made a very small breakthrough, for which I am extremely grateful, and I thank the Minister. I will not delay anyone any longer as we have another group of my amendments to come, but I look forward to some detailed discussions between now and Report to see if we can bring this back in a form that we are all able to support. I beg leave to withdraw the amendment.

--- Later in debate ---
Lord Reay Portrait Lord Reay (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend Lady Harding of Winscombe for her amendment, to which the noble Baroness, Lady Kidron, has added her name. We believe that this is a straightforward amendment. If we are to tackle cyber attacks seriously and to create a generally resilient cyber system, we should not simply stop at the reporting of incidents that happen. A key way of ensuring that we build not just a responsive but a preventive cyber system is by knowing what potential risks exist and who is attempting to commit cyber attacks, even if they have not done so yet. This is a reasoned amendment that places a requirement only on those already considered regulated persons, with the opportunity for others not regulated to report voluntarily. I hope that the Minister will agree.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness for raising this question about the requirement for regulated entities to report cyber threats, near misses and sub-threshold incidents within a 72-hour deadline.

I turn first to the question of voluntary reporting, which we touched on a little in the context of discussing the industry groupings on Tuesday and the trust groups that exist and are often facilitated by the NCSC. These are incredibly valuable groups. We absolutely encourage voluntary reporting, whether through those groups or other industry bodies. There is a question about whether putting such groups and mechanisms on a statutory footing helps or hinders that objective, because we need to engender the confidence to share information, as the noble Baroness and others mentioned. There is a question about whether that is within the regulatory perimeter, as it were, and whether it encourages that or not. I am happy to come back to that on Report.

I turn to the question of reporting sub-threshold incidents. The amendment concerns incidents that have been successfully contained or have proved ineffective, incidents that fall somewhere below the current reporting thresholds and any potential circumstance or event that could, if it occurred, affect a regulated entity’s systems or the users of a service provided through these systems. We discussed that in the context of data centres. Let me answer the question from the noble Baroness, Lady Kidron. In the discussion on data centres, I was speaking about near misses. We made the point highlighted by the noble Baroness, Lady Neville-Jones: near misses and those types of incidents would be captured for data centres, given the particular role they play in our digital infrastructure.

The extension of similar requirements—although, as we read it, they are much broader requirements—to all regulated entities would increase regulatory reporting very significantly. The noble Baroness, Lady Neville-Jones, made the point right at the beginning—although it could have possibly been someone else—about the ability of our regulators to effectively utilise the threat intelligence and manage it so that it can be conveyed into actionable advice and trend data. These are the considerations that we take.

Another consideration is that the entities that have more sophisticated surveillance and mitigations may be able to identify attacks more effectively. We would not want to set up a situation where there were any perverse incentives in the system for those who have very adept surveillance and assessments away from reporting or developing that.

Even though I heard very clearly that the motivation is that the amendment is just to catch to those incidents that just fall below, our reading of it is that it would be much wider, and it may indeed have some other effects. At this stage, I would not support the amendment as drafted.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

It was my suggestion to break up these amendments into different groups, otherwise we would have had about 100 amendments in one group. There is an awful lot of overlap in the discussion on this group in particular and Amendment 17 in the name of my noble friend Lady Neville-Jones. Would the Minister commit to having a joint meeting, where we could try to work this through together? I think we share a common goal of wanting to give as much relevant, immediate and up-to-date intelligence to the network as possible, without overwhelming, and recognising that, as the noble Lord, Lord Clement-Jones, said, time is absolutely everything in these cyber attacks. If we could discuss that together rather than separately, that would be extremely valuable.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

That would indeed be very valuable to discuss the questions around definition, scope, coverage, timeliness and impact on potential entities—sorry, I have just expanded our agenda.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

I have heard very clearly the willingness to discuss and collaborate from the Minister, which is extremely welcome, as were the contributions from all noble Lords. If the last hour and half has shown anything, it is that there is a genuine cross-Committee desire to work—this is what the House does at its best—to genuinely improve, with a shared goal of a piece of legislation that the country will benefit from if we can get it right. I beg leave to withdraw the amendment.

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness, Lady Kidron, for opening this debate on behalf of my noble friend Lady Morgan of Cotes. I will come to her amendment in a moment, after I touch on Amendment 167, tabled by the noble Baroness, Lady Ludford. Her comments, particularly about board ownership of cyber risk, were well founded and an extremely important foundation for the debate—as indeed were those of the noble Baroness, Lady Berger, who pointed out the difficulty of accelerating from zero cyber knowledge to sufficient. That is a non-trivial undertaking.

Amendment 167 is absolutely in line with the principle that we raised on the first day of this Committee in the form of Amendment 92B. It is the idea that executives should be held accountable for cyber security and resilience plans by their board and their shareholders, by reporting consistently on protections. This amendment, perhaps a little more explicitly, would require the same thing and I am very happy to support it.

I think Amendment 74 largely follows the same sentiment: that companies should and must be held accountable for their own cyber security. On this one, however, I need a little more persuasion. I am going to tread a little tentatively here, because I very much take on board the comments of my noble friend Lord Arbuthnot that we have not solved this problem yet and that carrying on as we are is probably not that sensible.

However, I do have some inner alarm bells ringing about this one. So, while we support the goal of making companies self-sufficient and accountable to their shareholders, this amendment would give the Information Commissioner powers to enforce compliance and sanction individual negligence. The concern here is that, as a matter of principle, the inner working of companies—who is accountable internally, to whom and for what—should be placed in a different category from the requirements placed upon them.

We should encourage companies to figure out internal issues themselves. By all means require board oversight of cybersecurity plans, as we have attempted to do, but my understanding is that this amendment would make it the Information Commissioner’s job to decide which individual is responsible when cyber attacks take place and are not adequately defended. I find this quite a tricky path forward, but I am clearly willing to keep talking and to be persuaded.

I am also concerned about the disincentives to become a director that this might put in place, because of what feels to me like the inherent uncertainties of the liabilities that may hang over board directors as they undertake these responsibilities. That being said, I, of course, completely agree with the underlying principle and look forward to hearing the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.

I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.

That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.

I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.

To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.

