(4 weeks, 1 day ago)
Lords Chamber
Baroness Lloyd of Effra
That the Bill be now read a second time.
Northern Ireland, Scottish and Welsh legislative consent sought. Relevant document: 3rd Report from the Constitution Committee
The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
My Lords, we are a proudly online nation, embracing interconnectivity in all walks of life. Cloud-based working, the rise of software as a service, the advent of artificial intelligence and more have rocketed the UK forward. They have enabled us to work faster, more efficiently and with more flexibility than ever before.
However, with these advancements come risks. As the technology powering our modern economy has leapt forward, so too have the tools that our adversaries use to extort, disrupt and surveil. Last year, more than 600,000 UK businesses were subject to cyber attacks. This is not only holding businesses back; it is undermining our security. These are criminals and hostile state actors seeking to disrupt the very foundations of our country.
The UK is now the most targeted country in Europe for cyber attacks. It is the duty of this Government to take bold action. We have been clear that all businesses must protect themselves from cyber attacks, but this does not mean regulating every single business. They know their customers and their suppliers, and they are best placed to protect themselves, using the free tools that we have provided.
I commend those who have already signed our Cyber Resilience Pledge, and urge more to do so, committing to take the three simple steps recommended in it: making cyber a board-level responsibility and following the cyber governance code of practice; signing up to the National Cyber Security Centre’s early warning service; and taking a risk-based approach to requiring Cyber Essentials across supply chains. This is our government certification scheme to help organisations improve their cyber resilience. Cyber Essentials works. Organisations with it are 92% less likely to claim on their cyber insurance than those without it. Taking these steps can make a huge difference.
However, where the risks are so great that public safety, the economy or our national security is threatened, it is right that we regulate. The Network and Information Systems—NIS—Regulations 2018 are the UK’s only cross-sector cyber legislation. They apply to operators of essential services in the energy, health, transport, drinking water and digital infrastructure sectors, as well as some digital service providers. The NIS regulations are designed to protect the security and resilience of our most essential services, to keep lights on, to ensure that taps keep running and to protect our NHS. We regulate only where we must, which is why the scope of the NIS regulations is precise. They are a targeted security intervention and the best tool in our arsenal to protect our most essential services. However, the regulations have fallen out of date. If we do not act, the essential services on which we all depend will remain under threat.
That is why we have introduced the Bill. The Cyber Security and Resilience (Network and Information Systems) Bill is a vital opportunity to improve the UK’s defences. In fact, it is the first Bill in British history to have “cyber” in its title. It will update the NIS regulations for the modern age and ensure that the Government can maintain their effectiveness and respond to imminent national security threats.
The objectives behind the Bill are threefold. First, it will safeguard the services on which our people rely most, making our essential and digital services more secure. Secondly, it will deliver a step change in our national security, improving our defences against the cyber attacks that threaten this country. Thirdly, it will better protect our economy. The UK will be a safer and more attractive place for businesses to establish themselves, thrive and grow.
The Bill will achieve these objectives through proportionate and timely measures, which I will speak to in turn. First, the Bill brings more sectors into scope of the NIS regulations. As our economy becomes more interconnected, so do the routes that cyber criminals exploit. For example, data centres in the UK have become critical to nearly all our economic activity and public services. From NHS patient records to financial systems, these vast digital depots are a key part of the modern world. That is why data centres meeting the Bill’s thresholds will be regulated as essential services, ensuring that they take steps to secure their networks.
The Bill also brings large load controllers under regulation. These are organisations that manage significant electricity flows to or from smart appliances. They must be safeguarded to secure our electrical grid and protect consumers using such appliances.
We are also bringing large and medium managed service providers—MSPs—into scope of the NIS regulations. These are organisations offering ongoing services, such as remote IT support or cyber security threat management, to customers. MSPs have deep access into their customers’ systems. As more and more organisations rely on them, MSPs become an increasingly attractive entry point for disruption.
Noble Lords will remember last April’s cyber attack on M&S. It involved a managed service provider being socially engineered, with attackers being able to gain access and compromise systems. We need to close this gap. But these regulations must be proportionate and targeted. Large and medium MSPs comprise fewer than one in 10 of the MSPs active in the UK but account for around 97.6% of the UK’s MSP revenue, so small and micro MSPs will be exempt from this measure. By targeting regulation where the risk and reach are greatest, we will protect almost all MSP customers without burdening small businesses.
In limited circumstances, small and micro-businesses supply critical goods or services to the essential and digital services on which we rely. The Bill therefore enables businesses, including smaller companies, supplying critical goods or services to be designated as “critical suppliers”. This is designed to combat the cyber risks stemming from increasingly complex supply chains.
Members may be aware of the 2024 attack on Synnovis, a pathology provider to some NHS trusts. Criminals thousands of miles away deployed ransomware and made Synnovis’s files unusable, delaying 11,000 appointments. This demonstrates the ripple effect that a compromised supply chain can have on the services at the ends. Duties that critical suppliers will be subject to will be set out in secondary legislation.
I turn to our 12 NIS regulators, whose sectoral expertise is critical to protecting our essential and digital services. These regulators are often operating with one hand tied behind their backs. They do not have the information, resources or levers necessary to properly fulfil their duties. For instance, organisations need only tell their regulator about an incident once it has already caused significant disruption. Under the Bill, they will have to report more types of breaches, to their regulator and the NCSC, within 24 hours and provide a full report within 72 hours. This includes incidents such as pre-positioning and ransomware, where an incident may not cause immediate damage but poses a real threat to the UK economy or society.
This will not only enable the NCSC to support those affected more quickly and warn others but allow the Government to better understand the threat landscape. Furthermore, the Bill requires digital and managed service providers and data centres to inform their customers about reportable incidents that are likely to adversely affect them. This way, customers can take appropriate steps to protect themselves.
However, effective reporting must be matched by consistency. Our 12 regulators cover all NIS sectors and the UK’s four nations. We must utilise their sectoral expertise but ensure that the rules are applied consistently. We cannot allow any sector to become an easy target. This Bill enables government to designate a single set of strategic priorities, as well as objectives tied to them, that regulators must seek to achieve. This will complement the security and resilience requirements, to come in secondary legislation, setting clear, consistent expectations and putting good practice on a firmer footing.
The Secretary of State will be required to consult the regulators on a draft of the statement before designating it. In addition, the Bill gives regulators new powers to recover their full regulatory costs from the organisations that they oversee. This includes enforcement costs, ensuring that this is not conducted to the detriment of a regulator’s books. Regulators must consult on how these fees will be calculated and publish a yearly statement to show how these funds were used.
The Bill also raises the maximum penalty enforceable for regulatory breaches while simplifying the penalty bands for easier, more consistent application. Regulators must consider all circumstances of a case before setting a penalty. This is not designed to punish companies but to incentivise their compliance. The ideal scenario is no penalties at all.
We are also fixing legacy issues concerning information sharing, so regulators can better understand what can and cannot be shared and with whom. All information shared must meet a specified purpose or require permission to be shared and be relevant and proportionate to the purpose for which it is shared. This Bill unties our regulators’ hands, giving them the information, resources and powers that they need to hold the line. That is what effective regulation should look like.
Finally, the Bill contains some important measures to enable future resilience, ensuring that the NIS regulations remain effective into the future. This Bill introduces a targeted, essential set of delegated powers to enable the NIS regulations to keep pace with the ever-changing cyber landscape. These include powers by which the Government can bring new services or sectors into scope of the regulations, so long as they meet the Bill’s strict criteria, or make regulations to further mitigate the risks from security and operational compromises. In the majority of cases, these delegated powers will be subject to consultation and the affirmative procedure will apply. Today’s threats were unimaginable in 2018, so we must not legislate as though today’s threats will stand still. These are carefully targeted, and it would be remiss not to take this opportunity to provide for careful, proportionate delegated powers. In almost all cases of these powers, the Government must consult on any changes. Parliament will still have the final say over legislation made under these powers. Our delegated powers memorandum contains greater detail.
In exceptional cases, even secondary legislation is too slow. Right now, if our intelligence community becomes aware of a NIS incident that threatens our national security, the Government have no emergency power within the NIS regulations to protect our people. This Bill provides powers for the Secretary of State to direct regulators and regulated entities where national security is threatened. This could entail instructing a sector to follow new guidance in response to a crisis or requiring an organisation to take technical steps to remove an intruder from a network. These are essential last-resort levers. The Bill has strong safeguards to ensure that they are used accordingly and only where strictly necessary for national security.
This Bill is about protecting the foundations of a modern economy. Growth cannot flourish where essential services are vulnerable, where businesses are exposed to disruption and where hostile actors can exploit weaknesses. We are not choosing between security and growth; we are recognising that one depends on the other. This will help secure the services that our people rely on, give businesses the confidence to invest and grow and strengthen our national security in an increasingly dangerous world. I beg to move.
The Earl of Effingham (Con)
My Lords, I thank the Minister for introducing the Bill before your Lordships’ House this afternoon. His Majesty’s loyal Opposition support the objective which lies behind this legislation. The cyber threat facing the UK is growing incrementally, both in scale and in sophistication. From hostile states to organised crime, from ransomware attacks on our public services to increasingly complex attacks on critical national infrastructure, the need to strengthen our national resilience is indisputable.
Many noble Lords will be familiar with a number of reforms contained within this Bill, predominantly because they originate from the review of the Network and Information Systems Regulations undertaken by the previous Conservative Government following the consultation that was launched in 2022. It should not be a surprise that we welcome measures to improve consistency across the various regulators responsible for enforcing the existing regime. However, support for the objectives of a Bill should never prevent your Lordships’ House from asking whether the legislation is sufficient and proportionate.
Most importantly, noble Lords would be right to constructively challenge whether this legislation forms part of a coherent strategy. That should be a central question. We are being asked to scrutinise and revise one of the fastest-moving areas of public policy without the Government having first published the cyber strategy within which these measures are intended to sit. Ministers have described this Bill as merely one component of a wider programme to strengthen Britain’s cyber resilience, so it is entirely fair and reasonable to ask, “Where exactly is that programme? Where is the strategy? Where is the explanation of how these powers fit within the Government’s broader approach to protecting our digital economy and our critical national infrastructure?”
Only last Thursday, we heard an Oral Question on the impact of AI in vaccine technology. It is obvious to all that AI is, regrettably, also transforming how cyber attacks are conducted, increasing both their scale and their sophistication. Hostile states have become more aggressive. Organised crime has become more capable. The boundary between economic security and national security has become ever more blurred. Yet little of that ever-shifting landscape appears to find expression within the Bill itself. In fact, artificial intelligence does not appear to feature in the legislation. Quantum cracking does not feature. Weaponised disinformation does not feature. The wider question of how government intends to respond to AI-enabled cyber threats remains unanswered. Nor does the Bill address the long-standing concerns surrounding the Computer Misuse Act, despite repeated calls from the industry for reforms that better reflect modern cyber security practice and remove the legal uncertainty facing legitimate cyber security researchers.
Legislation in this field is unlikely to come before Parliament every year. That places a particular responsibility on noble Lords now to ensure that what is enacted today remains relevant, as much as it realistically can be, tomorrow.
The Government have shown an enthusiasm for regulation across a number of sectors. Sometimes regulation is necessary; sometimes it is unavoidable; but good regulation should always be proportionate. This is especially true when it comes to firms that are already navigating an increasingly complex regulatory environment and face ever more costly obligations under the Government’s direct and indirect taxing of small businesses. The Bill introduces new obligations, new reporting requirements and new compliance duties for organisations operating in sectors that are undoubtedly important to our national resilience.
It may be the case that some of this regulation is justified. However, it also raises many questions for the Opposition, the most pressing of which is: what assessment have the Government made of the cumulative regulatory burden these measures will impose on businesses? Many organisations are already subject to reporting requirements under data protection legislation, sector-specific regulation and forthcoming proposals concerning ransomware reporting. If these various obligations are not properly aligned, businesses risk finding themselves complying with multiple reporting regimes for what is in reality the same cyber incident. This would not strengthen resilience but rather create additional bureaucracy during a time of crisis.
Nowhere is this of greater concern than for small and medium-sized enterprises. Large multinational organisations generally possess dedicated legal and compliance teams and cyber specialists capable of navigating increasingly complex regulatory requirements. Smaller businesses simply do not have the resources to do that, and often these businesses are the very scale-ups and high-growth companies upon which our future economic prosperity and unicorn status depends.
Everyone wants economic growth—none more so than His Majesty’s loyal Opposition—but if the Government want growth, they must ensure that cyber regulation does not become yet another barrier to enterprise and innovation. Will the Minister therefore confirm to your Lordships’ House that the overwhelming majority of SMEs will remain outside the scope of these new regulatory requirements? By what benchmark will an SME be defined in the legislation? Will the Minister please explain what support, alongside the new obligations, the Government intend to provide for those smaller organisations that may ultimately fall within the regime? Resilience cannot simply be legislated into existence; it requires expertise and resources.
The Bill grants significant new responsibilities to regulators operating across a wide range of sectors. For these provisions to operate successfully, the legislation assumes that such regulators possess both operational capacity and the expertise necessary to exercise those responsibilities effectively. Will the Minister outline how these assumptions have been stress-tested?
Finally, the Bill confers important national security powers on the Secretary of State. Although these powers may well prove necessary, they also reinforce the importance of transparency. The exercise of national security powers should be informed by clear principles and robust accountability, particularly where they concern hostile foreign actors seeking to undermine our critical infrastructure. Will the Minister inform the House what mechanisms are going to be in place to ensure such accountability?
His Majesty’s loyal Opposition do not dispute that the cyber threat facing our country is real; nor do we dispute that the Network and Information Systems Regulations require updating. Indeed, much of the work underpinning this Bill was initiated by the previous Conservative Government. But surely we need a strategic framework instead of having to ask: why these sectors, why these thresholds and why these powers, and how does this legislation fit alongside artificial intelligence, ransomware policy, national resilience and wider cyber reform? These are not unreasonable questions. They are precisely the questions that a responsible analysis of a slew of updated proposals require, and we ask the Government to provide the strategic context which accompanies the Bill before us.
My Lords, I too thank the noble Baroness for introducing the Bill. From these Benches we welcome the Bill, but we feel that in a number of ways it does not go far enough. Hostile state actors, organised crime and others are increasingly targeting our systems at every level with potentially catastrophic effects, as previous speakers have said. Attacks on our energy networks, water supplies, transport systems, financial infrastructure and digital services are becoming more frequent. It is clearly vital that organisations that deliver essential services have high standards of cyber security and that they should report serious incidents promptly and transparently. We also recognise that the coverage of those who need to report in this way should be widened. However, is the Bill ambitious enough?
I serve on the House of Lords Select Committee on National Resilience—there is at least one other speaker in the debate who also serves on that Select Committee—and I will draw here from some of the evidence that has been submitted to us. We were, of course, part of the EU arrangements until Brexit, and this is yet another area we needed to address after that. That resulted in the 2018 regulations, which this Bill seeks to update. The post-Brexit arrangements seem to have complicated putting in place clear primary legislation. The Minister in the Commons noted that Brussels is pressing ahead with its own updates “while we lag behind”. He stated that this
“procedural quirk has left essential UK services more exposed, which perhaps tells us something about why the UK has such appalling figures compared with some of our EU counterparts, as hackers and cyber criminals exploit gaps in our dated laws”.—[Official Report, Commons, 6/1/26; col. 179.]
We do indeed have the worst record in Europe for such attacks. I would argue, from submissions we received to our Select Committee, that it makes most sense for us to be aligned with the EU regulations. It has been put to us that this would mean that organisations do not need to answer to two sets of regulations in Europe. It is clear that this would assist us anyway, given that the EU regulations cover a wider range of areas, which it makes little sense to overlook as the Government appear to be doing. As it was put to us by ISC2,
“the government may have missed an opportunity to have the same taxonomy of CNI across jurisdictions. For example, the EU’s NIS2 directive on cybersecurity includes manufacturing, public administration and food production … These sectors are critical for the UK’s national and economic resilience. Under the proposed regime manufacturers operating across the UK and the EU, when victim of a cybersecurity incident in the UK, will be mandated to report”
this to EU authorities but not to the UK.
One of the submissions notes that the Bill is narrow in scope:
“large parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Government’s approach to … these unregulated sectors relies primarily on voluntary governance mechanisms, including its new Cyber Governance Code of Practice”—
although we have seen that yet. The submission argues:
“Without stronger incentives, measurement and accountability, there is a risk that this … will not deliver consistent or meaningful improvements”.
It warns:
“This creates a disconnect between the regulated NIS economy and the wider, unregulated economy, despite risks flowing directly between them”.
We know the wide, deep and prolonged effect of cyber attacks on M&S, JLR and Synnovis, yet JLR and M&S will be out of the scope of the Bill, as the Commons Minister himself noted. Surely, we need to take a whole-of-economy approach. We should surely include the public sector, and economically significant sectors such as retail and manufacturing.
In evidence to our Select Committee, UK Defence First also argued that the potential loss of control of satellite communications is a “severe” national risk and that the Bill should
“explicitly treat space assets as critical national infrastructure”.
Could the Minister comment?
DSIT has estimated that significant cyber attacks on businesses cost the UK almost £15 billion in 2024. The National Cyber Security Centre reported that nationally significant cyber incidents had more than doubled in a year. As ISC2 says:
“It is no longer a question of if an organisation will be attacked, but when”.
ISACA, a global professional association focused on this area, emphasises:
“Digital service providers, particularly cloud infrastructure, also represent a growing concentration of systemic risk. The financial sector is increasingly reliant on a small number of cloud providers, creating potential single points of failure across critical services. For example, evidence presented to the Treasury Committee highlighted that 73% of UK cloud services are provided by just three providers”.
