Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Lloyd of Effra Excerpts
If the Government do not believe that the UK Cyber Security Council should have the role proposed by Amendment 99, perhaps the Minister can tell us who is responsible for assessing the capability gap and what the Government intend to do about it.
Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - -

My Lords, I thank the noble Baroness for her amendment, in particular her focus on the importance of the skills and competence of the UK cyber security professionals on whom we all rely and our economy will continue to rely. As the noble Lord, Lord Vaizey, said, an important aspect here is the spirit behind the noble Baroness’s amendment, with its focus on the skill set and professionalisation of these individuals, which we wholeheartedly agree is incredibly important.

I will focus on the council itself for a moment. It is an independent, royal chartered body that unites government, industry and other sectors to boost the professionalism of the entire cyber sector. The council does important work that already encompasses the majority of functions named in the amendment. It sets professional standards and maintains a register of the UK’s accredited cyber professionals. It establishes pathways for cyber professionals—experienced and new entrants—to have an easier route into quality cyber roles.

We disagree that there is a necessity to put this on a statutory footing. The Government consider the council to be akin to other professional bodies in the UK. Although there are some professional bodies with a statutory role and oversight by either government or Parliament, it is standard practice in technical fields for an organisation to be recognised through a royal charter and afforded operational independence from government. This includes the Engineering Council and the Science Council. Going down the route that the amendment proposes would undermine the council’s independence, and that could affect its relationship with the sector.

That is a separate point from the importance of the need to professionalise the cyber sector and the Government’s strong support for that. Indeed, the Government have committed to funding the UK Cyber Security Council over the spending review period until it becomes self-sustainable, working closely with stakeholders across the profession and wider workforce. We believe that professional standards, accreditation and professional titles in cyber security will improve our cyber resilience.

Moreover, to the points raised by the noble Lords, Lord Clement-Jones and Lord Markam, and others, the adequacy of skilled persons remains important. The Government’s TechFirst programme is helping to build the pipeline of talent for all frontier technologies and is available to all secondary schools across the UK. This month, approximately 1,300 undergraduate and master’s students are starting in the TechFirst scholarship programme, including over 300 students on a cyber security pathway.

On the question about how the Government monitor the adequacy of this, the Government publish annual data on the state of the UK cyber security workforce which shows that the supply of cyber skills is increasing. There is currently a net annual shortfall of approximately 3,800 people in the UK’s cyber security market. For the second year running, the workforce gap has remained markedly lower than our previous estimates, now 3,800, compared to 11,100 in 2023 and 14,100 in 2022. Focusing on the skills pipeline is incredibly important and something that the Government are backing.

Equally, the Government agree with the noble Baroness that regulatory authorities must have regard to the information and standards provided by the council. Indeed, we stated the need to align with council standards in the Government Cyber Action Plan. The Government have already worked with regulators to embed cyber security accreditation and professional standards into their guidance. We want to go further, which is why we intend to use the Bill’s powers to introduce security and resilience requirements in secondary legislation. These are designed to be consistent with the NCSC’s cyber assessment framework, and we propose that these requirements will address relevant training, skills and professional standards. We will consult on these proposals later in the year to ensure that the industries, large and small, covered by the regulated sectors will be able to feed back on this, as will the regulators which will be responsible in this area.

To the questions on SMEs raised by the noble Baroness, Lady Neville-Jones, whether inside or outside, whether they are or are not regulated entities, SMEs have access to NCSC and cyber resilience centres. I am sure that we will go on shortly, in the context of the noble Baroness’s subsequent amendment, to discuss further support that we can provide to those SMEs.

We are very committed to the role and function of the UK Cyber Security Council as a wide-reaching and effective independent body, and we continue to support skills development in the UK. As such, we are not convinced that there is a need to put the council on a statutory footing at this stage.

Baroness Northover Portrait Baroness Northover (LD)
- Hansard - - - Excerpts

I thank the Minister for her thoughtful reply and I thank other noble Lords for their support here. Clearly, we are all seeking to move in the same direction. There is a challenge and risks here that are incredibly important. Whether this is the right way forward, we will have to see.

I am very grateful to those organisations that fed into our Select Committee, which led me to table this amendment. This is an area that we will need to return to before Report, to look carefully at whether the drivers that the Minister has mentioned are sufficient. But at this stage, I beg leave to withdraw the amendment.

--- Later in debate ---
The best protection against a cyber attack is the behaviour of firms and their staff, and the best way to drive safe behaviour is through insurance. The collective cost of insurance is certainly no greater than that of a national cyber response service, and that cost is absorbed by those who benefit the most directly. All that said, I look forward to the Minister’s response.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

My Lords, I thank the noble Baroness for her amendment and for linking the issue of cyber security with wider questions on national resilience; she is absolutely right to situate it in that space. I also thank her for introducing the topic of the right amount of cyber security support for the SMEs regulated under the Bill; indeed, the discussion has led to SMEs that are not regulated under the Bill.

We know that SMEs require dedicated cyber security support. That is why there are a wide range of free tools, guidance and training to help SMEs implement cyber security measures. These resources are available to any business, not just those regulated under the regime. As the noble Lord, Lord Vaizey, mentioned, this includes the Cyber Action Toolkit, designed to scale nationally to empower millions of small organisations through tailored cyber security advice with NCSC-certified cyber advisers. A number of noble Lords referenced the importance of Cyber Essentials, as well as insurance and incident response. If an SME with a turnover of less than £20 million has Cyber Essentials, it also has cyber insurance cover of up to £25,000. That incentive is intended to link the process of getting Cyber Essentials with the benefits of insurance. Likewise, SMEs get cyber incident support 24/7 with Cyber Essentials.

The noble Lords, Lord Vaizey, Lord Londesborough and Lord Birt, talked about the “push”. We are indeed encouraging, perhaps not pushing, the private sector to engage its supply chain through the cyber pledge, which is for entities outside the regulated scope. That is one of the key elements of the cyber pledge. Likewise, under the GCAP, the Government’s cyber action plan, Cyber Essentials, or equivalent, are needed for government procurements using official data. These are the mechanisms by which we are encouraging large organisations to look at their supply chains—on the point that the noble Lord, Lord Clement-Jones, made about the interconnectedness of all our organisations today—and encouraging the uptake of Cyber Essentials with these very tangible benefits.

I was asked a very fair question about the best way to provide cyber support to organisations. I heard at least one noble Lord say that SMEs do not like different provision. I think that many SMEs prefer—or, if asked, would request—local trusted advisers, which is exactly what the regional cyber resilience centres offer. They offer free support to SMEs across England and Wales, covering a wide range of services, such as incident response, a business continuity service and support with Cyber Essentials and security training.

The noble Lord, Lord Londesborough, made a point about a central, monolithic model compared with these local or regional models. There is a lot of merit in a regional model that has some common standards but is located much nearer to the SMEs that it serves. I reiterate that small and micro-organisations are exempt from being regulated as relevant digital service providers or relevant managed service providers. They can be regulated only if they are operators of essential services or designated as a critical supplier, for which there is a high bar. On the picture raised by the noble Lord, Lord Clement-Jones, we do not think that a huge number of small enterprises will be in scope of this legislation. All small businesses will benefit from the current provision, but they would not necessarily benefit from the model proposed by the amendment.

The amendment would also require the Secretary of State to have regard to international regimes. We are indeed aware of such schemes, such as the Australian Small Business Cyber Resilience Service. Many of the offerings that that service provides, such as tailored support and practical incident recovery support, already exist in the UK, as I have set out. We learn from international best practice, but we also tailor it to our local economy and the threats we see, to best support and meet the needs of UK businesses and interact with UK regulations.

I hope that I have set out that guidance for small and medium-sized organisations is already available through existing UK support. We are doing more to look at supply chains through discussions with large firms, through the GCAP and through this Bill. We think that a new dedicated service could divert resources from these existing services and potentially impact on their efficacy. On the central point that the noble Baroness started with, we absolutely agree with the importance of providing support to small and medium-sized enterprises under the Bill, ensuring that they have everything they need to be resilient and respond to incidents.

Baroness Northover Portrait Baroness Northover (LD)
- Hansard - - - Excerpts

I thank the Minister, and I thank noble Lords for their support. This is clearly an area where we agree that there is a problem; we are very vulnerable in the United Kingdom. What we have in place is clearly not working sufficiently well if 60% of SMEs that are hit by cyber attacks go under. That is the context in which we ought to look at proposals that might seek to address that. We clearly need to take SMEs forward in a way that does not overburden them.

I hear the point about extending insurance cover. We can indeed take more than one track, but there is a cost to not supporting SMEs. If they are going to go under, that will be an economic cost to the country and, if we do not support them, they are likely to be hit by cyber attacks, taking them and others under anyway, with that effect upon our economy. Clearly, the Government agree—hence putting in place the measures that the Minister has outlined.

I am suggesting, from the evidence we have received, that this needs to go further and faster. We can discuss exactly how, but it is clear that this is an escalating problem and that we need to do more to tackle it. That is on the basis, in particular, of the concerns expressed to the National Resilience Committee on which I serve and which, as I say, gave me the idea of putting this amendment forward. I think that we will need to return to this, because it is a major problem, but, in the meantime, I beg leave to withdraw the amendment.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this important group and all noble Lords for their contributions. Beginning with Amendment 148A, it is reasonable to suggest that there should be a further right to appeal, given that we are talking about potentially large penalties of £17 million or 10% of annual turnover. But, like my noble friend Lord Vaizey, I have concerns about whether the Upper Tribunal system can handle such a process. Right now, it has an open case load of over 800,000, which is a 19% year-on-year increase, and disposals have decreased by 4%. As such, I am hesitant to offer my support without being assured that further pressure will not be placed on tribunals and that this is a workable mechanism.

Amendments 174A and 174B, in my name and those of my noble friends Lord Camrose and Lord Holmes of Richmond, would require the Secretary of State to establish a register of foreign powers posing a cyber security risk to this country, and to review and report on the extent of the risk posed by powers on that list. Part 4 gives the Secretary of State significant new powers to intervene where the use of vendors’ goods and services or facilities pose a risk to national security. We support that objective. A power of that kind is only as good as the intelligence that informs it. At present, the Bill is silent on how the Secretary of State is to identify, in a systematic and transparent way, which foreign powers actually present that risk.

Amendment 174A aims to fill that information gap, outlining a thorough set of criteria for inclusion: a state confirmed by GCHQ to have perpetrated or attempted a cyber attack against the UK in the preceding seven years—one directed at an operator of an essential service or a critical supplier and carried out through a state department, agency or affiliate—or a state that GCHQ has separately warned poses a risk to such systems.

The importance of ensuring that we are fully informed of foreign threats can hardly be overstated. Just this year, the NCSC’s chief executive reported that three-quarters of all attacks on our critical national infrastructure over the preceding 12 months were carried out by hostile states, with Russia, China and Iran named specifically. The NCSC’s annual review recorded 204 nationally significant incidents in the year to August 2025—more than double the previous year, with 18 rated highly significant.

For illustration, the cyber attack that last month shut down a British power plant is reported to have been committed by Iran-backed hackers. Over the course of the last Parliament and this one, China has targeted Parliament and compromised the Electoral Commission; Russia’s FSB has targeted British parliamentarians and successfully stolen and leaked politically sensitive documents; and Iranian state actors have targeted British politicians, Governments and defence with sustained cyber espionage campaigns.

We are seeing a surge in cyber attacks driven largely by foreign threats. If the Government are serious about security and resilience, tackling foreign interference must be a priority. As a start, a published criteria-based register would bring much-needed transparency and rigour to the process. Amendment 174B seeks to achieve such transparency. It would require the Secretary of State, for each foreign power added to the register, to conduct a review of the extent and nature of the risk that that power poses. It also includes a built-in safeguard for the Government: where the Secretary of State considers that laying their report would be contrary to national security interests, they may instead make a Statement to Parliament confirming that the review has taken place and explaining that it cannot be published. It attempts to strike a balance between accountability and the sensitivities that intelligence assessment of this kind will naturally carry.

I anticipate that the Minister may say that such a register already exists in substance within government and that formalising and publishing it risks informing those very powers of the extent of our knowledge. I gently observe that the amendment does not require publication of intelligence sources, substance or methods—only the fact of designation against published criteria and a review to assess the risk. Given the scale of the threat that the NCSC describes and, given the very significant powers that this part confers on the Secretary of State, I believe that Parliament is entitled to ask that those powers rest on a clear, evidenced and reviewable basis. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank noble Lords for their amendments, starting with Amendment 148A, from the noble Lord, Lord Clement-Jones, which indeed is in line with the recommendation from the Constitution Committee, which I thank for its report and its detailed scrutiny of this legislation.

As the noble Lord points out, Part 4 enables the Secretary of State to issue penalties for regulated entities that do not comply with directions. The High Court will have jurisdiction to review the lawfulness of a particular penalty issued under Part 4. The noble Lord, Lord Vaizey, referred to precedent and consistency. Our assessment is that the High Court is the appropriate route for hearing sensitive national security cases, consistent with the approach that previous Governments have taken to national security legislation. The Telecommunications (Security) Act, the National Security and Investment Act, and the Procurement Act, key pieces of national security legislation, all follow this approach. That is the reason we have adopted it here.

To the point around parliamentary scrutiny of directions, the Government’s default position is that copies of directions will be laid in Parliament, to enable all parliamentarians to scrutinise the Government’s use of these powers. I am of course preparing a formal response to the Constitution Committee, which will be sent in due course.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I resume with Amendments 174A and 174B, which were introduced by the noble Lord, Lord Markham. They would require the Secretary of State to create a register of “foreign powers” that pose a threat to UK cyber security, to review this register and to lay the report in Parliament. This is intended to inform the use of the powers granted under Part 4 of the Bill. The noble Lord is right that hostile foreign actors pose a clear risk to our essential services. National security is the first responsibility of any Government, which is why we are addressing these risks actively, including through the Bill.

The Bill will grant the Secretary of State important new powers to issue national security directions to regulated entities or regulators, where their compromise poses a national security risk. We will seek to strengthen the Government’s national security toolkit further, to protect our supply chains from hostile actors. That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.

Any decision to use the powers in the Bill will be informed by expert national security advice, including from GCHQ. The direction powers provide a strategic case-by-case basis to safeguarding our national security, irrespective of the specific actor. As a result, a country-specific approach lacks the nuance required to assess and respond comprehensively to all relevant risks. We also need to proceed responsibly in how we categorise and present these risks in the public sphere.

That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber risks where it is appropriate to do so. As the noble Lord, Lord Markham, set out, the NCSC annual report highlights risks posed by foreign actors; we work with the NCSC to mitigate these risks.

I note that noble Lords have confronted this question before, notably during the passage of the Telecommunications (Security) Act, where there was cross-party support for vendors to be assessed on a case-by-case basis, rather than by designating nations themselves as hostile actors. I hope that, in that vein, noble Lords are reassured that the Government have the tools to act strategically, acting on the right intelligence where hostile states seek to do us harm.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I thank the Minister for her response and the noble Lords, Lord Vaizey and Lord Markham, for their contributions. I cannot help feeling that the approach to this by the noble Lord, Lord Vaizey, is coloured by his history as a Minister. I can understand that because I saw the frustration within Ofcom over the type of judicial review. It was a particular type of judicial review: it was not a full merits-based appeal, but it allowed merits to be considered as part of the judicial review process. Subsequently, that was changed, which has probably calmed the way in which appeals are carried on.

However, in this particular case, although he said that he was not sighted as to the secrecy aspects of this, it was quite interesting to hear what the noble Lord, Lord Markham, had to say. He started by saying that he supported the amendment, then—rather coloured, I think, by the response of the noble Lord, Lord Vaizey—he did a bit of a U-turn halfway through what was a speech originally written in support. I am sure that he knows in his heart that this is the right one.

Really, the argument in this case is expediency versus justice. I think that choosing expediency, especially in the light of what the Constitution Committee had to say, would be extremely inadvisable. I was encouraged by the fact that the Minister is producing a memorandum in response to the Constitution Committee; we all wait with bated breath for when that arrives. In the meantime, I beg leave to withdraw my amendment.