I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, can I just check something before the noble Baroness, Lady Kidron, rises? The Minister has uttered some very warm words about the responsibilities of directors, but am I right in thinking that in nothing of what she said is there any intent for the Bill to create a legal liability that compels directors in the way that these two amendments do, or any form of personal financial fiduciary duty on a director? What she is arguing for, despite the warm words, is, essentially, a voluntary scheme.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

We will consult on the security and resilience requirements that will come out of the Bill. They will contain a requirement on board governance and those expectations will be set out as a result of the Bill. The regulators and others enforcing the Bill will take that into account in their enforcement regime.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I am sorry to press, but the Minister is saying that these are expectations. Will she write to us? There is a huge lack of clarity in the middle of those warm words. We take encouragement from the fact that the Government want to see boards take responsibility, but where are the teeth?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Obviously, we have not yet gone out to consultation on the security and resilience requirements; we will do that after the Bill passes. I can certainly update on the process, the expectation and how that links with the enforcement duties in further detail.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

The Minister is also going to have to point out the power under which the Government are going to act to actually fix that liability, or make sure that the guidance, or whatever it is, is complied with, because we are talking about the power and the duties in primary legislation. It is all very well for the Government to say, “We’re going to produce guidance”, but unless there is something in the Bill that permits that and makes sure that the Government can make it stick, we are all going to feel dissatisfied.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

The noble Lord, Lord Clement-Jones, has done a lot of my work for me. I thank everyone who contributed. I was really struck by the expertise in this Room. We started this afternoon by talking about the importance of lived experience. I say very strongly to the Minister that I have been in the House long enough to see Acts of Parliament pass, be regulated and fail because we did not really understand how they were going to hit when they were in the world.

The comments on this group are really worth listening on, particularly those on Amendment 167. I say both to the noble Viscount, Lord Camrose, and to the Minister that there is such a high bar of connivance in Amendment 74. There is no accident. The words are “deliberately”, “knowingly”, et cetera—I read them out as part of my introduction. I will take up the noble Viscount’s offer to come to speak to him and persuade him, and I ask the Minister to really think about this, because we have heard that culture does not change without an incentive. This is an incentive to say that if you are seen to grossly mislead and undermine the regulation, then you are liable. That is what good law does. I beg leave to withdraw the amendment.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, we have heard very compelling cases from all noble Lords who have spoken on this group about why a particular sector should be included. I will not go through the list—it was gone through very well by the noble Lord, Lord Clement-Jones, a moment ago—but I think we can all agree that each one was a compelling case. That probably illustrates the wider problem, because we are almost getting into a game of cyber whack-a-mole here, where we can see them popping up left, right and centre. So our approach, with Amendments 92 and 92A in my name and those of my noble friends Lord Camrose and Lord Holmes, is to try to take a more strategic view, very much reflecting some of the views that the noble Lord, Lord Birt, was mentioning earlier as well. They ask the Government to assess strategically important entities outside the current NIS regime and consider whether they should be brought into scope where a cyber attack would have a sufficiently serious impact on the economy or the day-to-day functioning of society.

We are not asking for another long list of businesses to be regulated, because we need to be careful about the regulatory burdens that we are putting on people. Instead, Amendment 92A proposes a risk-based test and asks these questions: what would actually happen if this organisation went down? Would essential services stop? Would very important supply chains fail? Would significant parts of the economy cease to function? If the answer to those is yes, surely the Government should at least assess whether that organisation belongs within our national cyber security perimeter. This also illustrates why we need to see the national cyber action plan. It was promised this summer; we are now in September and, considering that this is very pertinent to everything we are talking about in Committee, I ask the Minister when we will see the plan.

I will highlight one further issue, which the noble Baroness, Lady Berger, illustrated very well, in the area of the data held in certain organisations, particularly in education. We all know that the reason that a lot of these organisations are attractive targets is not because of the essential services they often carry out but because they carry enormous quantities of valuable and sensitive data. Again, this was very much my experience with the attack on Synnovis when I was Health Minister. It caused massive disruption for operations and diagnostic services in London, but the question was: why was that organisation holding so much information in the first place? It had names and addresses of people going back 20 years, their test results and their full medical records, and it did not need any of it at all. It could all have been anonymised, and it definitely did not need to hold it for 20 years.

To me, the question we really need to answer—this speaks to an amendment we will be talking about later—is: what data do all these public bodies really need to hold? Of course, if the data is not there in the first place to be stolen, or if it is not interesting or valuable, then that is the best line of defence, because there is no reason for there to be a cyber attack on it. As I say, we will talk further on that on Amendment 174E, but the principle is directly relevant to what we are talking about here.

Before I come to the end, I have a special request from my colleague here, who I think knows a thing or two. I am told on good authority that the last government AI regulation White Paper has a lot of relevance and synergies here, so I would request the Minister to look at that between now and Report to see where, as I say, there are synergies and learnings from it.

In summary, first, we should systematically identify the organisations whose compromise would cause the greatest damage, as per our Amendment 92A, and, secondly, we should reduce both their vulnerability and attractiveness as targets, including by reducing the data prize available to the attacker, as per our Amendment 174E, which we will come to later on. That, to me, is genuine cyber resilience: not merely making the safe harder to crack but, wherever possible, ensuring that there is nothing valuable inside the safe to steal.

I hope the Minister will respond both on the important sectors raised by noble Lords and to the central question behind Amendment 92A: what systematic test are the Government applying to determine which strategically important organisations should fall within the NIS regime, and will that regulatory perimeter keep pace as technology and the threats change?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank noble Lords for raising so many aspects of the scope of the Bill. I recognise the sentiment among noble Lords today about the importance of expanding its scope. Our approach has been to target regulatory requirements on a select number of essential services, while using non-regulatory but effective measures to improve the cyber security and resilience of the wider economy.

As I set out at Second Reading, I have asked my officials to work across government to consider what additional services would merit being brought into scope of the regime in future. This will allow us to make a holistic and considered approach. To ensure our assessment is appropriately prioritised, I would first like to focus on the CNI sectors not already covered by the NIS regime.

I share the intent behind the objective from the noble Viscount, Lord Camrose—which the noble Lord, Lord Markham, spoke to—that the process to expand the scope of the regime should be rigorous and evidence based. As set out in the Bill, for something to be defined as a new essential activity under its powers, the Secretary of State must be satisfied that the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is reserved for the most vital activities in our nation. To the point raised by the noble Lord, Lord Birt, I believe that that is a clear test. In reaching a decision, the relevant departments would need to carry out a risk assessment and any economic assessments, and consider whether inclusion is proportionate. This is part of normal policy development. After that, proposals would be subject to consultations and the affirmative procedure.

The noble Viscount proposed in his amendment that assessment for inclusion be carried out on an entity-by-entity basis, which obviously differs from the sectoral approach we have taken thus far. Setting out the detail that would need to be published according to the amendment could lead to a release of information about individual companies that could pose commercial or national security risks, due to their criticality. I think that the sectoral approach is better. As others have said today, looking at a systemic approach to the sectors is the right way to look at what is in the statutory approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I am sorry to interrupt the Minister, but clarification along the way would be very helpful. She has asked her officials to see what other sectors should be brought in and has given an indication of the kind of test, but we are dealing with a bit more fog here. Is she promising us something in primary legislation or will it appear in secondary legislation? Will it just be something that government policy will cover, and we will have no say on the kinds of sectors that should be included?