ISACA also warns:
“Cyber risk is inherently systemic, meaning disruption is rarely confined to a single organisation or sector, but is increasingly transmitted through supply chains, shared infrastructure and third-party dependencies”,
which the Minister made reference to. According to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain.
In addition, it is reported that many SMEs may perceive that they are too small to be a target, yet government research has found that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for small businesses, a cyber incident can be existential: roughly 60% of SMEs that fall victim to a cyber attack go out of business in six months. It is all very well, as the noble Earl just indicated, being outside regulation here if our SMEs simply go to the wall as a result of inadequate preparation and protection.
Evidence to our Select Committee suggests that skills shortages are a key challenge for companies, especially SMEs and those in the public sector. Is that why the Government have not included them here? That leaves our economy wide open; that is surely not the right answer. Cyber education, training, apprenticeships and investment in skills must accompany regulatory reforms, and the regulators themselves will need to be properly resourced so that they can deal with their new responsibilities. We know that public bodies have often found themselves dependent on ageing digital systems, with the risks from that.
We also need to recognise the need for the highest level of leadership in this area in companies and other organisations. It cannot simply be left to IT departments: cyber security must now be a major consideration at board level. We also need leadership from the Government, working with allies on intelligence sharing, common standards, co-ordinated responses to hostile activity, and co-operation on investigation. We know we face increasing attacks from rogue states: it is spoken of now as being low-level warfare, and we have seen the effect in many other countries as democracies are under attack.
In conclusion, although we welcome the Bill, we are seriously concerned about its limitations. A start would be to align with the EU, which already recognises that a whole-of-economy approach is the right one. I look forward to the Minister’s response.
My Lords, the Government’s own cyber survey reports that 43% of UK businesses experienced a cyber attack last year, costing the UK economy an estimated £15 billion. Here are just a few examples of those many attacks: a deepfake video call cost Arup £20 million; Marks & Spencer was attacked in Easter last year, losing an estimated £300 million, with operations fully restored only three months later; and, most impactful of all so far, Jaguar Land Rover suffered an attack, had to halt production for around five weeks, was unable fully to restore its supply chains for four months and lost around £500 million. Moreover, the Government had to step in and guarantee a loan of £1.5 billion to stabilise JLR’s extensive supply chain. Yet our economy is barely touched by the Bill, as the noble Baroness, Lady Northover, just identified.
I think that a lot of people, untutored, have a mental model of a technology platform as something you might offload off the back of an HGV; in reality, any technology platform, even in a medium-sized business, can be a highly complex network composed of hundreds of providers, any component of which can present a vulnerability. Just two examples among very many are the widespread reliance by providers on free-to-use but vulnerable open-source software maintained by volunteers, and the external software providers bolted on to a technology platform offering a myriad of services —for example, payroll, finance, logistics, e-commerce or customer relationship management.
There is a possible vulnerability in every part of this complex network of providers, with many doors to pry open. Once one door is opened by a bad actor—a fraudster, a foreign power, a hacktivist or a ransom gang—there is the potential to explore and disable much or all of the system. Entry can be through a clever phishing email, perhaps AI-personalised with stolen data, or through application, network and infrastructure vendors failing to close down vulnerabilities immediately they are identified.
Here is a frightening example: a Chinese entity was able to penetrate a large number of services provided by Microsoft to the US Government. As a result, the mailboxes of the Secretary of Commerce and the US ambassador to China, among many, were read. In a coruscating report, the Cyber Safety Review Board, the US government agency that investigated the breach, concluded that
“Microsoft’s security culture was inadequate”
and that the incident resulted from
“the cascade of Microsoft’s avoidable errors”.
We need to act now, to protect our wider economy as well as our public sector institutions.
I am not a technologist, but for three decades I have had to deal constantly with digital technologies and technologists from a position of authority in many large organisations in the public and private sectors, at national, European and global level. I have discussed the Bill extensively with technology and cyber experts who I know and respect, and it has become perfectly clear to me that the Bill as constructed does not begin to match the threats that we in the UK face, which will only grow.
For instance, AI will increasingly empower malign reconnaissance, enabling attacks that probe, diagnose and bypass defences. At some point, quantum computing, with its awesome power, will fatally undermine our current approach to encryption. This is a highly demanding and ever-changing environment, and it is, frankly, preposterous to suppose that the 12 existing sector-specific regulators of our national infrastructure can acquire and constantly update the knowledge effectively to regulate cyber resilience.
I conclude emphatically that we need a single, focused, dedicated and expert regulator, which I suggest we call the office for cyber resilience—OCR—to span both the public and private sectors, including organisations and, vitally, those who supply them with the technologies they use. For clarity, the OCR should also regulate the national infrastructure providers.
First, I propose that the OCR should regulate platform and software providers to ensure that they sell and vouchsafe secure products up front and update them immediately when vulnerabilities become apparent. That does not happen at the moment. The Office for Product Safety and Standards does that in the UK for consumer goods and the Vehicle Certification Agency does it for cars. Why should there not be protection for our vital technology?
Secondly, companies and institutions of a significant size are currently required under statute to face an annual external audit, the purpose of which is to maintain high standards in financial reporting and corporate governance, under a code set by the FRC—Financial Reporting Council. We should extend the remit of that audit, under the auspices of the OCR, to report on the audited organisations’ and their suppliers’ management of cyber security and thus bring company boards clearly into play.
Thirdly and finally, we need to professionalise the skills of the cyber and IT community, which are highly variable. Every profession of which I am aware that can have a significantly adverse impact on individuals or society faces a hierarchy of qualification before a professional can operate at different levels—whether physician, lawyer, chartered accountant, architect or airline pilot.
How far across the economy would the OCR’s remit reach? It would extend precisely to the same extent as the obligation to have a statutory audit; that is, to companies with an annual turnover of about £15 million that have in excess of 50 employees. I have a perhaps surprising statistic for the noble Earl, Lord Effingham: that would mean only 2% of UK companies. But those companies represent around 70% to 80% of the UK economy.
To conclude, we simply must be bolder. We must take the opportunity that the Bill presents better to enable every kind of organisation in the UK to withstand the ever-growing and deeply disruptive threat of cyber attack.
My Lords, what a pleasure it is to follow such an interesting and constructive speech. I hope the noble Lord will take full part in Committee on the Bill. I declare my interest as chairman of the advisory panel of the technology company Thales UK. I thank the Minister for the briefing that she gave noble Lords a couple of months back, which was extremely helpful.
The best legislation has a permeating principle that helps to explain the purpose of the new law and inspire obedience to and observance of the new law. The Joint Committee on the National Security Strategy held an evidence session yesterday on deterrence in an age of Russian aggression, in which one of the witnesses told us that the key thing that should be included in the Bill is that it should hold vendors of software accountable for the reliability and security of their product. That follows on from what the noble Lord, Lord Birt, just said. That, after all, is what we do with cars. When Ciaran Martin was the head of the NCSC, that was one of his overall aims.
However, that is not what this Bill does—it does not have a permeating principle. It is a bit of a muddle. Winston Churchill might have said that this pudding has no theme. My noble friend Lord Effingham asked about strategy, and he was absolutely right to do so.
The Bill draws in some sectors but not others, without any clear explanation of the difference between those that it includes and those that it excludes. In another place, the shadow Secretary of State for Science, Innovation and Technology, Julia Lopez, said that she supported the Bill but feared it might not work in practice. I too support the Bill but fear it might not work in principle.
We live in an age when everything is connected to everything else. Drawing dividing lines between, for example, the private sector, some of which is included and some of which is excluded, and the public sector, which is excluded, is perilous and leads to incomprehension of the law.
That set of unclear distinctions also ignores the effect of cascade. During lockdown, a health crisis turned into an education crisis, with exam results becoming an unexpected casualty of Covid. When everything is dependent on computers, and the public sector is dependent on the private sector, and vice versa, it is unwise for new legislation to specify rigid demarcations.
Those taking part in this debate have received many useful briefing notes, from the Association of British Insurers, correctly drawing attention to the great value in behavioural terms of insurance, which can have a real impact on resilience of all types as well as cyber resilience; from the News Media Association, about the real danger posed by bots, which now form 50% of all internet traffic, which is accelerating fast; and from Zurich, correctly identifying the huge role played by SMEs in the cyber security sector yet worrying about the ability of SMEs to bear the demands of regulation, not least in reporting incidents within 72 hours; and many more.
I know that the Government are committed to reforming the Computer Misuse Act in the coming national security Bill, as the noble Lord, Lord Clement-Jones, has been demanding for many a year now. CyberUp’s long-running campaign on this is far too long-running. While I am talking about cyber security professionals—because that is the point of amending the Computer Misuse Act: to give them proper protection—I cite the very helpful briefing from ISC2. It says that the Bill will dramatically increase the demand for cyber security professionals even though there is currently a significant shortage of them.
As I understand it, the number of cyber security positions in government that are currently vacant stands at 50% of the total. That is horrifying. Some 58% of UK organisations have a critical or significant skills need and 87% of teams have experienced at least one consequence due to skills needs. The members of ISC2 have said that the biggest impediment to them complying with cyber legislation and regulation is a shortage of skills, so what does this legislation do to increase those skills? Could we look at defining the meaning of a “skilled person” in the Bill?
The shortage of such skills is likely to be exacerbated by there being 12 different regulators—here again I rather echo what the noble Lord, Lord Birt, said. There is going to be a risk of duplication of regulation, even potentially of contradictory regulation. What is an organisation meant to do if one regulator requires that it does one thing but another regulator requires that it does not? Will the Government ensure that regulators adopt common forms of evidence for demonstrating compliance and common cyber security standards? How does the legislation take into account the fact that many organisations will be subject to foreign legislation as well? I agree, as on many other things, with what the noble Baroness, Lady Northover, said about encouraging alignment with the European Union. How are we learning from overseas experience?
This is a well-meaning but muddled attempt to deal with an exceptionally fast-moving, difficult problem. Governments always find it hard to keep up with the pace of technology, so is it right that we should re-examine this Bill only every five years? The Secretary of State should have to report to Parliament earlier than every five years. I know I sound a bit miserable, but I support the Bill. I really do. It could be better, and we will have a lot of work to do in Committee.
Baroness Paul of Shepherd’s Bush (Lab)
My Lords, the Government’s whole-of-society approach to national security rightly recognises that resilience is not delivered by the state alone; it is delivered through partnership between government, regulators, industry, communities and, crucially, the private sector. Cyber resilience is no exception. It requires every bit of the infrastructure to play its part: those who defend networks, those who regulate standards and those who help organisations recover when incidents occur.
I welcome the Bill and I note the broad support it has received from across the resilience sector as a good start. The Bill makes important progress in strengthening incident reporting, modernising the NIS framework and placing greater obligations on essential service providers, digital services and critical suppliers. I particularly welcome the inclusion of managed service providers within the regulatory regime. As other noble Lords have mentioned, more and more organisations rely on MSPs to help them keep pace with the changing nature of the threat and the ever-expanding tools required to remain secure. Without them, many businesses and parts of our critical national infrastructure would struggle to access the expertise they need to keep themselves safe. At the same time, MSPs can present a potential vulnerability because of the privileged access that they often hold to clients’ infrastructure. The Bill is right to recognise this, and I am pleased to see them brought into scope.
In welcoming the Bill, I must also point to what I think is a significant omission, on which I will focus my remarks. There is no mention of the insurance sector, nor any real mention of the part that the private sector can play. I raise this not as a criticism, because there is ample opportunity to put this right and to enhance the Bill’s ambition. The Bill already expands incident reporting and increases the volume and quality of cyber incident data available to regulators and public authorities. That is an excellent step forward, but if the purpose of the Bill is to improve our understanding of cyber risk and strengthen resilience across the economy then it is worth asking whether we should enable structured, anonymised incident data to be shared with the insurance sector and others who can use it.
The purpose of this data is to provide a clear picture of the threat, so it is important that we share it as widely as possible with those who can help protect us. I ask the Minister to consider this. It would be an extension to the Bill, not a departure from it. It would build on the reporting architecture that the Bill already creates, and it would do so in a way that supports the Government’s whole-of-society approach to resilience. The principle is simple: better data enables better modelling; better modelling enables better pricing and strengthens resilience; and better pricing increases access to cyber insurance and strengthens resilience across the entire economy.
Cyber insurance is already an important part of keeping businesses safe. We know that it enables us to transfer financial risk so that it is shared between businesses in the private sector rather than being borne by the taxpayer. I am sure we all agree that cyber incidents and the cost of recovery should, in most cases, fall on the organisations affected.
As noble Lords know, insurance remains one of the most effective and economically efficient ways of achieving this, but it does not just pay out after an incident; it changes our behaviour before one. To secure affordable premiums, organisations are required to adopt practical cyber hygiene measures, such as multifactor authentication, timely patching, network segmentation and robust incident planning. These requirements are not set in stone but change as the threat involves. Beyond legislation which will mandate a change in behaviour, there are very few other ways to incentivise the scale and pace of the behavioural change required to improve our resilience than insurance. We have locks on our doors, safety features in our cars and sprinklers in our buildings because insurance encouraged and rewarded these measures. It has the potential to play the same role in cyber resilience.
It is worth noting that Cyber Essentials, which the Minister mentioned in her opening remarks, is believed to be held by just 1% of businesses. Although the growth rate is increasing, it would take decades to get to the point where Cyber Essentials is going to provide us with the level of resilience that we need, so we need to do something different and we need to incentivise things differently.
As we also know, cyber insurance helps mitigate the moral hazard where organisations underinvest in security because they assume government or someone else will bear the consequences. The risk to our economy makes this unsustainable. Independent analysis commissioned by the Department for Science, Innovation and Technology, which sponsors this Bill, shows that cyber attacks impose almost £15 billion of economic harm on the United Kingdom every year. That is equivalent to one month’s NHS expenditure, almost the entire annual policing budget, 30 new hospitals or more than three decades of universal breakfast clubs for every primary school child. It is enough to wipe out an entire year’s profit for vast numbers of British businesses.
Yet only a small proportion of that national cyber risk is insured. Based on the department’s modelling data, together with that of the Association of British Insurers and Lloyd’s of London, it is estimated that the UK cyber insurance market currently covers approximately £700 billion of annual losses. In other words, less than 5% of the economic harm caused by cyber incidents is insured. Therefore, more than £14 billion of losses fall directly on businesses, public services and, in some circumstances, the taxpayer. We all know that Marks & Spencer had cyber insurance and reportedly made a claim of around £100 million following its cyber incident last year, whereas Jaguar Land Rover did not have any cyber insurance and, in the end, the Government had to step in and provide a loan. As the frequency and severity of cyber events increases, it is in our interest to increase insurance take-up.
The Bill strengthens reporting obligations. Named suppliers will be required to report significant incidents within 24 hours and to report fully within 72 hours. The Bill expands the definition of a reportable incident to include pre-positioning attacks, significant near misses and incidents likely to have societal impacts even where disruption has not occurred. It must be permissible for regulators to share this information across public authorities and with insurance companies to create a more coherent national understanding of cyber risk. If we accept that it is possible to share in some circumstances, it must be possible for us to consider that it could be shared in others.
Lloyd’s of London, the ABI and brokers including Marsh, Aon and Willis Towers Watson have warned that scarcity of reliable data is one of the principal constraints on market and product development, so why would we not want to facilitate improvement in cover? Market analysis suggests that there is potential for the global cyber insurance market to expand annually by 25%. If the UK were to capture even a modest share of that growth, our domestic cyber insurance market could expand from its current value of around £700 million to well over £2 billion in a few years. This would lead to more highly skilled jobs in London and would maintain London’s position as the world’s leading centre for specialist insurance.
The Bill sets us in the right direction, but we have an opportunity to ensure that insurance is properly recognised as part of the resilience community. I believe that enabling structured, timely, anonymised data to be shared with insurers would be a modest extension to the Bill but would have the capacity to deliver enormous change to the cyber resilience of our country. I hope that the Government will consider this as the Bill progresses through the House.
My Lords, I support this Bill. I rather agree with those who have spoken previously that it is not particularly ambitious in its aims, but, if successful, it will be a largely useful piece of legislation. It is modest in its aims but liable to be of service for a period.
What it does not do is look forward very much. The threat landscape is deteriorating. I will not describe it, as that has been done well by others, but the criminals, and indeed other state operators, are leaders in technology adoption. We can be sure that AI is going to be used against us, and so we must be in a position to exploit it ourselves.
One of the conclusions that I draw from the discussion so far is that we will somehow have to learn to both legislate and make policy faster than we are doing at the moment. This Bill has taken a long time to get through the Commons. I hope that it will not take so long to get through this House. I suspect that we are already behind the curve again.
We have to learn to be willing to experiment and to change course if it is not working. We can take many views on the subject of whether we should have sectoral regulation or a single regulator—there are arguments in both directions. At the moment, I am, on the whole, willing to try sectoral regulation, which brings with it potentially more flexibility, as well as more complexity. If it does not work, we will need to be prepared to say that it is not working and that we will do something different. Changes of gear, and willingness to change gear, are things that we will have to come to terms with. When it is the case that we have not got it quite right, we will need to be prepared to say so.
The thrust of the Bill is certainly in the right direction. I will focus on some of the more detailed points in the drafting where I think we need to try to accomplish some improvements. There is quite a lot of looseness in the drafting, which needs tightening up. For example, terms such as “managed service provider” and “critical supplier”, as well as the wide definition of the notion of “incident”, all need greater precision. We need to avoid situations where words such as “incident” become a way in which companies that have no particular involvement get tangled up in regulation. If part of a company provides managed services, we need to know, and the company needs to know, whether the whole company is caught by the Bill or whether it is simply that part that provides managed services.
