Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Baroness Gill Portrait Baroness Gill (Lab)
- View Speech - Hansard - -

My Lords, too often we hear in the news that our local hospital cannot access patient records, or that the transport network in our cities has stalled, or, as I experienced last year, that the power has gone on and off for over a month as the local electricity grid is affected by cyber attacks. A decade ago, some of this would have sounded like the plot of a Hollywood movie. Today, it is a weekly briefing on the desk of our cyber security data centres.

Our world has fundamentally changed. We are no longer just fighting off rogue teenagers or opportunistic hackers looking for a quick payout. The UK is currently navigating a highly sophisticated and aggressive digital battlefield. Malign actors are often directed, tolerated or unleashed by hostile nation states such as Russia, Iran and China, which are actively infiltrating key UK assets. They are mapping our infrastructure, stealing government credentials and probing our defences. That is why I welcome the introduction of the cyber security and resilience Bill. It is a critical and long-overdue overhaul of our national baseline defence. It marks the moment that the UK stops playing catch-up with hostile states and starts to dictate the terms of its own digital safety.

To understand why the Bill matters, we have to look at how our digital ecosystem functions. Hostile actors do not just knock on the front door; they look for the weakest link in the supply chain. Look at what happened in September 2025, with the devastating cyber attack on Jaguar Land Rover. Russian-linked hackers deployed sophisticated ransomware that completely paralysed JLR’s IT networks and forced a total shutdown of production lines across major UK plants for weeks, which had a major impact on the workforce in my old West Midlands constituency. The disruption that cascaded down into the automotive supply chain affected thousands of component manufacturers, mostly SMEs, with many workers in the region facing lay-offs. It had a major impact on the regional economy. Likewise, the attack did not just hurt the brand; it cost the British economy an estimated £1.9 billion, directly denting our national GDP. This was not just a corporate crime; it was an act of economic sabotage.

The threat extends far beyond manufacturing. Just weeks later, a massive cyber incident crippled electronic check-in and baggage systems at Heathrow Airport and across Europe. Was Heathrow’s central system breached directly? No. The attackers targeted a third-party vendor, Collins Aerospace, and scrambled the shared MUSE software that multiple airlines rely on. The result was chaos at terminals, hundreds of disrupted flights, and over 1.5 million passenger records being compromised. This new legislation fundamentally expands our defensive perimeter to address this exact vulnerability. For the first time, it brings data centres, managed service providers and supply chain partners directly into the regulatory spotlight, establishing a framework to name designated critical suppliers. The Bill recognises a hard truth: our infrastructure is only as secure as the third-party software we plug into it

Because of these aggressive state threats, a wider net is useless without sharper teeth. The Bill introduces two massive shifts in how organisations must run: rapid transparency and genuine board-level accountability. Under the new rules, if a covered organisation suffers a significant incident, or even a near miss capable of causing harm, it must file a notification within 24 hours, followed by a full report within 72 hours. In a cyber crisis, time is our most valuable currency. When assets such as Heathrow or JLR go down, an early warning allows the National Cyber Security Centre and regulators to contain the digital contagion before it spreads.

There are real consequences of negligence. For too long, cyber security has been treated by some boards as a minor IT issue, tucked away obscurely in finance or some other department. I am very pleased that the Bill changes this calculation. Companies that do not comply face financial penalties of up to £17 million, or 4% of their worldwide turnover. This will force executives to realise that robust cyber security is a core fiduciary duty. If you do not protect your network, you are jeopardising your entire business.

Crucially, this legislation is built to outpace our adversaries. Nation states use criminal proxies because they are fast, scalable and disguise geopolitical motives. Static laws become obsolete within months. The Bill grants the Government agile powers to update regulations swiftly through secondary legislation. This means that, as new state-sponsored threats emerge—whether through weaponised artificial intelligence or quantum decryption —the UK can adapt its defences instantly, without waiting years for a new Act of Parliament. The Bill also mandates companies immediately to notify their own customers if a breach puts those customers at risk.

To conclude, let us be entirely clear that the Bill is demanding. It will require an unprecedented level of capital investment and profound cultural change in every boardroom in this country, though I urge the Minister to consider undue burden on the SME sector, while recognising that it can sometimes be the weakest link. But we cannot ignore the reality of implementation. Cultural change does not happen purely through good will; it happens when the risk of non-compliance becomes completely indefensible. I ask my noble friend the Minister a fundamental question. While the target of the Bill is correct, the level of commercial investment and cultural transformation needed to meet these 24-hour deadlines is staggering. Beyond the immense financial stick, what mechanisms, support and enforcement frameworks will the Minister use to ensure this legislation drives genuine resilience, rather than just defensive corporate box-ticking? How will she guarantee that this heavy stick builds a shield?