For instance, the Minister is the Space Minister. Do we have an indication that space, or any of the key activities within space, will be included? Do we have any white smoke from the department as to whether that sector will be included? Will we hear by Report what sectors might be included? It is all a bit vague, and that does not give us a great deal of assurance.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I was referring to the process by which sectors can be brought into scope of the Bill, as set out in it and using the powers in the Bill. That would follow the process I just mentioned, which would be subject to consultation and the affirmative procedure. That is the process that I am referring to.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

But the powers are further down the track; they are under secondary legislation. I am assuming the Minister is promising that the Secretary of State will set out the criteria by which a new sector is brought in. Is that right? Do we have any indication, apart from what the Minister has said today in response to the noble Lord, Lord Markham, as to what those criteria will be?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I have highlighted a few of those criteria regarding the extent to which the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. Obviously, we already have the list of critical national infrastructure. We need to go through a whole process, as others have mentioned. We would need to make our assessment and then consult with industry on that, so there is a process to go through here. That process of consultation and talking to industry, or any affected sector, is absolutely critical. I am absolutely happy to update noble Lords and engage further ahead of Report on this.

In terms of the report referenced in Amendment 92A, I do not think we would need a statutory obligation to bring this report back, as set out. I mentioned the focus on entities rather than sectors, and it is better to look at the sectoral approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, if the Minister could commit to adding that to the conversations we are bound to have to have between now and Report—

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am not only committing; I am offering, so I am happy to have the noble Lord confirm that that would be good. I am absolutely offering that as part of the engagement ahead of Report.

I have heard the numerous areas that have been raised for inclusion in the Bill. We should look in a methodical and sensible way at these and at the implications—as we have previously discussed—for the obligations that will placed on any entities that come within the scope of the Bill, such as incident reporting, board accountability and so on, so that we do this in a very sensible manner. That is why this is the right approach to take.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

Can I ask the Minister to comment on another point that the noble Lord, Lord Clement-Jones, raised? Why should this not apply to the higher reaches of government? I ask the Minister specifically: what is her view of 607,000 records being stolen, just weeks ago, from the Department for Education?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I absolutely intend to talk about the public sector. Given the numerous sectors that have been raised, I also want to respond individually on each sector. I absolutely agree that all sectors need to improve their cyber resilience; it is not the case for only those in the regulatory perimeter. It is also not the only way to improve; we should improve things right now. There is funding, and there are activities going on in all of these sectors that we might talk about—sometimes with public funding, sometimes with public advice and sometimes through industry groups.

I have spoken a little already about the cyber resilience pledge, which over 100 companies have now signed. It sets out the absolute best practice and what actions to take, including making cyber a board-level responsibility, following the Cyber Governance Code of Practice, signing up to the early warning service and taking a risk-based approach to requiring cyber essentials across supply chains.

In the retail sector, the DBIST industry-led Retail Sector Council is working with experts and business representatives to consider cyber security.

In respect of the space sector, it is absolutely critical; I could not agree more on the importance of PNT and satcoms, which underpin a huge amount of UK economic activity. The UK Space Agency is already strengthening cyber resilience in practice through the development of a space cyber assurance framework for the space sector, intending to help operators understand and demonstrate cyber resilience in a proportionate and practical way.

The UKSA also supports the provision of threat briefings and is working with industry on the potential development of a space information-sharing analysis centre. This would improve the flow of threat information, warnings and good practice between government and industry, and support links to international networks, such as the US-led global Space ISAC model. That would help operators to understand emerging threats and to act quickly.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, at the risk of irritating the Minister even further, it is great to hear of some of this activity, but that is not the same as bringing it under the terms of the Bill.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.

Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.

Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.

Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.

This brings me on to Amendment 81A—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

I thank the Minister for her point about the Government Cyber Action Plan, but do the strength of her arguments there not completely reinforce the urgent need to have the national cyber action plan, so that we can assess overall the cyber strategy of the nation and the role of the Bill within that strategy?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The cyber action plan is a very thorough document. It sets out a plan over many years to improve the cyber resilience of the Government and the public sector, which I think we all agree is absolutely needed. The fact that incidents are still occurring in the public sector reinforces the need to act. We will publish the cyber action plan and, as I mentioned two days ago, I will keep the Committee and the House updated on progress on that.

Education is an incredibly important sector, and the Department for Education takes an active approach to supporting the sector. This includes the Cyber Security Hub, providing schools in England with guidance, while the standards for schools and colleges help institutions to understand their cyber security requirements. Colleges have been required to meet cyber essentials since 2024, with more than 80% of colleges now meeting this requirement.

I come to the question of MHCLG and local government. The department is also taking meaningful steps and working with local authorities to increase their cyber defences. This includes the rollout of the cyber assessment framework for local government, which would be the equivalent to what is required in the cyber Bill, and the recently proposed revisions to the best value statutory guidance to set new expectations for local authorities on cyber resilience. That best-value duty provides an immediate and proportionate route to improving through existing governance and accountability mechanisms. In addition, MHCLG is supporting councils directly.

The question of electoral infrastructure and political parties, raised in Amendments 79 and 81D, is also incredibly important, as noble Lords have set out. The Government work with the NCSC to mitigate risks there. MHCLG specifically works with local authorities to strengthen their electoral cyber resilience and ensure electoral data is adequately protected. The Joint Election Security and Preparedness Unit has responsibility for co-ordinating election security. The MHCLG digital electoral services team maintains robust incident response arrangements to protect electoral systems and citizen data. As the noble Baroness, Lady Ludford, mentioned, the NCSC also has a broad package of support for political parties, candidates and elected representatives. This includes regular engagement with parties, which can access the NCSC’s active cyber defence services, as well as NCSC providing tailored advice to parties and candidates.

I have set all that out because the motivation behind bringing these matters into scope is to engender further action. I want to emphasise that further action is happening, whether or not it is within the scope of the regulatory perimeter.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

The Minister pointed to three examples of where education is considering issues around cyber security, specifically in schools and only 80% of colleges. One of the concerns I outlined in my contribution was around the examining bodies for both our secondary schools and universities. There was no mention of universities. Can I understand a bit more about how they are currently being considered, if they are not going to be included within the scope of this Bill?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The general approach is that the lead government department has responsibility for ensuring cyber security in the areas that it covers. I will need to write to my noble friend specifically on exam boards and examining authorities. I know that the DfE supports bodies that support higher education and further education, but for further details, I will come back to her.

