Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Baroness Lloyd of Effra and Baroness Neville-Jones
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

The general approach is that the lead government department has responsibility for ensuring cyber security in the areas that it covers. I will need to write to my noble friend specifically on exam boards and examining authorities. I know that the DfE supports bodies that support higher education and further education, but for further details, I will come back to her.

More broadly, I am happy to talk further with noble Lords between now and Report, and perhaps after, on the approach to assessing what should be within the regulatory perimeter and at what speed that can be advanced.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

Can I ask a couple of questions and make one comment? The more we hear about the conversation that is taking place on the Bill, the more anomalous the factors that have been chosen or included in the scheme become. Let me give the example of space. Plenty of us now receive our internet connection via satellite. It is inevitably an intimate part of the networking system of cyber security. What we appear to be told is that some parts of the telecoms and internet world are going to be governed by the Bill, but other parts, which are equally integrated and important, are going to be covered separately by a special different arrangement—they are not included. For example, as I understand what the Minister said about space, it is not going to be included in this Bill. With the greatest possible respect to the Minister, it does not make sense.

My question is: in the period ahead of us, could the Government have another look at the whole question of the scope of the Bill? This seems to be one of the problems that lies between us. As a result, Members are now trying to shove into the Bill all sorts of things on the grounds that they are essential services—some of which clearly need to be there, but for others it is arguable that they do not.

I heard what the Minister said about the action plan. I have read the action plan, and it is a good plan, but it lays a heavy responsibility on a department that no longer exists—DSIT. The function is set out so well and is important to keeping government departments up to the mark, which is going to be done separately. Where is that responsibility now going to sit? It will require a very considerable degree of expertise on the part of those conducting this system of keeping people up to the mark. How is that going to be done?

It seems to me that local government requires something of the same. Government is a whole thing. It is not that some things can be done in central government without regard to their implementation by local government or vice versa. Are the Government going to extend the system that is being mapped out in the action plan for government to local government as well, in order to get the same standard of performance and integrity of systems?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

Let me work backwards here. The noble Baroness makes a very good point: the services delivered at local level often mirror those at central government level. At the moment, we are consulting on the question of the best value duty to give additional prominence. One of the issues with mapping these requirements into local government is that many different services are indeed provided. We may need to come back to that in more detail.

The government cyber unit now resides within DCMS. The team has transferred over and is up and running; I have spoken to them many times recently. The unit is very active in progressing the government cyber action plan as per the timetable and the target plan.

On the question about the approach to looking at other sectors to bring in, that is why I mentioned at Second Reading that I had already asked my officials to work across government to consider what additional services would merit being brought in. I mentioned earlier today that focusing on CNI services not already covered by the NIS regime would be the right place to start.

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Baroness Lloyd of Effra and Baroness Neville-Jones
Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

In this recovery regime, will whatever organisations that are to be regulated be levied for the service of regulation that will be provided, or will the revenue come as a result of fines? If that is the case, I hope they will not raise the revenue by finding fault. What is the basis of the cost recovery? It needs to be perceived to be fair, not onerous and not directed at encouraging regulators to regulate for the sake of increasing their income.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - -

The intent behind the cost recovery model is to provide a fair approach so that regulators, when regulating on cyber, can recover the costs associated with that. Further guidance will be put out on this. I cannot recall the Bill’s exact provisions on fines. I will come back to the noble Baroness on that.