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this amendment and the noble Lord, Lord Arbuthnot of Edrom, whom I see in his place. I am sorry he was unable to attend the beginning of this debate, but we are told it was for very good reasons. I will not try to reproduce the many overwhelmingly powerful arguments that we have heard in favour of this amendment, which, on these Benches, we are also keen to support—as we support any measure on the basis that it would help organisations to protect themselves and their systems.

Penetration testing and the wonderfully named bug bounties are excellent ways to identify and address the more technically difficult vulnerabilities before they are exploited. Take one of the most widely used apps anywhere: Google Chrome, which has found that external researchers were responsible for almost a third of its patched and communicated vulnerabilities. The Government’s own consultation included respondents arguing that the Computer Misuse Act prevents cyber professionals, consumer groups and researchers undertaking this kind of legitimate public interest activity.

The amendment is wholly sensible in its design, in that it does not commit the Government to action but begins the conversation on this small but hugely important and valuable change, supported avidly, as we have heard, by everybody—more or less—within the cyber industry. It would explicitly condone good faith researchers and sanction ethical hackers to carry out their work. I cannot imagine why it would not at least be worth reviewing such a change on this basis.

I have some unsatisfied curiosity, as there are no published statistics showing how many Computer Misuse Act investigations, prosecutions or convictions involve good faith cyber security researchers, so it is hard to know how much of a dampening effect on ethical hacking the CMA is currently having. If any of the signatories to the amendment, or of course the Minister herself, could shed any statistical light on that, I would be most grateful. As I said, this amendment would allow all such considerations to be taken into account without committing the Government and, as such, I strongly support it.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.

The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.

The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I thank the Minister for that response. The noble Lord, Lord Vaizey, said that we know what the Minister will say: that it will be in a future piece of legislation. To that extent, we are pleased that at least we have a commitment to it, but this has been going on for an awfully long time. We tabled amendments during the passage of the Crime and Policing Act and the Data (Use and Access) Act. There has been plenty of time for the Home Office, or any other department to address this—DSIT could have taken this by the scruff of the neck—because it is such an egregious aspect of the current legislation.

I am pleased to hear that the Minister has read the correspondence. I hope she did not fall asleep while doing so; it is pretty interminable. She may well find that we come back to this on Report because, as she said at the beginning, feelings are running high about it. It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.

I thank noble Lords who have spoken today and demonstrated support across the board. On a light-hearted note, I say to the noble Lord, Lord Tarassenko, that of course Claude said that; it is trained on my speeches. As the noble Baroness, Lady Harding, said, this is self-evidently sensible. The trouble is, it is self-evident to us, but we despair sometimes, and the perfect must not be the enemy of the good. As the noble Baroness, Lady Neville-Jones, said, the objective is to put researchers in a safe position.

Finally, the noble Lord, Lord Vaizey, exhorted me to make sure that we have a date and a timeline. When will the national security Bill come forward? We saw it in the King’s Speech but I have had no contact from anybody in the Home Office about what they might insert in the Bill. I do not know whether anybody in this Committee has had notice of when a Bill might come forward. I think the Minister recognises the sheer impatience that most of us feel in this field, and I very much hope that, between Committee and Report, we can get some more clarity in this area for the benefit of all those researchers. In the meantime, I beg leave to withdraw the amendment.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, despite the fact that this is the last group, it is a really important area and this amendment rightly reflects that. We strongly support Amendment 174E. It would introduce a fundamentally elegant and highly necessary cyber security principle that the Bill has otherwise completely ignored: that of data minimisation and the proactive reduction of what is called our national data attack surface.

The most sophisticated cyber defence system in the world cannot protect data that has already been stolen. Conversely, the most ruthless ransomware gang or hostile state-sponsored actor cannot compromise data that was never collected or which has already been securely deleted. In the realm of digital defence, we must move past the narrow defensive mindset of simply building thicker walls around our databases. We must begin to ask a more fundamental strategic question: why are we keeping these massive, un-anonymised and highly vulnerable data honeypots in the first place?

The empirical evidence from our public sector is deeply alarming. We have received detailed and coruscating briefings from the Centre for Long-Term Resilience and our technical authorities. The National Audit Office’s January 2025 report on government cyber resilience revealed that approximately 28% of government technology is legacy software, leaving our public bodies highly vulnerable to attack.

Consider the catastrophic ransomware attack on the British Library in October 2023. When the library refused to pay a ransom of 20 bitcoins, the Rhysida ransomware group released 600 gigabytes of stolen customer and staff data on to the dark web. The library’s own subsequent post-mortem was clear: its reliance on legacy applications and older network designs substantially and unnecessarily increased the volume of sensitive customer data sitting on the network. This was data hoarding, plain and simple, and the price was paid by the British citizens whose personal details are now permanently compromised.

Consider the hack by ExfilSquad, when normal teenagers living with their parents managed to breach a public database, leaking the sensitive personal details of 100,000 police officers and staff on the dark web, alongside data from the Ministry of Defence and the Department for Education. How did they do it? They did not deploy supercomputers or advanced zero-day exploits, they simply exploited a basic, misconfigured Power Pages database. The hackers’ own boast on the dark web was chilling. They said the data was accessible without any authentication whatever.

Why are these databases so large? Because our public bodies routinely collect and indefinitely retain vast, sprawling, unanonymised datasets, from birth certificates and benefit records to housing benefits and electoral roles, without any systematic statutory drive to minimise or anonymise them. That is why the Association of British Insurers and the NCSC both advise that data encryption and data minimisation are critical to reducing the leverage that a threat actor has in ransomware attacks. By rendering exfiltrated data unreadable through encryption—or better yet, non-existent through deletion—we take away the hackers’ ammunition.

While the Bill focuses heavily on the administrative paper exercise of incident reporting, it remains completely silent on the contents of the databases themselves. Amendment 174E would provide a strategic corrective. It would legally oblige the Secretary of State to open a public consultation within one month of the Bill’s passing to evaluate the cyber-resilience benefits of minimising data collection and increasing data anonymisation across our public bodies. By forcing our public sector to lead by example, this amendment could begin the vital work of shifting the UK towards a genuine resilience-by-design model. It would reduce our vulnerability, harden our national defences and protect the digital lives of our citizens. I urge the Minister to accept this vital safeguard.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security. 

Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.

Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.

As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on.

I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

In the spirit of her final remarks on the Bill overall, is the Minister able to give any update as to when the national cyber action plan might emerge?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I have nothing further to add what I have said in previous sittings.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

Nice try. I will get the final word then. First, I thank the noble Lord, Lord Clement-Jones, for his strong support. Honey pot is a very descriptive and apt term for it. I thank the Minister for her comments and will definitely take up her offer of a meeting. I must admit that the responses she gave were almost exactly the responses that the NHS gave to me on all this, so she is absolutely right: everything is being kept under GDPR. Data security and how that is held were mentioned quite a few times, but I did not hear anything about data minimisation and why we are collecting or keeping it in the first place. That is a gap in all of this because, as I said, a lot of this data does not need to be held or gathered in that way. It is just basic discipline. I would very much like to take up that offer on how we can do that, because—perhaps the Minister can look at this ahead of our meeting—I do not think this issue is addressed anywhere in the Bill.

I do get the last word. I thank everyone who has taken part in this. There have been a number of important issues raised. I really appreciate the willingness of the Minister to engage, and I know there are a number of follow-up meetings that I think we will all want, because there is a lot that we need to work on between now and Report to make sure that the Bill really gives us the sort of protection we would all hope to have. I beg leave to withdraw my amendment.

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Lloyd of Effra Excerpts
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I start by thanking my noble friend Lady Neville-Jones for introducing this group and setting out her stall so clearly and compellingly. I apologise that some of the amendments that have been looked at here I had in my record as being part of the next group. So, if I do not cover them all now, they will be covered by my noble friend Lord Markham as we get into the next group.

Let me begin by outlining the amendments in my name and those of my noble friends Lord Markham and Lord Holmes of Richmond. The need for action on ransomware has never been higher. The NCSC handled 204 nationally significant ransomware attacks in the year to September 2025 that we know about—up by 130% on the year prior, leading the NCSC to name ransomware as the most pressing threat to the country in its annual report. Of course, one of the challenges we face with ransomware attacks is not knowing when they happen, to whom and how often. The victims too often have strong reasons, generally associated with legal liability, not to report them. This makes it challenging, if not impossible, for any government agency seeking to identify commonalities across attacks to pursue repeat offenders and warn vulnerable organisations.

We could seek to make reporting of such attacks mandatory, but at the risk of placing hacked organisations in an impossible position where public reporting creates a legal bind that worsens the damage already done by the attack. I take on board the cogent concerns expressed by the noble Lord, Lord Clement-Jones, but the moral hazard occurs today where companies do not report ransomware attacks, thereby damaging our collective ability to defend others yet to be attacked.

Our amendment therefore seeks to find a channel that reports the facts of the hack and the metadata around it in a way that is not disclosed beyond the agency charged with cyber protection and does not become public knowledge. I do not pretend that this will be straightforward. For instance, we would have to understand how to deal with FoI requests and so on. That is why we propose a consultation. But if we were able to achieve something on this basis, we would greatly enhance our ability to protect UK PLCs from these hugely damaging attacks.

Amendment 172 seeks to require a review on the impact of the new reporting requirements introduced by the Bill. Again, this is fairly straightforward. The strengthened incident reporting requirements are being introduced to allow the regulators and the Government to help with providers and suppliers who have been attacked. Whether these requirements actually serve that purpose, and whether they do so at the expense of providers, cannot yet be known, but we must be able to form an assessment and adjust if necessary. Everyone in this Room would accept that we need statutory agility in the face of fast-moving technology, and a review on these lines could and would enable just that.

For a similar reason, I support the desire for transparency in Amendment 165 in the name of the noble Lord, Lord Clement-Jones. This may even overlap with our own amendment; we could probably think about merging the two in some way. It seems clear that both Houses of Parliament should be informed as to what the reporting regime is being used for and whether it is fulfilling its function. I hope that the Minister agrees.

I very much support Amendment 17 in the name of my noble friend Lady Neville-Jones. We are going from an incident constituting an actual adverse event on the security of network and information systems to it being capable of having such an effect. Arguably—the noble Lord, Lord Clement-Jones, made this point very well—almost any incident would meet this condition. We need language that expresses genuine risk to avoid all incidents being caught in the net. This seems wholly pragmatic to me and I commend it to the Minister, to whose response I look forward.

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
- Hansard - -

I thank noble Lords for their amendments in this group; in fact, subsequent groups also speak to this question of the nature, scope and timeliness of incident reporting. What we are all trying to do, I think, is to get the right balance in reporting actionable information that can be used by regulators and the NCSC to improve the security of the United Kingdom and the entities that operate essential services within it. That is obviously what the Government have put forward. I have heard clearly the arguments made by noble Lords, some of which probe the intention and the detail, and I will attempt to clarify those as I speak.

First, I shall speak to Amendments 19, 36 and 44 in my name. Improving incident reporting under the NIS framework is a key pillar of the Bill. Without an understanding of incidents, our regulators and the NCSC cannot assist in recovery, assess risk and bolster resilience. The amendments that I have tabled will ensure that the incident reporting measures for regulated entities reflect what we are trying to achieve.

The Bill already requires relevant regulated entities to consider a list of factors when determining whether an incident is likely to have a significant impact and be reportable. This includes whether data relating to users is, or is likely to be, compromised. Government Amendments 19, 36 and 44 remove the reference to “users”, meaning that all data compromises relating to the relevant network and information system are in scope of incident reporting. This will enable key incidents to be reported, including the compromise of commercially sensitive information or the exposure of access details or usernames of the regulated service.

These incidents will need to be reported to the NCSC and the relevant regulator. I say in response to the noble Lord, Lord Clement-Jones, that that is the motivation behind the change to that categorisation. This will ensure that the regulators have full oversight of significant security compromises, supporting them to keep the UK safe and secure. We will shortly consult on what constitutes a significant impact and put further detail in secondary legislation and guidance.

I turn now to the amendments tabled by—

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

May I interrupt the Minister before she moves on to the next set of amendments? I do not intend to ambush her as regards her amendments this time around, but I seek an assurance, given that there seems to be quite a philosophical difference between her amendments today and those put forward by the noble Baroness, Lady Neville-Jones. There is considerable industry concern about the disproportionality involved. I seek an assurance from the Minister that, between Committee and Report, she will actively consult on the impact of this part of the Bill—Clause 15—and not just when it is in black-letter form. There is quite a lot of concern from many industry voices. It is incumbent on the Government to listen to those voices on the impact of this reporting structure and these duties before they go ahead in a way that many of us believe will not be helpful for the running of these businesses.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

We have already undertaken some consultation and I am happy to commit to contact affected businesses and business organisations and have further conversations between now and Report. Perhaps if I progress a little more, I may be able to answer some of the questions that may have given rise to some of this but, equally, there are different rationales for some different thresholds in the Bill, which, again, I am just about to come on to. I will set out the rationale for those because I think that they are well motivated and are linked to the risk profile that we see in the country and the connectedness of certain regulated entities in the country.

I turn to the amendments tabled by the noble Baroness, Lady Neville-Jones, and her questions to me on the link between the definitions and whether they apply beyond incident reporting. They apply to the security duties within the Bill, which means that regulated entities have a duty to prevent or minimise the impact of incidents. The amendments from the noble Baroness would limit this and reduce their security and resilience. We think that not every incident should be reportable but that organisations need to take appropriate and proportionate steps to mitigate the risks before, during and after a broader set of incidents.

On the second part of the noble Baroness’s amendments and her second question, the Government have recognised that the reporting threshold for data centres is broader than that for other regulated entities under the Bill. This reflects the distinctive role and risk profile of data centres. They are the physical infrastructure underpinning digital services across the economy and the public sector. Unlike the virtual cloud layer, for instance, they combine cyber, physical, personal and operational technology risks. This is particularly important in collocation facilities where infrastructure belonging to numerous customers is concentrated in one location. Then they need physical access to the premises and information about facilities or operational systems. A single incident could therefore exploit both physical and digital vulnerabilities, potentially affecting the confidentiality, integrity or availability of services belonging to multiple customers and sectors. The consequences may also extend beyond the facility’s immediate geographic location, because the hosted service can support users and central services elsewhere. That is the rationale for having this threshold applying to data centres.

To come on to the questions raised, including by the noble Lord, Lord Clement-Jones, on the use of the phrase “capable of”, and the points made in the amendment from the noble Baroness, Lady Neville-Jones, replacing “could have had” or “capable of having” with “likely to have” would exclude some incidents because their eventual impact was uncertain or successfully contained. It would also constrain the security duties, as I mentioned. In reference to the incident reporting definitions introduced by Clause 15, the subsequent detail sets out how the notification of incidents applies in each regulated sector, except for data centres. That is how the definition is made for regulated sectors other than data centres.

There are a lot of safeguards in the Bill to ensure that reporting remains proportionate. It is intended to capture significant near misses, not routine scanning, unsuccessful low-level attacks or ordinary operational events, and clear guidance will ensure that the industry understands this threshold. As the noble Baroness, Lady Neville-Jones, pointed out, we will set this out in secondary legislation and that will allow the consultation to take place that the noble Lord, Lord Clement-Jones, emphasised is so important—we agree with that. We have undertaken extensive engagement to date and will continue to do so.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

As per the points made by other noble Lords, this is a prime example of when you realise how valuable it is to have in this House and, in particular, in this Committee people who have lived experience. Because of that, this is a well thought out set of proposals; I thank my noble friend Lady Harding for bringing them before us, and I thank my noble friend Lord Holmes and the noble Baroness, Lady Kidron, for supporting them.

These amendments mirror a lot of what I saw from the other side when I was the Health Minister and we had the problems with Synnovis and testing. That is where I am coming from: you realise that you need some real teeth because, even though you have public bodies such as the NHS, which you think would listen to the Minister on certain requirements, that that does not always follow. The point made by my noble friend Lady Harding about everyone telling you to keep quiet applies to state organisations just as much as it does to private companies. Having teeth is an important part of all this and of making things happen.

The staged approach has been mentioned. In your first 72 hours, it is all about wanting just to get the information out there. One of my questions—I will come on to the rest in a minute—is: what are we doing on our side with that information? We must make sure that it is being used valuably and used to alert others. Only later on, around the 30-day mark, do you get into the “lessons learned” stage. So staged reporting would be a very sensible and well thought out approach.