More broadly, I am happy to talk further with noble Lords between now and Report, and perhaps after, on the approach to assessing what should be within the regulatory perimeter and at what speed that can be advanced.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

Can I ask a couple of questions and make one comment? The more we hear about the conversation that is taking place on the Bill, the more anomalous the factors that have been chosen or included in the scheme become. Let me give the example of space. Plenty of us now receive our internet connection via satellite. It is inevitably an intimate part of the networking system of cyber security. What we appear to be told is that some parts of the telecoms and internet world are going to be governed by the Bill, but other parts, which are equally integrated and important, are going to be covered separately by a special different arrangement—they are not included. For example, as I understand what the Minister said about space, it is not going to be included in this Bill. With the greatest possible respect to the Minister, it does not make sense.

My question is: in the period ahead of us, could the Government have another look at the whole question of the scope of the Bill? This seems to be one of the problems that lies between us. As a result, Members are now trying to shove into the Bill all sorts of things on the grounds that they are essential services—some of which clearly need to be there, but for others it is arguable that they do not.

I heard what the Minister said about the action plan. I have read the action plan, and it is a good plan, but it lays a heavy responsibility on a department that no longer exists—DSIT. The function is set out so well and is important to keeping government departments up to the mark, which is going to be done separately. Where is that responsibility now going to sit? It will require a very considerable degree of expertise on the part of those conducting this system of keeping people up to the mark. How is that going to be done?

It seems to me that local government requires something of the same. Government is a whole thing. It is not that some things can be done in central government without regard to their implementation by local government or vice versa. Are the Government going to extend the system that is being mapped out in the action plan for government to local government as well, in order to get the same standard of performance and integrity of systems?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Let me work backwards here. The noble Baroness makes a very good point: the services delivered at local level often mirror those at central government level. At the moment, we are consulting on the question of the best value duty to give additional prominence. One of the issues with mapping these requirements into local government is that many different services are indeed provided. We may need to come back to that in more detail.

The government cyber unit now resides within DCMS. The team has transferred over and is up and running; I have spoken to them many times recently. The unit is very active in progressing the government cyber action plan as per the timetable and the target plan.

On the question about the approach to looking at other sectors to bring in, that is why I mentioned at Second Reading that I had already asked my officials to work across government to consider what additional services would merit being brought in. I mentioned earlier today that focusing on CNI services not already covered by the NIS regime would be the right place to start.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, will the Minister show some greater enthusiasm for her own regulatory scheme? I hope that the criteria that she adopts within the department as to whether certain sectors are going to be brought in will be about not only the criticality of the services but the need for transparency on the incidents themselves. We have had this whole debate about notification being beneficial so that organisations such as the NCSC actually know what is going on, that we the public know what is going on and the level of threat, and that our intelligence services are fully apprised.

The noble Baroness, Lady Neville-Jones, was entirely right on critical sectors, such as space. If there is no duty of notification on, say, a satellite manufacturer or something, we will all be in the dark. The Government rightly introduced this Bill to introduce greater transparency and duties on some very important sectors. We simply want to make sure that we capture all the important sectors and that they are all subject to the duty. This shying away from the Government’s own framework seems completely contrary.

--- Later in debate ---
Lord Reay Portrait Lord Reay (Con)
- Hansard - - - Excerpts

My Lords, I thank all noble Lords who have added their names to the amendments and who have spoken in this debate. Both amendments in this group are underpinned by the same principle that national security and national technological capabilities deserve a unified plan—not one that targets some sectors and entities and not others, but a holistic plan that brings together all sectors and industries into a single framework. His Majesty’s Opposition therefore support the intention behind the amendments.

However, at risk of repetition, the Government could avoid the need for these propositions. They could do away with your Lordships’ worries if they would commit, as mentioned by my noble friend Lord Camrose, to publishing a national cyber action plan within a set timeframe, and commit to including national digital sovereignty as part of that plan. In light of Tuesday’s debate on AI, we request a review and update of the previous Government’s AI White Paper to ensure that AI regulation and cyber regulation are aligned. They need to operate in lockstep, and this Bill is an appropriate place to do it. It is evident that national sovereignty and a reduced reliance on foreign technology is vital to ensuring national wholesale cyber security. I commend these amendments in their aims to achieve that, and I look forward to the Minister’s reply.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for continuing the debate with which we ended the previous session: the very important topic of the technological and digital sovereignty of the UK. That is very important to this Government and we are taking action on it. It possibly has not been focused on enough in past years but, across many areas, that is what we are doing.

We are clear that we need a coherent approach and a clear direction. We obviously need to take into account that technologies and markets evolve, and the core of that approach was set out in the modern industrial strategy and the Digital and Technologies Sector Plan. That set out the direction of travel, and the Government will continue to consider how our priorities are best articulated.

Our objective, as I articulated at the end of July, is not complete independence but strategic resilience through a combination of domestic capability, diversified international partnership and targeted management of critical dependencies. This allows us to access the best of global markets while capitalising on our domestic capabilities. That is why we already have in place a range of regulatory and non-regulatory frameworks that enable us to embed those objectives through existing industrial, technological and resilience strategies. I will talk to some of those now.

For essential services in scope of the network and information systems regime, such as drinking water, health and energy, all entities are required to manage and mitigate the risks posed to their systems that deliver essential services. This includes the risks set out in the amendment of the noble Baroness, Lady Ludford.

On market concentration, which the noble Baroness, Lady Kidron, and the noble Lord, Lord Clement-Jones, referred to, the CMA is acting. It concluded an investigation into the cloud services market in July last year, highlighting competition issues arising from market concentration. It has since announced packages of actions to improve competition in cloud services. This work has directly informed our thinking, as we develop a more strategic approach to how the public sector procures cloud services.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I point out to the Minister that not all is rosy in that particular cloud services garden. The CMA failed to designate those major US hyperscalers as having strategic market status, which, for many of us, was a rather extraordinary outcome.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It has announced a series of measures, including actions from Microsoft and Amazon, to support greater choice for UK businesses and the public sector.

On my noble friend Lady Berger’s question, it is true that cloud spend is distributed across departments and managed through a range of departmental contracts and commercial arrangements. We have established a cross-government cloud consumption dashboard to improve the visibility of cloud usage across the public sector, and we are working with both suppliers and departments to further improve the quality and completeness of our cloud infrastructure spend data to provide a joined-up view today and for the future. That is something that the Government are acting on.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

For clarification, that is on the spend, but my question is specifically about where the cloud services are hosted and/or whether they are under the jurisdictions of Governments beyond the UK. It was not just about what money is being spent; it was about who is responsible for it and where it is located.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

That is well noted.

For all digital services, as many noble Lords have pointed out, government departments are required to carry out robust security and resilience assessments in their procurement to ensure that the actions of foreign states or hostile actors cannot disrupt the delivery of public services. In June, the Cabinet Office published procurement policy note 025, Protecting the UK’s National Security through Public Procurement, and AI will be one of four key sectors recognised as critical for national security, with new guidance for departments prioritising contracts for British business where necessary to protect our national security.