There is plenty of implementation detail on which we will need to have a closer fix. I am willing to give the Government the power to fill in the detail and update the law through secondary legislation, as it seems to me that we cannot always have primary legislation doing everything. However, we will need a duty to consult written into the Bill for it to be a safe proposition. One thing I would like to ask the Minister is about the timetable for secondary legislation. Will the Government be willing to consult when it comes to putting that through? That will be a very substantial part of the Bill.
I want to make a couple of comments about the effects of the scope of the Bill. First of all, with the exception of service providers, who are classed as “critical suppliers”, and data centres, the Bill, as other people have remarked, is exclusively concerned with the public sector. As the Government Minister and indeed others have pointed out, some of the biggest losses have occurred in the private sector. I do not need to describe these, as they have been described already.
The Government may argue that they properly seek not to regulate the private sector. I certainly have considerable sympathy with that, but it is not satisfactory from the point of view of the taxpayer that the Government had to bail out with public finance Jaguar Land Rover. Under current conditions, I do not think that that breach, which was expensive, is likely to be the last one with sizeable financial effect.
The Government have recognised the problem and are encouraging private sector companies to make a pledge to improve the management of cyber security at board level. I am all in favour of that: improve reporting in the corporate code and increase activity by the audit committee, whose members, if properly equipped with cyber expertise, will make a valuable contribution. That is part of the way that we must move forward. Having said all that, private sector security self-help, while essential, is not sufficient. So what should we do?
The Government correctly tell us that their first duty is the defence and security of the nation. Cyber security strategy—which I know something about, having been involved in it—was founded on the proposition that the protection of the economy involved active partnership between public and private sectors. The NCSC does a vital job in increasing understanding about the threat and giving advice and guidance on countering it, but it could do an even more important and larger job. It was intended at the outset to be more public-facing than is currently the case. It has, to some extent, retreated from its previous public start. I would like to see the NCSC re-emerge from the shadows with more threat analysis, advice and guidance, and its funding increased to do this.
This would be particularly helpful to SMEs. We have all been worried about their access to expertise and considered that the cost to them of security, which is not insignificant, should be somehow alleviated. They are valuable to us. Small companies provide very important parts of larger systems. If the NCSC were to be a much more active security partner to the corporate world, there would be a strong case for financial support from the private sector to it, to make this much more of a joint enterprise.
I urge the Government to put their intelligence capabilities to greater effect in supporting the private sector to raise its level of security. I do not think this is beyond us. We ought to try to do something where there is much closer co-operation between public and private sectors. The banking world, though different, gives us some pointers on the way in which that could be done.
Secondly, within the public sector, the scope of the Bill is puzzlingly selective, as other speakers have touched on. There is palpable anxiety among the general public about the security of One Login and accessing government services safely. This is a moment when the Government could increase confidence. However, not all government services are covered. To take an example, DWP has in its possession detailed personal—not to say intimate—information about its clients and beneficiaries. Surely it should be a candidate for coverage, but it is not. What are the criteria that govern whether a public sector service is covered or not? On the face of it, I do not think selectivity looks wise. The Government have chosen—
Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
I gently remind the noble Baroness that there is an eight minute advisory Back-Bench speaking time.
I will conclude. The Bill recognises the need for regulatory co-operation, and it is certainly going to be very important if it is made to work. I also agree with those who think that we should align with things such as NIS2 to reduce the potential conflict between us and other international regulators.
My last thought is that we need to ensure that another definitional issue in the Bill, the level of security
“appropriate to the risk posed”,
is pinned down. There is a great deal in the Bill that we will want to talk about in Committee so that those implicated know exactly where their limits lie.
Baroness Alexander of Cleveden (Lab)
My Lords, this is proving a fascinating and valuable debate, recognising the Bill’s many strengths, what could be tweaked, and what perhaps is missing as we look ahead. To begin with the strengths, we heard from the noble Earl, Lord Effingham, that the Bill builds on the work of the previous Government and commands cross-party support. We have just heard from the noble Baroness, Lady Neville-Jones, that national security is the first obligation of government. This is unarguably an important step in protecting the nation against cyber criminals, hacktivists and hostile states. It will quite simply make the UK a better place to live, work and do business in.
We have heard already from the noble Lord, Lord Birt, about the economic impact of cyber attacks and from my noble friend the Minister about the 11,000 NHS appointments that are lost to cyber attacks. It therefore seems very timely that we have this Bill, which will cover more essential services, improve regulatory effectiveness, and speed up responses to cyber threats. It is clearly desirable that we have a stronger board level responsibility around cyber. It must be right that data centres are now included in the Bill, helping maintain the UK’s position as a global destination for secure data hosting and for innovation. The focus on high-impact firms means that small companies will not be unduly burdened.
As my noble friend the Minister made clear, this is part of a wider national security effort that includes a cyber action plan for the public sector, a forthcoming cyber action plan for business, the Cyber Essentials certification scheme, and free cyber security support from the NCSC. All these measures will help contribute to our cyber security. The 24-hour incident reporting system will mean that regulated entities have to notify customers impacted by incidents. The tougher penalties for breaches will modernise enforcement and, I hope, improve the uptake of cyber insurance in the way that my noble friend Lady Paul has indicated is so vital. We have to hope that, together, this will mean that cutting corners will no longer be cheaper than doing the right thing. Nevertheless, given the speed at which new cyber threats are emerging, the Bill tries to strike a reasonable balance between maintaining parliamentary oversight and ensuring that the Government can act quickly, as required.
I turn to the question of tweaks. Many of them have been touched on so I will not dwell further on them. We heard from the noble Lord, Lord Arbuthnot, about the importance of the workforce and the increasing demand for cyber security skills. Will the proposed codes of practice include a framework for workforce development and training?
The second tweak, as many noble Lords have touched on, is to the Bill’s scope. I have some sympathy with the noble Baroness, Lady Northover, about the case for closer alignment with EU regulations when we have British companies operating and complying with EU legislation in the areas that are covered. I also think that a broader scope would drive the sort of behavioural change that my noble friend Lady Paul cited. I note that the Minister already said that secondary legislation is available to expand the scope. I look forward to her comments on why we do not have a broader scope now, given the groundswell already in this debate, perhaps to include public administration, in particular local government, given the scale and sensitivity of data and the essential nature of public services.
The third tweak is something else that has been widely noted already: the risks associated with having 12 regulators. I appreciate that the Government’s intent is minimising regulatory upheaval. There is a balance to be struck. The noble Lord, Lord Birt, approached the issue of risk from the desire and need to ensure expertise. I will look at it through the lens of the risk of duplication. At lunchtime today, I spoke at a NED event hosted by a US law firm that counts among its clients a major cloud provider, insurance companies, professional services firms and a board effectiveness practice that works with both public and private sector organisations. The strong consensus in the room was that a common cyber security standard across all regulators, upon which appropriate sector-specific requirements could be layered, merits consideration. This approach is in the spirit of the Government’s amendments, tabled in the other place, to streamline reporting and avoid unnecessary complexity. I hope that issue is given further consideration.
In my few remaining minutes, I will touch on what is not in the Bill. As others have noted, technology is advancing faster than government frameworks can keep pace with it. The Bill was published last year, just as it became clear that AI was tipping the advantage to attackers. Attackers need to succeed only once, while defenders potentially need to patch millions of users. There is currently no technology to automate patching at the pace required. The Bill needs to say more on the role of integrating AI tools into cyber defences. The Bill arguably has an AI-shaped hole in it, although I am encouraged that the incoming Prime Minister has signalled a fresh look at AI regulation. Even Sam Altman, faced with a capricious President, has come round, writing in the FT that
“citizens and their elected representatives must make the rules”.
We have also seen the Five Eyes intelligence partnership warning in a very rare joint communiqué last month that the West’s adversaries were within months of developing cyber attacks that could overwhelm the defences of Governments and companies and noting that frontier AI models will fundamentally transform cyber capabilities. All this is now with us, so raising our defensive capability in the face of this rising AI functionality will be essential. Our spy chiefs are asking western companies to use AI models to strengthen their defences.
I fully appreciate that the Government are completely across this threat landscape. The question is: how do we collectively legislate or regulate in such a threat landscape? Some suggestions that we can consider in Committee are, first, that advanced AI providers could perhaps be designated as covered entities under the Bill. Secondly, since the impact of AI in the cyber field is increasingly systemic rather than sector specific, perhaps we need common AI cyber security guidance supporting all regulators in this fast-moving landscape as they then layer on the needs of their sector. Thirdly, perhaps there should be an AI field in the mandatory incident reporting regime. Finally, we should perhaps think about an AI oversight framework giving the NCSC more teeth and the AISI a more co-ordinating role.
In conclusion, as widely recognised, the Bill will support our economy and our people and make the country safer. It is part of a package. It is a crucial building block rather than the final destination. I strongly commend it to the Chamber.
My Lords, there is a risk of agreement breaking out at this juncture. I too very much welcome the cyber security Bill and agree with others who have raised the omissions. There is nothing for the private sector and nothing on local authorities. It focuses on the size of service provider rather than risk and, in doing so, fails to learn from the battles during the Online Safety Act which established beyond doubt that the size of the company does not equate to the risk it poses in any system. There is also no mandate for executive responsibilities, as in NIS2 in Europe. All these things feel like critical omissions but, above all, there is nothing on AI, as we have just heard. That is where I will focus my remarks.
In February, Darktrace, a cyber security firm based in Cambridge, surveyed cyber security professionals; 73% of them reported that AI-powered threats are already significantly impacting their organisations. Nine out of 10 said they needed major upgrades to their defences. Only weeks ago, the US Government instructed Anthropic to withdraw two frontier models, going from zero regulation of AI to a 100% ban within 90 minutes. This was on the understanding that it posed a national security threat, with capabilities that experts anticipate will be mirrored by other frontier models, including Chinese ones, within months. It seems extraordinarily ill advised, therefore, that AI is not front and centre of the Bill. Clearly, this is a decision rather than an omission so, when she responds, can the Minister explain why, given the scale of the cyber security threat presented by AI, the Government have chosen not to identify it and tackle it explicitly in the Bill?
The absence of AI from the Bill also means the absence of the AI Security Institute. AISI is recognised globally as world leading, yet since this Government came to power its name has been changed from “Safety” to “Security” institute. We have heard repeatedly from insiders that they have been instructed not to upset the Americans. Most recently, a decision was made to fold its societal resilience team—which dealt with things including psychological harms, child safety, environmental harms, synthetic media abuse and faults with using AI for hiring, police and credit scoring—in favour of the existential threat agenda, which frontier companies prefer to discuss because industry prefers to talk about the harms of the future rather than the ones that are here right now.
I sit on the Joint Committee on the National Security Strategy and simply cannot overstate the repeated cries from security experts for society-wide resilience and a broader definition of security, including information integrity and digital sovereignty. They understand that threats to security are structural and multifaceted and need constant oversight. Can the Minister say why we are not using this Bill to strengthen and empower AISI as an independent statutory body to ensure the safety and security of the nation and to provide a constant source of wisdom and expertise over AI across all domains, with a statutory remit that allows it to investigate the full spectrum of unsafe security risks and mandatory rules for AI safety training and reporting of security incidents directly to it?
It is easy to dismiss these issues as outside the cyber security remit, but that is not the case. I was at a conference about agentic AI last week where medical researchers showed that, in 51% of cases where a person should go to hospital, AI told them not to. This has profound consequences for the health of a nation. More chilling still, the same experts pointed out that, as AI becomes integrated with health records and prescribing systems, a malign actor or hostile state could in one fell swoop manipulate the online prescriptions of an entire nation.
Similarly, in my conversations with specialist police they have said that they are extremely worried about the way digital services are fuelling an ever-growing pipeline of extremists. Recent research by the Center for Countering Digital Hate shows that eight out of 10 chatbots are willing to plan a school shooting or an attack on a synagogue. In 2025, for the first time, automated traffic overtook human traffic online, much of it concealing its identity, leaving operators unable to distinguish benign automation from hostile traffic. This enables the mass harvesting of data used to facilitate a future cyber attack at scale. As non-human traffic climbs, our exposure to cyber attacks grows with it.
At best, the Bill is unclear how these sorts of harms impact our security and adds to the mishmash of provisions and the powers taken by the Secretary of State in several previous Bills. At worst, these issues are not covered at all. The Minister in the other place said that the Bill is “technology agnostic”. Can the Minister explain what that means in practice? AI is not simply another risk to be regulated; it changes the nature, speed and scale of cyber attacks themselves.
Two weeks ago, I and several other noble Lords received a briefing from the Institute for AI Policy and Strategy and the Centre for Long-Term Resilience. They are at the forefront of tracing emerging technologies and threats and have set out a clear strategy built around four ideas: delay, defend, detect and disrupt. They have practical proposals under each heading to improve the Bill, giving us greater oversight and transparency and narrowing and neutralising the spectrum of risk. But as it stands, the Secretary of State, as she has done on so many occasions, has taken powers herself rather than offering Parliament a coherent plan of action.
In short, the greatest omission from the Bill is that it focuses primarily on what a limited set of companies and service providers should do and too little on the resilience of the wider digital system. Over the last two years, we have seen the way in which dependencies on US tech have muted our ability to protect children and creatives and made our NHS, government data and our economy vulnerable. A truly secure cyber policy is a sovereign one which gives the Government control over key chokeholds in the system and oversight over critical infrastructure while encouraging a far greater range of providers. It is one that retains valuable data in the UK, prioritises UK tech companies and deliberately works alongside other middle powers by building relationships in which we are a rule-maker rather than a rule-taker. That, to my mind, is the real opportunity presented by this Bill. It is an opportunity yet to be realised.
My Lords, it is a great pleasure to follow the noble Baroness, Lady Kidron. I will come back to her points about digital sovereignty. I also thank the Minister for introducing this Bill.
I have been reflecting back. I am approaching my eighth year in your Lordships’ House, and we have come a long way. About seven years ago, I was standing behind the Bar and a Member of your Lordships’ House who shall remain nameless sidled up to me and said: “They’re talking about catfishing. I gather that doesn’t mean being beside a river with a rod”. I said, “No, you’re right. Well done, well worked out”. We have come a long way. But, of course, the world has changed an enormous amount in those eight years and the message from all corners of your Lordships’ House today is that the Government are not keeping up. Your Lordships’ House will have to do its best to keep up for them and push the Government in those ways.
In her introduction, the Minister talked about data centres being a key part of the modern world. Their security is very reliant on water and energy supplies, just as all our security is being impacted by their consumption of those supplies. Something we have not really talked about yet, but need to think about a lot, is that we tend to think about these information systems and networks as being up in the cloud, but of course they are very much physically down to earth and dependent on all our natural physical systems. That cannot be forgotten.
I will focus mostly on two areas of concern that are missing or inadequately covered in this Bill in terms of our network and information systems. In Trafalgar Square at this moment, there is literally a Trojan horse—a reminder, in mythological form, to beware of Greeks bearing gifts, at least if they have just been besieging your city. I put it to the Government that this is a parallel that they should be considering: beware of Silicon Valley tech bros bearing shiny undeliverable promises, with large lobbying budgets and frighteningly undemocratic values, and that bear allegiance to a state with doubtful levels of democracy and consistency. I also want to respond directly to the noble Lord, Lord Birt, who spoke about the risks of volunteer-run, open-source software. Of course, it is very possible to question which is the greater risk: a Silicon Valley tech bro or a whole lot of people who are trying to work for the common good. We might debate that as we go along.
As the noble Baroness, Lady Kidron, identified, we are talking about digital sovereignty. I draw the attention of your Lordships’ House to an amendment tabled by my honourable friend Siân Berry in the other place, which was not debated there, calling for the Government to have a digital sovereignty strategy. It proposed that the Government should have and maintain such a strategy and
“set out the Government’s assessment of the risks to … network and information systems arising from … dependence on hardware, software, or digital services that may be subject to foreign interference”
of the kind that the noble Baroness, Lady Kidron, referred to, in terms of AI systems;
“extra-territorial legal requirements that may be imposed on non-domiciled suppliers;”
and
“vulnerabilities, undue control, or supply-chain dependency on foreign states or entities”.
I am sure everyone in your Lordships’ House knows what I am talking about, but I will pick one example as a case study: the company whose place in our society, and the values of its founders, owners and leaders, are a great cause for concern in Parliament and with the public. I am talking, of course, about Palantir. Last month, the Science, Innovation and Technology Committee warned that
“it’s not the only company capable of providing the ‘middleware’ required by public bodies”.
The committee also identified Microsoft and Amazon Web Services. Let us focus on this: you do not even need the fingers of one hand to count the absolutely central suppliers here. The committee said such dependencies were putting us
“‘at the mercy’ of foreign actors”,
and it very explicitly called for the Government to exercise the 2027 break clause in the NHS Federated Data Platform contract—ideally to develop an in-house replacement. That is one sovereign issue.
A second sovereign issue faces towards a more obvious international danger that the Government will not, I hope, deny. As debated in the other place, this is the need for critical safeguard in this field for an anti-transnational repression amendment. I happen to know that the noble Lord, Lord Alton of Liverpool, who cannot be with us today unfortunately, intends to table an amendment as we progress this legislation. At the moment, this Bill creates a dangerous loophole. It permits the sharing of highly sensitive network and information systems data with overseas authorities, without checking whether those authorities operate within a system that guarantees legal standards and human rights. There needs to be a rule that says, “Let’s check and think before we share”.