That brings me on to another point; I would be grateful if the Minister could address it. If we are requiring businesses to provide such information to the Government very quickly, what will they get back? The strong justification for rapid incident reporting is surely that the NCSC can aggregate the intelligence, identify common attack vectors and vulnerabilities, and rapidly warn other organisations before they, too, are attacked. Obviously, that is the difference between regulatory reporting and genuine national cyber defence. I would be grateful if the Minister could explain the planning and what will happen operationally when one of these early notifications is received. How quickly will the information be assessed? How quickly will actionable intelligence be disseminated to other potentially vulnerable organisations? What obligations will there be on the Government and the regulators to ensure that the information provided by one organisation improves the resilience of everyone else?

Of course, there is a wider point here. Throughout our consideration of the Bill, we need to guard against measuring success by the number of organisations regulated or the number of reports submitted. Rather, the real test is whether fewer attacks succeed, whether we identify attacks faster, whether organisations can recover more quickly and whether intelligence from one attack prevents the next one. That is the outcomes we want this regime to achieve.

I hope that the Minister will look seriously at the principles behind these amendments, and in particular at whether we can achieve a reporting structure that gives the Government the information they genuinely need quickly while allowing organisations to concentrate their scarce cyber expertise on the thing that matters most: defeating the attack.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank noble Lords for their amendments in this group. We have spoken previously about the importance of effectiveness, proportionality and clarity. I absolutely hear the experience of the noble Baroness, Lady Harding, in leading a telecommunications company and the experience it had.

We have learned from experiences across all sectors in introducing the new regime that is in the Bill, which puts in, as others have said, a staged approach that includes an early alert to regulators and the NCSC within 24 hours. That will provide awareness and enable the NCSC and regulator to provide early support, as well as potentially understand whether it is impacting multiple regulated entities.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, before the noble Baroness, Lady Harding, stands up, I heard what the Minister had to say about consulting across sectors. I was reminded that, at Second Reading, I mentioned the fact that the law firm with which I am associated, DLA Piper, was subjected to a NotPetya ransomware attack back in 2017. What the Minister said is completely at odds with not only what the noble Baroness, Lady Harding, said, but the experience that we had in the way that we needed to understand how these events unfold. It would be really helpful to know from the Minister, or for her to publish, the sectors where the Government have had those discussions and which parts of industry have agreed that this is an appropriate form of incident reporting.

What we are trying to do, throughout the Bill, is to ground it in what is practical. At the moment, despite the fact that we are letting through some government amendments, it seems that we are heading in the wrong direction with this clause. It is going to be disproportionate in the way that it impacts on business and is not even going to be fit for purpose, despite the disproportionality. It is just not going to work.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I think we all agree that we want a proportionate and clear regime. The noble Lord supports further incident reporting here—additional stages of incident reporting. In our impact assessment, we clearly set out the implications of that in its cost to business and so on. We will come on shortly to discuss potentially broadening the scope of incidents that would be reported. We have not been able to quantify that potential impact, as a sort of counterfactual, because we are only just discussing that.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I have listened really carefully to the Minister and thank her for her response, but I feel that we just had a completely black and white no, which is extremely disappointing. We have had something almost worse than a black and white no, because if I heard her correctly—I will need to go back and read it again—I think she has added uncertainty, because suggesting that it is okay because regulators have the ability to ask for extra reporting is a company’s worst nightmare. What you want is really clear black and white guardrails, as we have been trying to introduce in these amendments.

I had hoped that we could have follow-up discussions between now and Report, but I feel like the door has been rather slammed in my face. I would be very keen to understand, as the noble Lord, Lord Clement-Jones, has just said, what consultation has really happened and to have a recognition that you need to consult organisations that have experienced a substantial cyber attack. If an organisation has not, then I am afraid it will want to keep quiet and will not want to report anything. It is easy to ask broad groups of organisations, “Would you like more reporting?” We all know what the answer to that would be. That is an easy consultation.

I would really value more detailed discussions with the Minister and her officials between now and Report, because I feel that we will come back to this, particularly given the support that my amendments have received from across the Committee, for which I am extremely grateful. I beg leave to withdraw the amendment.

--- Later in debate ---
Moved by
19: Clause 15, page 22, line 14, leave out “users of”
Member’s explanatory statement
This amendment would require an operator of an essential service to consider whether any data relating to the essential service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.
--- Later in debate ---
Moved by
36: Clause 15, page 26, line 31, leave out “users of”
Member’s explanatory statement
This amendment would require a relevant digital service provider to consider whether any data relating to the relevant digital service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.
--- Later in debate ---
Moved by
44: Clause 15, page 30, line 4, leave out “users of”
Member’s explanatory statement
This amendment would require a relevant managed service provider to consider whether any data relating to the relevant managed service has been compromised (not just data relating to users of the service) when determining whether an incident should be reported.
--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I, too, thank my noble friend Lady Harding of Winscombe for tabling this important set of amendments, which we welcome, and for clarifying the refinements of the grouping process, which had slightly eluded me up to that point. As with the previous group, this would amend four key areas of, on this occasion, customer reporting. It would tighten the timing to notify customers; widen the incidents expected to be reported by removing the adverse impact criterion; add extra reporting triggers; and add an “advice on remedies” duty.

Of course, businesses should be supported in the case of cyber attacks and our priority must be preventing, containing and controlling such incidents, but this cannot come at the expense of the customers that businesses serve and depend on. Customers deserve to know when a firm they depend on is targeted, even if such an attack does not necessarily directly adversely affect them. They deserve to be informed promptly and they deserve to be informed of potential remedies.

It is worth saying that there is a welcome side effect to doing so, based on the premise that behaviours are the best guard against cyber attack. Constantly being aware that cyber attacks are going on will improve behaviours. As was said earlier, the goal is not to create panic but, on a continuum between insouciance and panic, we must imbue a point closer to concern more widely in the population to keep people aware that we are constantly at risk of being hacked. On these Benches we feel these are wise, pragmatic and helpful changes. I certainly hope the Minister agrees.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank the noble Baroness for raising important points around customer communication. As set out in the Bill, it takes forward the current duties to notify customers that the Bill places on data centres, OESs, RDSPs and RMSPs. That duty was designed to ensure that providers of key digital and data infrastructure services consider whether their customers are likely to have been adversely affected by a reported incident—whether through disruption of service, compromise of their data or exposure of their systems to cyber threats—and to notify them.

I will explain the logic in response to the point of the noble Lord, Lord Clement-Jones, about the importance of meaningful communication with customers. The reason we have drafted the Bill so that customer notification follows the 72-hour incident report is to ensure that regulated entities can focus on understanding the nature of the incident and contact customers when they are more likely to understand its potential impacts.

We have discussed the question of what an organisation might reasonably be expected to know within 24 hours of identifying an incident. The point is that customers should be communicated with in a timely manner, with sufficient information, so that they can take the necessary action. On that point, the rationale for 72 hours was to time it, for simplicity, with the 72-hour report. I am happy to consult further with the noble Baroness to explain the logic of the 72-hour and 42-hour requirement to communicate with customers, because the motivation is exactly the same: to have actionable and meaningful communication with customers.

I turn to the degree of depth of communication, the advice that can reasonably be put on regulated entities on technical measures, and what technical mitigations customers should take on their own. It is reasonable that the regulated entity should share what they know about the nature of the incident. The question about whether the regulated entity is in the right position to provide advice to customers on what mitigations they should take is both practical and technical. Would they have enough insight to have an effective understanding of the situation of the customers and a detailed understanding of the customers and their businesses in order to give effective meaningful advice in that way—or would that just be a requirement on the entities that would not have the intended impact? On that point, I am not quite persuaded that the line is drawn in the right position.

On keeping in touch, mentioned by the noble Baronesses, Lady Kidron and Lady Harding, I am happy to come back to that on Report to make sure that we have the right balance between the initial notification and the right type of customer communication.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

I thank all the noble Lords who, again, have supported my long list of amendments and I thank them for their excellent contributions. It feels as if we made a very small breakthrough, for which I am extremely grateful, and I thank the Minister. I will not delay anyone any longer as we have another group of my amendments to come, but I look forward to some detailed discussions between now and Report to see if we can bring this back in a form that we are all able to support. I beg leave to withdraw the amendment.

--- Later in debate ---
Lord Reay Portrait Lord Reay (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend Lady Harding of Winscombe for her amendment, to which the noble Baroness, Lady Kidron, has added her name. We believe that this is a straightforward amendment. If we are to tackle cyber attacks seriously and to create a generally resilient cyber system, we should not simply stop at the reporting of incidents that happen. A key way of ensuring that we build not just a responsive but a preventive cyber system is by knowing what potential risks exist and who is attempting to commit cyber attacks, even if they have not done so yet. This is a reasoned amendment that places a requirement only on those already considered regulated persons, with the opportunity for others not regulated to report voluntarily. I hope that the Minister will agree.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

My Lords, I thank the noble Baroness for raising this question about the requirement for regulated entities to report cyber threats, near misses and sub-threshold incidents within a 72-hour deadline.

I turn first to the question of voluntary reporting, which we touched on a little in the context of discussing the industry groupings on Tuesday and the trust groups that exist and are often facilitated by the NCSC. These are incredibly valuable groups. We absolutely encourage voluntary reporting, whether through those groups or other industry bodies. There is a question about whether putting such groups and mechanisms on a statutory footing helps or hinders that objective, because we need to engender the confidence to share information, as the noble Baroness and others mentioned. There is a question about whether that is within the regulatory perimeter, as it were, and whether it encourages that or not. I am happy to come back to that on Report.

I turn to the question of reporting sub-threshold incidents. The amendment concerns incidents that have been successfully contained or have proved ineffective, incidents that fall somewhere below the current reporting thresholds and any potential circumstance or event that could, if it occurred, affect a regulated entity’s systems or the users of a service provided through these systems. We discussed that in the context of data centres. Let me answer the question from the noble Baroness, Lady Kidron. In the discussion on data centres, I was speaking about near misses. We made the point highlighted by the noble Baroness, Lady Neville-Jones: near misses and those types of incidents would be captured for data centres, given the particular role they play in our digital infrastructure.

The extension of similar requirements—although, as we read it, they are much broader requirements—to all regulated entities would increase regulatory reporting very significantly. The noble Baroness, Lady Neville-Jones, made the point right at the beginning—although it could have possibly been someone else—about the ability of our regulators to effectively utilise the threat intelligence and manage it so that it can be conveyed into actionable advice and trend data. These are the considerations that we take.

Another consideration is that the entities that have more sophisticated surveillance and mitigations may be able to identify attacks more effectively. We would not want to set up a situation where there were any perverse incentives in the system for those who have very adept surveillance and assessments away from reporting or developing that.

Even though I heard very clearly that the motivation is that the amendment is just to catch to those incidents that just fall below, our reading of it is that it would be much wider, and it may indeed have some other effects. At this stage, I would not support the amendment as drafted.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

It was my suggestion to break up these amendments into different groups, otherwise we would have had about 100 amendments in one group. There is an awful lot of overlap in the discussion on this group in particular and Amendment 17 in the name of my noble friend Lady Neville-Jones. Would the Minister commit to having a joint meeting, where we could try to work this through together? I think we share a common goal of wanting to give as much relevant, immediate and up-to-date intelligence to the network as possible, without overwhelming, and recognising that, as the noble Lord, Lord Clement-Jones, said, time is absolutely everything in these cyber attacks. If we could discuss that together rather than separately, that would be extremely valuable.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

That would indeed be very valuable to discuss the questions around definition, scope, coverage, timeliness and impact on potential entities—sorry, I have just expanded our agenda.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

I have heard very clearly the willingness to discuss and collaborate from the Minister, which is extremely welcome, as were the contributions from all noble Lords. If the last hour and half has shown anything, it is that there is a genuine cross-Committee desire to work—this is what the House does at its best—to genuinely improve, with a shared goal of a piece of legislation that the country will benefit from if we can get it right. I beg leave to withdraw the amendment.

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness, Lady Kidron, for opening this debate on behalf of my noble friend Lady Morgan of Cotes. I will come to her amendment in a moment, after I touch on Amendment 167, tabled by the noble Baroness, Lady Ludford. Her comments, particularly about board ownership of cyber risk, were well founded and an extremely important foundation for the debate—as indeed were those of the noble Baroness, Lady Berger, who pointed out the difficulty of accelerating from zero cyber knowledge to sufficient. That is a non-trivial undertaking.

Amendment 167 is absolutely in line with the principle that we raised on the first day of this Committee in the form of Amendment 92B. It is the idea that executives should be held accountable for cyber security and resilience plans by their board and their shareholders, by reporting consistently on protections. This amendment, perhaps a little more explicitly, would require the same thing and I am very happy to support it.

I think Amendment 74 largely follows the same sentiment: that companies should and must be held accountable for their own cyber security. On this one, however, I need a little more persuasion. I am going to tread a little tentatively here, because I very much take on board the comments of my noble friend Lord Arbuthnot that we have not solved this problem yet and that carrying on as we are is probably not that sensible.

However, I do have some inner alarm bells ringing about this one. So, while we support the goal of making companies self-sufficient and accountable to their shareholders, this amendment would give the Information Commissioner powers to enforce compliance and sanction individual negligence. The concern here is that, as a matter of principle, the inner working of companies—who is accountable internally, to whom and for what—should be placed in a different category from the requirements placed upon them.

We should encourage companies to figure out internal issues themselves. By all means require board oversight of cybersecurity plans, as we have attempted to do, but my understanding is that this amendment would make it the Information Commissioner’s job to decide which individual is responsible when cyber attacks take place and are not adequately defended. I find this quite a tricky path forward, but I am clearly willing to keep talking and to be persuaded.

I am also concerned about the disincentives to become a director that this might put in place, because of what feels to me like the inherent uncertainties of the liabilities that may hang over board directors as they undertake these responsibilities. That being said, I, of course, completely agree with the underlying principle and look forward to hearing the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.

I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.

That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.

I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.

To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.

I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, can I just check something before the noble Baroness, Lady Kidron, rises? The Minister has uttered some very warm words about the responsibilities of directors, but am I right in thinking that in nothing of what she said is there any intent for the Bill to create a legal liability that compels directors in the way that these two amendments do, or any form of personal financial fiduciary duty on a director? What she is arguing for, despite the warm words, is, essentially, a voluntary scheme.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

We will consult on the security and resilience requirements that will come out of the Bill. They will contain a requirement on board governance and those expectations will be set out as a result of the Bill. The regulators and others enforcing the Bill will take that into account in their enforcement regime.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I am sorry to press, but the Minister is saying that these are expectations. Will she write to us? There is a huge lack of clarity in the middle of those warm words. We take encouragement from the fact that the Government want to see boards take responsibility, but where are the teeth?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

Obviously, we have not yet gone out to consultation on the security and resilience requirements; we will do that after the Bill passes. I can certainly update on the process, the expectation and how that links with the enforcement duties in further detail.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

The Minister is also going to have to point out the power under which the Government are going to act to actually fix that liability, or make sure that the guidance, or whatever it is, is complied with, because we are talking about the power and the duties in primary legislation. It is all very well for the Government to say, “We’re going to produce guidance”, but unless there is something in the Bill that permits that and makes sure that the Government can make it stick, we are all going to feel dissatisfied.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

The noble Lord, Lord Clement-Jones, has done a lot of my work for me. I thank everyone who contributed. I was really struck by the expertise in this Room. We started this afternoon by talking about the importance of lived experience. I say very strongly to the Minister that I have been in the House long enough to see Acts of Parliament pass, be regulated and fail because we did not really understand how they were going to hit when they were in the world.

The comments on this group are really worth listening on, particularly those on Amendment 167. I say both to the noble Viscount, Lord Camrose, and to the Minister that there is such a high bar of connivance in Amendment 74. There is no accident. The words are “deliberately”, “knowingly”, et cetera—I read them out as part of my introduction. I will take up the noble Viscount’s offer to come to speak to him and persuade him, and I ask the Minister to really think about this, because we have heard that culture does not change without an incentive. This is an incentive to say that if you are seen to grossly mislead and undermine the regulation, then you are liable. That is what good law does. I beg leave to withdraw the amendment.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, we have heard very compelling cases from all noble Lords who have spoken on this group about why a particular sector should be included. I will not go through the list—it was gone through very well by the noble Lord, Lord Clement-Jones, a moment ago—but I think we can all agree that each one was a compelling case. That probably illustrates the wider problem, because we are almost getting into a game of cyber whack-a-mole here, where we can see them popping up left, right and centre. So our approach, with Amendments 92 and 92A in my name and those of my noble friends Lord Camrose and Lord Holmes, is to try to take a more strategic view, very much reflecting some of the views that the noble Lord, Lord Birt, was mentioning earlier as well. They ask the Government to assess strategically important entities outside the current NIS regime and consider whether they should be brought into scope where a cyber attack would have a sufficiently serious impact on the economy or the day-to-day functioning of society.