--- Later in debate ---
Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

Before the Minister sits down, I ask her to reflect, at the end of our second day in Committee, that the noble Viscount, Lord Camrose, has mentioned more than once that he would like to see a national cyber security strategy, but is not the takeaway from these two days that we are all very clear on the challenges facing the UK? There is a great deal of uniformity across the Room, as well as in the quality of the Minister’s answers, but does the Bill not need to deal with all the issues that have surfaced and been addressed? Frankly, it does not do that at the moment. If the Bill passes in its less ambitious form, how long will it be before we get another Bill to address the strategies? If we have to wait that long, how much more damage is going to be done to our economy and our society in the meantime?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Going back to the point made by the noble Lord in an earlier intervention, the Bill is a substantive Bill that substantially increases coverage of the digital infrastructure on which much of our economy relies. That is a very important point. As I mentioned at the start of my remarks just now, the question of whether the Bill is the right place to articulate the breadth of many of the issues that have been raised is, indeed, a good one. I am not sure that it is the right place to articulate all the very good questions that have been asked, because some are much more wide-ranging than the scope of the Bill.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, I thank all who have spoken for their excellent contributions. I will make three quick points. First, in the course of the afternoon, I opened the Explanatory Notes, which is always a bit of a danger. I just want to put on the record that paragraph 2 states:

“These reforms are intended to better protect the services and other activities that are essential to the day-to-day functioning of society in the UK, and the economy, through safeguarding relevant network and information systems (the systems that allow computers and other devices to communicate with each other) and their surrounding environment”.


I do not think that the Bill, as it stands, does that job, and the last two groups have absolutely illustrated that.

The second thing that I would like to say to the Minister, and I absolutely recognise all the things that she mentioned, is that I did find myself counting, and it was 11. We do not have a strategy. It is 11, but it does not cover the scope of what we are discussing; it does not even cover the scope of security.

The third thing, which I am slightly loath to say but will now say, because otherwise we will get nowhere, is that I have been in the room with Ministers when they have indicated directly that they cannot do something because of America’s desire—absolutely categorically, yeah? That is the bit that we did not get from the Minister. Sovereignty is about being able to impose and choose our laws, and to decide what we can and cannot do and what we are willing to risk and give up for it.

I am not saying that it is easy, but I think everybody in the Committee has been completely reasonable in saying that we are not trying to replace the stack; we are trying to talk about chokeholds and we are trying to be strategic. What we are really trying to do is make the country safe and secure and, dare I say, make it respond to its own laws. I do not think that anything that the Minister said has dealt with that fact. It was not asking for much to actually have a think about what strategy is and have a look at how we might get to a better place. Let us have a vision of where we want to go and work out how to get there. Individual things and departments and leaving things out is not the answer.

This is an easy amendment for the Government to say yes to and I hope that, by Report, they will. I beg leave to withdraw the amendment.

Cyber Security and Resilience (Network and Information Systems) Bill

(Limited Text - Ministerial Extracts only)

Read Full debate

This text is a record of ministerial contributions to a debate held as part of the Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 passage through Parliament.

In 1993, the House of Lords Pepper vs. Hart decision provided that statements made by Government Ministers may be taken as illustrative of legislative intent as to the interpretation of law.

This extract highlights statements made by Government Ministers along with contextual remarks by other members. The full debate can be read here

This information is provided by Parallel Parliament and does not comprise part of the offical record

If the Government do not believe that the UK Cyber Security Council should have the role proposed by Amendment 99, perhaps the Minister can tell us who is responsible for assessing the capability gap and what the Government intend to do about it.
Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness for her amendment, in particular her focus on the importance of the skills and competence of the UK cyber security professionals on whom we all rely and our economy will continue to rely. As the noble Lord, Lord Vaizey, said, an important aspect here is the spirit behind the noble Baroness’s amendment, with its focus on the skill set and professionalisation of these individuals, which we wholeheartedly agree is incredibly important.

I will focus on the council itself for a moment. It is an independent, royal chartered body that unites government, industry and other sectors to boost the professionalism of the entire cyber sector. The council does important work that already encompasses the majority of functions named in the amendment. It sets professional standards and maintains a register of the UK’s accredited cyber professionals. It establishes pathways for cyber professionals—experienced and new entrants—to have an easier route into quality cyber roles.

We disagree that there is a necessity to put this on a statutory footing. The Government consider the council to be akin to other professional bodies in the UK. Although there are some professional bodies with a statutory role and oversight by either government or Parliament, it is standard practice in technical fields for an organisation to be recognised through a royal charter and afforded operational independence from government. This includes the Engineering Council and the Science Council. Going down the route that the amendment proposes would undermine the council’s independence, and that could affect its relationship with the sector.

That is a separate point from the importance of the need to professionalise the cyber sector and the Government’s strong support for that. Indeed, the Government have committed to funding the UK Cyber Security Council over the spending review period until it becomes self-sustainable, working closely with stakeholders across the profession and wider workforce. We believe that professional standards, accreditation and professional titles in cyber security will improve our cyber resilience.

Moreover, to the points raised by the noble Lords, Lord Clement-Jones and Lord Markam, and others, the adequacy of skilled persons remains important. The Government’s TechFirst programme is helping to build the pipeline of talent for all frontier technologies and is available to all secondary schools across the UK. This month, approximately 1,300 undergraduate and master’s students are starting in the TechFirst scholarship programme, including over 300 students on a cyber security pathway.

On the question about how the Government monitor the adequacy of this, the Government publish annual data on the state of the UK cyber security workforce which shows that the supply of cyber skills is increasing. There is currently a net annual shortfall of approximately 3,800 people in the UK’s cyber security market. For the second year running, the workforce gap has remained markedly lower than our previous estimates, now 3,800, compared to 11,100 in 2023 and 14,100 in 2022. Focusing on the skills pipeline is incredibly important and something that the Government are backing.

Equally, the Government agree with the noble Baroness that regulatory authorities must have regard to the information and standards provided by the council. Indeed, we stated the need to align with council standards in the Government Cyber Action Plan. The Government have already worked with regulators to embed cyber security accreditation and professional standards into their guidance. We want to go further, which is why we intend to use the Bill’s powers to introduce security and resilience requirements in secondary legislation. These are designed to be consistent with the NCSC’s cyber assessment framework, and we propose that these requirements will address relevant training, skills and professional standards. We will consult on these proposals later in the year to ensure that the industries, large and small, covered by the regulated sectors will be able to feed back on this, as will the regulators which will be responsible in this area.

To the questions on SMEs raised by the noble Baroness, Lady Neville-Jones, whether inside or outside, whether they are or are not regulated entities, SMEs have access to NCSC and cyber resilience centres. I am sure that we will go on shortly, in the context of the noble Baroness’s subsequent amendment, to discuss further support that we can provide to those SMEs.