It is important to say that this would not be an actor-specific measure; it would be a universal principle-based safeguard that would apply to any regime, anywhere in the world, that rejects the rule of law. It would require the Secretary of State to actively consult subject matter experts and civil society groups to identify compromised jurisdictions. We have to be realistic about the state of the world now. Authoritarian states have a long and troubling track record of using international structures, such as Interpol notices for example, to mask political persecution under the guise of criminal justice.
I should declare at this point that, until recently, I was co-chair of the All-Party Parliamentary Group on Hong Kong, and I will focus briefly on the issue of China. UN special rapporteurs have pointed out the issues there. We cannot assume that so-called safe third countries will protect dissidents. Countries such as Spain have authorised extraditions to China, Cyprus has accepted individual “assurances”, and countries such as Hungary and Serbia are deepening judicial co-operation with Beijing. The UK has suspended its formal treaty with Hong Kong, but recent proposed changes to the Extradition Act 2003 open the door to case-by-case ad hoc arrangements. NIS data includes IP addresses, digital fingerprints and user-level logs, so the concern is not just about extradition but that this would allow authoritarian states to identify dissidents in the UK. We know that transnational repression against dissidents has been a great and growing to diaspora communities and human rights defenders.
This Bill needs a lot of work, as many people have said. There is really foundational work here that needs to be done.
Lord Forbes of Newcastle (Lab)
My Lords, the Bill sits squarely within the wider national security and preparedness agenda to which this House has repeatedly returned in recent months since the publication of the strategic defence review. We have spoken often about the interlocking nature of modern threats: geopolitical instability, climate shocks, pressure on critical infra- structure and the growing complexity of our digital systems. The Bill is therefore not a narrow technical measure; it is a national security Bill, and it deserves to be treated as such.
Every essential service in the United Kingdom, whether that be our energy grids, water systems, transport networks, hospitals or financial services, now depends on digital infrastructure. The boundary between physical and digital security has dissolved. A cyber attack on a hospital is not an IT problem; it is a threat to life. A breach in a water company’s control systems is not a data incident; it is a public health emergency. A compromise in a major data centre or managed service provider can cascade and cause chaos across the economy in minutes.
In recent years, we have seen how ransomware attacks have disrupted patient care or student learning, how supply-chain vulnerabilities have exposed critical national infrastructure, and how hostile actors—some criminal, some state-linked—have sought to test the resilience of our systems to destruction. The economic costs run into billions. The strategic cost is greater still: weakened confidence, reduced competitiveness and a nation continually forced into reactive crisis management rather than forward-looking preparedness. Resilience is not a cost; it is a foundation stone of our national strength. And the Bill is a necessary step in strengthening that foundation.
The existing Network and Information Systems Regulations, introduced in 2018, were an important milestone, but the digital ecosystem has changed beyond recognition in the years since. Cloud computing, large-scale data centres, outsourced managed services and complex supply chains now underpin almost every aspect of our national life. The regulatory perimeters and safeguards put in place almost a decade ago have not kept pace with the reality of modern risks.
The Bill addresses that gap. It expands the scope of regulation to include data centres, managed service providers and critical suppliers. Crucially, it recognises that vulnerabilities often sit not in the front-line operators but in the third-party services on which they depend. It strengthens incident reporting by ensuring that regulators receive timely, accurate information and that customers are informed when their services or data may be affected. It introduces statutory codes of practice, giving clarity to industry and consistency to regulators, and provides modern enforcement and cost-recovery powers, enabling regulators to act decisively when standards are not met.
Crucially, the Bill requires the Secretary of State to publish a statement of strategic priorities for cyber resilience. This is a significant and very welcome development. It aligns regulators, industry and public services around a shared national mission. It ensures that our approach to cyber resilience is not fragmented or reactive but coherent, strategic, and future-focused.
The Bill is not simply about technology; it is about people. Cyber incidents disrupt lives through cancelled hospital appointments, delayed trains, compromised personal data, businesses being unable to trade and local authorities unable to deliver essential services. The public rightly expect that the systems they rely on every day are secure. The Bill helps us to continue to meet those expectations. It also fits squarely within the broader preparedness agenda that many of us in your Lordships’ House have championed since the gracious Speech. We have argued consistently for a whole-system approach to resilience: one recognising that national security considerations are not confined to the worlds of defence or intelligence, but include the stability of our infrastructure, the integrity of our supply chains and the confidence of our citizens. Cyber resilience is now as fundamental as physical resilience. The two cannot be separated.
We have also emphasised the importance of place-based resilience. Local authorities, NHS trusts, utility companies and regional industries all depend on secure digital systems. A cyber incident in one part of the country can have national consequences. Strengthening digital resilience strengthens local resilience, and vice versa.
We also continue to make the economic case. Secure systems underpin investment, innovation and job creation. They are essential to the competitiveness of our industries and the stability of our financial markets. In a world where digital infrastructure is as critical as roads or railways, cyber resilience is now an economic imperative. Cyber resilience is, and must be, a shared responsibility. Government, regulators, industry, public services and communities all have a role to play. The Bill strengthens the framework within which that shared responsibility can be exercised, so it is timely and necessary, but it is not sufficient.
Legislation alone cannot deliver the resilient digital nation we need to become. We must understand the current limitations of our sovereign digital capabilities and take urgent steps to address this major vulnerability. We must invest in skills, innovation and the capacity of regulators. We must support industry to meet higher standards, and foster a culture of preparedness: one that anticipates risk rather than waiting for crisis.
I end with a brief reference to the motto of my home city of Newcastle upon Tyne. I am not a Latin speaker, so I apologise if my pronunciation offends any of your Lordships who are. “Fortiter defendit triumphans”—triumphing by brave defence—emblazoned across our city’s crest, celebrates the victories it won in the 1600s against marauding invaders. It symbolises the city’s ability to withstand such assaults through its collective spirit of preparedness and fortitude. The lesson I believe we can draw from the history of Newcastle for this modern age is that by strengthening the digital sinews that hold our country together, we strengthen the country itself. In the very act of doing so, we cast a defensive shadow against those who seek to do us harm and, ultimately, we reduce the risk of attack in the first place. The Bill is an important step in that direction, and I am pleased to support it today in your Lordships’ House.
My Lords, I see that I have gone down on the speakers’ list as “B Ludford—first half”, presumably in the expectation that I will make the second half of my speech later. I am only kidding.
I knew that I would learn a lot in this debate and I have not been disappointed. I am no expert on cyber issues and I am speaking only because, first, it is an interesting as well as vital topic; secondly, because my noble friend Lord Clement-Jones is very persuasive; and, thirdly, because the Bill has prompted me to revisit my memory of being the victim of a cyber attack 13 years ago.
As an MEP I was involved in drafting the general data protection regulation—GDPR. I see the noble Lord, Lord Moraes, nodding in collective memory. I had sought to take a balanced approach, safeguarding personal data while not totally hampering digital services by overloading them with red tape. This middle way did not please a group of extremist hacktivists, who labelled me an agent of big tech and launched a denial of service attack against my MEP website. It was successfully defended by the small firm which hosted my website—and those of some Lib Dem MPs, including a coalition Minister or two—and it kept all the logs for me, as I wanted to notify the police. I could not find anyone in the Met to speak to so, since I was in touch with Europol and its British director at the time, his chief of staff kindly spoke to old Met colleagues and got an inspector to ring me. This chap was not only uninterested but cross that I had got rank pulled on him, and he did not deign to pursue any inquiry.
I relate that anecdote to illustrate, first, that cyber resilience is a whole-of-society concern which needs to bring in all of us non-experts but, secondly, that the exclusion from the Bill of public sector services is a worrying hole. Politicians and political parties as well as the police, local authorities and others are rather key players in the cyber security ecosphere. I hope that we will explore at further stages the Government’s rationale for exclusions.
At Second Reading in the other place, the Minister for Digital Government and Data, Ian Murray, agreed that cyber security
“is very much an economic growth issue … as we can see from the impact it has on our economy”.—[Official Report, Commons, 6/1/26; col. 171.]
Both Mr Murray and his DSIT colleague Kanishka Narayan cited the £15 billion a year cost of cyber attacks to UK businesses. But in response to calls to include sectors such as retail and manufacturing, as well as small and medium-sized companies, Minister Narayan claimed:
“Introducing blanket coverage for whole new sectors would create extensive regulatory burdens for more of our economy, stifling economic growth”.—[Official Report, Commons, 6/1/26; col. 226.]
So, on the one hand, the Government acknowledge the devasting cost to the economy of cyber security breaches of both public and private operators but, on the other hand, say that including them in the Bill would damage the economy. There is absolutely no logic to this.
The sorely needed intent to boost the pipeline of professionals is of course welcome. But another thing the Government could do on training is to protect the practice of ethical hacking, as part of the testing of networks, so that this workforce is as prepared as it possibly can be to combat weaknesses in cyber protection. Is this going to happen via reform and updating of the Computer Misuse Act 1990?
The effort needs to encompass not only professionals but all of us non-techies, even oldies such as me, given that the most common password in this country is apparently “password”. Much lip service is paid to addressing digital exclusion but there are huge numbers of people—a lot, but not all, of them old—who have not received any training and are still left out. How do the Government plan to extend whole-of-society awareness of cyber safety to everyone living in this country and not regard it just as a limited legislative exercise? While doing that, the Government could surely not avoid the issue of cyber-enabled fraud, a multi-billion-pound epidemic in which criminals often compromise individual customers as a route into wider systems. I do not think that is covered at all in the Bill.
The Government’s response to demands for the Bill to place responsibilities on boards and senior executives has been as feeble as their muddle on the economic impact. Minister Narayan told the other place that last year the Government wrote to chief executives “requesting”—requesting—
“that they make cyber-security a board-level responsibility”.—[Official Report, Commons, 6/1/26; col. 228.]
That in my opinion is pathetic. With the consequences of neglect so clear, a request is simply not good enough. The Government should make cyber security a legal requirement on bosses, which would boost accountability. Alongside that, they could slim the Bill’s administrative load by clarifying responsibilities, definitions and thresholds, having a single unified reporting portal rather than 12 regulators, avoiding overreporting, which would simply make the wood invisible for the trees, and including a duty, not just an option, to consult on secondary legislation—among many other streamlining measures.
Leaving the strategic priorities statement to the Government to draw up is a huge chunk of delegation. This Bill is really a bit of a mess: a combination of lots of executive power and lots of amending of the 2018 NIS regulations. It might have been better to write a whole, clean, comprehensive new Bill.
We can no longer channel EU law into our jurisdiction because the European Communities Act was abolished, but, in an era of alignment—indeed, dynamic alignment —the disparities between the Government’s choices in the Bill and the EU’s proposed NIS 3 directive are puzzling, as my noble friend Lady Northover and others pointed out. Both to lighten the regulatory load on UK companies working across Europe and to facilitate co-operation with the EU, it would make sense to have greater similarity between this Bill and the EU’s imminent new directive.
The Bill is much more limited than the draft directive in its sectoral coverage and regulatory design: for instance, keeping different categories of regulated entities when the EU is bringing them all together, and then distinguishing purely between “essential” and “important”. I am all for regulation being proportionate and flexible when that works—I and some other British MEPs sought with some success to bring that into the GDPR—but can the Minister be explicit about why the Government have diverged rather decisively from the EU model, and indeed left so much detail to executive discretion?
When it comes to the desired digital sovereignty, to avoid in future the servitude to US tech and the US Government that the Mythos episode demonstrated, would it not make more sense to work more closely with the EU so that British companies can help contribute to and benefit from a European market in digital commercial opportunities?
I look forward to working with colleagues on these Benches and across the House to improve this rather unambitious Bill.
My Lords, it is a pleasure to take part in this debate at Second Reading. I am taking part not because I was once hacked but because I was very briefly the Cyber Security Minister—which is almost as surprising as learning that I was once the Minister of Fashion.
Several themes have emerged during this very interesting debate and I always find it interesting to debate a Bill on technology, because the process of legislation is so ponderous and takes so long while digital technology moves so fast. I think there is a recurring theme, of course, that everything is digital. The other thing I always find odd when we debate legislation such as this is how we seem to continue to work in silos. AI has been mentioned so many times and it so important, but I recognise the need for legislation to provide the Government with a framework, just as the Online Safety Act has provided the Government with a framework on which we can move forward on online safety. I am less concerned about executive action and endless consultation; I want the Government to have the powers to move quickly in this important area.
As an opening remark, I will say something perhaps counterintuitive, which is that cyber security as well as being a threat is also a great opportunity. It is very important for us not to lose sight of the fact that the UK is one of the leading countries in the world for cyber security expertise. We have a cluster of great companies built around GCHQ. We must not lose sight as we debate these important issues of the fact that we have world-leading expertise that can contribute to the growth in our economy. When we talk about the defence investment plan, for example, it is important to talk about the huge opportunities we have to create great defence tech companies. Nor should we lose sight of the opportunity to create great British cyber security companies, which goes to the whole debate about potential sovereignty and giving us our own capability.
Let me begin by echoing a number of speeches about how important it is to work in lockstep with our EU partners. It is a piece of irony that this legislation emerges in effect from a European directive that we were beginning to debate when I was the Cyber Security Minister. In fact, the legislation is necessary because we can no longer transpose European legislation directly into British legislation. The noble Baroness, Lady Ludford, mentioned the GDPR, and it is a fact that Brussels can often take the lead in regulation such as this, and that big multinational companies tend to look at the biggest regulatory space in order to adhere to it. So it is important that we are mindful of how Brussels plans to proceed in this area, even if we find areas where we can be more flexible.
People have talked about our bad record in the UK on cyber security on account of cyber security attacks. I suspect that that is because we remain, I think, the most digital nation in the EU, and the English language as well provides us, weirdly, with some kind of vulnerability. But we are at the forefront of cyber security attacks, and it is important that we have the legislation and the bodies capable of responding to them.
Several themes have emerged. When I was the Cyber Security Minister, we began preparations for the National Cyber Security Centre: I thought that was incredibly important. I used to have a mantra that business in particular needed one front door that it could walk through to get the advice and expertise it needed to draw on to protect itself. We have talked constantly in this debate about 12 regulators, and I echo the calls to provide a uniform platform that can read across all the regulators, and they can add on top of that any sector- specific needs they meet.
I also recognise the calls from many noble Lords to say that this is perhaps an artificially constrained Bill, focusing on only a few vital sectors that are important to protect, instead of, as it were, seeing the whole picture and understanding, as many noble Lords have said, that cyber security pervades everywhere. There are so many ways in which we should look to protect ourselves in this age, one of which, of course, is in not losing sight of the hardware. The Minister spoke about software as a service. It is very important to remember that many of our public service providers, for example, still rely on ageing infrastructure, which provides huge vulnerabilities to cyber security attacks. I wonder whether the Government have a strategy to update much of the hardware that is still being used.
I was also interested in the remarks made about how vendors of software should be accountable. That is a very important avenue to explore: perhaps we could introduce kitemarks and audits of software providers to ensure that they are providing cyber-secure software that is as robust as it can be—again, as the noble Baroness said, we can count on the fingers of one hand the main providers of the software that is used in a vast number of businesses—and that they also work with us, as it were, to be on the front line.
It is interesting that this issue has become one of sovereignty. I am fascinated by the debate on the use of Palantir, for example. Personally, I have no problem working with Palantir. I think it provides a vital service, and I hope that the Government will be cautious in listening to the siren calls of people who say “Don’t work with these companies” simply because they disagree with the slightly bizarre views of some of their chief executives. Nevertheless, it perhaps calls for the Government to have a consistent story on this.
One thought that occurred to me during this debate was what has happened to the debate about encryption? This is a dog that no longer seems to be barking. In the last few years, we have had a vigorous debate on potential backdoors to encryption and security services being given, as it were, cyber keys to access encrypted services such as WhatsApp and Signal, and we saw a big pushback from the tech industry on how that would create big cyber vulnerabilities. I wonder whether the Government have come to a settled view on that.
Returning to the theme of the opportunities for the economy, the need to invest in cyber skills in our workforce is absolutely vital. We need to create a cyber workforce and a cyber defence force that work to protect the country, as well as giving companies the kind of skills base they need to make themselves secure. I echo the call from the noble Baroness, Lady Ludford, about boards. I was astonished to read in the House of Lords Library briefing that the number of board members with a responsibility for cyber has apparently fallen. I do not know if that is true, but I wonder whether it is possible to work with business bodies such as the IoD and the CBI to make it a strong corporate governance recommendation that every board should have somebody with a responsibility for cyber.
As I said at the beginning, this is a partnership: it is business, as much as government, that will protect us from cyber. For example, there has been reference to the insurance industry. One of the best ways we can ensure that companies invest in cyber security is to make it mandatory for them to get cyber insurance—which you cannot get unless you put cyber-secure measures in place—and to employ law firms to protect themselves from liability and to put in place important cyber measures.
I have not had a chance to support the noble Lord, Lord Clement-Jones, in his 50-year call for ethical hackers to be allowed to hack. I also echo the earlier call to hear the Minister’s views on the rise of bots and their impact on cyber security.
Baroness Gill (Lab)
My Lords, too often we hear in the news that our local hospital cannot access patient records, or that the transport network in our cities has stalled, or, as I experienced last year, that the power has gone on and off for over a month as the local electricity grid is affected by cyber attacks. A decade ago, some of this would have sounded like the plot of a Hollywood movie. Today, it is a weekly briefing on the desk of our cyber security data centres.
Our world has fundamentally changed. We are no longer just fighting off rogue teenagers or opportunistic hackers looking for a quick payout. The UK is currently navigating a highly sophisticated and aggressive digital battlefield. Malign actors are often directed, tolerated or unleashed by hostile nation states such as Russia, Iran and China, which are actively infiltrating key UK assets. They are mapping our infrastructure, stealing government credentials and probing our defences. That is why I welcome the introduction of the cyber security and resilience Bill. It is a critical and long-overdue overhaul of our national baseline defence. It marks the moment that the UK stops playing catch-up with hostile states and starts to dictate the terms of its own digital safety.