We are not asking for another long list of businesses to be regulated, because we need to be careful about the regulatory burdens that we are putting on people. Instead, Amendment 92A proposes a risk-based test and asks these questions: what would actually happen if this organisation went down? Would essential services stop? Would very important supply chains fail? Would significant parts of the economy cease to function? If the answer to those is yes, surely the Government should at least assess whether that organisation belongs within our national cyber security perimeter. This also illustrates why we need to see the national cyber action plan. It was promised this summer; we are now in September and, considering that this is very pertinent to everything we are talking about in Committee, I ask the Minister when we will see the plan.

I will highlight one further issue, which the noble Baroness, Lady Berger, illustrated very well, in the area of the data held in certain organisations, particularly in education. We all know that the reason that a lot of these organisations are attractive targets is not because of the essential services they often carry out but because they carry enormous quantities of valuable and sensitive data. Again, this was very much my experience with the attack on Synnovis when I was Health Minister. It caused massive disruption for operations and diagnostic services in London, but the question was: why was that organisation holding so much information in the first place? It had names and addresses of people going back 20 years, their test results and their full medical records, and it did not need any of it at all. It could all have been anonymised, and it definitely did not need to hold it for 20 years.

To me, the question we really need to answer—this speaks to an amendment we will be talking about later—is: what data do all these public bodies really need to hold? Of course, if the data is not there in the first place to be stolen, or if it is not interesting or valuable, then that is the best line of defence, because there is no reason for there to be a cyber attack on it. As I say, we will talk further on that on Amendment 174E, but the principle is directly relevant to what we are talking about here.

Before I come to the end, I have a special request from my colleague here, who I think knows a thing or two. I am told on good authority that the last government AI regulation White Paper has a lot of relevance and synergies here, so I would request the Minister to look at that between now and Report to see where, as I say, there are synergies and learnings from it.

In summary, first, we should systematically identify the organisations whose compromise would cause the greatest damage, as per our Amendment 92A, and, secondly, we should reduce both their vulnerability and attractiveness as targets, including by reducing the data prize available to the attacker, as per our Amendment 174E, which we will come to later on. That, to me, is genuine cyber resilience: not merely making the safe harder to crack but, wherever possible, ensuring that there is nothing valuable inside the safe to steal.

I hope the Minister will respond both on the important sectors raised by noble Lords and to the central question behind Amendment 92A: what systematic test are the Government applying to determine which strategically important organisations should fall within the NIS regime, and will that regulatory perimeter keep pace as technology and the threats change?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

My Lords, I thank noble Lords for raising so many aspects of the scope of the Bill. I recognise the sentiment among noble Lords today about the importance of expanding its scope. Our approach has been to target regulatory requirements on a select number of essential services, while using non-regulatory but effective measures to improve the cyber security and resilience of the wider economy.

As I set out at Second Reading, I have asked my officials to work across government to consider what additional services would merit being brought into scope of the regime in future. This will allow us to make a holistic and considered approach. To ensure our assessment is appropriately prioritised, I would first like to focus on the CNI sectors not already covered by the NIS regime.

I share the intent behind the objective from the noble Viscount, Lord Camrose—which the noble Lord, Lord Markham, spoke to—that the process to expand the scope of the regime should be rigorous and evidence based. As set out in the Bill, for something to be defined as a new essential activity under its powers, the Secretary of State must be satisfied that the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is reserved for the most vital activities in our nation. To the point raised by the noble Lord, Lord Birt, I believe that that is a clear test. In reaching a decision, the relevant departments would need to carry out a risk assessment and any economic assessments, and consider whether inclusion is proportionate. This is part of normal policy development. After that, proposals would be subject to consultations and the affirmative procedure.

The noble Viscount proposed in his amendment that assessment for inclusion be carried out on an entity-by-entity basis, which obviously differs from the sectoral approach we have taken thus far. Setting out the detail that would need to be published according to the amendment could lead to a release of information about individual companies that could pose commercial or national security risks, due to their criticality. I think that the sectoral approach is better. As others have said today, looking at a systemic approach to the sectors is the right way to look at what is in the statutory approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I am sorry to interrupt the Minister, but clarification along the way would be very helpful. She has asked her officials to see what other sectors should be brought in and has given an indication of the kind of test, but we are dealing with a bit more fog here. Is she promising us something in primary legislation or will it appear in secondary legislation? Will it just be something that government policy will cover, and we will have no say on the kinds of sectors that should be included?

For instance, the Minister is the Space Minister. Do we have an indication that space, or any of the key activities within space, will be included? Do we have any white smoke from the department as to whether that sector will be included? Will we hear by Report what sectors might be included? It is all a bit vague, and that does not give us a great deal of assurance.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I was referring to the process by which sectors can be brought into scope of the Bill, as set out in it and using the powers in the Bill. That would follow the process I just mentioned, which would be subject to consultation and the affirmative procedure. That is the process that I am referring to.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

But the powers are further down the track; they are under secondary legislation. I am assuming the Minister is promising that the Secretary of State will set out the criteria by which a new sector is brought in. Is that right? Do we have any indication, apart from what the Minister has said today in response to the noble Lord, Lord Markham, as to what those criteria will be?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I have highlighted a few of those criteria regarding the extent to which the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. Obviously, we already have the list of critical national infrastructure. We need to go through a whole process, as others have mentioned. We would need to make our assessment and then consult with industry on that, so there is a process to go through here. That process of consultation and talking to industry, or any affected sector, is absolutely critical. I am absolutely happy to update noble Lords and engage further ahead of Report on this.

In terms of the report referenced in Amendment 92A, I do not think we would need a statutory obligation to bring this report back, as set out. I mentioned the focus on entities rather than sectors, and it is better to look at the sectoral approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, if the Minister could commit to adding that to the conversations we are bound to have to have between now and Report—

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I am not only committing; I am offering, so I am happy to have the noble Lord confirm that that would be good. I am absolutely offering that as part of the engagement ahead of Report.

I have heard the numerous areas that have been raised for inclusion in the Bill. We should look in a methodical and sensible way at these and at the implications—as we have previously discussed—for the obligations that will placed on any entities that come within the scope of the Bill, such as incident reporting, board accountability and so on, so that we do this in a very sensible manner. That is why this is the right approach to take.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

Can I ask the Minister to comment on another point that the noble Lord, Lord Clement-Jones, raised? Why should this not apply to the higher reaches of government? I ask the Minister specifically: what is her view of 607,000 records being stolen, just weeks ago, from the Department for Education?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I absolutely intend to talk about the public sector. Given the numerous sectors that have been raised, I also want to respond individually on each sector. I absolutely agree that all sectors need to improve their cyber resilience; it is not the case for only those in the regulatory perimeter. It is also not the only way to improve; we should improve things right now. There is funding, and there are activities going on in all of these sectors that we might talk about—sometimes with public funding, sometimes with public advice and sometimes through industry groups.

I have spoken a little already about the cyber resilience pledge, which over 100 companies have now signed. It sets out the absolute best practice and what actions to take, including making cyber a board-level responsibility, following the Cyber Governance Code of Practice, signing up to the early warning service and taking a risk-based approach to requiring cyber essentials across supply chains.

In the retail sector, the DBIST industry-led Retail Sector Council is working with experts and business representatives to consider cyber security.

In respect of the space sector, it is absolutely critical; I could not agree more on the importance of PNT and satcoms, which underpin a huge amount of UK economic activity. The UK Space Agency is already strengthening cyber resilience in practice through the development of a space cyber assurance framework for the space sector, intending to help operators understand and demonstrate cyber resilience in a proportionate and practical way.

The UKSA also supports the provision of threat briefings and is working with industry on the potential development of a space information-sharing analysis centre. This would improve the flow of threat information, warnings and good practice between government and industry, and support links to international networks, such as the US-led global Space ISAC model. That would help operators to understand emerging threats and to act quickly.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, at the risk of irritating the Minister even further, it is great to hear of some of this activity, but that is not the same as bringing it under the terms of the Bill.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.

Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.

Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.

Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.

This brings me on to Amendment 81A—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

I thank the Minister for her point about the Government Cyber Action Plan, but do the strength of her arguments there not completely reinforce the urgent need to have the national cyber action plan, so that we can assess overall the cyber strategy of the nation and the role of the Bill within that strategy?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

The cyber action plan is a very thorough document. It sets out a plan over many years to improve the cyber resilience of the Government and the public sector, which I think we all agree is absolutely needed. The fact that incidents are still occurring in the public sector reinforces the need to act. We will publish the cyber action plan and, as I mentioned two days ago, I will keep the Committee and the House updated on progress on that.

Education is an incredibly important sector, and the Department for Education takes an active approach to supporting the sector. This includes the Cyber Security Hub, providing schools in England with guidance, while the standards for schools and colleges help institutions to understand their cyber security requirements. Colleges have been required to meet cyber essentials since 2024, with more than 80% of colleges now meeting this requirement.

I come to the question of MHCLG and local government. The department is also taking meaningful steps and working with local authorities to increase their cyber defences. This includes the rollout of the cyber assessment framework for local government, which would be the equivalent to what is required in the cyber Bill, and the recently proposed revisions to the best value statutory guidance to set new expectations for local authorities on cyber resilience. That best-value duty provides an immediate and proportionate route to improving through existing governance and accountability mechanisms. In addition, MHCLG is supporting councils directly.

The question of electoral infrastructure and political parties, raised in Amendments 79 and 81D, is also incredibly important, as noble Lords have set out. The Government work with the NCSC to mitigate risks there. MHCLG specifically works with local authorities to strengthen their electoral cyber resilience and ensure electoral data is adequately protected. The Joint Election Security and Preparedness Unit has responsibility for co-ordinating election security. The MHCLG digital electoral services team maintains robust incident response arrangements to protect electoral systems and citizen data. As the noble Baroness, Lady Ludford, mentioned, the NCSC also has a broad package of support for political parties, candidates and elected representatives. This includes regular engagement with parties, which can access the NCSC’s active cyber defence services, as well as NCSC providing tailored advice to parties and candidates.

I have set all that out because the motivation behind bringing these matters into scope is to engender further action. I want to emphasise that further action is happening, whether or not it is within the scope of the regulatory perimeter.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

The Minister pointed to three examples of where education is considering issues around cyber security, specifically in schools and only 80% of colleges. One of the concerns I outlined in my contribution was around the examining bodies for both our secondary schools and universities. There was no mention of universities. Can I understand a bit more about how they are currently being considered, if they are not going to be included within the scope of this Bill?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

The general approach is that the lead government department has responsibility for ensuring cyber security in the areas that it covers. I will need to write to my noble friend specifically on exam boards and examining authorities. I know that the DfE supports bodies that support higher education and further education, but for further details, I will come back to her.

More broadly, I am happy to talk further with noble Lords between now and Report, and perhaps after, on the approach to assessing what should be within the regulatory perimeter and at what speed that can be advanced.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

Can I ask a couple of questions and make one comment? The more we hear about the conversation that is taking place on the Bill, the more anomalous the factors that have been chosen or included in the scheme become. Let me give the example of space. Plenty of us now receive our internet connection via satellite. It is inevitably an intimate part of the networking system of cyber security. What we appear to be told is that some parts of the telecoms and internet world are going to be governed by the Bill, but other parts, which are equally integrated and important, are going to be covered separately by a special different arrangement—they are not included. For example, as I understand what the Minister said about space, it is not going to be included in this Bill. With the greatest possible respect to the Minister, it does not make sense.

My question is: in the period ahead of us, could the Government have another look at the whole question of the scope of the Bill? This seems to be one of the problems that lies between us. As a result, Members are now trying to shove into the Bill all sorts of things on the grounds that they are essential services—some of which clearly need to be there, but for others it is arguable that they do not.

I heard what the Minister said about the action plan. I have read the action plan, and it is a good plan, but it lays a heavy responsibility on a department that no longer exists—DSIT. The function is set out so well and is important to keeping government departments up to the mark, which is going to be done separately. Where is that responsibility now going to sit? It will require a very considerable degree of expertise on the part of those conducting this system of keeping people up to the mark. How is that going to be done?

It seems to me that local government requires something of the same. Government is a whole thing. It is not that some things can be done in central government without regard to their implementation by local government or vice versa. Are the Government going to extend the system that is being mapped out in the action plan for government to local government as well, in order to get the same standard of performance and integrity of systems?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

Let me work backwards here. The noble Baroness makes a very good point: the services delivered at local level often mirror those at central government level. At the moment, we are consulting on the question of the best value duty to give additional prominence. One of the issues with mapping these requirements into local government is that many different services are indeed provided. We may need to come back to that in more detail.

The government cyber unit now resides within DCMS. The team has transferred over and is up and running; I have spoken to them many times recently. The unit is very active in progressing the government cyber action plan as per the timetable and the target plan.

On the question about the approach to looking at other sectors to bring in, that is why I mentioned at Second Reading that I had already asked my officials to work across government to consider what additional services would merit being brought in. I mentioned earlier today that focusing on CNI services not already covered by the NIS regime would be the right place to start.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, will the Minister show some greater enthusiasm for her own regulatory scheme? I hope that the criteria that she adopts within the department as to whether certain sectors are going to be brought in will be about not only the criticality of the services but the need for transparency on the incidents themselves. We have had this whole debate about notification being beneficial so that organisations such as the NCSC actually know what is going on, that we the public know what is going on and the level of threat, and that our intelligence services are fully apprised.

The noble Baroness, Lady Neville-Jones, was entirely right on critical sectors, such as space. If there is no duty of notification on, say, a satellite manufacturer or something, we will all be in the dark. The Government rightly introduced this Bill to introduce greater transparency and duties on some very important sectors. We simply want to make sure that we capture all the important sectors and that they are all subject to the duty. This shying away from the Government’s own framework seems completely contrary.

--- Later in debate ---
Lord Reay Portrait Lord Reay (Con)
- Hansard - - - Excerpts

My Lords, I thank all noble Lords who have added their names to the amendments and who have spoken in this debate. Both amendments in this group are underpinned by the same principle that national security and national technological capabilities deserve a unified plan—not one that targets some sectors and entities and not others, but a holistic plan that brings together all sectors and industries into a single framework. His Majesty’s Opposition therefore support the intention behind the amendments.

However, at risk of repetition, the Government could avoid the need for these propositions. They could do away with your Lordships’ worries if they would commit, as mentioned by my noble friend Lord Camrose, to publishing a national cyber action plan within a set timeframe, and commit to including national digital sovereignty as part of that plan. In light of Tuesday’s debate on AI, we request a review and update of the previous Government’s AI White Paper to ensure that AI regulation and cyber regulation are aligned. They need to operate in lockstep, and this Bill is an appropriate place to do it. It is evident that national sovereignty and a reduced reliance on foreign technology is vital to ensuring national wholesale cyber security. I commend these amendments in their aims to achieve that, and I look forward to the Minister’s reply.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank noble Lords for continuing the debate with which we ended the previous session: the very important topic of the technological and digital sovereignty of the UK. That is very important to this Government and we are taking action on it. It possibly has not been focused on enough in past years but, across many areas, that is what we are doing.

We are clear that we need a coherent approach and a clear direction. We obviously need to take into account that technologies and markets evolve, and the core of that approach was set out in the modern industrial strategy and the Digital and Technologies Sector Plan. That set out the direction of travel, and the Government will continue to consider how our priorities are best articulated.

Our objective, as I articulated at the end of July, is not complete independence but strategic resilience through a combination of domestic capability, diversified international partnership and targeted management of critical dependencies. This allows us to access the best of global markets while capitalising on our domestic capabilities. That is why we already have in place a range of regulatory and non-regulatory frameworks that enable us to embed those objectives through existing industrial, technological and resilience strategies. I will talk to some of those now.