We are very committed to the role and function of the UK Cyber Security Council as a wide-reaching and effective independent body, and we continue to support skills development in the UK. As such, we are not convinced that there is a need to put the council on a statutory footing at this stage.

Baroness Northover Portrait Baroness Northover (LD)
- Hansard - - - Excerpts

I thank the Minister for her thoughtful reply and I thank other noble Lords for their support here. Clearly, we are all seeking to move in the same direction. There is a challenge and risks here that are incredibly important. Whether this is the right way forward, we will have to see.

I am very grateful to those organisations that fed into our Select Committee, which led me to table this amendment. This is an area that we will need to return to before Report, to look carefully at whether the drivers that the Minister has mentioned are sufficient. But at this stage, I beg leave to withdraw the amendment.

--- Later in debate ---
The best protection against a cyber attack is the behaviour of firms and their staff, and the best way to drive safe behaviour is through insurance. The collective cost of insurance is certainly no greater than that of a national cyber response service, and that cost is absorbed by those who benefit the most directly. All that said, I look forward to the Minister’s response.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness for her amendment and for linking the issue of cyber security with wider questions on national resilience; she is absolutely right to situate it in that space. I also thank her for introducing the topic of the right amount of cyber security support for the SMEs regulated under the Bill; indeed, the discussion has led to SMEs that are not regulated under the Bill.

We know that SMEs require dedicated cyber security support. That is why there are a wide range of free tools, guidance and training to help SMEs implement cyber security measures. These resources are available to any business, not just those regulated under the regime. As the noble Lord, Lord Vaizey, mentioned, this includes the Cyber Action Toolkit, designed to scale nationally to empower millions of small organisations through tailored cyber security advice with NCSC-certified cyber advisers. A number of noble Lords referenced the importance of Cyber Essentials, as well as insurance and incident response. If an SME with a turnover of less than ÂŁ20 million has Cyber Essentials, it also has cyber insurance cover of up to ÂŁ25,000. That incentive is intended to link the process of getting Cyber Essentials with the benefits of insurance. Likewise, SMEs get cyber incident support 24/7 with Cyber Essentials.

The noble Lords, Lord Vaizey, Lord Londesborough and Lord Birt, talked about the “push”. We are indeed encouraging, perhaps not pushing, the private sector to engage its supply chain through the cyber pledge, which is for entities outside the regulated scope. That is one of the key elements of the cyber pledge. Likewise, under the GCAP, the Government’s cyber action plan, Cyber Essentials, or equivalent, are needed for government procurements using official data. These are the mechanisms by which we are encouraging large organisations to look at their supply chains—on the point that the noble Lord, Lord Clement-Jones, made about the interconnectedness of all our organisations today—and encouraging the uptake of Cyber Essentials with these very tangible benefits.

I was asked a very fair question about the best way to provide cyber support to organisations. I heard at least one noble Lord say that SMEs do not like different provision. I think that many SMEs prefer—or, if asked, would request—local trusted advisers, which is exactly what the regional cyber resilience centres offer. They offer free support to SMEs across England and Wales, covering a wide range of services, such as incident response, a business continuity service and support with Cyber Essentials and security training.

The noble Lord, Lord Londesborough, made a point about a central, monolithic model compared with these local or regional models. There is a lot of merit in a regional model that has some common standards but is located much nearer to the SMEs that it serves. I reiterate that small and micro-organisations are exempt from being regulated as relevant digital service providers or relevant managed service providers. They can be regulated only if they are operators of essential services or designated as a critical supplier, for which there is a high bar. On the picture raised by the noble Lord, Lord Clement-Jones, we do not think that a huge number of small enterprises will be in scope of this legislation. All small businesses will benefit from the current provision, but they would not necessarily benefit from the model proposed by the amendment.

The amendment would also require the Secretary of State to have regard to international regimes. We are indeed aware of such schemes, such as the Australian Small Business Cyber Resilience Service. Many of the offerings that that service provides, such as tailored support and practical incident recovery support, already exist in the UK, as I have set out. We learn from international best practice, but we also tailor it to our local economy and the threats we see, to best support and meet the needs of UK businesses and interact with UK regulations.

I hope that I have set out that guidance for small and medium-sized organisations is already available through existing UK support. We are doing more to look at supply chains through discussions with large firms, through the GCAP and through this Bill. We think that a new dedicated service could divert resources from these existing services and potentially impact on their efficacy. On the central point that the noble Baroness started with, we absolutely agree with the importance of providing support to small and medium-sized enterprises under the Bill, ensuring that they have everything they need to be resilient and respond to incidents.

Baroness Northover Portrait Baroness Northover (LD)
- Hansard - - - Excerpts

I thank the Minister, and I thank noble Lords for their support. This is clearly an area where we agree that there is a problem; we are very vulnerable in the United Kingdom. What we have in place is clearly not working sufficiently well if 60% of SMEs that are hit by cyber attacks go under. That is the context in which we ought to look at proposals that might seek to address that. We clearly need to take SMEs forward in a way that does not overburden them.

I hear the point about extending insurance cover. We can indeed take more than one track, but there is a cost to not supporting SMEs. If they are going to go under, that will be an economic cost to the country and, if we do not support them, they are likely to be hit by cyber attacks, taking them and others under anyway, with that effect upon our economy. Clearly, the Government agree—hence putting in place the measures that the Minister has outlined.

I am suggesting, from the evidence we have received, that this needs to go further and faster. We can discuss exactly how, but it is clear that this is an escalating problem and that we need to do more to tackle it. That is on the basis, in particular, of the concerns expressed to the National Resilience Committee on which I serve and which, as I say, gave me the idea of putting this amendment forward. I think that we will need to return to this, because it is a major problem, but, in the meantime, I beg leave to withdraw the amendment.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this important group and all noble Lords for their contributions. Beginning with Amendment 148A, it is reasonable to suggest that there should be a further right to appeal, given that we are talking about potentially large penalties of ÂŁ17 million or 10% of annual turnover. But, like my noble friend Lord Vaizey, I have concerns about whether the Upper Tribunal system can handle such a process. Right now, it has an open case load of over 800,000, which is a 19% year-on-year increase, and disposals have decreased by 4%. As such, I am hesitant to offer my support without being assured that further pressure will not be placed on tribunals and that this is a workable mechanism.

Amendments 174A and 174B, in my name and those of my noble friends Lord Camrose and Lord Holmes of Richmond, would require the Secretary of State to establish a register of foreign powers posing a cyber security risk to this country, and to review and report on the extent of the risk posed by powers on that list. Part 4 gives the Secretary of State significant new powers to intervene where the use of vendors’ goods and services or facilities pose a risk to national security. We support that objective. A power of that kind is only as good as the intelligence that informs it. At present, the Bill is silent on how the Secretary of State is to identify, in a systematic and transparent way, which foreign powers actually present that risk.