To understand why the Bill matters, we have to look at how our digital ecosystem functions. Hostile actors do not just knock on the front door; they look for the weakest link in the supply chain. Look at what happened in September 2025, with the devastating cyber attack on Jaguar Land Rover. Russian-linked hackers deployed sophisticated ransomware that completely paralysed JLR’s IT networks and forced a total shutdown of production lines across major UK plants for weeks, which had a major impact on the workforce in my old West Midlands constituency. The disruption that cascaded down into the automotive supply chain affected thousands of component manufacturers, mostly SMEs, with many workers in the region facing lay-offs. It had a major impact on the regional economy. Likewise, the attack did not just hurt the brand; it cost the British economy an estimated £1.9 billion, directly denting our national GDP. This was not just a corporate crime; it was an act of economic sabotage.
The threat extends far beyond manufacturing. Just weeks later, a massive cyber incident crippled electronic check-in and baggage systems at Heathrow Airport and across Europe. Was Heathrow’s central system breached directly? No. The attackers targeted a third-party vendor, Collins Aerospace, and scrambled the shared MUSE software that multiple airlines rely on. The result was chaos at terminals, hundreds of disrupted flights, and over 1.5 million passenger records being compromised. This new legislation fundamentally expands our defensive perimeter to address this exact vulnerability. For the first time, it brings data centres, managed service providers and supply chain partners directly into the regulatory spotlight, establishing a framework to name designated critical suppliers. The Bill recognises a hard truth: our infrastructure is only as secure as the third-party software we plug into it
Because of these aggressive state threats, a wider net is useless without sharper teeth. The Bill introduces two massive shifts in how organisations must run: rapid transparency and genuine board-level accountability. Under the new rules, if a covered organisation suffers a significant incident, or even a near miss capable of causing harm, it must file a notification within 24 hours, followed by a full report within 72 hours. In a cyber crisis, time is our most valuable currency. When assets such as Heathrow or JLR go down, an early warning allows the National Cyber Security Centre and regulators to contain the digital contagion before it spreads.
There are real consequences of negligence. For too long, cyber security has been treated by some boards as a minor IT issue, tucked away obscurely in finance or some other department. I am very pleased that the Bill changes this calculation. Companies that do not comply face financial penalties of up to £17 million, or 4% of their worldwide turnover. This will force executives to realise that robust cyber security is a core fiduciary duty. If you do not protect your network, you are jeopardising your entire business.
Crucially, this legislation is built to outpace our adversaries. Nation states use criminal proxies because they are fast, scalable and disguise geopolitical motives. Static laws become obsolete within months. The Bill grants the Government agile powers to update regulations swiftly through secondary legislation. This means that, as new state-sponsored threats emerge—whether through weaponised artificial intelligence or quantum decryption —the UK can adapt its defences instantly, without waiting years for a new Act of Parliament. The Bill also mandates companies immediately to notify their own customers if a breach puts those customers at risk.
To conclude, let us be entirely clear that the Bill is demanding. It will require an unprecedented level of capital investment and profound cultural change in every boardroom in this country, though I urge the Minister to consider undue burden on the SME sector, while recognising that it can sometimes be the weakest link. But we cannot ignore the reality of implementation. Cultural change does not happen purely through good will; it happens when the risk of non-compliance becomes completely indefensible. I ask my noble friend the Minister a fundamental question. While the target of the Bill is correct, the level of commercial investment and cultural transformation needed to meet these 24-hour deadlines is staggering. Beyond the immense financial stick, what mechanisms, support and enforcement frameworks will the Minister use to ensure this legislation drives genuine resilience, rather than just defensive corporate box-ticking? How will she guarantee that this heavy stick builds a shield?
My Lords, I declare my interest as a chief engineer working for AtkinsRéalis and I support the Bill. Given the threats that we are facing, strengthening the cyber security of the UK is vital. I think that the flexible, risk-based approach taken within the Bill is the right one.
Noble Lords have made many of the broader points already, so I will focus on a few narrower points. My remarks are really centred around the impact on economic growth and the need for proportionate regulation, because this legislation supports growth through, first, increasing our cyber resilience. The noble Baroness, Lady Northover, gave the example of the £15 billion cost of cyber attacks in 2024: that is a significant fraction of our GDP, around 0.5%.
I am also glad that the noble Lord, Lord Vaizey, brought up our world-leading cyber industry: the Bill represents a great opportunity for one of our key industries. However, there are threats to that growth agenda within the Bill, particularly through how larger corporates and SMEs will be affected, and we need to tread extremely carefully here. Business already has to deal with much burdensome regulation, as the noble Earl, Lord Effingham, set out. As ever in legislation, we need to think about those unintended consequences. To this end, there are three points I want to make.
Looking at some of the detail of the Bill, my first point is around supply chains. Clause 12 rightly brings in the concept of “critical suppliers” and ensures that supply chains are within the scope of the regulations. However, given the ambiguity of the criteria for designation, there is a risk that a significant number of SMEs could be affected, perhaps unintentionally, by this legislation, so I would be grateful if the Minister would set out what steps the Government are taking to ensure that the “critical supplier” designation is restricted to suppliers posing genuine systemic risks to the UK economy. Terms such as “potential to cause disruption”, which is the wording used in the Bill, are qualitative, and there are no hard quantitative thresholds in the Bill. The risk, of course, is that a significant number of SMEs could be bought within scope, stifling those businesses with unnecessary regulation. We need to ensure that is proportionate.
Secondly, going through the Bill and continuing on this theme, we come to Clause 15, on reporting. To expand on what the Minister set out at the start, Clause 15 expands the definition of “a reportable incident” to include those capable of having
“an adverse effect on … network and information systems”.
The risk is that this could lead to overreporting, as even a minor phishing email could be deemed to be capable of having “an adverse effect”, and then we could perhaps see overreporting overwhelming systems and bringing the risk that genuine threats could get through. So, I would also be grateful if the Minister could tell us how the Government will ensure that the “capable of having an adverse effect” threshold does not lead to overreporting of low-level incidents.
Thirdly, we have heard a lot of talk about AI in this debate, and perhaps a little less about quantum. I want to bring up quantum as a specific aspect, as the noble Lord, Lord Birt, referred to. I appreciate that there is a difficult balance here. This is a framework Bill, and it is perhaps not appropriate to set out specific technologies or technology impacts in it. However, the threat of quantum computers using algorithms like Shor’s algorithm to crack current public key crypto, such as RSA, enabling “harvest now, decrypt later” attacks on sensitive data, is something that will come, sooner or later, and quantum computing is evolving astonishingly quickly. The Parliamentary Office of Science and Technology, POST, where I am vice-chair of the board, has set out around a 10-year timescale for when a quantum computer will be able to break conventional encryption, and that aligns with the National Cyber Security Centre, which has already set out that organisations must complete migration to post-quantum crypto by 2035. I would be grateful for the Minister’s thoughts on how this could perhaps be strengthened within the Bill. For example, could there be something in the statement of strategic priorities in Clause 25 to help to join together the regulators in terms of the focus that is required on quantum cryptography? I would be very grateful for the Minister’s thoughts on that key area too.
In general, as I said, I support the Bill and I look forward to working with the Minister and her team as we move towards Committee.
My Lords, earlier today, the noble Viscount, Lord Colville, and I were saying that we were both quite late down this list and feared that everything would already have been said. That appears to be the case, but, fear not, I will still use my eight minutes.
I support the Bill and I agree with many noble Lords that we also need a much more comprehensive cyber security strategy. Like others, I have some specific suggestions for this specific Bill. My unique contribution, if it is unique, is not that I am an engineer and tech expert, as the noble Lord clearly is. I think that, in health terms, I would be described as an expert by lived experience, in that I suspect I am the only noble Lord today, probably the only noble Lord on the roster, who has actually been a CEO faced with a cyber attack. I have been that CEO whose company has been targeted by a gang of hackers, trying to work out how to navigate the crisis. I have had to go out and communicate to regulators, to customers, to shareholders.
To Ministers, indeed—to my noble friend himself. In those days, the National Cyber Security Centre did not exist—I am obviously referring to my time as chief executive at TalkTalk. Instead, we were directed to the Metropolitan Police’s hostage negotiation team. They were lovely but unfortunately had no tech experience at all. In fact, we did no better ourselves. The security expert who came to brief the TalkTalk board had just come from Mexico, where he had been trying to get a bank manager back who had been kidnapped.
That was only 11 years ago. At TalkTalk, we took the view that communicating was the only way to help our customers and therefore the only way to save the company, and I stand by that decision now, but not everyone takes that view. I was accused at the time of being hopelessly naive for going out, within 24 and 48 hours, on to the airwaves and saying, “My customers have been attacked and, no, I don’t know exactly what has happened”. That is the timetable in this legislation. Most CEOs I talk to say, first, “God, I’m glad I wasn’t in that situation. That’s my nightmare”. Secondly, they are surprised when I say that, actually, I would communicate earlier if I was in that situation again and not later. Cyber attacks are a modern-day taboo in the business world. Business leaders are terrified of admitting that they have been attacked, and I am afraid that that means that mandating reporting is essential, because, 11 years after I was in that situation, I do not think that that has changed. I think that unless we make it mandatory to report, people will not do it.
I was surprised at the time, in 2015, that had Sainsbury’s or Tesco been hacked, I would not have had to tell anybody—I had just come from Sainsbury’s in my previous job. It is really depressing, 11 years later, to see that retail is still excluded. I cannot quite understand why water is “essential” but food is not. I think that Covid taught us that our food retail supply chain is an essential service, and those who work in it are essential workers.
Managed service providers are in, but generative AI is out. Only a decade ago, that might have been OK, but it is not now. In the other place, the Minister said there are powers in the Bill so that we can get it right in the future. Well, we need to get it right now, and we also need the powers to try to keep up. I am not against giving Ministers the power to keep this live, but that is not an excuse for not being up to date today. As other noble Lords have said, it looks, sadly, as though the EU has got this more right than we have. We should be humble enough to admit that, rather than be afraid and insist on doing the wrong thing.
The other area I have some lived experience in, which, again, has been mentioned by other noble Lords, is the challenge of 12 NIS regulators and the lack of join-up. When the TalkTalk hack happened, we immediately stood up a series of workstreams—the obvious things such as trying to work out what had happened. That is the biggest problem with a cyber attack—you genuinely do not know whether you have been attacked by a nation state or kids in a bedroom. You somehow hope it might be the former, but more often than not it turns out to be the latter. So you have to know what has happened and you have to start communicating before you know what has happened. That is two workstreams. You have to work out how to get your systems back up again. That is another workstream. Even 11 years ago, without any of these additional regulators, we had to have a “communicating with regulators” workstream.
Now, spare a thought for the poor managed service providers. They are companies that serve transport, telecoms, energy and the NHS. I think they might have a full house. If you were a managed service provider that was the victim of an attack, you would probably have to deal with all 12 regulators. Those of us who have been here for a while know that if you give 12 different public sector bodies the ability to define terms, they will define them in 12 different ways and have 12 different forms. That will stop you, in the first day or the first week of a cyber attack, doing the things that you should be doing to try to protect your customers. As an expert through lived experience, I plead with the Minister: join-up is essential. It should not be optional. We all know it is hard to do. If you do not sort it out in the Bill, it will not happen. Please do not make that join-up a forum.
I can take myself back to October 2015 and imagine having to communicate with—as much as I love it—the DCRF. If we had had to convene a meeting of 12 regulators in the heat of the crisis to work out what to do, that would not have helped anybody. So we need either a single regulator, as the noble Lord, Lord Birt, so eloquently set out, or a lead regulator, as I know the Government are looking at in a number of other areas, to try to reduce the burden of regulation. I very much support what my noble friend Lord Effingham said: regulation does look like it is necessary here but we need to be careful that we are not just layering burden upon burden, and doing it 12 times most definitely is.
I feel I have said nothing original at all but have said it possibly from a unique perspective. I am rare among former chief executives who have experienced a cyber attack in that I am willing to talk about it, which is exactly why this legislation is important. But I very much hope that, as with so many tech issues, the Minister will hear that we agree more than we disagree and that we could work together to improve the Bill, as this House is often quite good at doing.
My Lords, I thank the Minister for introducing this important Bill. Cyber security is clearly vital to the protection and prosperity of our nation. But if we fail to plan, we plan to fail, and this Bill is at the heart of the Government’s cyber security plan.
I was born and raised in a part of the world that many think of as paradise, bliss, utopia. It is called Birmingham, just off the M6 by the gasworks. I can see there is some accord in the Chamber—or maybe it should go to VAR. I was a district councillor in that region. One of the largest employers there is Jaguar Land Rover. This giant motor vehicle manufacturer is the head of a supply chain of over 4,000 companies. JLR was the victim, as we all know, of a cyber attack last year and was bailed out by this Government to the tune of a £1.5 billion loan guarantee. The Government believed they had no choice because if they had let JLR fall, thousands of workers would have lost their jobs. I have some sympathy with that rationale, but it did set a dangerous precedent. It is also worth noting, surely, that the company had not completed taking out an insurance policy against cyber attacks.
So the first point I want to make to the Minister is that there is no mention in the Bill of the role of the insurance industry. Surely the issue of essential and compulsory cyber insurance needs to be looked at; otherwise, we will have another situation where we have to bail out another huge company.
The retail chain Marks & Spencer lost 99% of its profits due to a ransomware attack which disrupted services and stole customer data last year. Harrods and the Co-op also experienced cyber breaches over recent months. Surely, then, there is a glaring weakness in the Bill in that it will have no impact on private companies such as these. Can the Minister explain why the scope of the Bill cannot be extended—not in the future but now—to include large private retailers, at least those over a certain defined size or turnover? I understand there is potential in the Bill for improving things in the future, but why not do it now?
One of the lessons of history is that we must learn lessons from history, and surely a vital lesson is to take into account the changes in the world around us. In the Bill, the Government recognise that the artificial intelligence revolution has increased the need for more effective cyber security. Yet there is still no UK AI regulation, no cyber strategy, no mention at all of quantum computing or encryption. These matters need to be discussed and looked at now, not some time in the future, when you consider how fast AI is progressing.
We also have a cyber security skills shortage, with 49% of UK companies admitting a lack of cyber foundational skills. As well as protecting the nation, in this AI age it is skills that will pay the bills and grow the economy. It is right that the Government have announced initiatives to attempt to fill vacancies in the cyber security industry, but there is no definition in the Bill of what is required to be a “skilled person” in this context. I just ask the question: why not? Why not look at it now?
We are living longer, and the demands on the public sector are growing, but there is a lack of focus in the Bill on the public sector, particularly the risk to NHS data. For example, Synnovis, which has been mentioned, is a company which provides pathology services to the NHS. A couple of years ago, a ransomware attack on Synnovis cost £32.7 million and resulted in delays to more than 11,000 appointments and even, allegedly, one death. Surely all companies, private and public, that hold personal data should demonstrate that they have effective defences against cyber attacks. I have tried to find out whether Synnovis or its suppliers would be covered by the Bill; there is some ambiguity over that, and that ambiguity at this stage is not helpful.
I welcome that the expanded scope of the Bill now includes data centres, managed service providers, electrical load controls and critical suppliers. But the Bill does not go far enough to protect the UK economy. The current structure of the Bill allows the Secretary of State, in principle, to expand the number of sectors in the scope of the regulations. But even to implement secondary legislation will require the Government to meet a number of conditions. The Minister has referred to emergency powers, but that is still a process rather than an event. Surely the principle of the Secretary of State reporting back to Parliament every five years is not good enough in this fast AI world that we are living in.
The Government also need to recognise that many companies operate across borders, including in the EU, where they have to comply with European directives on cyber security that do not apply in the UK. Over- regulation must not stifle innovation. With 12 regulators enforcing this Bill, there is a danger of regulatory duplication. This is especially so for organisations covered by more than one regulator. Where appropriate, the Government should seek to ensure that UK cyber security regulations align across each regulated sector and across borders with other jurisdictions such as the EU. For example, the Government could ensure that all regulators accept common forms of evidence demonstrating compliance.
There needs to be the adoption of a common baseline security standard, alongside ongoing evidence of security requirements across regulated sectors. This should also recognise that different sectors have their own particular needs: farming is different from fashion, which is different from football. The standard could be the National Cyber Security Centre’s cyber assessment framework. An example of co-ordinating regulators already exists in the Digital Regulation Cooperation Forum, which helps deliver a coherent approach to digital regulation.
Some 43% of all UK companies experienced a cyber breach in the past 12 months. The Department for Science, Innovation and Technology reports that cyber attacks cost the UK economy £14.7 billion a year, and the problem is increasing. For 10 years, I had the privilege of being vice-president of the British Board of Film Classification. Hollywood sometimes produces entertaining films that see the future; for example, Steven Spielberg’s movie “A.I.” was made 25 years ago—an incredible thought. There was a consistent theme in many of the more positive films that we regulated, in that good overcame evil. With a stronger version of this Bill, we can defeat the cyber monsters. In the more positive and hopeful movies we regulated, RoboCop prevailed over the Terminator and Luke Skywalker overcame Darth Vader.
My Lords, I strongly welcome the intention of the Bill to strengthen the United Kingdom’s defences by updating our cyber security legislation as it applies to critical national infrastructure. That is good and overdue. As my noble friend Lady Gill pointed to, there is barely a week, if not a day, that passes without a significant business, hospital, local authority or supplier to government reporting a serious cyber incident. Every part of our infrastructure is vulnerable, and a legislative update to reflect that reality is one that this House should have absolutely no hesitation in supporting.