For essential services in scope of the network and information systems regime, such as drinking water, health and energy, all entities are required to manage and mitigate the risks posed to their systems that deliver essential services. This includes the risks set out in the amendment of the noble Baroness, Lady Ludford.

On market concentration, which the noble Baroness, Lady Kidron, and the noble Lord, Lord Clement-Jones, referred to, the CMA is acting. It concluded an investigation into the cloud services market in July last year, highlighting competition issues arising from market concentration. It has since announced packages of actions to improve competition in cloud services. This work has directly informed our thinking, as we develop a more strategic approach to how the public sector procures cloud services.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I point out to the Minister that not all is rosy in that particular cloud services garden. The CMA failed to designate those major US hyperscalers as having strategic market status, which, for many of us, was a rather extraordinary outcome.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

It has announced a series of measures, including actions from Microsoft and Amazon, to support greater choice for UK businesses and the public sector.

On my noble friend Lady Berger’s question, it is true that cloud spend is distributed across departments and managed through a range of departmental contracts and commercial arrangements. We have established a cross-government cloud consumption dashboard to improve the visibility of cloud usage across the public sector, and we are working with both suppliers and departments to further improve the quality and completeness of our cloud infrastructure spend data to provide a joined-up view today and for the future. That is something that the Government are acting on.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

For clarification, that is on the spend, but my question is specifically about where the cloud services are hosted and/or whether they are under the jurisdictions of Governments beyond the UK. It was not just about what money is being spent; it was about who is responsible for it and where it is located.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

That is well noted.

For all digital services, as many noble Lords have pointed out, government departments are required to carry out robust security and resilience assessments in their procurement to ensure that the actions of foreign states or hostile actors cannot disrupt the delivery of public services. In June, the Cabinet Office published procurement policy note 025, Protecting the UK’s National Security through Public Procurement, and AI will be one of four key sectors recognised as critical for national security, with new guidance for departments prioritising contracts for British business where necessary to protect our national security.

--- Later in debate ---
Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

Before the Minister sits down, I ask her to reflect, at the end of our second day in Committee, that the noble Viscount, Lord Camrose, has mentioned more than once that he would like to see a national cyber security strategy, but is not the takeaway from these two days that we are all very clear on the challenges facing the UK? There is a great deal of uniformity across the Room, as well as in the quality of the Minister’s answers, but does the Bill not need to deal with all the issues that have surfaced and been addressed? Frankly, it does not do that at the moment. If the Bill passes in its less ambitious form, how long will it be before we get another Bill to address the strategies? If we have to wait that long, how much more damage is going to be done to our economy and our society in the meantime?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

Going back to the point made by the noble Lord in an earlier intervention, the Bill is a substantive Bill that substantially increases coverage of the digital infrastructure on which much of our economy relies. That is a very important point. As I mentioned at the start of my remarks just now, the question of whether the Bill is the right place to articulate the breadth of many of the issues that have been raised is, indeed, a good one. I am not sure that it is the right place to articulate all the very good questions that have been asked, because some are much more wide-ranging than the scope of the Bill.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, I thank all who have spoken for their excellent contributions. I will make three quick points. First, in the course of the afternoon, I opened the Explanatory Notes, which is always a bit of a danger. I just want to put on the record that paragraph 2 states:

“These reforms are intended to better protect the services and other activities that are essential to the day-to-day functioning of society in the UK, and the economy, through safeguarding relevant network and information systems (the systems that allow computers and other devices to communicate with each other) and their surrounding environment”.


I do not think that the Bill, as it stands, does that job, and the last two groups have absolutely illustrated that.

The second thing that I would like to say to the Minister, and I absolutely recognise all the things that she mentioned, is that I did find myself counting, and it was 11. We do not have a strategy. It is 11, but it does not cover the scope of what we are discussing; it does not even cover the scope of security.

The third thing, which I am slightly loath to say but will now say, because otherwise we will get nowhere, is that I have been in the room with Ministers when they have indicated directly that they cannot do something because of America’s desire—absolutely categorically, yeah? That is the bit that we did not get from the Minister. Sovereignty is about being able to impose and choose our laws, and to decide what we can and cannot do and what we are willing to risk and give up for it.

I am not saying that it is easy, but I think everybody in the Committee has been completely reasonable in saying that we are not trying to replace the stack; we are trying to talk about chokeholds and we are trying to be strategic. What we are really trying to do is make the country safe and secure and, dare I say, make it respond to its own laws. I do not think that anything that the Minister said has dealt with that fact. It was not asking for much to actually have a think about what strategy is and have a look at how we might get to a better place. Let us have a vision of where we want to go and work out how to get there. Individual things and departments and leaving things out is not the answer.

This is an easy amendment for the Government to say yes to and I hope that, by Report, they will. I beg leave to withdraw the amendment.

Digital Government (Disclosure of Information) Regulations 2026

Baroness Lloyd of Effra Excerpts
Wednesday 2nd September 2026

(4 weeks ago)

Grand Committee
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Moved by
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra
- Hansard - -

That the Grand Committee do consider the Digital Government (Disclosure of Information) Regulations 2026

Relevant document: 10th Report from the Secondary Legislation Scrutiny Committee

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - -

My Lords, these regulations make three important amendments to the information sharing powers in Part 5, Chapter 1 of the Digital Economy Act 2017. The core aim of these regulations is to help the Government to support households facing financial hardship, improving access to support for those eligible and ensuring that public services can respond more effectively to people’s needs. Too often, people do not receive the right support because the information needed to identify them is held by different public authorities. Enabling relevant information to be shared safely and legally will help support to reach the right people more quickly and effectively.

On the measure related to the delivery of energy debt relief schemes, Part 5, Chapter 1 of the Digital Economy Act already provides a well-established framework for information sharing to support public service delivery. Under Section 36, specified public bodies can share information with energy suppliers with the intention that the suppliers use the information in connection with a prescribed fuel poverty measure to support households experiencing fuel poverty.

None of the fuel poverty measures currently allows this power to be used to support households with energy debt. These regulations will amend Section 36 to create a new fuel poverty measure that will enable information to be shared between certain public authorities—including the Department for Work and Pensions and the Department for Energy Security and Net Zero—and energy suppliers to enable households eligible for support under an energy debt relief scheme to be identified and to deliver support to them. An example of a scheme that could be facilitated by this change is a proposed debt relief scheme that Ofgem consulted on in winter 2025. While the detailed operational design of the scheme is currently being developed by DESNZ and Ofgem, its ambition is clear: to help eliminate between £500 million and £1 billion of energy debt, remove administrative burdens and deliver meaningful relief to households struggling with energy arrears and financial hardship.

The second measure will amend the Digital Government (Disclosure of Information) Regulations 2018 to enable DSIT to rely on the Act’s fuel poverty objective to share information with certain other public authorities for the purpose of assisting people living in fuel poverty. This will support initiatives such as the National Data Library’s kickstarter project, which seeks to bring together cross-government data, including earnings, benefits and energy usage, which will enable government to identify households in fuel poverty and to target energy bill support more effectively. I should note that the draft regulations were laid when responsibility for the relevant government data function sat within DSIT. Following the Written Statement by my noble friend Lady Smith of Basildon on 21 July, this function is being transferred to the Department for Digital, Culture, Media and Sport. The regulations will be made as currently drafted and any necessary amendments to reflect the transfer of functions will be made separately. This does not affect the policy intent or operation of the measure.

The third technical measure will also amend the 2018 regulations to expressly add DESNZ to the fuel poverty objective. The relevant function was transferred to DESNZ when it was created in 2023 but the regulations were not consequentially amended at that time. This measure will not have any immediate operational impact, but we are taking the opportunity to make the change in the interests of legal certainty.

More broadly, these measures reflect the Government’s commitment to make better use of data to improve public service delivery. The information sharing is with a clear public purpose: helping households struggling with energy debt, while supporting action to tackle fuel poverty and outcomes for citizens.

The Government have undertaken appropriate engagement on each of the three measures. For the energy debt relief scheme measure, a public consultation was conducted. Respondents were overwhelmingly supportive of the proposal, recognising the important role that information sharing can play in identifying eligible households and delivering targeted support to those struggling with energy debt. To add DSIT and DESNZ to the list of public authorities connected with the fuel poverty objective measure, the Government consulted the specific consultees, as required by Section 44 of the Digital Economy Act—namely, the Information Commissioner’s Office, the devolved Governments and HMRC. Consultees were supportive of the proposal and content for it to proceed.

Furthermore, I also wish to reassure noble Lords that robust safeguards will continue to apply to all information sharing undertaken under these powers. Part 5, Chapter 1, of the Digital Economy Act contains a strong framework for governing the sharing of data. The powers in Chapter 1 permit information to be shared only by a limited number of bodies, mostly public authorities, and only for the purposes specified in the Act. There are also statutory restrictions on the re-use and onward disclosure of information received under the powers in Chapter 1.

As well as this, any public body exercising the data-sharing powers must adhere to existing data protection legislation, namely the UK GDPR and the Data Protection Act 2018. It must also have regard to the statutory code of practice under the Digital Economy Act, which emphasises requirements regarding data privacy, security, governance and transparency. The code of practice sets out processes that bodies exercising the powers are expected to follow, including recording information-sharing agreements made under these powers in a publicly available register, providing transparency about how the powers are used. These safeguards help ensure the responsible use of data by allowing information to be shared only where appropriate and subject to robust protections, helping to maintain public trust.

In terms of scrutiny, the regulations were considered by both the Joint Committee on Statutory Instruments and the Secondary Legislation Scrutiny Committee, neither of which drew them to the special attention of the House, with the latter including an information paragraph only in its report.

These regulations will enable better use of information to help households facing energy-related hardship. They will allow for information to be shared to identify eligible households, improve the delivery of targeted assistance and support collaboration between public authorities. In doing so, they will help ensure that support reaches those who need it most, while upholding the highest standards of privacy, with information handled lawfully, responsibly and securely.

Earl Russell Portrait Earl Russell (LD)
- Hansard - - - Excerpts

My Lords, more than 3 million customers are now in energy debt or arrears, owing a total of around £6 billion, with an average debt of approximately £1,800 per household. No household should be trapped indefinitely by energy debt accumulated during an exponential national crisis. Non-targeted support, as we have seen in the past, has been prohibitively expensive and not terribly efficient. I have called for better information sharing to enable the better use of targeted support by government. The purpose of these regulations is therefore one that we support. They amend the Digital Economy Act 2017 to enable data sharing for Ofgem’s purposes of a proposed debt-relief scheme.

The Government estimate that this scheme could clear between £500 million and £1 billion of outstanding energy debt. This is a significant intervention, with the potential to help many households directly. It should reduce the burden of uncoverable debt that is ultimately socialised across all customers’ bills. We welcome the role of Ofgem. The principle of the common framework is sound. We further recognise that part of this instrument corrects an earlier administrative error. The addition of DESNZ is a necessary one. Adding DSIT may also be reasonable if it allows the Government to co-ordinate support more effectively.

These regulations authorise an important extension of data sharing. However, they must be fair, proportionate and accountable, and I note the assurances that the Minister has given. The first phase will target people receiving means-tested benefits, subject to other eligibility and engagement criteria. That may be administratively convenient, but it is not a true test of vulnerability. There are obviously, as the Minister knows, people just above the benefit threshold who still struggle to pay their energy bill, and there are those who are entitled to support but do not claim. There are older people, disabled people, carers and people and people with fluctuating incomes, and there are households which are not digitally confident or which have not been able, for numerous reasons, to claim in the past. We must ensure that the people who most need help are not excluded because they are the least able to complete administrative processes.

I ask the Minister: what is meant by engagement criteria within the SI? Does it mean customers must actively respond to gain this relief? If that is the case, it is still a serious obstacle to people being able to claim these benefits. The scheme should provide accessible routes through telephone and post, advice agencies, trusted intermediaries or, better still, an automated identification process, which I think is where this is ultimately going. Perhaps the Minister could say just a word on that. Where households are plainly eligible, the presumption should be that relief is delivered automatically wherever possible.

The Minister talked about limited and specifically defined information, but could she just say what that means in practice? I think she has been clear on that, but could she confirm that it does not mean it will be shared with any further agencies and will not be sent to debt collectors, or for credit scoring or marketing? The information should be collected solely for the purposes here and overseen by the Information Commissioner. These safeguards are really important, particularly in light of the Government’s wider ambition to link household data to further aims for targeted support.

The Explanatory Memorandum says that the Government will conduct an expanded annual assessment, but these regulations do not contain a statutory review clause. Given the sensitivity of the information involved and the scale of the proposed debt relief, is that felt to be sufficient? Regular information on the number of eligible households, the value of the debt cancelled, complaints, corrections, exclusions and any data breaches should be publicly available. We should know whether people who change supplier are protected and continue to receive the benefits that they are entitled to through that process.

It would also be useful if the Government published the operational rules. These regulations create a legal gateway, but many of the questions that matter most to households will be answered in the Ofgem requirements and the administrative guidance. I also feel that these documents should be available to both Parliament and the public.

These regulations address a genuine problem, and I welcome them. I have personally called for greater data sharing so that we can target this support, but that alone is not the sole solution to the problem. I will ask just one question about timing. Obviously, the cap rises by 4% on 1 October, and we are coming into winter. Is it expected that once this SI is passed, this process will move swiftly? Can the Minister give me some indication whether that will happen at all this winter for energy bill payers?

To conclude, targeted debt relief is necessary, but alone it is not sufficient. We still need further and broader work across government to bring down energy bills, to take levies off those bills and to fundamentally reform the energy markets, but we welcome these regulations as a step in the right direction. They do need some careful and firm controls of the data. I think the Information Commissioner has been clear, and we generally welcome these regulations.

Earl of Effingham Portrait The Earl of Effingham (Con)
- Hansard - - - Excerpts

My Lords, these regulations relate to the Digital Economy Act 2017, which enables data sharing between public authorities and energy suppliers. The regulations will permit the sharing of information to support the delivery of a debt relief scheme by allowing specified persons to disclose information to energy suppliers for the reduction or cancellation of customers’ debt. The Government have committed to delivering targeted support for households most affected by rising energy costs.

The state must help those in need—that is absolutely right—but the reality is that this commitment will do nothing to address the root cause of rising energy costs, which continue to appreciate in part by trying to meet impossible net-zero targets. The most recent contracts for difference allocation rounds held by the Government saw maximum strike prices for offshore wind of £113 per megawatt hour. That is higher than those agreed in previous allocation rounds, higher than the average cost of electricity in the years before and the highest prices in a decade. His Majesty’s loyal Opposition have undertaken the work to tackle the root causes of high energy costs, proposing a cheap power plan to maximise extraction of our own oil and gas resources in the North Sea and to scrap the carbon tax on electricity generation from gas and the renewables obligation subsidy scheme, as well as removing VAT on domestic energy bills. These are constructive proposals endorsed by experts to help tackle the root causes of the cost of living crisis.

These regulations add the Department for Energy, Security and Net Zero and the Department for Science, Innovation and Technology to the list of specified persons that may share information. It may help your Lordships’ House if the Minister will clarify why these regulations make provision to share information with DSIT when the Government have, as far as we understand, abolished and dismantled that department. If these regulations help those in need, that is a good thing, but they are short-term and, as the noble Earl, Lord Russell, quite rightly said, alone they are not sufficient. The only sustainable long-term solution is the one proposed by His Majesty’s loyal Opposition that I briefly outlined.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

My Lords, I thank the noble Earls, Lord Russell and Lord Effingham, for their support for the importance of tackling poverty and I thank the noble Earl, Lord Russell, for recognising the centrality and importance of data sharing and the way in which that can improve efficiency and the way we can design administratively well-targeted schemes. The level of scrutiny that has been brought is very welcome.

The point of these regulations is to improve outcomes, enable government to identify the right households, target assistance more effectively and ensure that support reaches those who need it most. The debt that I mentioned has been building up over many years. It is very much an attribute of what people and households are experiencing, and that is the motivation for this.

Moved by
1: Clause 2, page 2, line 13, leave out “on the Secretary of State”
Member's explanatory statement
This amendment is consequential on my new Clause (Functions under this Part).
Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - -

My Lords, I will also speak to the other amendments in my name in this group. I thank noble Lords for their constructive engagement on this topic over the Summer Recess. I particularly thank the noble Viscount, Lord Camrose, and his colleagues for sending their questions in advance. I will seek to address those in my opening remarks.