Amendment 174A aims to fill that information gap, outlining a thorough set of criteria for inclusion: a state confirmed by GCHQ to have perpetrated or attempted a cyber attack against the UK in the preceding seven years—one directed at an operator of an essential service or a critical supplier and carried out through a state department, agency or affiliate—or a state that GCHQ has separately warned poses a risk to such systems.

The importance of ensuring that we are fully informed of foreign threats can hardly be overstated. Just this year, the NCSC’s chief executive reported that three-quarters of all attacks on our critical national infrastructure over the preceding 12 months were carried out by hostile states, with Russia, China and Iran named specifically. The NCSC’s annual review recorded 204 nationally significant incidents in the year to August 2025—more than double the previous year, with 18 rated highly significant.

For illustration, the cyber attack that last month shut down a British power plant is reported to have been committed by Iran-backed hackers. Over the course of the last Parliament and this one, China has targeted Parliament and compromised the Electoral Commission; Russia’s FSB has targeted British parliamentarians and successfully stolen and leaked politically sensitive documents; and Iranian state actors have targeted British politicians, Governments and defence with sustained cyber espionage campaigns.

We are seeing a surge in cyber attacks driven largely by foreign threats. If the Government are serious about security and resilience, tackling foreign interference must be a priority. As a start, a published criteria-based register would bring much-needed transparency and rigour to the process. Amendment 174B seeks to achieve such transparency. It would require the Secretary of State, for each foreign power added to the register, to conduct a review of the extent and nature of the risk that that power poses. It also includes a built-in safeguard for the Government: where the Secretary of State considers that laying their report would be contrary to national security interests, they may instead make a Statement to Parliament confirming that the review has taken place and explaining that it cannot be published. It attempts to strike a balance between accountability and the sensitivities that intelligence assessment of this kind will naturally carry.

I anticipate that the Minister may say that such a register already exists in substance within government and that formalising and publishing it risks informing those very powers of the extent of our knowledge. I gently observe that the amendment does not require publication of intelligence sources, substance or methods—only the fact of designation against published criteria and a review to assess the risk. Given the scale of the threat that the NCSC describes and, given the very significant powers that this part confers on the Secretary of State, I believe that Parliament is entitled to ask that those powers rest on a clear, evidenced and reviewable basis. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments, starting with Amendment 148A, from the noble Lord, Lord Clement-Jones, which indeed is in line with the recommendation from the Constitution Committee, which I thank for its report and its detailed scrutiny of this legislation.

As the noble Lord points out, Part 4 enables the Secretary of State to issue penalties for regulated entities that do not comply with directions. The High Court will have jurisdiction to review the lawfulness of a particular penalty issued under Part 4. The noble Lord, Lord Vaizey, referred to precedent and consistency. Our assessment is that the High Court is the appropriate route for hearing sensitive national security cases, consistent with the approach that previous Governments have taken to national security legislation. The Telecommunications (Security) Act, the National Security and Investment Act, and the Procurement Act, key pieces of national security legislation, all follow this approach. That is the reason we have adopted it here.

To the point around parliamentary scrutiny of directions, the Government’s default position is that copies of directions will be laid in Parliament, to enable all parliamentarians to scrutinise the Government’s use of these powers. I am of course preparing a formal response to the Constitution Committee, which will be sent in due course.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I resume with Amendments 174A and 174B, which were introduced by the noble Lord, Lord Markham. They would require the Secretary of State to create a register of “foreign powers” that pose a threat to UK cyber security, to review this register and to lay the report in Parliament. This is intended to inform the use of the powers granted under Part 4 of the Bill. The noble Lord is right that hostile foreign actors pose a clear risk to our essential services. National security is the first responsibility of any Government, which is why we are addressing these risks actively, including through the Bill.

The Bill will grant the Secretary of State important new powers to issue national security directions to regulated entities or regulators, where their compromise poses a national security risk. We will seek to strengthen the Government’s national security toolkit further, to protect our supply chains from hostile actors. That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.

Any decision to use the powers in the Bill will be informed by expert national security advice, including from GCHQ. The direction powers provide a strategic case-by-case basis to safeguarding our national security, irrespective of the specific actor. As a result, a country-specific approach lacks the nuance required to assess and respond comprehensively to all relevant risks. We also need to proceed responsibly in how we categorise and present these risks in the public sphere.

That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber risks where it is appropriate to do so. As the noble Lord, Lord Markham, set out, the NCSC annual report highlights risks posed by foreign actors; we work with the NCSC to mitigate these risks.

I note that noble Lords have confronted this question before, notably during the passage of the Telecommunications (Security) Act, where there was cross-party support for vendors to be assessed on a case-by-case basis, rather than by designating nations themselves as hostile actors. I hope that, in that vein, noble Lords are reassured that the Government have the tools to act strategically, acting on the right intelligence where hostile states seek to do us harm.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I thank the Minister for her response and the noble Lords, Lord Vaizey and Lord Markham, for their contributions. I cannot help feeling that the approach to this by the noble Lord, Lord Vaizey, is coloured by his history as a Minister. I can understand that because I saw the frustration within Ofcom over the type of judicial review. It was a particular type of judicial review: it was not a full merits-based appeal, but it allowed merits to be considered as part of the judicial review process. Subsequently, that was changed, which has probably calmed the way in which appeals are carried on.

However, in this particular case, although he said that he was not sighted as to the secrecy aspects of this, it was quite interesting to hear what the noble Lord, Lord Markham, had to say. He started by saying that he supported the amendment, then—rather coloured, I think, by the response of the noble Lord, Lord Vaizey—he did a bit of a U-turn halfway through what was a speech originally written in support. I am sure that he knows in his heart that this is the right one.

Really, the argument in this case is expediency versus justice. I think that choosing expediency, especially in the light of what the Constitution Committee had to say, would be extremely inadvisable. I was encouraged by the fact that the Minister is producing a memorandum in response to the Constitution Committee; we all wait with bated breath for when that arrives. In the meantime, I beg leave to withdraw my amendment.

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this amendment and the noble Lord, Lord Arbuthnot of Edrom, whom I see in his place. I am sorry he was unable to attend the beginning of this debate, but we are told it was for very good reasons. I will not try to reproduce the many overwhelmingly powerful arguments that we have heard in favour of this amendment, which, on these Benches, we are also keen to support—as we support any measure on the basis that it would help organisations to protect themselves and their systems.

Penetration testing and the wonderfully named bug bounties are excellent ways to identify and address the more technically difficult vulnerabilities before they are exploited. Take one of the most widely used apps anywhere: Google Chrome, which has found that external researchers were responsible for almost a third of its patched and communicated vulnerabilities. The Government’s own consultation included respondents arguing that the Computer Misuse Act prevents cyber professionals, consumer groups and researchers undertaking this kind of legitimate public interest activity.

