Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Ludford Excerpts
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, having exchanged some gestures with the noble Lord, Lord Hunt, I think it is me next. I am pleased to support this amendment, which I have cosigned, and I very much agree with everything that the noble Lord, Lord Markham, said.

My remarks will principally have China in mind. China is not the only repressive regime, of course, but certain examples come to mind. Take, for example, the political prisoners in Hong Kong, such as Jimmy Lai and Joshua Wong, who was in the news recently when he was outrageously imprisoned, on so-called national security grounds, for democratic expression and protest. There are many other such examples, of course. There are also concerns about electroshock weapons being demonstrated inside the Chinese embassy here, and we recently saw a considerable eight-year sentence under our National Security Act for the manager of the Hong Kong Economic and Trade Office in the UK because of attempts at repression in the UK. So there are problems of justice—or, rather, injustice—in Hong Kong and China, but the tentacles of repression are very much reaching into this country, particularly for the Hong Kong diaspora.

We have seen other examples, such as Interpol red notices being misused, so there is a great concern that requests for digital information sharing that have a nefarious purpose could be made by authoritarian states under the Bill. We have had examples in Hong Kong of residential surveillance and holding individuals incommunicado for up to six months, without access to a lawyer or family, which amount to enforced disappearance and increase the risk of torture. We have the lack of judicial independence, as the noble Lord, Lord Markham, mentioned, which explicitly prevents a fair trial, particularly in so-called national security cases. The treatment of imprisoned activists undermines any semblance of a fair trial. There are concerns about the admission of evidence obtained through torture in Chinese courts, which includes Hong Kong. The situation in prisons is intolerable. I understand that Jimmy Lai is being held in conditions where he is practically boiling in the heat of his cell. Anyway, this gives the Committee an illustration of everything that I think noble Lords are already aware of.

I understand that, under the Extradition Act, co-operation between the UK and Hong Kong authorities is permitted on a case-by-case ad hoc basis; if that is incorrect, I would accept correction. But if, under the Bill, NIS data—including sensitive information such as IP addresses, digital fingerprints and user-level logs from digital service providers—could increase the risk of extradition to a country without a bilateral treaty with the UK then that could trigger special extradition arrangements, bypassing traditional human rights safeguards. We are on a slightly uncertain basis of extradition to Hong Kong, into which the Bill could add another element, so there are no permanent safeguards against extradition to Hong Kong and this data sharing could serve as an intelligence-gathering tool, which facilitates that process by providing the evidence which then justifies the filing of an ad hoc extradition request. So we could increase the likelihood of an ad hoc extradition request, which would make it more difficult for the British authorities.

Of course, we all know that many of the diaspora in the UK are living in fear of their lives—not just fear for their safety but for their lives, with bounties on their heads. We are also aware of all the cyber attacks that we understand are being launched from a Chinese direction. This NIS data could help to identify the architecture of the UK’s critical systems and choke points. It could also assist with the harassment of dissidents and human rights defenders living in the UK.

For all these reasons, I very much support the amendment. As the noble Lord, Lord Markham, said, if the Government believe that there are institutional drafting problems then it is incumbent on them—if they agree with us that there is a danger in this zone of sharing data with a repressive regime, and I cannot see how they would not—to come up with something which fits the existing parameters but prevents opening the door to assisting repression. That would certainly be against any values in this country.

Lord Hunt of Kings Heath Portrait Lord Hunt of Kings Heath (Lab)
- Hansard - - - Excerpts

My Lords, I will briefly follow the noble Lord, Lord Markham, and the noble Baroness, Lady Ludford, in supporting this amendment. The noble Lord, Lord Alton, who is the architect of the amendment—indeed, of many amendments relating to China and human rights—unfortunately cannot be here, but both the noble Lord, Lord Markham, and the noble Baroness, Lady Ludford, explained eloquently why this is important, particularly the focus on China.

Over the years, British Governments of all colours have had a very ambiguous policy towards China. On the one hand, in terms of trade and the economy, it is crucial. On the other, we have to admit that Chinese repression and China’s appalling human rights record mean that the Government need to tread very carefully in their relationships with China.