This package of amendments introduces new powers that will enable the UK to address vendor-related cyber risks in our critical infrastructure. The principal new clause introduces a new direction power. It enables the Secretary of State to direct entities in scope of the power where they are using, or may potentially use, vendor-supplied goods, services or facilities in connection with their network and information systems that could create national security risks.

It is becoming increasingly clear that there are axes of cyber risks that the Government need to address. These risks arise from goods or services supplied by another company being harnessed as tools for sabotage, surveillance or espionage. But they also exist where goods or services constitute critical points of failure due to their defective design or vulnerabilities. Noble Lords would have had some sense of these risks from debates during this Bill—in particular, discussions about remote access in embedded products such as cellular modules and the scope for hostile interference and control.

GCHQ has also raised escalating concerns about supply-chain vulnerabilities in the wider geopolitical context. The director of GCHQ explicitly called out those risks in her annual lecture in May this year when discussing the challenges posed by a relationship with China and the threats posed by Russian cyber operations. That is why we have tabled Amendment 102 to tackle decisively these risks and protect our national security. Our intention is to limit the use of this power to operators of essential services in the first instance, although we will review the case for bringing other entities into scope in the future.

Supplementary amendments contain the mechanisms needed to operationalise the power. They enable the Secretary of State to set statutory timeframes for decision-making, to specify and update which entities are in scope of the vendor-related direction power and to introduce mandatory procurement screening should this ever be considered necessary to protect national security. They also introduce a power to bring more entities into scope of the existing direction power in Clause 43.

The powers to bring entities into scope of this framework are rightly restricted. To be brought into scope, the Secretary of State or Chancellor of the Duchy of Lancaster must be satisfied that the entity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is consistent with the Bill’s definition of essential activity in Clause 24. Either Minister can exercise the power. It has been drafted like this to accommodate machinery of government changes.

The decision to introduce the amendments has not been taken lightly. The Bill already includes important national security powers to direct regulated entities whose systems have been compromised, or which are at risk of being compromised, by hostile actors. This new power allows the Government to act before vendors become embedded in supply chains and before taking action becomes costly and disruptive. It will give operators greater confidence in their procurement planning and avoid the need for costly interventions down the line.

Crucially, we are not proposing to introduce these powers in isolation. They will be part of a broader framework which will also include procurement guidance for operators and a voluntary referral route into government where operators have identified potentially risky procurements. The voluntary self-referral route will enable the Government to assist operators with vendor-related concerns, provide them with guidance on how to proceed and, where necessary, inform decisions about the issuing of a direction.

We intend to consult on the implementation of the framework in due course. This will include the criteria for referral and how the mechanism will work in practice. In the event that this Government ever determined a mandatory referral scheme was necessary, we would intend to consult on the definition of a “qualifying transaction” before laying the necessary secondary legislation. However, I emphasise that it is not our current intention to set up a mandatory scheme.

Ultimately, we expect this wider framework will minimise the need for formal interventions using the new powers. However, it is crucial that the power is in place as a backstop to guarantee the Government’s ability to protect the UK’s national security. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I assume that there are no Back-Bench contributions at this point, so I will speak on behalf of the Liberal Democrats to this very significant group of amendments tabled by the Minister as recently as 24 August. I thank her for her introduction today and for her brief meeting shortly after their tabling.

At the outset, from these Benches we express our strong concern about the timing and the sheer scale of the Government’s package of new amendments. To drop 65 amendments of this nature on the eve of Committee, which will completely reshape the architecture of this Bill, after its passage through the Commons, is a major challenge to effective parliamentary scrutiny. The Minister’s letter, also dated 24 August, came alongside these 65 new amendments, so we have had very little time to consider them. As far as I can see, a full Ministerial Statement did not accompany them; we had to rely on the coverage of Computer Weekly to understand the Government’s motives.

The Government have quietly established a major parallel high-risk vendor regime. Under Amendments 102 and 103, the Secretary of State—and now, crucially, under Amendment 101, the Chancellor of the Duchy of Lancaster—are granted unilateral powers to issue vendor-related directions. They can legally order an organisation to prohibit, restrict, remove, disable or modify any software, hardware or digital facility supplied by a designated high-risk vendor. Furthermore, under Amendment 105 they are given the power to establish a mandatory referral scheme, legally forcing companies to submit technology procurement contracts to the Cabinet Office for security clearance before signing.

Let us look closely at the operational mechanism in Amendment 103, which ISC2 has rightly highlighted. The proposed new clause mandates that a company appoints a “skilled person” to oversee compliance and, under subsection (5) of the proposed new clause, permits the Secretary of State to rely on a list of persons published by GCHQ. I ask the Minister: what is this list? Is it public or classified? What objective criteria will govern inclusion? How will conflicts of interest be avoided, and how will independent professional competence be assured? To create statutory compliance roles backed by secret lists is entirely unacceptable.

Under Amendment 108, the Secretary of State can make regulations bringing any specific company into the scope of the Clause 43 directions without bringing them into the NIS regulations as a whole. Under Amendment 127, the Government will insert an emergency “made affirmative” procedure allowing regulations and vendor bans to take effect immediately without prior parliamentary debate. Furthermore, under Amendment 148 the Secretary of State can prohibit a company disclosing that they have received a direction or are in consultation, backed by civil penalties of up to £10 million or £50,000 per day.

There is also a second critical implication—the backdoor regulation of advanced artificial intelligence systems. At Second Reading, the Minister assured the House that advanced AI systems and LLMs were out of scope. These amendments appear to reverse that position. Under Amendment 108, any entity providing essential goods or services can be specified. As our critical infrastructure increasingly integrates agentic AI models, such as GPT-5 or Anthropic’s Mythos, these developers become points of supply chain risk concentration. It seems that, under Amendment 102, the Government can designate AI developers as high-risk vendors and mandate pre-procurement vetting. Is that the case and, if so, why not say so?

The Government will no doubt resist the transparent, legally bounded emergency shutdown power proposed by Amendment 84, with its High Court backstops and seven-day parliamentary reporting, yet here the Government demand sweeping, secretive executive powers to ban software, veto procurement and gag businesses with zero judicial checks. These Benches cannot give these 65 government amendments a free pass. I remind the Minister that, in Grand Committee, unanimity is required for amendments to carry. We insist that the Government come back on Report with strict guardrails and clear limits on executive market intervention without parliamentary consent before these new powers can be exercised.

Quite apart from that, both the Constitution Committee and the Delegated Powers and Regulatory Reform Committee had something to say about the existing powers in the Bill, but neither committee has had a chance to look at these amendments. I am sure that they will have comments to make in due course.

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.

That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.

However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.

Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.

I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.

I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.

Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank noble Lords for their comments, views and questions, and I will endeavour to respond to them.

In respect of why the power is being granted to the Secretary of State or the Chancellor of the Duchy of Lancaster, it is to anticipate any unforeseen machinery of government changes. It is nothing more than that—to avoid future changes that would be needed when government departments change. On the skilled persons list, I am advised that that is currently available on the NCSC website, so it is accessible to all.

I come back to the heart of the questions: why is this power needed? It is needed because, even though we are taking powers on critical suppliers, it can be the case that vendors have the capability and intent to cause harm, particularly where they have a link to a third country. That is the element I would highlight today. It is through such vendors that a third country can gain access to or control of critical systems, enabling disruption to UK national infrastructure, surveillance through access to data at scale or espionage through access to sensitive information. The risk landscape is evolving quickly, which is why we are taking action now. On the questions posed by the noble Viscount, Lord Camrose, this is very much in the context of all the other things we are doing—all the other powers in the Bill, the scope of the Bill and the Government’s cyber action plan. This is an additional power focused in particular on being able to act earlier in a preventive manner.

On the definition of “qualifying transactions”, the amendment contains a power to create a statutory referral system. This system would need to state which procurements or transactions were in its scope, but, as the noble Viscount mentioned, we do not anticipate needing to do that now. The process of the Bill is such that we will enact both the mechanisms in the Bill and the voluntary referral mechanism. We will then be able, in the period of assessing the effectiveness of the Bill, to look at the effectiveness of the voluntary referral route. Should we need to introduce a mandatory route—obviously, we have done this in different areas of national security—we will be able to do so.

On scrutiny by Parliament, I appreciate that the fact that we tabled these amendments over the summer has meant that not everybody has been able to familiarise themselves with them and we have not been able to have as many in-depth discussions as we would normally when Parliament is sitting. I would be extremely happy to meet noble Lords with officials so that, after Committee, we can go through all the questions and points of detail that have been raised in this session on how these powers will be enacted, parliamentary scrutiny, the consultation process and all the elements that we have set out in our amendments.

A few noble Lords focused on AI. The power could be extended to high-risk AI models that are procured by operators of essential services. The test for using the vendor power direction does not specify or distinguish particular types of goods or services, in keeping with the technology-agnostic approach of the Bill. If an operator of an essential service were using a vendor-supplied AI model in connection with its network and information services, and this would give rise to a national security risk, it could be in scope of the power. That is very much in keeping with what I believe I said at Second Reading about other areas of connection with network and information services in the rest of the Bill and where that may apply to AI.

With that, I beg leave to withdraw—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

Before the Minister sits down, I note that there are a lot of “just in case” elements of the Bill; to me, it feels that there are rather too many. For example, I refer the Minister back to the Chancellor of the Duchy of Lancaster v the Secretary of State. Any department is, at any time, subject to machinery of government changes, but never in any Bill that I have seen—admittedly, I have not seen that many—have both been specified, so why is it so in this Bill? Why do this now? Why not simply make a choice and amend later if necessary?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I am very happy to look at the points that noble Lords have raised in the course of this discussion. I believe that elements such as the consultation and the process of scrutiny are well thought out. I believe that in terms of the elements of subsequent parliamentary scrutiny—the reports that will be made both on the application or when the direction is affected—this is very much in keeping with other national security legislation which has been agreed by this and previous Governments. Many of these elements are very akin to processes that are operational in other areas of government. However, I am very happy to look at, and indeed will look at, all the points that noble Lords have raised. We will discuss them in subsequent meetings, and we will revert to them on Report.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

Can the Minister explain why GCHQ is not the right home to exercise these powers? I am sure we will all agree that national security is a significant issue, but it is being lodged in departments that have no prior experience of it. What is wrong with existing GCHQ procedures, which are respected and trusted?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I will need to write to the noble Lord on that specific question of how GCHQ’s powers are executed in respect of operational decisions such as this. I am aware that in other areas they are within Secretary of State responsibility, whether they are exercised by a Secretary of State, advised by GCHQ or whether, as the noble Lord suggests, they are actually undertaken by GCHQ.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I thank the Minister for her gracious, intended withdrawal of Amendment 1, and I am sure we will have a much better debate on Report as a result, particularly once we have had a chance to read her remarks on both interventions today. However, I hope she will agree with me, especially in terms of what she said about being technology agnostic through the Bill, that we will have a much better debate as we come to talk about specific AI issues as a result of not having already incorporated those in the Bill. So, all the way around we will have a much better debate about the proper shape of the Bill as a result of those amendments being withdrawn.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

With that, I believe now is the time where I beg to leave to withdraw Amendment 1.

Amendment 1 withdrawn.
--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank the noble Baroness, Lady Kidron, for her introduction and my noble friend Lady Harding for setting out the motivation for ensuring that we have the right balance of risk and regulation here. The amendments from the noble Baroness, Lady Kidron, seek to allow for the designation of systemically important data centres, RDSPs and RMSPs which do not already meet the threshold. The Government have considered this issue in the development of the regime and have taken an approach which reflects the markets of the various digital services in scope of the regime.

In respect of data centres, the Government agree that a data centre’s significance is not determined solely by size and recognise that smaller facilities may play an important role in supporting the economy and wider society. For that reason, the Bill already provides a route for such operators to be brought into scope outside the standard threshold requirements. The competent authority, Ofcom, has powers to gather information from operators and assess whether designation is appropriate in individual cases.

However, with respect to the RDSP and RMSP measures, the existing small and micro-enterprise exclusions have been designed to be proportionate and avoid imposing undue burden on entities with limited resources and market coverage, while focusing on providers whose disruption would have significant societal impact or economic risk to the UK. Although many small and micro-enterprises operate in the digital and managed services market, large MSPs hold a disproportionate share of market value. The largest MSPs account for 86% of revenue in the UK, despite representing just 4% of all MSPs. It is the disruption of these services that is most likely to cause significant harm to the UK.

The Bill also has measures in place to bring small or micro digital or managed service providers into the scope of the Bill if they are considered to provide a critical service to a regulated entity. If these entities meet the designation criteria, they can be designated as a critical supplier and be subject to mandatory cyber security and resilience requirements. I assure the noble Baroness that I recognise the discrepancy between these two regimes and her concerns, and I am content to explore this, and the points made by the noble Lord, Lord Markham, further, and to provide a more detailed response on Report.

On the issue raised by the noble Lord, Lord Clement-Jones, for his amendment which would amend the relevant managed services definition by excluding specific services, I take seriously the importance of providing clear definitions in the Bill. That is why the definition in the Bill is designed to capture services posing a risk to the UK economy and society, both today and beyond. I reassure the noble Lord that the relevant managed services that would be excluded by this amendment are already likely to be excluded by virtue of them not meeting the definition in the Bill. However, we cannot and should not list every service not in scope or we risk providing a definition that quickly becomes outdated and fails to accommodate new trends in both technology and services—a point frequently made by noble Lords in respect of the development of technology and online services. The Bill requires a delicate balance to ensure that the definition includes the right level of detail. The regulator, the Information Commission, will provide guidance on the application of the regulations prior to commencement of the RMSP provisions, including elements of the RMSP definitions.

On the point raised by the noble Lord, Lord Clement-Jones, on privileged access, MSPs pose risks because they provide ongoing management of customers’ IT services and often have deep and broad access to the networks, infrastructure and data those customers rely on, so the Bill focuses on any connection or access to network and information systems relied on by the customer rather than only access whether privileged or administrative. That is because requiring privileged access would narrow the definition and include some firms we intend to regulate as providers composed of cyber risks through non-privileged access without holding elevated administrative rights. For that reason, I caution against adding these exclusions to the definition of a managed service.

Finally, Amendments 4 and 5 are tabled in my name. They are targeted and technical amendments that improve the clarity and consistency of the Bill by strengthening the definition of load control in Clause 6. They clarify that the relevant activity must be carried out for system balancing purposes. System balancing purposes are defined as purposes which contribute to the,

“balancing, flexibility, security or stability of the electricity system”.

The policy intention has not changed. This amendment simply provides greater clarity about the activities the regime is intended to capture. It will reduce the risk of misinterpretation, provide greater certainty for industry and regulators and support effective regulatory oversight. This will ensure that the regime captures the activities intended to fall within scope and reduces the risk of inadvertently capturing activities that are not relevant to the operation and resilience of the electricity system.

Regarding the questions about the further scope of the Bill in respect of local government and the Government’s cyber action plan, I believe we will return to that in later groups.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

I am very grateful to the Minister for suggesting that there will be some consideration of the gap, as she put it, and I look forward to that. I want to raise one thing, which is that I was very struck by her reference to a small number of companies having 86% of the market. In a sector that is dominated by the concentration of power in very small numbers of companies owning many pieces of the stack, is she not worried that making those companies protected and safe and the smaller ones not may further serve to increase the concentration of power and market concentration? Is that not a problem for the future?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

The purpose of the Cyber Security and Resilience (Network and information Systems) Bill is to further enhance the scope and powers we have to protect essential services connected through network and information services. The market as it exists today is as I described. What is within the scope is not the totality of our approach to supporting the further cyber resilience of the UK economy. That is why, for example, we have CRCs locally to support SMEs so that whatever size they are, they can get assistance on the best cyber protection they can take. It is why we have Cyber Essentials and why the NCSC provides advice—all that the economy needs to take appropriate action to be secure. That is one aspect. The second aspect is that small and micro digital managed service providers are in scope of the Bill if they are considered to provide a critical service to a regulated entity, so even very small entities could possibly be in scope if they are so designated.