Noble Lords have already raised concerns about a number of things relating to what is or is not in the Bill, and things that perhaps need to be tweaked—how we should consider the economic impact of cyber attacks, as well as issues around insurance, reporting, workforce development and training, making AISI a statutory body and the lack of joined-up work across 12 different regulators. These are all concerns that I share.
I want to use the time I have available to add some details on the significant gap that has already been shared by others: the Bill currently makes no provision at all for artificial intelligence or, connected to that, for cyber sovereignty. This is not a hypothetical concern. Our allies have already grasped that, if their critical systems, their public services and their citizens’ data will depend increasingly on AI, relying entirely on foreign-built, foreign-hosted models is itself a national security question and diminishes those countries’ resilience. This is now the direction of travel right across Europe, and we should not assume that we can simply stand outside it.
The Netherlands has built GPT-NL, a sovereign open language model developed by a consortium led by the research institute TNO alongside SURF and the Netherlands Forensic Institute and funded by the Dutch Government. It exists explicitly so that Dutch public bodies are not routing sensitive data through services they do not control, governed by laws they did not write and using models they did not develop or test. Germany has gone further still with Soofi—Sovereign Open Source Foundation Models—a government-backed initiative bringing together German research institutions and industry to build an open foundation model of around 100 billion parameters intended to underpin domestic industry and to handle complex technical and analytical tasks. These are not vanity projects; they are deliberate decisions by Governments to secure and keep control of the systems their public services are increasingly relying on.
The strategic logic is plain. A handful of foreign providers now sit upstream of much of the world’s AI capability, and a dependency that concentrated is a single point of failure that no Government should accept for their critical national infrastructure. Sovereignty over the AI that runs our critical systems cannot be an optional extra; it should be treated as part of our national cyber security and national resilience decisions. The Bill as currently presented is entirely silent on that question.
I will raise two specific areas where this absence should concern your Lordships. The first is education infrastructure, specifically exams and marking, which are increasingly stored and processed online. I understand that awarding bodies in this country are already exploring AI-assisted marking. If AI becomes embedded in that process, the accuracy of a child’s marks will depend partly on how that AI model behaves, and yet it will sit outside the Bill’s jurisdiction. We are creating a critical dependency for the life chances of every child in this country, resting on a model we may neither own nor be able to scrutinise, with no corresponding legislative safeguard. We would have all the risk of a critical dependency with none of the legal guardrails that the Bill is designed to provide.
The second area is electoral services and the data held on the electoral register. I do not think I need to labour the point about why the integrity, security and sovereignty of electoral roll datasets matter. If AI systems come to play any role in how our electoral registers are compiled, verified or protected—we should assume that they will—we must be able to answer three questions: who controls the model, where does the data go, and what happens if that dependency is disrupted or compromised? A register we cannot fully account for is a register that we all cannot fully trust. The Bill should be equipping us to answer those questions.
None of these points is an argument against the Bill; they are an argument for finishing it. As many noble Lords have already alluded to, technology is moving faster than any Bill can be introduced. There are many stats on the speed of tech evolution; the one that consumes me the most is that the maximum length of tasks that AI models can successfully complete is now doubling roughly every four months. We owe it to the public to build in adaptability from the start, rather than returning to primary legislation each time the landscape shifts.
We have here in the United Kingdom one of the largest and richest bodies of public data anywhere in the world, not least from our NHS and our public service broadcasters. As the cost of building capable AI systems continues to fall, we have a genuine opportunity to harness that data ourselves; to help clinicians reach diagnoses faster; to ease the administrative burden that weighs so heavily on our public servants; and to build public services that reflect our own standards, accountability and values, rather than simply adopting whatever the market happens to offer.
Building this capability at home is also how we ensure that the guardrails and safety measures that we believe are necessary are actually built in to bolster the opportunity for full cyber security, rather than inheriting it from systems designed to other standards and other priorities without any concern for real safety and security. This is something for which I will continue to advocate and which, I believe, will supercharge the realisation of the aims of the Bill. I therefore welcome my noble friend the Minister’s reflections on whether AI and cyber sovereignty might yet find a place in this legislation.
I look forward to the rest of this debate and to playing my part in scrutinising and enhancing this legislation.
My Lords, I, too, welcome much of the Bill. It could not be more important in a world in which warfare is not just physical but digital. It is essential as part of our national security that our Government step in to protect us from such attacks.
Most noble Lords, I think, welcome the list of bodies to be regulated in Part 2. I am very glad that data centres, large load controllers and specified management services have been brought within the scope of the Bill. After all, the Government celebrated the huge investments of AWS and DC01UK in data centres. It is important that they are now covered by the Bill as an essential part of our national security.
There has obviously been an attempt to future-proof the Bill against the fast-changing world of tech. At the beginning of Part 3, Clause 24 gives the Secretary of State enormous and flexible powers to designate what is essential activity for the economy of the United Kingdom and the day-to-day functioning of society. This flexibility is then reinforced in Clause 43 in Part 4, which gives powers to issue directions to regulated persons and to decide what should be reported and to whom it should be reported.
My fear is that the Bill does not go far enough to address the present threats, let alone the future ones. Noble Lord after noble Lord has raised concerns about the failure to mention AI in the Bill at all. I, too, was at the terrifying meeting mentioned by my noble friend Lady Kidron, which was held earlier this month, by the Institute for AI Policy and Strategy and the Centre for Long-Term Resilience. They guided us through the world of software vulnerabilities and patches. In the arms race that is the search for software vulnerabilities, it is a fight between the attacker and the defender to find the flaw first. Even then, the rollout of patches to downstream defenders can be slow and leave them open to further attacks.
Having absorbed these concerns, we were then told about automated AI attacks, in which an automated AI agent can carry out all the steps of a cyber attack on its own as an autonomous operator. AI agents no longer need skilled labour to develop an attack—expertise can be rented from AI systems—and the attacks can vary in their approach and learn from each failure so that initial defences can be breached once again.
The AI Security Institute found that, between December 2005 and December 2006, a single hacker weaponised the Claude and GPT-4.1 systems to bypass safety guardrails and develop 400 attack scripts. The breach exposed the personal data of 195 million citizens in Mexico, including their tax and electoral registers. At the very least, if data centres can be added in at a later stage in the shaping of the Bill, frontier AI models operating in this country can and should be added in as well. They need to be protected from attack by foreign agents and rivals.
I am aware that, as Ministers have often said, regulation can be an obstacle to new start-ups. If that is the case, there needs to be a threshold on the size of the frontier AI models that would need to abide by the demands of the Bill. There also needs to be in the Bill a new clause in which AI frontier providers are designated as essential models.
The noble Baroness, Lady Harding, was right: I am going to repeat what other noble Lords have said. The Bill leaves lacunae over large sectors of the economy, which I am sure most noble Lords regard as essential services. The Bill must include critical manufacturing and retail, both of which suffered devastating cyber attacks in the past few months. Many noble Lords have mentioned the huge attack on Marks & Spencer. Noble Lords only have to imagine the effect on the country if there were successful attacks on one or two of our big supermarket chains. The result would throw the national food supply chain into crisis. Surely supermarkets, which provide much of our nation’s food and other services, need to be considered very carefully for coming within the scope of the Bill.
I understand that, unlike the finance, telecom and digital sectors, the manufacturing and retail sectors do not have a regulator. Nevertheless, Clause 24 allows for flexibility in this space, so I support the calls from the noble Lord, Lord Birt, and the noble Baroness, Lady Harding, for a cross-sectoral regulator. Perhaps the Government need to set up a second tier of essential service sectors that should be preparing to be brought within the scope of the Bill. In the longer term, it might be important to ensure that they are building the highest resilience to AI-powered cyber attacks.
This work must further strengthen resilience at board level. It cannot be left to AI departments to work out resilience on their own. I suggest that the Minister makes further changes to the UK Corporate Governance Code straightaway so that more responsibility for reporting incidents is taken at board level. The Minister is in a unique position to do this, being the Digital Economy Minister and having previously been in the DBT.
My other area of concern about the Bill is the importance of co-ordinating the reporting of cyber attacks, especially AI cyber attacks, to build cyber resilience. There should be an extensive list of sectors that are brought into scope, as the EU legislation has suggested. It is terrifying that so many of the automated AI attacks are what the industry calls “misalignments”, meaning that their outcome is not what the original design of the model had intended. Not only do they create outcomes that were not the original intention of the creators of the model but those creators do not even know that these misalignments have taken place.
I know that the Government have created the Cyber Resilience Pledge for our FTSE 350 companies, which means that they will sign up to the NCSC’s early cyber attack alerts and recommend a Cyber Essentials suppliers kit. The Government have put aside £90 million for resilience centres to give advice against attacks on SMEs. However, these all depend on voluntary responses by the affected companies. The Government need to mandate a reporting requirement so that effective defences can be rolled out across the economy.
I understand the flexibility on reporting given by Clause 43, but this country is confronted with the prospect of automated AI attacks. It is essential that the widest range of reporting of these attacks is included in the Bill. There must also be a mechanism for mandating the co-ordination of reporting these attacks. The Government must ensure that information about the attacks is brought together and that advice is co-ordinated on how to build a defence against those attacks. The information is crucial for AI frontier model companies to know that their agents are creating misalignments and for downstream companies affected by the attacks to build secure defences. The essential reporting on attacks needs to be brought together by the NCSC or the AISI. The Bill then must ensure that there is a cross-cutting regulator in the longer term.
The Bill recognises that we live in an ever more dangerous digital world. The introduction of autonomous AI into the digital world will affect us all and could do so to a disastrous degree. I call on the Government to ensure that AI is in the Bill, both in the sectors in scope and in the reporting requirements for these and other sectors. Failure to do so will open our country to attacks which will devastate our economy and our society for years to come.
My Lords, it is a pleasure to take part in this Second Reading debate and to follow my friend, the noble Viscount, Lord Colville of Culross. Though he, by his own words, repeated some of the earlier points, he was the first speaker to say “lacunae”, for which I am particularly grateful; it sounds like a technology company. I declare my technology interests as set out in the register, as advisor variously to the Crown Estate and to Simmons & Simmons LLP.
As has been noted, this Bill is significant by having “cyber” in the title. This is long overdue, much needed and critical, as the Minister said, taking a cross-sector approach to cyber. Yet the first interesting point is that the Bill does not do that. Most notably, it is extraordinary that neither food nor space are included in the Bill. Similarly, it is said to take a cross-economy approach, yet it does not. However, it is worth mentioning the two sides of that economic coin and the huge economic growth potential from our cyber industries. I echo all the points that have been made about the need for skills and education, and to enable the cyber sector to grow and deliver that economic benefit.
Reporting has been mentioned widely throughout the debate. It is unfortunate if one finds themselves in a situation such as that of my noble friend Lady Harding, with multiple agencies to have to report to. Surely it would make sense to have a single reporting point for the speed, efficiency and effectiveness of that reporting system. Similarly, there is so much opacity around many of the definitions within the Bill. I pull out “significant impact” as one of them. What does this mean? If it stays as set out, the natural and understandable response from business is to go for the low-level mass reporting to avoid regulatory intervention. Does that enable the economy and the country to be better protected in this respect? I think not.
Similarly, the 24-hour and 72-hour reporting requirements feel oddly constructed around the artificial concept of a day set out in 24 hours. When one considers the real-time velocity of these attacks, it would seem logical that something way ahead of 24 hours would be advantageous at that stage and potentially something extending beyond 72 hours to do the second bit of the reporting process. What evidence is there to support this quite arbitrary 24 hours—or, as otherwise described, a day?
Security and resilience are the concepts most central to the Bill and will be the markers of its success or otherwise. For issues around proportionality and the ability to evolve and develop, does the current structure of the Bill really optimise this? MSPs have already rightly been mentioned. The burden for them is overbearing as currently set out. Surely it would make more sense to have a concept around what is reasonable for MSPs to oversee, what can legitimately be seen as within their control and how they can evidence that.
Understandably, the multiple regulator issue has been well discussed. It is critical, because how will we have co-ordination across all those organisations? A forum is certainly not the solution, as my noble friend Lady Harding rightly set out. A lead regulator, a single regulator or something around that has to be the way to go. I would argue that the NCSC should have the loudest voice in determining what is the best model and the best structure for doing that.
I was interested in the Minister’s introduction. She talked about the criticality of cross-sector consistency. I agree entirely, but in a debate on AI on 4 June in Grand Committee, she argued that consistency was not necessarily a central principle for the Government in the regulation of AI. I believe that a true cross-sector approach to cyber makes sense in this Bill. We can add to what is currently there and make that happen, but it is surely logical, and indeed a consistent approach to consistency, that we take that approach with AI. Can the Minister say why, if this argument is good for cyber, it is not good for AI—with a cross-sector approach, as will benefit this Bill, that is principles based and outcomes focused, with inputs understood?
I have another point on consistency. When the Minister sums up, can she set out the advantages that she sees in all the divergences that the Government have taken from the EU’s NIS2? I would be interested to hear the Government’s arguments for the advantages that they are seeking to bring from that.
My noble friend Lord Arbuthnot has rightly mentioned the CMA, and I know that my friend, the noble Lord, Lord Clement-Jones, will also mention this. It is right to mention it in this Bill, even though the national security Bill is said to be the vehicle through which this will come forward. It is right to give it a run around the track in the legislative process with this Bill, because we are talking about coverage currently holding our cyber professionals back because of a 1990 statute. To give some sense of what that means, in 1990 it had been only 24 years since England had won the World Cup. It is in urgent need of reform. We need to empower and enable our great cyber security professionals to do their job.
I have a quick point on DVS. I am not sure the Minister was involved when we did the Data (Use and Access) Act, but there was rightly a lot of discussion around DVS. In some ways, parts of this Bill are the other side of that coin. Currently we have a situation that is not addressed in the Data (Use and Access) Act or in this Bill: what happens to verification services when they have an attack where synthetic data is injected directly into the data stream, in effect bypassing the camera to get verification? How does this Bill address that issue? Do Clause 12, the potential regulations under Clause 30 or the guidance under Clause 36 address this? If not, what is the Minister’s view as to how we address that critical issue around synthetics?
The success of the Bill and of cyber in the UK will rest so heavily on the shoulders of our cyber security professionals, the women and men who do so much to keep our system—and, through that, us—safe. We owe them so much. Understandably, they often do this in the shadows, in dark rooms and in the Doughnut. We give them our sincere thanks, and we must demonstrate that thanks through the amendments we bring forward to make the Bill better.
Lord Moraes (Lab)
My Lords, it is a pleasure to follow the noble Lord, Lord Holmes. The noble Baroness, Lady Harding, has inspired me, as I am so low down the list—nearly at the end—not to do that thing of saying, “Everything has already been said, but not yet by everyone”, which I was thinking of while she was speaking. I will not do that; I am going to dump my very boring speech, inspired by the noble Baroness, Lady Ludford, who reminded me of what we used to do for a living. This contextualises exactly what the Government are trying to do.
My noble friend the Minister has a very tough job—I will explain a little why I think it is so difficult—but it is a job that we said we would do. We wanted to update the NIS regulation in 2018 and, as the noble Baroness, Lady Neville-Jones, said, to move fast and have some urgency. I know why she said that: I will come on to what the intelligence services are dealing with every single day, with hacking and what the Russians are doing. She knows that, as that is part of her DNA. We have to move fast, and we have to do something. That is exactly what the Government are doing. I want to try to contextualise what they are doing, why this is a national priority and how we can be as constructive as we can in building cyber security and cyber resilience.
A number of noble Lords, including the noble Baroness, Lady Harding, mentioned the EU network and information systems directive, which is very much the context of what we are doing. The noble Baroness, Lady Northover, spoke in some detail about our alignment with it and the noble Baroness, Lady Ludford, had some critical views about where we are in terms of our alignment. This really contextualises the complexity, as well as the urgency, of what we are doing here in the UK.
Noble Lords have said this because there are really only three global regulators doing this now—in the United States, the European Union and China—and they are diverging very badly. China does its own thing. In the United States, you may remember Mark Zuckerberg coming to the EU inquiry, going to Congress and saying, “Well, we need a GDPR, obviously”, but most of the legislation in the United States on cyber is in fact state led. The FTC looks at it, but it is really not national legislation. The EU is one of the few places, whether you like it or not, which has decided that it is a global regulator and that the cyber threat and cyber resilience are very much a global issue.
That does not take away from or dilute in any way some of the things that have been said, for example by the noble Lord, Lord Vaizey, about the United Kingdom’s special position as a country. We have the best intelligence services in the world, which is very relevant to this area. We have GCHQ and all that, and the technologists and companies close to this area, which are some of the best in the world. But the issue is with global regulation, and that is why it is so difficult.
The noble Baroness, Lady Ludford, made exactly the point that I was going to make, except I come to a different conclusion. She talked about the way that the two Ministers, Ian Murray and Kanishka Narayan, seem to be saying two different things. One is saying that we are taking a big hit and that real businesses and people are being hit by cyber breaches; whether or not it is 0.5% of our GDP, it is a big problem for the United Kingdom. Our other Minister said that we need the 12 regulators, to which the noble Lord, Lord Birt, referred, because they have the expertise, and that that is why it is so complicated and if we do anything else it is a huge burden on business. But I believe that both are true.