My interest in this came from the problems, particularly in Xinjiang province, with enforced organ harvesting of dissidents and followers of Falun Gong. When we say “forced organ harvesting”, we essentially mean that prisoners are killed so that their organs may be taken and sold, in essence, on an international market. China makes billions of pounds from this appalling practice.

Over the years, the noble Lord, Lord Alton, has chipped away, legislatively, at a number of pieces of legislation to, in essence, preclude British companies from supplying China with goods, medicines or chemicals that could then possibly be used for organ harvesting. There are a number of pieces of legislation where this happens. Obviously, this Bill is different, but I note the argument that the noble Baroness, Lady Ludford, and the noble Lord, Lord Markham, made about why we should have special provisions for fair trials and the release of information to authoritarian countries.

I fully take the point from the noble Baroness, Lady Ludford, who, like the noble Lord, Lord Markham, referred back to the debates in the other place and the difficulty of drafting. I hope that the Government might be prepared to talk, particularly to the noble Lord, Lord Alton, about whether we can find a way forward here.

--- Later in debate ---
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

I apologise for interrupting the noble Baroness. My understanding was that, although the treaty had been suspended, there could be consideration on a case-by-case, ad hoc basis. Is that wrong? Is there a complete ban on extradition or, notwithstanding the suspension of the treaty, could there still be a case-by-case, ad hoc extradition?

Baroness Ramsey of Wall Heath Portrait Baroness Ramsey of Wall Heath (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness. I will write to her on the case-by-case point.

Finally, I know that my noble friend the Minister will be very happy to meet noble Lords again to discuss this further, as she has done quite recently with the noble Lord, Lord Alton.

--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, Amendment 74 is in my name and those of the noble Baronesses, Lady Morgan and Lady Ludford. The noble Baroness, Lady Morgan, is very sorry that she cannot be in the Committee this afternoon but she particularly wanted me to thank the Minister for their helpful meeting last week. This amendment and Amendment 167 in the name of the noble Baroness, Lady Ludford, relate to the governance of regulated bodies that will be caught under this Act. The reason for this legislation is to reflect the rapidly changing cyber environment and to strengthen areas of current vulnerabilities of those organisations providing services critical to societal or economic life.

As we have discussed, regulators will be given powers to designate critical suppliers whose disruption could have a significant impact on essential services. As we have discussed in previous groups, many of us think the Bill does not go far enough in setting out who those critical suppliers are. We are going to see similar amendments in other forthcoming Bills that make provision for senior manager liability when new responsibilities are legislated. This is something that we have been through in other Bills: the only way to change the culture of an organisation is to start at the top.

I am sure that boards will grumble when they accept new duties, but they will keep their regulators happy were they to be in sight of the law. What really makes the difference to successful implementation is knowing that if it can be proven—I shall read out proposed new subsection (1)(b)—that

“the failure was committed with a consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly”,

that individual will be held responsible. I point noble Lords to recent court cases in the area of social media, where disclosure has repeatedly shown that senior executives knew of harm or stood in the way of harm mitigation for years. The idea that this might capture an unwilling or unwitting senior executive is shown clearly not to be the case by what I have just read out.

I understand that the Minister and the noble Baroness, Lady Morgan, also discussed this in the context of financial services and a regime introduced after the 2008 financial crash with the very intention of changing the culture of financial service businesses and focusing senior minds on the damage those businesses can do if they do not meet their responsibilities. A more recent example is the introduction of the consumer duty by the Financial Conduct Authority, which required relevant boards to appoint an individual consumer duty champion, something that the noble Baroness, Lady Morgan, was involved in. I also point to the Building Safety Act that was a response to the Grenfell Tower disaster.

I am hoping that the Government are sympathetic to this amendment, but if they find themselves unable to be sympathetic, I would be interested also to hear the Minister’s thoughts on whether we could require the relevant regulator to introduce a named senior manager regime, which indeed we did in the Online Safety Act.