The amendment is wholly sensible in its design, in that it does not commit the Government to action but begins the conversation on this small but hugely important and valuable change, supported avidly, as we have heard, by everybody—more or less—within the cyber industry. It would explicitly condone good faith researchers and sanction ethical hackers to carry out their work. I cannot imagine why it would not at least be worth reviewing such a change on this basis.

I have some unsatisfied curiosity, as there are no published statistics showing how many Computer Misuse Act investigations, prosecutions or convictions involve good faith cyber security researchers, so it is hard to know how much of a dampening effect on ethical hacking the CMA is currently having. If any of the signatories to the amendment, or of course the Minister herself, could shed any statistical light on that, I would be most grateful. As I said, this amendment would allow all such considerations to be taken into account without committing the Government and, as such, I strongly support it.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.

The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.

The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I thank the Minister for that response. The noble Lord, Lord Vaizey, said that we know what the Minister will say: that it will be in a future piece of legislation. To that extent, we are pleased that at least we have a commitment to it, but this has been going on for an awfully long time. We tabled amendments during the passage of the Crime and Policing Act and the Data (Use and Access) Act. There has been plenty of time for the Home Office, or any other department to address this—DSIT could have taken this by the scruff of the neck—because it is such an egregious aspect of the current legislation.

I am pleased to hear that the Minister has read the correspondence. I hope she did not fall asleep while doing so; it is pretty interminable. She may well find that we come back to this on Report because, as she said at the beginning, feelings are running high about it. It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.

I thank noble Lords who have spoken today and demonstrated support across the board. On a light-hearted note, I say to the noble Lord, Lord Tarassenko, that of course Claude said that; it is trained on my speeches. As the noble Baroness, Lady Harding, said, this is self-evidently sensible. The trouble is, it is self-evident to us, but we despair sometimes, and the perfect must not be the enemy of the good. As the noble Baroness, Lady Neville-Jones, said, the objective is to put researchers in a safe position.

Finally, the noble Lord, Lord Vaizey, exhorted me to make sure that we have a date and a timeline. When will the national security Bill come forward? We saw it in the King’s Speech but I have had no contact from anybody in the Home Office about what they might insert in the Bill. I do not know whether anybody in this Committee has had notice of when a Bill might come forward. I think the Minister recognises the sheer impatience that most of us feel in this field, and I very much hope that, between Committee and Report, we can get some more clarity in this area for the benefit of all those researchers. In the meantime, I beg leave to withdraw the amendment.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, despite the fact that this is the last group, it is a really important area and this amendment rightly reflects that. We strongly support Amendment 174E. It would introduce a fundamentally elegant and highly necessary cyber security principle that the Bill has otherwise completely ignored: that of data minimisation and the proactive reduction of what is called our national data attack surface.

The most sophisticated cyber defence system in the world cannot protect data that has already been stolen. Conversely, the most ruthless ransomware gang or hostile state-sponsored actor cannot compromise data that was never collected or which has already been securely deleted. In the realm of digital defence, we must move past the narrow defensive mindset of simply building thicker walls around our databases. We must begin to ask a more fundamental strategic question: why are we keeping these massive, un-anonymised and highly vulnerable data honeypots in the first place?

The empirical evidence from our public sector is deeply alarming. We have received detailed and coruscating briefings from the Centre for Long-Term Resilience and our technical authorities. The National Audit Office’s January 2025 report on government cyber resilience revealed that approximately 28% of government technology is legacy software, leaving our public bodies highly vulnerable to attack.

Consider the catastrophic ransomware attack on the British Library in October 2023. When the library refused to pay a ransom of 20 bitcoins, the Rhysida ransomware group released 600 gigabytes of stolen customer and staff data on to the dark web. The library’s own subsequent post-mortem was clear: its reliance on legacy applications and older network designs substantially and unnecessarily increased the volume of sensitive customer data sitting on the network. This was data hoarding, plain and simple, and the price was paid by the British citizens whose personal details are now permanently compromised.

Consider the hack by ExfilSquad, when normal teenagers living with their parents managed to breach a public database, leaking the sensitive personal details of 100,000 police officers and staff on the dark web, alongside data from the Ministry of Defence and the Department for Education. How did they do it? They did not deploy supercomputers or advanced zero-day exploits, they simply exploited a basic, misconfigured Power Pages database. The hackers’ own boast on the dark web was chilling. They said the data was accessible without any authentication whatever.

Why are these databases so large? Because our public bodies routinely collect and indefinitely retain vast, sprawling, unanonymised datasets, from birth certificates and benefit records to housing benefits and electoral roles, without any systematic statutory drive to minimise or anonymise them. That is why the Association of British Insurers and the NCSC both advise that data encryption and data minimisation are critical to reducing the leverage that a threat actor has in ransomware attacks. By rendering exfiltrated data unreadable through encryption—or better yet, non-existent through deletion—we take away the hackers’ ammunition.

While the Bill focuses heavily on the administrative paper exercise of incident reporting, it remains completely silent on the contents of the databases themselves. Amendment 174E would provide a strategic corrective. It would legally oblige the Secretary of State to open a public consultation within one month of the Bill’s passing to evaluate the cyber-resilience benefits of minimising data collection and increasing data anonymisation across our public bodies. By forcing our public sector to lead by example, this amendment could begin the vital work of shifting the UK towards a genuine resilience-by-design model. It would reduce our vulnerability, harden our national defences and protect the digital lives of our citizens. I urge the Minister to accept this vital safeguard.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security. 

Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.

Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.

As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on.

I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

In the spirit of her final remarks on the Bill overall, is the Minister able to give any update as to when the national cyber action plan might emerge?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I have nothing further to add what I have said in previous sittings.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

Nice try. I will get the final word then. First, I thank the noble Lord, Lord Clement-Jones, for his strong support. Honey pot is a very descriptive and apt term for it. I thank the Minister for her comments and will definitely take up her offer of a meeting. I must admit that the responses she gave were almost exactly the responses that the NHS gave to me on all this, so she is absolutely right: everything is being kept under GDPR. Data security and how that is held were mentioned quite a few times, but I did not hear anything about data minimisation and why we are collecting or keeping it in the first place. That is a gap in all of this because, as I said, a lot of this data does not need to be held or gathered in that way. It is just basic discipline. I would very much like to take up that offer on how we can do that, because—perhaps the Minister can look at this ahead of our meeting—I do not think this issue is addressed anywhere in the Bill.

I do get the last word. I thank everyone who has taken part in this. There have been a number of important issues raised. I really appreciate the willingness of the Minister to engage, and I know there are a number of follow-up meetings that I think we will all want, because there is a lot that we need to work on between now and Report to make sure that the Bill really gives us the sort of protection we would all hope to have. I beg leave to withdraw my amendment.