This is where the complexity of enacting good-quality cyber legislation happens. I know this because, as the noble Baroness, Lady Ludford, will testify, I chaired many of the GDPR legislative trilogues and the ePrivacy trilogues and I had to scrutinise many of the cyber conventions that are part of the EU treaties and body of law. I will cite the latest AI rapporteur—we now have another AI Act forthcoming in the EU because the older Act is out of date, the GDPR is out of data and the ePrivacy legislation is out of date. I said to the AI rapporteur, “You have the latest AI legislation”, and he said, “Yes, it’s a bit like you just jump off the cliff and build your wings on the way down”. Why somebody from Italy was quoting Ray Bradbury I do not know, but it is kind of correct. I know that the Minister has wings already—she has wings and she need not worry; she will be fine—but the point is that you have to move with such speed. The point that the noble Baroness, Lady Neville-Jones, made is that somehow you just have to move. The urgency is great.
The noble Lord, Lord Vaizey, who is not in his place, has inspired me to depart from my notes. He explained very eloquently, having been a Minister at that time, how complicated this is for our current Ministers in government. He talked about encryption and said that we knew that the companies—Microsoft, Facebook, which is now Meta, Reddit, Snap Inc, and all of them—wanted end-to-end encryption and did not want it weakened. Why? Because with strong end-to-end encryption, you deal with cyber threats. At the time, as noble Lords will remember, there were a lot of terrorism threats around, so most enforcement agencies were saying, “No, we need a backdoor to encryption”. That was the prevailing wisdom, and that argument won out. But the companies, in my view, were right. They were talking about the banking system, privacy and all the threats that we now have if we weaken encryption.
The noble Lord, Lord Vaizey, said that because the context here is that it is extremely complex to come up with good cyber security and resilience legislation. The noble Lord, Lord Birt, is so good with his communication that I almost think the OCR is a real thing. That is because he is who he is—he could persuade anyone. Of course, everyone is saying, “Let’s get rid of the 12”, but I caution about the complexity of dealing with cyber threats. I will give one last example about the daily threats we have from foreign actors—this is very different from the corporate threats, some of which come from within the United Kingdom and need a very different response, as we also saw in the European Union.
My time is up, but I just want to contextualise how tough this is going to be. Let us jump off the cliff, build the wings on the way down, get this done and do what we can in Committee, because this is a national priority. Is it perfect? Of course it is not. But we need to get moving, because the threats are very real.
My Lords, it is getting late, and I am told that we are now competing with the Spain v France World Cup semi-final—the winner may well face England in the final—so I will try to be brief. I speak not as a cyber expert or technologist but as a former CEO of a tech-enabled mid-sized business. I want to bring some ground-level perspectives of these oft-mentioned SMEs, one of which I currently chair.
I welcome the Bill, but like many others, I have some concerns over its scope, its impact on those apparently outside the scope but who sit within critical infrastructure supply chains, the challenges of a horizontal piece of legislation being layered over multiple sectors and their regulators, and why, as so many people have asked, there is no specific strategy for AI. All of that has been covered, and I will not repeat those points. However, I want to question why central government and local authorities will remain out of scope. The National Audit Office’s report last year found serious slow-to-fix security flaws across 58 of the 72 government systems that were reviewed. The public sector badly needs binding legal requirements, not just a voluntary action plan.
As we have heard, the UK is already the most targeted country in Europe for cyber attacks, with more than 40% of UK businesses experiencing such attacks at a cost put at almost £15 billion annually. But those numbers are almost certainly an underestimate not just because they apply to 2024 but because a whole range of cyber incidents go unreported and therefore unmeasured, especially in the world of SMEs. In fact, 96% of UK businesses that suffered a cyber attack were SMEs, not because they are targeted but because they are easier to breach. If you factored in all the incidents and took into account all the costs, including the distraction from core business, the real cost this year might well be closer to £30 billion—roughly 1% of our GDP.
Let us face it: when this Bill is enacted, it will already be out of date. That is not an argument for delay, but it is an argument for shaping legislation to allow changes and add-ons down the line as the threats change without going through the long and arduous processes of legislating through both Houses of Parliament. I suggest that we are pragmatic and that we balance the need for parliamentary scrutiny and consultation with speed and agility.
I am going to finish by focusing on the mid-market and small businesses. The Bill tells us that high impact suppliers of any size could be designated as critical suppliers. That has raised quite a few question marks. Two-thirds of medium-sized UK businesses reported a cyber breach last year alone, yet only 15% of those businesses had formally reviewed the cyber risks that their immediate suppliers posed to them. This Bill will make mid-market players take compliance, incident reporting, risk assessments and audits more seriously. Those should no longer be seen as the sole responsibility of the IT department or the CTO but become a board- level issue that CEOs need to engage with. Currently, only 27% of UK businesses have board-level cyber accountability. That needs to change.
It is confession time. I was once one of those mid-market CEOs who took too little interest at board level in the risks to our company’s infrastructure and systems, delegating them to mid-management and our offshore partners and nearly paying the price when our online platform, which contained all our customer data and 20 years of content, came under attack and was very nearly successfully hacked. Lessons were quickly learned. Will the Minister say how the Government plan to address and resource the information, communication and training challenge that this Bill will present to mid-market players?
I raise the same question for those SMEs that will get dragged into supply chain compliance issues, whatever their size, but without the specialist resources needed. In the other place, the Liberal Democrats proposed what I thought was a very sensible amendment for the establishment of a cyber security support service to help SMEs comply with their regulatory duties. This was dismissed by the Minister, who said that very few SMEs would be in scope, but nobody has put a number to this and I think this misses the point. I fear that the Government underestimate this challenge, both for mid-market and small players.
If this information, resource, communication and education piece is not properly addressed, we will not just lose links in the supplier chain but reduce the level of competition. This will be bad for business and economic growth and, indeed, for trade with our European neighbours, who are way ahead of us in this area.
My Lords, my noble friend Lady Harding talked about speaking half way down the list, and the noble Lord, Lord Moraes, of being nearly at the end of the list. I am last, as your Lordships will be glad to hear.
I must declare my interest as an employee of Marsh Risk, an insurance brokerage company with a large cyber practice. Like many other noble Lords, I welcome the Government’s ambition to strengthen the UK’s cyber defences and, in doing so, to protect the continuity of the essential services on which the public depend.
The Bill’s direction of travel is right: widening the scope of the existing regulatory framework to reflect modern supply chains, strengthening oversight and improving the flow of information to regulators and the National Cyber Security Centre so that we can build a clearer national picture of threats and vulnerabilities. However, I will press the Minister on two areas where the Bill, as drafted, risks leaving practical gaps: first, the role of cyber insurance in building national resilience; and secondly, whether the proposed incident reporting timelines will, in practice, help resilience or inadvertently hinder it.
On insurance, my argument is straightforward. Regulation, technical standards and guidance are essential, but they are not, on their own, a resilience strategy. Resilience also means the ability to recover quickly: to fund remediation, to access specialist incident response capability at speed, and to keep vital services running while systems are rebuilt. My noble friend Lord Arbuthnot referred to cyber insurance. On its own it is not a silver bullet, but it is one of the few tools that can mobilise financial and operational support within hours. Time is of the essence to limit further damage, as we have seen in a number of recent incidents.
The noble Baroness, Lady Paul, discussed how insurance can incentivise behaviour. I very much agree with that and a lot of what she said. I will take the process a little further. In the cyber insurance market, the best policies do more than pay claims. They typically provide 24/7 emergency hotlines, pre-vetted panels of incident response firms, forensic expertise, legal and communications support, extortion specialists and business interruption expertise, all of which can be decisive in reducing harm, shortening outages and supporting faster restoration of services. Some insurers even pay loss or claims expenses directly to the party owed—for example, breach counsel and forensic vendors—saving their clients from having to pay large incident response costs out of pocket. For many small and medium-sized organisations, it is often the only affordable way to access that depth of capability. This support can potentially prevent the Government having to step in, as they had to offer to do in the Jaguar Land Rover incident.
Yet cyber insurance can play that stabilising role only if organisations are encouraged to take it up as part of a wider risk management approach. Indeed, my noble friend Lord Vaizey talked about it being mandatory. At the very least, we need to create greater awareness of the benefits that cyber insurance can bring to businesses. Personally, I tend to prefer a carrot rather than a stick approach.
My first question to the Minister is: what incentives are the Government considering to encourage greater uptake of cyber insurance, particularly among smaller operators and critical suppliers who may sit outside the largest corporate balance sheets but whose disruption can cascade through supply chains? Has she considered introducing a moratorium on insurance premium tax of, say, three years for companies that take out cyber policies for the first time, as a way to incentivise uptake? Incentives are not just about premiums. They are also about information and confidence, ensuring that organisations understand what insurance does and does not cover, encouraging consistent baseline controls so that insurers can price risk responsibly, and supporting appropriate data sharing so that lessons from incidents can improve both national defences and underwriting insight. In short, the objective should be a virtuous circle: better cyber security, greater insurability, more uptake and stronger national resilience.
I turn to incident reporting, as discussed by the noble Lord, Lord Ravensdale, and my noble friend Lord Holmes. The policy intent to ensure that regulators and the NCSC receive timely warning of significant events is understandable. Many noble Lords have mentioned this in principle. But in a major cyber incident, the earliest hours and days are dominated by triage, containing the threat, protecting services, preserving evidence and restoring critical functionality. Those involved in the response work around the clock to keep the businesses running. In that context, the requirement for rapid reporting can create real operational tension.
As I understand it, the approach envisages a two-stage process: an initial notification shortly after the organisation becomes aware of a significant incident, followed by a fuller report within a tight timeframe. My concern is not with the concept of early warning; rather, it is that the requirement to produce a comprehensive report within 72 hours risks driving premature, incomplete or speculative reporting, and it can pull scarce technical leadership away from response and recovery at precisely the moment it is most needed.
That is why I intend to table an amendment to adjust the reporting time so that the full report is due within 30 days, with an expectation that the affected entity provides an initial notification promptly and submits updates as material facts become clear. This would preserve the Government’s need for awareness and situational insight, but it would also recognise the practical realities of incident response. Organisations often cannot state with confidence the root cause, scope of compromise or data impact within 72 hours, particularly where third-party suppliers and complex networks are involved. Can the Minister confirm whether the Government have considered an approach of this kind—one that distinguishes clearly between early warning and a detailed, evidence-based report? Requiring a detailed report too early can reduce the quality of the information that authorities receive, increase the risk of later correction, meaning rework and additional expense for all concerned, and potentially undermine trust and transparency.
I support the Bill’s overall aims, but if we are serious about resilience we must think not only about prevention but about recovery and continuity. Cyber insurance, properly understood and appropriately incentivised, can be one of the mechanisms that turns a cyber event from a national disruption into a managed incident. Finally, on reporting, we should insist on a regime that delivers timely awareness without undermining operational response.
My Lords, first, I declare an interest as an adviser to DLA Piper on AI policy and regulation. I should also say that we as a law firm were subject to a ransomware attack by NotPetya back in 2017. It was not a pleasant experience.
I thank the Minister for her introduction and earlier engagement on the Bill and thank all noble Lords who spoke today in such an expert fashion. On these Benches, like many other noble Lords, we support the fundamental objectives of this legislation to modernise our outdated cyber security framework. But what has been remarkable today is the consensus across the Benches that the Bill is not nearly ambitious enough. Indeed, as my noble friends Lady Northover and Lady Ludford, the noble Lord, Lord Vaizey, and the noble Baronesses, Lady Neville-Jones and Lady Harding, have said, this could be a missed opportunity to align much more closely with the EU framework.
I would prefer not to be jumping off a cliff, with or without wings, with all due deference to the noble Lord, Lord Moraes, and I do not think that we are really living up to the motto of the city of Newcastle either. As the noble Lord, Lord Arbuthnot, said: where are the principles? The noble Earl, Lord Effingham, said: where is the strategy? The noble Baroness, Lady Kidron, asked where the plan of action was. There is quite a bit missing from the Bill, and I shall take noble Lords through some of those areas.
As many noble Lords have illustrated, the threat landscape has deteriorated sharply. The National Cyber Security Centre has managed 204 nationally significant incidents in a single year, double the year before. Yet, as the noble Lord, Lord Birt, pointed out, the Bill will apply directly to only a tiny minority of organisations; meanwhile, 43% of UK businesses have experienced a cyber breach in the last 12 months. One of the most glaring omissions is the almost entire exclusion of the public sector, as the noble Baroness, Lady Alexander, and the noble Lord, Lord Londesborough, pointed out. Central government, public administrations and local authorities are almost entirely exempt from the Bill’s direct statutory duties.
How can we claim national resilience when the state itself is exempt? We have seen the data of 270,000 military personnel compromised in the Ministry of Defence hack, and the devastating attack on the British Library, which destroyed irreplaceable data. Local authorities hold vast repositories of citizen data, from electoral registries to social care records. The ransomware attack on Redcar and Cleveland cost £10 million, the one on Hackney £12 million.
As my noble friends Lady Northover and Lady Ludford, the noble Lords, Lord Birt and Lord Vaizey, the noble Baroness, Lady Kidron, and the noble Viscount, Lord Colville, all said, we must make cyber security a boardroom issue. It was very good to hear from the noble Baroness, Lady Harding, with her lived experience of cyber attack, yet only 27% of businesses now have a board member explicitly responsible for cyber risk, down from 38% three years ago. The noble Lord, Lord Vaizey, was correct. Unlike the EU’s NIS2, the Bill fails to mandate executive responsibility. I support the noble Lord, Lord Birt, in saying that we must now extend corporate financial audits to report on how an organisation and its suppliers manage cyber security using existing governance codes.
The urgency here is multiplied by the rapid rise of agentic artificial intelligence. The noble Baroness, Lady Alexander, described this as “an AI-shaped hole”, and the noble Baronesses, Lady Kidron and Lady Harding, and the noble Viscount, Lord Colville, all pointed to this omission.
Anthropic recently withheld wide release of its Mythos model because it could autonomously find and exploit software vulnerabilities across every major operating system. The UK’s own AI Security Institute, as we have heard, found Mythos substantially more capable at cyber offence than any model previously assessed, and warned that frontier AI capability is doubling every four months. Of course, that will be further amplified by quantum computing, as mentioned by the noble Lord, Lord Ravensdale.
The EU’s AI Act already imposes binding cyber security and incident reporting duties on the handful of frontier model providers that it judges to pose systemic risk. California and New York do the same for the largest developers. This Bill, by contrast, does not mention AI systems at all, as many noble Lords have pointed out. Last month, the cyber security agencies of the Five Eyes alliance, including our own National Cyber Security Centre, issued a joint statement warning that frontier AI is shrinking the gap between vulnerability discovery and exploitation from months to a matter of days, and this can no longer be treated as a technical issue rather than a leadership responsibility.
Meanwhile, our own defenders have a skills crisis. The noble Lords, Lord Birt, Lord Arbuthnot and Lord Vaizey, and the noble Baroness, Lady Alexander, all raised the skills issue. ISC2 warns that 88% of UK cyber professionals have experienced a breach in the last 12 months as a direct result of skills shortages, yet Clause 43 references “a skilled person”, as pointed out by the noble Lord, Lord Taylor of Warwick, who must liaise with the Secretary of State during national security directions, without defining what “a skilled person” is.
Who will actually enforce the rules? The Bill distributes duties, as we have heard today, across 12 separate sectoral regulators, many of which, such as Ofwat, already struggle to regulate their own domains. This fragmented approach guarantees duplication and gaps. Again, I agree with the noble Lord, Lord Birt, and, indeed, the Joint Committee on the National Security Strategy: the UK needs a single expert or lead regulator —as mentioned by the noble Baronesses, Lady Alexander and Lady Harding, the noble Lords, Lord Vaizey and Lord Holmes, and the noble Viscount, Lord Colville—to oversee both public and private sectors. Failing that, the Government should at least adopt the EU’s Digital Omnibus model of a single report-once portal. I share the ambitions of the noble Baroness, Lady Paul, and those of the noble Lord, Lord Holmes, in this respect.
We must, as the noble Baroness, Lady Neville-Jones, said, fix the Bill’s definitions—also mentioned by the noble Lord, Lord Ravensdale. For instance, techUK warns that the current definition of a managed service provider is dangerously broad, risking capture of any basic IT support in the country.
The Bank of England’s own data shows that just three US giants control 73% of the cloud computing services supporting UK financial firms. A number of noble Lords raised the issue of cyber sovereignty. The Trump Administration blocked European and UK firms from accessing Mythos. If a foreign ally can pull the plug on a critical cyber security tool overnight, how can this Government claim true national resilience? That is why, as many noble Lords today have said, we need a comprehensive digital sovereignty strategy. My noble friend Lady Ludford called this “servitude” and the noble Baroness, Lady Berger, talked about critical defence. We need to assess our foreign policy dependencies and support domestic UK providers. I welcome what was said by the noble Baronesses, Lady Kidron, Lady Bennett and Lady Berger, in that respect.
The Bill is silent on cyber-enabled fraud, which costs our economy billions of pounds every year and exploits precisely the same weaknesses this Bill is meant to fix. The noble Lord, Lord Arbuthnot, mentioned a related threat which is emerging, as Thales has tracked that automated bot traffic has overtaken human traffic online for the first time. As suggested by the NMA, we need the Secretary of State, under this Bill, to assess the cyber security risks that anonymous bot traffic poses to UK websites.
If we expect businesses to defend themselves, we cannot handicap our own cyber professionals. I welcome what has been said by a number of noble Lords, including the noble Earl, Lord Effingham, the noble Lords, Lord Arbuthnot and Lord Holmes, and my noble friend Lady Ludford, on the question of the Computer Misuse Act, which badly needs amending.