The final point I make is that the senior manager must be senior. The intention behind the amendment is to change the culture of an organisation to ensure preventive action is taken to avoid penalties. As I said at the outset, culture change starts at the top. The services covered in the Bill are, by definition, considered by Ministers to be critical to national life, which means that the most senior governing body should be discussing them and responsible for them. While day-to-day management may be delegated, overall oversight and responsibility should sit at the top. For that reason, I support—as I know the noble Baroness, Lady Morgan, supports—Amendment 167, tabled by the noble Baroness, Lady Ludford. Her proposed new clause would focus the minds of those at the most senior levels of organisations caught by the Bill, and I really hope that the Government support this ambition. I beg to move.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I am pleased to speak to Amendment 167 and grateful for the support from the noble Baroness, Lady Kidron—the support is mutual, as I co-signed her amendment. The two amendments are complementary, because Amendment 74 is about the liability of senior executives while Amendment 167 is about board oversight of an individual executive, responsibility and accountability. I was interested to hear the noble Baroness refer not only to financial and consumer conduct but to building safety as areas where such responsibility exists.

I am simultaneously involved in the Public Office (Accountability) Bill—the Hillsborough law—which will introduce a duty of ethical conduct, candour and transparency on public authorities and public officials. Perhaps what some of these other sectors have in common is that it has been an after-the-event thought that maybe boards and senior executives ought to have some kind of responsibility in this area. If we have had a catastrophe, often with a great deal of harm created—such as Hillsborough—maybe it would be a good idea if the people at the top, who are often extremely highly paid, took some interest in the area, rather than regarding it as some sort of lowly service, rather like cleaning the loos in the HQ building. I know it is now routine to refer to examples such as Jaguar Land Rover and Marks & Spencer, but there have been huge financial effects of cyber attacks. This is not some negligible issue; cyber security ought to be a core responsibility for senior people.

I am sitting close to the noble Baroness, Lady Harding, who today has referred to her own personal experience—we all remember it. I am sure it was painful for her and very public. She has actually been through it, so nobody knows better what it can be like when you have a big cyber data breach or cyber attack. It really is long past due that this ought to be a top responsibility of boards, directors and senior executives. Yet we understand—I think I get this from my noble friend Lord Clement-Jones—that the Government’s own Cyber Security Breaches Survey reveals that board-level ownership of cyber risk in the UK has declined from 38% to 27% over the past three years. It is going precisely in the wrong direction.

I do not think I need to persuade anyone here of how important it is for senior people in an organisation to be aware and carry not only responsibility, awareness and accountability but liability, so that it hits where it hurts if something goes wrong. Personally, it seems pretty much a no-brainer, and I hope the Minister will agree.

--- Later in debate ---
Moved by
79: After Clause 24, insert the following new Clause—
“Services to support political parties to be specified as essential activities(1) The Secretary of State must, within six months of the day on which this Act is passed, make regulations under section 24(3) to specify that an activity carried out for the primary purpose of the operation of a registered political party is an essential activity.(2) In this section “registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.(3) Regulations made under subsection (1) must designate one or more appropriate regulatory authorities for the specified activities.”Member’s explanatory statement
This new clause would require the Secretary of State to specify services with the primary aim to support the operation of political parties as essential activities under Part 3, bringing them within the scope of the Bill’s security and resilience regime.
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, this is a group of rather wide scope. I am kicking off. I will also speak to Amendment 168 in my name so as not to speak twice. It is on an entirely different subject from Amendment 79, so we will probably have quite a long debate on this group.

Amendment 79 is about including political parties in this Bill. My honourable friend Victoria Collins MP made the same case in the other place, tabling a proposed new clause to designate political parties as carrying out essential activities. We have discussed, over several days, how cyber security is not just a technical matter confined to server rooms and IT departments; it is a matter of national resilience, economic strength, the functioning of society and, I argue, democratic integrity. On this last count, the Bill is silent.