The last point I shall make—and I am sure we will come on to this further when we come to talk about AI—is that the Government are doing a huge amount in regulation and funding through public finance institutions to support the development of UK technology companies and UK innovators and to ensure that they have the right procurement contracts with the public sector so that they can grow and so that the entirety of our companies can benefit from the best global managed service providers and the best UK managed service providers.

Amendment 3 withdrawn.
--- Later in debate ---
Moved by
4: Clause 6, page 4, line 31, after “controller” insert “—
(a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and”Member’s explanatory statement
This amendment would ensure that the threshold requirement relating to the essential service of load control, inserted by Clause 6 of the Bill, applies only to organisations which carry out activities for system-balancing purposes.
--- Later in debate ---
I finish by returning to the broader point. The reason for this group—the debate around AI in the context of cyber security—is that I am afraid we are still unclear about the Government’s wider approach to cyber security and AI. We need to see the bigger picture in the form of a national action plan or White Paper that explains to us overall how the Government see the evolving world enabled by these extremely powerful technologies. We can go sector by sector and debate the best way to regulate and protect them against cyber attacks, but what matters is the Government’s applied philosophy. Until we see that, we are debating ideas in the dark.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank noble Lords for their amendments, and I recognise the concerns that have been expressed. Technology is evolving at a rapid pace, and it is important that we harness the benefits and, equally, protect against the risks it may pose.

The noble Lord, Lord Holmes of Richmond, asked about the approach that we take. We understand how quickly technology is evolving, and it is important that we have a flexible and future-proof approach. If we limit ourselves to specific technologies, we will not capture new developments. For instance, when the NIS regulations were introduced in 2018, we could not have predicted the role that AI and quantum would play in cyber. That is why the Bill takes an “all hazards, all threats, all technologies” approach. This requires regulated entities to manage all the risks relevant to their network and information systems. For example, if AI forms a part of the system that the essential service relies on—for example, in the provision of drinking water—that entity must assess and mitigate the risks it poses.

More generally, the Government take the concerns very seriously. The UK is taking a leading role with our approach to AI security. I will set out my response to each amendment in turn, but while we do not consider the amendments proposed to be the right approach, I reassure noble Lords that the Government are exploring whether additional targeted interventions may be needed in future to address the most significant AI-related national security risks. As the Government’s thinking is at an early stage, I would be open to future engagement with noble Lords on potential options. Any future approach would need to have carefully designed measures, with the evidence base proportionate to and targeted at the risks in question, while minimising unintended impacts on growth, innovation and the operation of critical services.

I turn to the amendments. The intention of the NIS regime is to require organisations to protect themselves from risks that could compromise their network and information systems, which could include a cyber attack, a natural disaster or even human error. That protection would be appropriate and proportionate to the risks faced by those organisations, including state-of-the-art technology such as AI. I reassure noble Lords that this would include relevant risks from AI embedded within the systems of regulated organisations. To take one example, healthcare providers in scope of the regime would be required to manage risks associated with the AI products they use to provide their services. This is because essential services in scope must look at, and work to mitigate, risks posed to their network and information systems.

As AI is increasingly becoming embedded across the economy, we will keep its impact on the regulatory landscape under review. The Bill is focused on the cyber security and resilience of network and information systems; broader questions about the regulation of AI systems are more appropriately addressed through separate discussions, for example on online safety.

Bringing providers of AI services—those companies at the cutting edge of frontier AI development—and their products into the scope of the NIS regime, which Amendment 6 seeks to do, would not address the harms that can be posed by some AI products and services. Specifically, it would not prevent their misuse by hostile actors. Instead, the Government are already taking firm action in more appropriate ways, which also speaks to the concerns that Amendment 75 would aim to address and which the noble Baroness, Lady Foster, asked about.

First, the UK AI Security Institute, as noble Lords are well aware, is world leading in its research on advanced AI capabilities. AISI was set up to build a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose. It works with developers to strengthen security before models are released and ground policy decisions in evidence rather than speculation, especially as they relate to national security matters.

Secondly, the UK Government are taking a leading role in addressing these risks in both the domestic and international setting. As the noble Lord, Lord Tarassenko, and others have set out, including the noble Viscount, Lord Camrose, it is critical that this approach has global impact. Our AI cyber security code of practice has formed the basis of the world’s first global standard, EN 304 223, which sets baseline security requirements for developers and deployers across the AI life cycle. This demonstrates our global leadership and commitment to shaping international technical standards, which go wider than some of the issues raised in this Bill.

Underpinning all this is a simple but powerful message, which was set out in a joint Five Eyes statement in June. It recommended that as AI capabilities evolve all industry, including vendors, should seek to step up their cyber defences. This is a clear call to action for all organisations, including the Government, and a reminder that the key tenets of cyber hygiene still stand strong. That is also why we are committed to building a national-scale AI-enabled cyber defence for the UK, Cyber Shield. It will scan UK systems continuously to discover vulnerabilities and apply national-level mitigations.

The noble Baroness, Lady Kidron, tabled Amendment 75, which sets out several red lines on AI capabilities that would enable an AI system to facilitate significant risks to the UK. The noble Baroness will recognise that AI is one of many technologies that can be used for beneficial and harmful purposes, as she has mentioned on previous occasions. In addition to the example of chemistry questions, banking services can be used to connect families but might also be used to finance illegal terrorist activities. Equally, while powerful AI capabilities can be used by malicious actors to cause harm to the UK, they might also be used by the national security community to defend the UK and by UK organisations and companies to protect themselves from harm. It is therefore not in the UK’s national interest to restrict UK organisations and the public sector accessing powerful AI capabilities, especially given the global nature of AI risks. It is also unlikely that AISI would be able to give conclusive assurances regarding AI models in the way envisaged in this amendment. Testing shows what a model can do, but not conclusively what it cannot, as the noble Viscount, Lord Camrose, pointed out.

The noble Lord, Lord Tarassenko, tabled Amendment 12, which would require RDSPs to follow guidance issued by the AI Security Institute. For the reasons I set out on Amendment 6 and because it is not AISI’s role to provide guidance of this nature, I do not think it would be appropriate. I will set out more detail on AISI’s role later in my response.

On Amendment 84, tabled by the noble Lord, Lord Clement-Jones, we have chosen to go further than our EU counterparts and the NIS2 regime to respond to these risks by bringing forward powers in the Bill to direct regulated entities if there is a national security risk in relation to their network and information system. This may be used, for instance, to require a regulated entity to cease using and isolate an AI model.

We believe this is a more proportionate and effective response, as data centres operate in highly complex ecosystems and AI systems are often distributed across different data centres and jurisdictions. It is much less desirable to direct multiple data centres to shut down, with the impact this could have on services that rely on them, than to direct them to cease using an AI model. This is important, as our economic security will grow as UK companies grow as they increase AI adoption as we develop our domestic capabilities and attract global talent, underpinned by our data centre and digital infrastructure.

I refer to my introductory remarks on exploring further targeted interventions. This includes examining whether proportionate containment powers could provide a more effective and targeted response, including powers to restrict access to specific AI systems where necessary to prevent or mitigate serious harm. The amendment tabled by the noble Lord, Lord Clement-Jones, also seeks a regular report on AI security. In December 2025, the AI Security Institute published Frontier Al Trends Report, which sets out high-level trends on AI progress based on two years of government-led testing of leading models.

Amendments 85, 86, 92 and 98, tabled by the noble Lords, Lord Tarassenko and Lord Clement-Jones, are a testament to AISI’s leading role and expertise. They seek to provide AISI with powers to address potential risks arising from frontier AI models. I have already set out the important role that AISI plays building a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose, working with developers to strengthen security before models are released and grounding policy decisions in evidence rather than speculation. These amendments would give AISI a role that it was not designed to fulfil. AISI’s focus on frontier technology and trusted relationships with the world’s leading AI labs allow it to keep pace with the fast-moving technology, thereby providing critical awareness of the most novel and serious AI risks. This amendment would undermine the voluntary collaboration on which AISI operates. A regulatory role for AISI is therefore the wrong answer, but the Government remain committed to ensuring that AISI is equipped to fulfil its vital role and will continue to keep the House updated on its work as appropriate.

As I have just set out, such amendments raise a real risk of placing barriers on AI adoption and deployment in the UK. Due to the scope of the Bill, the amendments cannot address wider AI harms or cyber security in the wider economy. I share concerns about the potential of hostile actors using frontier AI models against our essential services. Placing these restrictions on their deployment in the UK, as amended, would not be effective.

I shall respond to the direct question asked by the noble Baroness, Lady Kidron, on large language models. Large language models are not typically considered online search engines in respect of the CSRB. While some LLMs can be seen to share similar characteristics and may utilise online search engines, their functions tend to be much broader.

I hope that I have addressed the points raised—well, I hope that I have at least touched on all the points raised today. On the points made on changes to the Government, I very well recall the numerous discussions that we have had on AI over the past few months and continue to be the point of continuity on them. As I have said, the Government will be happy to engage with noble Lords as options are being considered. We always stand ready to protect our national and economic security.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

If I have understood what the Minister said, the NHS must protect itself, but the AI that is attacking it has no duties or obligations under the Bill to check itself before it is used in those ways. That is what I think is the Government’s position, and I would be grateful, when she responds, if she could answer that.

I also want to say two other things. One is that I think these issues will come back on Report, so I would be grateful for some proper discussion before then, so that we can see whether we come to a certain place. I do not have it at my fingertips—I may be helped by one of my colleagues—the amount of search that now happens through AI, but it is almost ludicrous to suggest that LLMs are not search. It is deliberate that I got that answer.

--- Later in debate ---
Finally, on the AISI point—we will probably come back to it a little bit in the next group—a few months ago AISI dropped the societal harms piece of its remit. That was largely due to pressures within government. As much as I recognise that it was set up to do one thing, it is very much at the behest of whoever is immediately pulling the strings. I think that there was a very deep understanding among those who were concerned about this issue that the frontier companies were much more comfortable talking about future security risks, which are a little way ahead and about which we can say we do not know what is going to happen, than the societal risks, which are happening right now. So I think that on both of these things we will be back, but I am grateful for the offer of a discussion.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

To respond to the question about how the Bill approaches certain AI products and services, as I mentioned in respect of Amendment 6, were AI services to be brought into the ambit of the Bill as proposed in Amendment 6, that would not address some of the harms that the noble Baroness, Lady Kidron, and other noble Lords, have set out. The way the Bill works is that it is about risks that are relevant to the systems of the affected organisations. As in the healthcare example I gave, it is about risks associated with products that might be used to provide those services. That is the way the Bill is set up. Obviously, as I also said, we are very well aware about the increasingly embedded nature of AI in the economy, and we will keep its impact on the regulatory landscape under review.

Amendment 6 withdrawn.
--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Birt, for introducing this debate and all noble Lords who have spoken. I appreciate the rigorous strategic thinking that the noble Lords, Lord Birt and Lord Londesborough, have put into the proposal for an office for cyber resilience, but I will try to keep my remarks to the principle of a single regulator.

As others have set out very powerfully, I see the appeal of having a single regulator: it is easy to issue directives, to store data and information centrally, to take a systemic approach overall and to better manage the hiring of scarce, skilled resources. That said, as my noble friend Lady Neville-Jones pointed out, it is important to see the value of sectoral regulators supported by a centre-of-excellence model. More sector-specific expertise, more direct communication with the industry and more flexible approaches are all easier to achieve with smaller, more specific regulators. At a sufficient level of abstraction, it almost does not matter which of those models you go for; it is about having resourced, skilled and empowered people performing monitoring and enforcement activities, regardless of the body under which they sit.

More broadly, the point is that, while differences between a more centralised or more sectoral approach are worthy of debate—I do not think we would ever hit the extremes of either of those—what actually matters is ensuring that, whichever route the Government choose to take us, they make certain that the regulators are adequately resourced and that they exist within a wider strategy.

I am not sure, and look forward to finding out, whether the first of those is the case. The Government have chosen the more sectoral approach, but we do not yet know how the regulators are going to be resourced and what additional resourcing needs will be needed to cope with the increased responsibilities that will be laid at their door. I look forward to hearing from the Minister on how the regulators are going to be funded, how the funding needs will be calculated and how they are going to be supported in this significant expansion of their role.

The second point is that the regulators should exist as a part of a wider strategy, which is not currently the case. I apologise to noble Lords for banging on about this, but it is very difficult to get the past the hole in the Bill in the shape of a wider national cyber strategy. Whether the regulators are many or one matters little without the bigger picture into which they fit. In an ideal world, we would review the overall cyber strategy and then debate what regulatory structures might be appropriate to deliver it but, for now, sadly, that is not the world that we are in.

The Secretary of State—or, indeed, the Chancellor of the Duchy of Lancaster; it is not reassuring that we still do not know which one—must commit to publishing the national plan, after which we can assess the efficacy of its many parts.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank the noble Lords, Lord Birt and Lord Clement-Jones, for their introduction to this section and for setting out the motivation behind a single cyber regulator.

As others have pointed out, this is a question of sectoral expertise and cyber expertise. It is my view that, given the complex cyber landscape, establishing a single regulator would not be as effective as the approach that we are pursuing. Different sectors have different risks, technologies, operational environments, market structures and resilience challenges within their industries. To take an example, the energy sector has a greater reliance on operational technology—such as turbines, substations and gas pipes—as compared to the digital services sector, which is predominantly information technology-based. Noble Lords will see that the guidance on quantum, for example, differs in that respect. This is why expert regulators are needed to ensure compliance in a manner that reflects the realities of their sectors.

I do not recognise the assertion that there is a single internationally recognised model of best practice. There are very near neighbours who have the model that we are pursuing, which keeps the sectoral expertise. Additionally, I do not believe that it would be an effective use of resources to establish a new regulator, and the proposed 12-month establishment period would delay the implementation of this regime.

Finally, cyber would continue to exist within a multi-regulator landscape as there are separate regulatory approaches for telecommunications and financial services. I agree with the point made by many noble Lords—highlighted in particular by the noble Lord, Lord Holmes, both at Second Reading and now—that a consistent approach to implementing and enforcing the regime is crucial. The Bill will drive this through by establishing common security and resilience requirements and secondary legislation for all regulated entities, clear guidance for regulators, and a statement of strategic priorities setting common objectives that regulators must seek to achieve. These will cover issues such as governance, skills, risk management, business continuity, supply chains, incident response, and appropriate testing and exercising. They will be consulted on, and any relevant secondary legislation will be subject to the affirmative procedure.

Regulators will supervise and enforce the common requirements while providing guidance that is tailored to the risks and operational realities of their sectors. Crucially, information-sharing gateways and cost-recovery mechanisms will bolster the well-resourced, experienced regulators who stand ready to collaborate while best supporting their respective sectors. I believe that the Bill’s approach gets the right balance between sectoral expertise and a common approach.

On Amendment 91, which would require specific organisations to conduct an annual independent audit, I agree that independent assessments play an important role in providing assurance and leveraging external expertise; that is why the current framework already enables regulators to require independent audits or inspections. However, it is for the sectoral regulators to set the frequency and nature of audits, bearing in mind proportionality and their expertise in the risks and operational realities of their sectors. We will continue to drive uptake of assured independent audits across sectors, using the range of levers that the Bill provides. That is what the current framework provides for and what the implementation of the Bill will ensure.

I turn to Amendment 90, which would require the proposed OCR to work with the UK Cyber Security Council in order to ensure sufficiently qualified cyber security professionals among regulated entities; I note that the amendment laid by the noble Baroness, Lady Northover, on this topic will be debated later. The Government strongly support the need for the professionalisation of the cyber sector. We already work with the UK Cyber Security Council and regulators to encourage cyber professionalisation across NIS sectors. We also intend to set further expectations for regulators to encourage cyber professionalism through the Bill’s security and resilience requirements, which, as I just mentioned, will be set out in secondary legislation. They will address relevant training, skills and professional standards, and the Bill’s regulators must publish guidance on these requirements.

--- Later in debate ---
Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

In this recovery regime, will whatever organisations that are to be regulated be levied for the service of regulation that will be provided, or will the revenue come as a result of fines? If that is the case, I hope they will not raise the revenue by finding fault. What is the basis of the cost recovery? It needs to be perceived to be fair, not onerous and not directed at encouraging regulators to regulate for the sake of increasing their income.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

The intent behind the cost recovery model is to provide a fair approach so that regulators, when regulating on cyber, can recover the costs associated with that. Further guidance will be put out on this. I cannot recall the Bill’s exact provisions on fines. I will come back to the noble Baroness on that.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

My Lords, I confess to a real disappointment listening to the Minister’s response. We have sat here all afternoon and heard many strong contributions on many matters, but so far, the Government do not appear to have moved an inch on any of them.