Finally, in the face of autonomous AI threats, the Government need an ultimate backstop. We support proposals from ControlAI to introduce strictly constrained last resort powers, allowing the Secretary of State to direct the shutdown of data centres or AI systems in a catastrophic emergency. The cost of inaction vastly outweighs that compliance burden. The noble Baroness, Lady Gill, graphically described the situation at Jaguar Land Rover, which lost around £500 million in a single attack. But currently JLR sits entirely outside the scope of the Bill, as does the retail sector, as a number of noble Lords have pointed out. The noble Baroness, Lady Paul, indicated that that was true of the insurance sector too.
The Bill is a necessary foundation. In Committee, we will push hard for amendments to reflect the changes that are needed. In this way, we can ensure that our national cyber defences are genuinely whole of society and fit for the age of AI. We are going to have a very well-informed Committee; I hope the Minister is looking forward to it.
My Lords, I am grateful to all noble Lords who have contributed to the debate and, of course, to the Minister for her introduction. It has been a really thoughtful, compelling and persuasive debate. It is clear that, on all sides of the House, there is a shared recognition of the scale of the threat that this legislation seeks to address and the importance of doing so effectively.
As my noble friend Lord Effingham said, we on these Benches support the objectives of the Bill. Indeed, much of what is in it has its origins in work begun by the previous Government, following the 2022 consultation, and we applaud the continuity. We do not intend to try to make the perfect the enemy of the good, although I wholly endorse the cyber insurance argument set out by the noble Baroness, Lady Paul of Shepherd’s Bush, my noble friend Lord Ashcombe and others.
Listening to the debate has only reinforced for me the central question with which we began: where is the strategy? Ministers have described the Bill as one part of a wider programme, yet the national cyber action plan that was promised before the end of last year, and then promised again for this summer, remains unpublished. I observe as an aside that, as with the defence investment plan, we are in danger of creating the perception, which we must avoid, that there is a pattern of delay and avoidance when it comes to defending ourselves. Noble Lords across the House have, in their own ways, returned again and again to that same point.
I started off the debate diligently writing down everybody who called for a change to the scope but that turned out to be everybody, which makes our task today far harder. I absolutely accept that this is a Bill designed to have a narrow scope, but we have no way to understand the broader context in which that narrow scope sits. It is like trying to judge an orchestra but being allowed to hear only the woodwind section.
It is inevitable that we will have questions, concerns and suggestions that go beyond the narrow scope and intent of the Bill. How will SMEs learn to protect themselves better? Many people have raised that. A great many noble Lords—again, almost everybody—mentioned AI, but what response overall is envisaged to the threats of emerging technologies of which as yet we know little, such as new AI models at the frontier, quantum cracking and so on? How will we reduce the number of vacancies for cyber roles? By the way, it is not a new problem, by any means, that there are too many vacancies for cyber roles. We were wrestling with it when we were in government. It is an intractable problem that we need to find better ways to address.
How will we address the growing prevalence and effectiveness of weaponised disinformation that does so much harm to our society every day, right now? More fundamentally, what are our strengths and weaknesses relative to those of our assailants and our allies? Let me express the hope—I will return to this point—that, during the Bill’s passage, and ideally before Committee, we have the national cyber action plan to answer these and no doubt many other questions. This could make the passage of the Bill considerably easier for all of us, in particular for the Minister, and indeed help bring about the wish of my noble friend Lady Neville-Jones that we get through the Bill quickly in order to get these measures on to the statute book as soon as possible.
Even the National Cyber Security Centre itself has publicly called on government to set out a clearer strategic policy agenda. If GCHQ’s own technical authority feels moved to say so, that ought to give the Minister and the Government pause.
In the other place, my honourable friend Dr Ben Spencer made precisely this point, warning that the National Audit Office had found
“inconsistent, and in some cases glacial, progress”,—[Official Report, Commons, 6/1/26; col. 223.]
in cyber resilience, and that the Bill risked becoming “yet another missed opportunity”. My honourable friend Julia Lopez for her part reminded the Commons that, if the pandemic had accelerated the adoption of digital technology, artificial intelligence would embed it further still. Yet, as she noted, and as noble Lords, including my noble friend Lord Arbuthnot, have echoed this evening—in fact, as everybody has said this evening—the Bill is silent on AI. It is silent on the Computer Misuse Act. These omissions go to the heart of whether this legislation will still be fit for purpose in five years’ time, given how disappointingly rarely Parliament revisits this ground.
On the question of regulatory burden, I was also struck by how many noble Lords share our concern for smaller businesses. I hope that the Minister agrees that this is not a party-political point. It was raised by members of the party opposite in the other place too, who rightly noted that SMEs are disproportionately targeted by cyber crime, yet are the least equipped to absorb new compliance obligations. In fact, techUK, as the noble Lord, Lord Clement-Jones, pointed out, has warned that leaving so much of the detail of this regime to secondary legislation, as well as using some of the rather woolly language that was commented on by the noble Lord, Lord Ravensdale, risks creating exactly the kinds of legal uncertainty and cost that fall hardest on smallest firms.
Again, I am trying to make not a political point—we urgently need this Bill—but a practical point. Indeed, my noble friend Lady Harding’s account of attempting to communicate while managing the crisis caused by an attack was absolutely salutary and I hope the Minister will take note of it.
So, as we move towards Committee after the Summer Recess—I think Committee promises to be a very productive activity—I hope the Minister will reflect carefully on the questions raised today and, in her closing, perhaps answer the following questions. First, will the Government commit to a firm date for publishing the strategy within which this legislation is meant to sit? Secondly, how will the effectiveness or otherwise of the Bill’s measures be assessed, and how will that assessment be reported to Parliament—we hope not every five years? Thirdly, what assessment has been made of the cumulative reporting burden facing businesses of all sizes already subject to data protection and sector-specific obligations? Fourthly, what confidence can the Minister offer the House that the 12 regulators tasked with enforcing this regime, which we have heard a great deal about, will have and will continue to have the resources and expertise to do so effectively?
In Committee, we on these Benches will continue to press the Government on precisely these questions because, as with any regulation, it must be built on a foundation of strategic clarity rather than being asked to substitute for it. I look forward to the Minister’s response.
Baroness Lloyd of Effra (Lab)
I thank noble Lords for their insightful and wide-ranging content, and I am pleased to hear the broad support for the Bill. I also thank the Minister in the other place and the parliamentarians who engaged with your Lordships and others ahead of the Bill’s introduction. The dialogue has been shaped by pragmatism and a genuine interest in protecting our people and businesses. Should I not be able to respond in the allocated time to all the very many specific points that were raised today, I will make sure that I review Hansard carefully and reply to noble Lords accordingly, placing copies in the Library.
The noble Viscount, Lord Camrose, raised an excellent point about the scope of the Bill and the many other government actions and activities to equip our businesses to tackle cyber threats. I agree that the national cyber action plan is the right place to set out exactly how this is all put together, but today I cannot provide noble Lords a date for the publication of the national cyber action plan.
As other noble Lords did, I started writing down the names of all the noble Lords who raised the question of scope—and I too decided that it was probably better to say “everybody”. This is a very pertinent question. Cyber security and resilience are a shared responsibility. The Government and the NCSC provide a range of tools for all parts of the economy, and it is for all organisations to make use of those to enhance their protections. We have invited all businesses, charities and other organisations to sign the Cyber Resilience Pledge and take the three tangible actions that can help boost their resilience to cyber attacks. For many organisations, this will be a significant step in their defences, and regulation will not be necessary nor proportionate.
Under the Bill, we have chosen to regulate where disruption to services—hospitals, drinking water, and cloud service providers—would mean that people and businesses are left with little or no easy alternatives. The significant steps we are taking in the Bill are reflective of the digital nature of our economy today and the risks we encounter. I recognise and share the sentiment of exploring other parts of the economy that would benefit from being under these regulations in the future, and I assure the House that I have asked my officials to work with other government departments to consider what additional services could be brought into scope in future. At the same time, this work needs to be undertaken with thorough consideration for a range of factors, such as the threats posed to such services by hostile actors and the potential impact they could have on the wider economy, as well as the overall value of the sector. We need to take into account the important points that noble Lords have made about proportionate regulation. I confirm to the noble Baroness, Lady Neville-Jones, that, were we to extend these regulations to further sectors, that would follow consultation.
The noble Baronesses, Lady Northover, Lady Neville-Jones and Lady Ludford, and the noble Lords, Lord Londesborough and Lord Clement-Jones, raised an important point about the government cyber action plan. It is crucial that our Government and public sector are covered. The government cyber action plan, which was published in January, will transform cyber security and resilience across government and the entire public sector by 2030. It will enable us to achieve the same outcomes that we want to achieve for services regulated under the Bill: clear and robust requirements, better incident reporting, and stronger accountability and transparency. The plan sets out accountability structures to ensure that cyber risks at all levels of government are actively owned and effectively managed. I assure your Lordships that we will continue to work with Parliament to ensure proper oversight of the plan’s implementation.
The extension to local government is also covered under the overarching strategy of the Government’s cyber action plan. I say to my noble friend Lady Alexander of Cleveden that MHCLG is taking action to strengthen local authorities’ cyber resilience, backed by £20 million of cyber grant funding and technical support, because it is incredibly important that local authorities are prepared and enhance their cyber action.
On the question about the food and retail sector, raised by the noble Lords, Lord Holmes of Richmond and Lord Taylor of Warwick, and the noble Baronesses, Lady Northover, Lady Ludford and Lady Harding of Winscombe, probably among others, it is very important that the sector enhances its cyber resilience. The food sector is unusual among critical sectors because of its high levels of diversity. There are approximately 20,000 small and medium-sized food manufacturers in the UK alone, and many more farms, distribution services, retailers and other types of businesses that form the UK’s food supply chain. Given the lack of a single point of failure, we think there are more proportionate levers to pull than bringing food into the scope of the NIS regime.
The question of AI was raised by the noble Earl, Lord Effingham, the noble Viscount, Lord Colville of Culross, the noble Baroness, Lady Kidron, and my noble friend Lady Berger. The Government are committed to protecting our national security against the risks posed by advanced AI models, and our AI Security Institute is world leading and one of a small group of organisations with access to Anthropic’s Claude Mythos model before its release. As for addressing the risks of cyber attacks facilitated by AI, it is true that AI capabilities are moving very fast, but strong cyber fundamentals still work. Our advice, and that of the NCSC, is to ensure that organisations get the basics right and that they are managing risks at board level. There is extensive guidance on this from the Government and from the NCSC.
As for whether AI is in scope, the Bill does not specifically bring large language models or AI companies into scope, but where organisations in scope use AI models and systems, those organisations will need to take appropriate and proportionate steps to manage the risks to these from hackers. For example, if an LLM is used as part of the day-to-day software available to staff in a hospital, and is therefore part of the network and information systems, it would be considered in scope.
On the example given by the noble Baroness, Lady Kidron, of how this would happen, the Bill grants the Secretary of State the power to direct entities if the compromise of the relevant NIS or the threat of one gives rise to a national security risk. This could, for example, require an entity to cease using and to isolate an AI model. These powers are a backstop to an effective cyber security regime, enabling the Government to act swiftly in the face of unexpected national security threats, but they are also designed to be proportionate, recognising the need for stability among regulated entities and the importance of proper accountability.
Many noble Lords reflected on the need for effective implementation and the importance of consultation and secondary legislation. There will indeed be secondary legislation and guidance and a business adjustment period for the Bill. To answer the question posed by the noble Baroness, Lady Neville-Jones, this will probably be for the period up to 2028, when we expect the duties to come into force.
On the questions about incident reporting raised by the noble Earl, Lord Effingham, the noble Lord, Lord Ravensdale, and the noble Baronesses, Lady Northover and Lady Harding of Winscombe, we have heard the clear ask from businesses to minimise the time they spend filling in different reporting templates following an attack. We understand the pressure that institutions can be under in the midst of an attack, and we want to make sure that they can prioritise the technical response. We are exploring all options and will look closely at other regimes in the UK and the new template used by EU member states for the NIS2 reporting, reflecting questions posed by noble Lords about where we are looking at the EU regime.
We do not believe that there is a risk of overreporting, but we will provide further clarity by setting out thresholds in secondary legislation following consultation. That will set out when an incident is considered to have had, or to be likely to have had, a significant impact—a question posed by the noble Lords, Lord Holmes of Richmond and Lord Ravensdale.
On the questions raised by the noble Baroness, Lady Bennett of Manor Castle, the ability to share information with like-minded countries is important if we are to make cyber security a global effort. But the Bill does not mandate information sharing across borders, and there are important safeguards around the sharing of information for the purpose of prosecuting a crime. I followed the debate on this topic in the other place, and I would be happy to meet with those interested in this topic to discuss it further.
Noble Lords raised the question of the balance between a single consistent approach and being attuned to sector-specific issues. One of the ways in which we are going to pursue consistency and provide clarity on what is expected is through the new security and resilience requirements for regulated entities, which will be set out in secondary legislation. These will set out the clear and consistent steps that regulated entities will need to take to mitigate their security risks. On the questions posed by the noble Lords, Lord Arbuthnot, Lord Birt and Lord Ravensdale, these will be high-level, outcomes-based requirements that will be consistent with the NCSC’s cyber assessment framework, including requirements on board responsibility and governance, supply chain and incident reporting and recovery, as well as requirements around testing and exercising protective security. These proposals will be technology- and sector-agnostic, and take an all-hazards approach to ensure resilience in the face of an evolving threat landscape and emerging technologies. They reflect the requirement for regulated entities to have regard to state-of-the-art technology when assessing the risks they face.
On the question posed by the noble Lord, Lord Ravensdale, and others on post-quantum cryptography, and that posed by the noble Lord, Lord Birt, on quantum, these would be considered as part of that requirement by regulated entities, but would not necessarily be singled out as a specific technology in the regulation so that we keep these regulations up to date and matched to the cyber risks that individual entities face.
In addition to how the requirements in the Bill will capture board responsibilities, we recognise that board-level governance is essential to effective cyber risk management, which is why the Cyber Resilience Pledge sets out that making cyber a board responsibility is one of the three clear tangible actions that any organisation can make to boost its resilience. The Government’s forthcoming modernising corporate reporting consultation will seek views on whether the existing risk reporting framework produces sufficient reporting on cyber risk management as an additional step that could be considered.
On the questions about the Secretary of State reporting to Parliament at least every five years, this is a minimum baseline. Additional reports can be published if deemed appropriate.
The noble Earl, Lord Effingham, and the noble Lords, Lord Londesborough and Lord Ravensdale, asked about business burden and the definition of small businesses. We believe that this legislation is targeted and proportionate, only regulating where necessary to protect the most essential services on which we rely. That is why small and micro digital service providers are exempt from the regulations, unless designated as a critical supplier. Small businesses are defined as entities that employ up to 50 people and have an annual turnover or balance sheet of less than €10 million. They are exempt from being an RDSP or an RMSP under the Bill. They can be regulated only if they are designated as critical suppliers, for which there will be a high bar for designation.
My noble friend asked how we can support small businesses. This is a very important part of our approach. The NCSC provides support through the Cyber Action Toolkit and Cyber Essentials, which also includes cyber insurance for those who get the certification. For any organisation that experiences an incident, the Government’s Cyber Incident Signposting Service helps point them towards where the issue should be reported and where appropriate support can be sought.
Questions on regulator capacity and consistency were raised by the noble Lord, Lord Vaizey, and my noble friend Lady Alexander. The framework will drive consistency across sectors through these common security requirements and through the statement of strategic priorities, which will set the objectives that regulators must seek to achieve. Sector-specific guidance from regulators will also remain key to address sectoral nuances and risks, building on a common foundation of good practice.
Many noble Lords raised the importance of building out sovereign capability in the UK, and I note that the Government are committed to pursuing that. I am sure that we will have other opportunities to talk further about tech sovereignty in the coming week in Oral Questions and the forthcoming debate on that subject.
My noble friend Lady Paul of Shepherd’s Bush and the noble Lords, Lord Ashcombe and Lord Arbuthnot, discussed cyber insurance. It can absolutely play an important role as part of a wider approach to cyber resilience, particularly in helping organisations to manage the impacts of cyber resilience and to support recovery. We do not believe that cyber insurance is a replacement for cyber security, but it is definitely part of a wider suite of cyber measures.
Many noble Lords made points about skills, which are incredibly important. We are improving industry understanding of cyber security, we are investing in cyber skills through TechFirst, and we are working with the UK Cyber Security Council to develop professional standards to bring cyber security in line with professions such as engineering and accounting. I also heartily endorse the points made by the noble Lords, Lord Ravensdale and Lord Vaizey, about the strength of the cyber security industry and sector in this country. It is not only strong within this country; it is also exporting to many other parts of the world, building on our strengths.
I note that product security, which was mentioned by many today in the sense of building in requirements, is indeed a feature of our product security and telecoms infrastructure—or PSTI—regime, which is an important complement to what is in the Bill.
Finally, the noble Lord, Lord Clement-Jones, led the charge on the Computer Misuse Act. We highlighted in the King’s Speech that a Bill focused on national security will update that Act and provide law enforcement with the updated powers and capabilities, so they can remain effective in the digital age.
I, too, look forward to Committee. This is an incredibly important Bill. I welcome the high level of engagement from across the House tonight on the practicalities and the details.
This Bill is fundamentally about national security. It will deliver stronger protections against those who want to disrupt our way of life. It will do so with growth at the forefront, focusing first on support and partnership and regulating only where it is necessary. I thank noble Lords and look forward to the Bill’s next stages.
Baroness Lloyd of Effra
That the bill be committed to a Grand Committee, and that it be an instruction to the Grand Committee that they consider the bill in the following order:
Clauses 1 to 22, Schedule 1, Clause 23, Schedule 2, Clauses 24 to 61, Title.