1 Baroness Alexander of Cleveden debates involving the Department for Science, Innovation & Technology

Baroness Alexander of Cleveden Portrait Baroness Alexander of Cleveden (Lab)
- View Speech - Hansard - -

My Lords, this is proving a fascinating and valuable debate, recognising the Bill’s many strengths, what could be tweaked, and what perhaps is missing as we look ahead. To begin with the strengths, we heard from the noble Earl, Lord Effingham, that the Bill builds on the work of the previous Government and commands cross-party support. We have just heard from the noble Baroness, Lady Neville-Jones, that national security is the first obligation of government. This is unarguably an important step in protecting the nation against cyber criminals, hacktivists and hostile states. It will quite simply make the UK a better place to live, work and do business in.

We have heard already from the noble Lord, Lord Birt, about the economic impact of cyber attacks and from my noble friend the Minister about the 11,000 NHS appointments that are lost to cyber attacks. It therefore seems very timely that we have this Bill, which will cover more essential services, improve regulatory effectiveness, and speed up responses to cyber threats. It is clearly desirable that we have a stronger board level responsibility around cyber. It must be right that data centres are now included in the Bill, helping maintain the UK’s position as a global destination for secure data hosting and for innovation. The focus on high-impact firms means that small companies will not be unduly burdened.

As my noble friend the Minister made clear, this is part of a wider national security effort that includes a cyber action plan for the public sector, a forthcoming cyber action plan for business, the Cyber Essentials certification scheme, and free cyber security support from the NCSC. All these measures will help contribute to our cyber security. The 24-hour incident reporting system will mean that regulated entities have to notify customers impacted by incidents. The tougher penalties for breaches will modernise enforcement and, I hope, improve the uptake of cyber insurance in the way that my noble friend Lady Paul has indicated is so vital. We have to hope that, together, this will mean that cutting corners will no longer be cheaper than doing the right thing. Nevertheless, given the speed at which new cyber threats are emerging, the Bill tries to strike a reasonable balance between maintaining parliamentary oversight and ensuring that the Government can act quickly, as required.

I turn to the question of tweaks. Many of them have been touched on so I will not dwell further on them. We heard from the noble Lord, Lord Arbuthnot, about the importance of the workforce and the increasing demand for cyber security skills. Will the proposed codes of practice include a framework for workforce development and training?

The second tweak, as many noble Lords have touched on, is to the Bill’s scope. I have some sympathy with the noble Baroness, Lady Northover, about the case for closer alignment with EU regulations when we have British companies operating and complying with EU legislation in the areas that are covered. I also think that a broader scope would drive the sort of behavioural change that my noble friend Lady Paul cited. I note that the Minister already said that secondary legislation is available to expand the scope. I look forward to her comments on why we do not have a broader scope now, given the groundswell already in this debate, perhaps to include public administration, in particular local government, given the scale and sensitivity of data and the essential nature of public services.

The third tweak is something else that has been widely noted already: the risks associated with having 12 regulators. I appreciate that the Government’s intent is minimising regulatory upheaval. There is a balance to be struck. The noble Lord, Lord Birt, approached the issue of risk from the desire and need to ensure expertise. I will look at it through the lens of the risk of duplication. At lunchtime today, I spoke at a NED event hosted by a US law firm that counts among its clients a major cloud provider, insurance companies, professional services firms and a board effectiveness practice that works with both public and private sector organisations. The strong consensus in the room was that a common cyber security standard across all regulators, upon which appropriate sector-specific requirements could be layered, merits consideration. This approach is in the spirit of the Government’s amendments, tabled in the other place, to streamline reporting and avoid unnecessary complexity. I hope that issue is given further consideration.

In my few remaining minutes, I will touch on what is not in the Bill. As others have noted, technology is advancing faster than government frameworks can keep pace with it. The Bill was published last year, just as it became clear that AI was tipping the advantage to attackers. Attackers need to succeed only once, while defenders potentially need to patch millions of users. There is currently no technology to automate patching at the pace required. The Bill needs to say more on the role of integrating AI tools into cyber defences. The Bill arguably has an AI-shaped hole in it, although I am encouraged that the incoming Prime Minister has signalled a fresh look at AI regulation. Even Sam Altman, faced with a capricious President, has come round, writing in the FT that

“citizens and their elected representatives must make the rules”.

We have also seen the Five Eyes intelligence partnership warning in a very rare joint communiqué last month that the West’s adversaries were within months of developing cyber attacks that could overwhelm the defences of Governments and companies and noting that frontier AI models will fundamentally transform cyber capabilities. All this is now with us, so raising our defensive capability in the face of this rising AI functionality will be essential. Our spy chiefs are asking western companies to use AI models to strengthen their defences.

I fully appreciate that the Government are completely across this threat landscape. The question is: how do we collectively legislate or regulate in such a threat landscape? Some suggestions that we can consider in Committee are, first, that advanced AI providers could perhaps be designated as covered entities under the Bill. Secondly, since the impact of AI in the cyber field is increasingly systemic rather than sector specific, perhaps we need common AI cyber security guidance supporting all regulators in this fast-moving landscape as they then layer on the needs of their sector. Thirdly, perhaps there should be an AI field in the mandatory incident reporting regime. Finally, we should perhaps think about an AI oversight framework giving the NCSC more teeth and the AISI a more co-ordinating role.

In conclusion, as widely recognised, the Bill will support our economy and our people and make the country safer. It is part of a package. It is a crucial building block rather than the final destination. I strongly commend it to the Chamber.