I remind the Committee that, between August 2021 and October 2022, as we later learned, hostile actors sat undetected inside the systems of the Electoral Commission and exfiltrated copies of the electoral registers—an intrusion the Government attributed to a China state-affiliated actor. There was apparently reconnaissance against the email accounts of parliamentarians who had spoken out against China. So we are hearing of more and more denial-of-service attacks and other incidents affecting critical national infrastructure, which may have some knock-on effect on our democratic structures. Think about what political parties hold: membership lists, canvassing databases covering millions of electors, data on political opinion and special category data of the most sensitive kind—perhaps precisely the material valuable for espionage, transnational repression and targeted disinformation in a campaign period.

Let us think about the kind of defences that are protecting this information. Those of us who have experience of local party activity know that we are normally talking about a small office with a handful of staff and many volunteers, not massive enterprises—and they themselves have been the subject of cyber attacks. We perhaps have quite a weak link at the heart of our democracy.

The National Cyber Security Centre has defending democracy guidance, but this is voluntary, done on an opt-in basis and unenforced; there is no duty to report an incident, no assessment framework, no designated regulator and no floor beneath which a party cannot fall. So there is weakness around the cyber security of political parties and of electoral infrastructure. I am sure that the Minister will tell me that parties are not infrastructure—indeed they are not—but the Bill encompasses data centres and managed service providers on the basis that disruption there would significantly affect the day-to-day functioning of society. If the compromise of a major party’s voter database in the final week of a general election would not meet that test, I struggle to think what would.

Nothing in this amendment invites the Government into the internal affairs of parties; it asks only that the organisations through which the British people exercise their democratic voice are held to a basic standard of resilience. Democracy is essential infrastructure. It is a privilege that we must defend with the utmost priority, and the Bill should reflect that.

I will cover another, completely different matter in my Amendment 168. This amendment was prompted because, probably like others here, in July I had several notifications from either a charity, an arts organisation or an academic organisation—I cannot remember; I think I had four or five altogether—warning me of a data breach. This was a named company—I think it has been in the public domain—called Beacon. It experienced a cyber security incident involving unauthorised access to its systems. I understand it stores data on the membership and customers of a lot of organisations—about 1,000, I read.

This is a probing amendment because I am asking the Government where organisations like this sit. They are variously described as a customer relationship management service provider or a software as a service relationship provider. I do not think they fall into RMSP or RDSP; they are not cloud computing, they are not an online marketplace or search engine and so on. Maybe, arguably, they are a managed service or IT management, support, maintenance or monitoring. I do not know what the precise relationship is between the organisation and the Beacon customer relationship management service provider. I do not really understand it, and the point of the amendment is to find out whether the Government know where it sits in the sphere of cyber and data services. They will often have lots of personal data, including date of birth, contact data, records of donations and memberships, and the booking of events. There is quite a lot where you could profile somebody and find out a lot about them, so it is quite risky to have all of that in unauthorised hands.

I think these breaches triggered reporting duties to the Information Commissioner under the GDPR, but, as far as I know, I do not think that a comparable incident would trigger this Bill’s incident reporting duties. I do not know where these organisations fit, so can the Minister tell me where they live in the ecosystem and what could or should be done to try to increase their support for the organisations that they work for? I beg to move.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I wish to speak to Amendment 81A in my name. I was glad to add my name to Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron. I am sorry that I was unable to speak to them on Tuesday due to some caring responsibilities.

Amendment 81A is all about education. Our British educational institutions sit at the heart of our communities. They are key to developing our children and young people, and helping them grow, supporting them through the most important developments of their lives. This year, the UK was ranked as having the third best public education system in the world, something that we should be so proud of but which we must safeguard. We have seen our education system change rapidly in the past decade. We now have exam results revealed via an app. We have homework set through online portals. I receive it weekly for both of my children. Increasingly, vast amounts of student data is being stored online, including around attainment. If our young people are to be properly supported, that must extend beyond the classroom to the network and information systems now essential to their education—a point only reinforced as universities and colleges continue to further embrace online learning.

