Cyberattacks: EU Committee Report Debate

Full Debate: Read Full Debate
Department: Home Office

Cyberattacks: EU Committee Report

Baroness Hamwee Excerpts
Thursday 14th October 2010

(13 years, 11 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Hamwee Portrait Baroness Hamwee
- Hansard - -

My Lords, I thank the noble Lord, Lord Jopling, for introducing this debate. I am glad that there are people who understand all this and can speak the language and handle the acronyms. I use that thought to evade the rule that there should be only one formal thanks to maiden speakers before the winders. I am very glad that we have a “big beast” who was able to get his head around the issues sufficiently to start a new area of work. I am not sure that I should refer to the Minister as a big beast other than intellectually and, to be even-handed, as someone who also has a track record in security.

The noble Lord, Lord Harris, and I briefly discussed the report the other day. Although his speech did not tend in this direction, we agreed at the time that this amounted to something very serious and that something should be done. I tend to see that thought in the report, where we read:

“There was consensus among our witnesses that this was a legitimate area for the EU to be concerned about, and that it had some role to play, but there was no unanimity as to what that role should be”.

I suppose that is formal speak for the same thought.

This is a report about the EU but I entirely take the point made in the speeches we have heard so far that this is a global issue. I was not surprised to read that American witnesses were encouraging about the role of the EU as distinct from national roles. This is a global issue. The phrase “asymmetrical development” is a very polite term for describing the problem of the lowest common denominator.

This is not just about the EU and it is not just about government. As the noble Lord, Lord Harris, said, it concerns every sector from contractors to government departments and the services provided by the private sector. We heard about Northgate but utilities could be affected—the water services, to take one—and traffic lights. The list is very long indeed and it does not take a lot of imagination to get beyond the jargon and think about the real problems that a cyberattack could cause.

I very much agree with the committee that it is for the public sector to take the initiative and offer a real say to experienced internet entrepreneurs in how public/private partnerships are best developed and not leave it to the private sector to come forward with ideas.

While I take the point made by the noble Lord, Lord Jopling, that this is not about cybercrime, like the noble Lord, Lord Harris, I will be interested to hear from the Minister about the role of the new National Crime Agency. Behind technology of any sort are people. That comes through very clearly in the committee’s comments on ENISA. The noble Lord, Lord Harris, referred to juvenile delinquents. I sometimes wonder whether states should thank innocent or naive hackers for showing them where problems and weaknesses arise.

The other day I heard a tale from Bletchley Park about a code—not Enigma—which was cracked because the transmitter of a message in code realised that he had made a mistake and transmitted a second message correcting it. That gave those at Bletchley the material to be able to crack the code. It is individuals who can, in what might appear to be small ways, undermine the security of systems.

I, too, am interested in resilience to cyberattacks, the work that is going on and that which can be undertaken in this area—that must be harder to tackle at an international level than at a national or local level—to anticipate technological aspects and human reactions in dealing with cyberattacks. I know that I am not the only person in the Chamber who has heard about what went on immediately following the 7 July bombings. One of the problems of which we became aware pretty quickly was people’s tendency to use mobile phones and the effect that had on the mobile phone networks. It is a very human reaction to pick up a phone to find out whether one’s family is safe. I wonder whether any thought has been given to involving the media in resilience exercises. I take this lesson also from 7/7: the media have a very important role as people tend to turn on their televisions and radios.

Finally, as result of work that I and other Members of the London Assembly did following those July bombings, I keep in mind the words of the then managing director of London Underground. He said that the big lesson for us was:

“Invest in your staff, rely on them. Invest in technology, but do not rely on it”.