I have a few quick points. The Minister just referred to the regulators. There are 12 regulators of 12 sectors, which is a tiny fraction of the economy. We have had this very profound discussion about AI today. Is she really asking us to believe that Ofwat is capable of mastering the complexity and continuing challenge that AI poses? To me, the answer is all too obvious.

Secondly, I say to the noble Baroness, Lady Neville-Jones, in particular, that I have sat on many boards over recent decades at different levels in the UK, in Europe and globally. An awful lot of expertise comes to the table, but it is absolutely out of the question that every board in the land will have a real cyber expert on it—hence the notion. A financial audit is a really powerful thing these days. It gets into the bowels of a company, and if anything is going wrong anywhere then it will find out about it. That is why I propose that we have a cyber resilience audit—not for every company in the land but for those that fall under the heading of essential services.

Finally, we are at war, and I completely agree with the noble Lord, Lord Londesborough, that the scale of the damage to our economy is almost certainly vastly underestimated. The framework imposed in this Bill is for fighting a war, but we see around the world at the moment that—guess what—wars change. Different weapons are used and different tactics come up. It is as if we have split the MoD and said that the Army will be with DCMS, the Navy will be with another department and the Air Force with another. The idea that you cannot have effective co-ordination within government and outside government honestly does not carry any weight. I beg leave to withdraw my amendment.

--- Later in debate ---
Lastly, I am grateful to the noble Lord, Lord Clement-Jones, for his amendments, in particular, Amendment 95, which would reduce the maximum interval between legislation and operational reports from five years to three years. That is welcome. The world of cyber security is ever changing and it will do so with increased speed as our AI continues to develop. A five-year maximum timeframe is simply too long for any Government to reflect on the effectiveness of existing legislation. I hope that the Minister will take that point, along with the others I have made.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank noble Lords for their amendments in this group, which I will endeavour to cover in my response, starting with the lead amendment from the noble Baroness, Lady Ludford. Fraud risks and fraud are indeed important to address. The Bill requires relevant digital service providers to prevent or mitigate risks through an all-hazards approach. We already expect RDSPs to address risks posed by fraud as part of their security duties. The reason why we do not single out risk posed by fraud is that this may not reflect the full range of risks faced. It is important that regulators in their guidance, for example, in respect of the ICO, respond to the risks that their sectors are experiencing, which could include fraud. I heard clearly the facts that the noble Baroness set out, but that will be something that will come in due course.

On the important points made by the noble Lord, Lord Ravensdale, on the risks posed by quantum computing, the “all hazards, all threats, all technologies” approach enables a flexible and future-proof regime. It is important that each version of the statement of strategic priorities is not bound by the risks posed by specific technologies because they could become outdated; it cannot necessarily prefigure what will be a particular risk in 10 years’ time. Post-quantum cryptography is incredibly important. The department is working on guidance documents that will support organisations to manage their transition, in line with the NCSC guidance and deadlines. On the question specifically about the next statement of strategic priorities, we will encourage regulators through the statement to understand the evolving threat landscape and adapt their regulatory response accordingly, which could include risks from quantum or fraud, if those are the most pressing ones at that time.

On the approach suggested in Amendment 94 by the noble Lord, Lord Clement-Jones, we appreciate good practice standards, and we continue to promote their adoption across the wider economy. However, a more advanced cyber security framework is required to ensure adequate protection and assurance for the services in scope of the Bill. I am confident that the Bill’s outcomes-based approach is the right one. It allows existing good practice to contribute to demonstrations of compliance with existing and future requirements. We will introduce security and resilience requirements in secondary legislation. These requirements will be linked to the security duties and will provide clearer outcomes that organisations in scope must meet. We are engaging with regulators and industry throughout this development, and we intend to consult on these proposals later this year.

I turn to the question of how regulated entities demonstrate their compliance with their duties. Amendment 92B seeks to require large businesses in scope to report on their cyber security and resilience plans. Our proposed security and resilience requirements under the Bill will require regulated entities to maintain overarching security policies, implement a continuous risk management framework, maintain incident response and recovery plans, and ensure appropriate board-level oversight of these. This will be supported by guidance from regulators which must be regarded. Entities would be expected to maintain evidence demonstrating compliance with these requirements. The information provided to regulators and the NCSC will enable effective regulatory supervision, which holds organisations to account, and will enhance wider threat and resilience analysis and support. This will feed into government monitoring and evaluation, where public post-implementation reports will provide insights and assess the effectiveness of the regime. I will come on to the timing of those later.

The UK’s corporate reporting framework is currently undergoing wider modernisation efforts. Future consultation will seek views on whether the existing risk reporting framework produces sufficient reporting on cyber risk management, so it is best dealt with as part of that work.

On funding and information sharing in Amendment 169, ISACs can play an important role; there are many initiatives under way, many of which are supported by the NCSC. They have a voluntary approach which builds trust and brings about positive cultural changes. We believe that there is a real risk that the Government could undermine these benefits and complicate the regulatory landscape by intervening and recasting these initiatives as mechanisms of regulatory oversight and enforcement. However, I agree that more can be done to understand their impact, and how the Government can support them. That is why the Bill’s formal review mechanism was included, which will consider the entirety of the regime’s impact, including for information sharing.

Coming back to the question of regulator funding, and to expand a little on the new cost recovery powers to ensure that regulators are able to recover the full costs relating to their NIS duties, this will enable regulators to be autonomously funded and sufficiently resourced to carry out their responsibilities. We will also enable regulators to better focus their resources through establishing a unified set of objectives through the statement of strategic priorities. The current framework therefore already ensures sufficiently and independently funded regulators, without a delayed commencement of the regime. To respond to the question posed earlier by the noble Baroness, Lady Neville-Jones, it is anticipated that fines levied under the regime would go to the Treasury.

On the absolute criticality of skills in the sector and Amendments 15, 174C and 174D from the noble Lord, Lord Arbuthnot, and to all those who spoke on skills and cyber capability, the Government absolutely agree that workforce is crucial for effective implementation of the regime. I have previously set out how we intend to introduce security and resilience requirements, which will be consistent with the CAF. We propose that the SRRs will address organisational capability and personnel skills and training, driven from board level. These requirements will be developed in collaboration with industry, experts and regulators and formally consulted on before they are mandated. The SRRs will be supported by regulator guidance, tailored by sector, as well as government implementation guidance for regulators. We do not believe that additional guidance and a separate strategy would be proportionate, and it could be duplicative given the existing guidance published under the Bill.

Cyber skills obviously go much broader than the Bill. That is why we are working closely with the UK Cyber Security Council and regulators to encourage cyber training and professional standards. Additionally, we have TechFirst, the Government’s flagship tech skills programme, which goes to the point made by the noble Baroness, Lady Ludford, everywhere from school children through to professionals and the university sector.

Briefly, we talked earlier about skilled persons and Amendment 114. I mentioned earlier that a skilled person is a person with expertise. However, we do not think that we should tie the Government’s hands to specific skills requirements, which would reduce the Secretary of State’s flexibility in this space and could impede the regulated entity’s ability to take the necessary action required by the direction.

On the question of reporting, we recognise the pace of cyber developments alongside the importance of regular assessments of the regime. We must be as effective as possible and agile in the face of new developments. Amendments 95 and 95A, tabled by the noble Lords, Lord Arbuthnot and Lord Clement-Jones, would reduce the period that the report on the operation of the legislation should be published to every three or even two years. As raised in the other place, the five-year period set out in the Bill is a minimum baseline and the Government will consider more frequent reports if deemed necessary. This framing follows the precedent set by the Telecommunications (Security) Act and the existing NIS regulations. This will provide the Government with the time they need to meaningfully review the cross-sectoral regime, analyse the information received from regulators and understand how it has evolved, and identify what improvements can be made.

However, I stress that the Bill will also require the Secretary of State to provide Parliament with an annual report setting out how regulators have sought to achieve their objectives set out in the statement of strategic priorities. This annual report will enable more frequent monitoring of the regime and how it is working in practice by reporting on the regulators who implement it. The first report will be published one year after the publication of the SSP, which is targeting 2027. As a result, we anticipate that the first report would be published under two years after Royal Assent.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

The content of the statement of strategic priorities will be subject to consultation and we will be working with regulators on that. It could include specific risks, whether from quantum or from fraud. What I do not want to do right now is to commit that it will include that, because we are going through a process.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - - - Excerpts

My Lords, I thank the Minister for her reply. Her last words gave me a little bit more hope than the rest of her response, to be honest, when she said that the statement of strategic priorities could include specific risks, because it seemed to me that she was otherwise being a bit generic and unspecific—almost above the fray. When I came in on a previous group—and other noble Lords are much more knowledgeable and expert in this field than I am—I picked up some frustration that the feedback from the Government and from the Minister today was a bit vague and not very responsive. All this is happening out there; there are huge cyber threats and there is a feeling that the Government are not really getting to grips with the actualité quite as much as they might.

I understand that the Minister might not be able to say now what will be in the statement of strategic priorities, but what we are searching for is that it will grapple with real problems out there in the economy, in society. I must admit that Amendment 82 from the noble Lord, Lord Ravensdale, on post-quantum cryptography, is somewhat above my pay grade. I wish I was more knowledgeable, but I ain’t. But I understand what he is saying, how real this is: the threat is out there. You just have to read newspapers to get the drift of what is happening. I mentioned that fraud is nearly half of all crime, so these are big issues. I think that what we want from the Government is a feeling that they get it, that there is going to be specificity in the way that they are going to implement this Bill and that they are really going to be on the case of these big threats. The Minister’s last words were a bit more encouraging than some of the rest of what she has been saying. That said, I am sure we will come back to some of these issues on Report, but I beg leave to withdraw my amendment.

--- Later in debate ---
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend for introducing this group; as it is the final group of the day, I will keep my remarks brief.

Amendments 15A and 15B in the names of my noble friend Lord Arbuthnot and the noble Lord, Lord Clement-Jones, seek to allow regulatory oversight of critical suppliers on whom operators of essential services and relevant service providers depend, be it directly or indirectly. We believe that this must be a reasonable approach. The aim of Clause 12 is to ensure the continued functioning of the central suppliers and providers by providing support for their critical suppliers. Surely whether they are supplied directly or indirectly is of little importance.

Amendment 16 from the noble Lord, Lord Ravensdale, would restrict the designation of critical suppliers to those who present systemic risk rather than a simple single-entity risk. We should seek to minimise government oversight wherever possible, and suppliers should not be designated unless they pose a genuine risk. I am also supportive of the noble Lord’s focus on cross-sectoral consistency and general macroeconomic risks, which is too often something that the Government neglect.

However, I am hesitant to endorse the amendment in its entirety. Having to assess every supplier of every OES, RDSP or RMSP and having to decide whether it meets the systemic threshold have the potential to place an unrealistic administrative burden on designated competent authorities. We are already concerned about the resources that they will need to undertake the changes that the Bill introduces; I am unsure whether we need to ask more of them.

To wrap up, I return to a more general point: the risk to the economy or to national security is a scale, and the legislation that we pass should reflect this. Perhaps the noble Lord, Lord Ravensdale, is correct that the designation of critical suppliers based solely on whom they serve is too permissive, but it is equally as likely that restricting designation to systemic risks would be too restrictive. This highlights—it goes back to earlier groups—that the binary distinction about which we are talking now does not cover the gradation of different types of risk. That is why I come back to the original point that my noble friend Lord Camrose made on adopting, perhaps, the Cyber Monitoring Centre’s severity scale, which offers a template for a more nuanced approach to definitions. I hope that the Minister can commit to reviewing the Bill’s definitions ahead of Report.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

I thank noble Lords, in particular the noble Lords, Lord Arbuthnot and Lord Ravensdale, for engaging with the incredibly important question of drawing the right scope in the Bill for the designation of those in the supply chain. It is incredibly important that we get this right and take into account the economic and security impact. To begin, let me explain our reading of the amendments and the practical impact they would have.

Amendments 15A and 15B would enable regulators to designate suppliers as critical beyond those which directly supply to regulated entities, if they are materially dependent on that supplier to provide the regulated service. This would extend the scope of the measure to include suppliers further down the chain, even where they have no direct relationship with the regulated entity. In addition, the amendments would introduce an additional assessment of whether a regulated entity is materially dependent on a supplier, which would form part of the designation process. This could create a higher bar for designation of a direct supplier than currently exists in the Bill and could limit designation by excluding suppliers whom it would be reasonable and prudent to include.

The Bill recognises the importance of supply chain security, has considered the risks that supply chains pose and has developed targeted and proportionate measures to address those risks. First, regulated entities are subject to an overarching duty to identify and manage the risks posed to the systems they rely on to provide their services. A core part of this is to consider the risks arising from their supply chains. Secondly, as will be set out in the forthcoming security and resilience requirements, we will require regulated entities to take specific steps to manage their supply chains through an analysis of the risks they could pose, and to include a requirement to put in place contractual obligations on those suppliers to manage the immediate risks and the risks posed further down the supply chain, which may not be in the immediate view of the primary regulated entity. Thirdly, it is recognised that some suppliers in the market are critical to certain sectors and therefore the most proportionate step is to regulate them in their own right and to subject their security posture to the scrutiny of regulators.

This clause is already designed to be a proportionate and targeted measure and is aimed at bringing into scope only those suppliers who are genuinely critical to the regulated entities they supply directly. Finally, as we discussed at the beginning of this Committee, some suppliers may present additional risk and are potentially the vector of attack from hostile actors. That is why we believe that we need to take measured but decisive steps to manage that risk before it crystallises and before those vendors are embedded in critical systems. The amendments would significantly increase the number of potential suppliers that regulators may need to consider for designation and could risk imposing additional burdens on smaller suppliers that may be several layers removed from the regulated service.

On Amendment 16 in the name of the noble Lord, Lord Ravensdale, I agree that a supplier should be designated only where they are genuinely critical to the provision of a regulated service. That is why the Bill includes strict designation criteria that must be met before a supplier can be designated. Importantly, an incident affecting the systems relied on by the supplier could disrupt regulated services in a way that significantly impacts the economy or the functioning of society. The Bill maximises the proportionality of the measure so that only the most critical suppliers to regulated entities are designated. It will also limit the number of small and micro enterprises that are likely to be designated.

The noble Lord’s amendment intends to limit that further. Its intention is to focus on suppliers whose activities being disrupted would cause systemic risk to the UK’s digital ecosystem, economy or essential services, and to prohibit designation if a supplier provides goods or services only to a single operator of essential services, a critical national infrastructure entity or a public authority.

We discussed a little earlier in Committee the risk of small but risky suppliers. Amending the designation criteria to focus on systemic risk to a wider number of entities could potentially leave many of the UK’s most essential services vulnerable to disruption. In fact, the compromise of just one of these providers could still have a significant impact on the economy or functioning of society in the UK or any part of it. Under the noble Lord’s amendments, a supplier that is essential to a single energy provider responsible for a county’s power, an NHS hospital looking after a whole city or a single cloud service provider used nationwide may not be judged as posing a systemic risk if it were disrupted. This would leave these essential end services vulnerable to severe disruption if that supply were compromised, with significant impacts for the huge number of citizens relying on them.

The amendment would also require the Government to issue statutory guidance for regulators on designating critical suppliers. I agree that consistency in the decisions taken by regulators will be crucial to the success of this regime. That is why my department will work with regulators to develop guidance to drive this consistency, and regulators will be required to consult with other regulators before designating suppliers where there is a relevant connection to multiple sectors. As we have discussed before, the statement of strategic priorities will also provide common objectives for regulators, which will further increase alignment between their approaches.

I heard very clearly what noble Lords said in introducing their amendments and the important other contributions during this discussion, which highlight how important it is to strike the right balance for this measure. I believe that the Bill establishes a proportionate and targeted framework that captures genuinely critical suppliers without extending regulation or excluding risks within the supply chain.

Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - - - Excerpts

My Lords, I listened carefully to what the Minister said. She made some very reasonable points and she may even be right, but I will need to take it away and think about it. In the meantime, I beg leave to withdraw my amendment.