Exam results determine a young person’s future opportunities. We all remember just a couple of weeks ago the pictures, the interviews of the young people and the elation of many 16 and 18 year-olds as they received and revealed their GCSE and A-level results. We owe it to the next generation to do everything we can to give them the best possible chances—to protect the integrity of the system that determines their future and to prevent the chaos that could follow if, for example, university place allocation, clearing or accommodation processes could not proceed. Anyone who might have friends or family whose 18 year-olds are currently going through that process knows it is frenetic enough at this time—scrambling to get a place for young people who might not have made their grades, changing universities, changing courses, trying to get a university spot or university accommodation.

We have already seen what chaos looks like on a small scale. Noble Lords perhaps will recall students who sat their A-level physics paper with Cambridge International who had their results voided after just one paper was leaked online, with a substitute mark calculated from other components. That was just one paper from one exam board, and it was still enough to undermine confidence in the results for every student affected. We need to look no further than the terrible experience recently in India where the National Testing Agency’s medical entrance exam results were withdrawn after a paper was leaked. It triggered mass protests and, tragically, at least 21 reported suicides among students who had sat the exam. If a single compromised paper can cause that level of devastation, we cannot afford to leave our education system exposed to a compromise on a grand scale.

Amendment 81A would establish that the education sector is an essential activity by requiring the Secretary of State to make regulations under Part 3 of the Bill. This would bring within scope any institution that provides primary, secondary, further or higher educational and vocational training. It includes exam boards involved in setting, marking or awarding and grades, higher education admission bodies, and any body that is essential to the provision of primary or secondary education that holds substantial volume of student or staff data. The obligations would require that education bodies take appropriate and proportionate technical and organisational measures to manage risks to the security of their network and information systems. The bodies must: take appropriate and proportionate measures to prevent and minimise the impact of cyber incidents, with a view to ensuring continuity of service; have regard to the state of the threat; ensure that they have a high level of security appropriate to the risk; and have regard to any relevant guidance issued by their regulator.

--- Later in debate ---
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

I cannot possibly reply on any matters other than political parties. I am left unpersuaded that political parties are sufficiently supported and protected. Maybe bigger parties are not run on a shoestring as much as some of us. I am not talking about national level, but at the local level it could be justified to see some beefing up of the obligations and the support required.

Political parties come in for a lot of flak. They are always getting bashed around—“Who wants parties?”—but, actually, we would not have democracy in most cases without it being channelled through political parties, so they are an obvious target for any malefactor who wants to get at our democracy. It is really unsatisfactory not to give further support to political parties. Perhaps between now and Report we could reflect more on that.

On CRMs, the noble Lord, Lord Russell, prompted me to look at the website of the company Beacon—it is out there, so I am not giving away any secrets. It claims that 1,500 charities, NGOs and other organisations were affected. One was the English National Ballet, which I got a notification from. It manages an awful lot of personal data that has been subject to a cyber security incident. That happened in July, and I tabled this amendment in July, so I would welcome something from the Minister and her team to get a little more of a steer about where an organisation such as that stands in relation to this Bill and whether it should be encompassed to some extent within it.

From this company’s website, you would not know that anything had happened. Maybe that is par for the course. It lists all these security credentials and so on, saying how wonderful it is—I am sure it is, and I do not wish to impugn it—but the fact is that it has had a major cyber security incident affecting apparently maybe 1,500 organisations and the personal data of millions and millions of people in this country. Yet I did not feel we got much back from the Minister, so perhaps we can think more about that between now and Report. I beg to leave to withdraw Amendment 79.

Amendment 79 withdrawn.
--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, Amendment 83, in my name and those of the noble Baroness, Lady Ludford, and the noble Lords, Lord Holmes and Lord Tarassenko, would require the Secretary of State to publish and maintain a digital sovereignty strategy. Before the Recess, many of us participated in a debate on digital sovereignty, and the level of agreement across the Chamber was absolutely overwhelming about the importance of UK national sovereignty and the current threats to it from our current arrangements with the tech sector, particularly US-based behemoths. The same sentiment is articulated by Amendment 166 in the name of noble Baroness, Lady Ludford, and it is a sentiment shared in the other place, where Conservatives, Liberal Democrats and Greens all tabled similar Motions.

During the debate, I identified four areas in which the UK has surrendered its leverage to make its own decisions. We surrendered our political leverage by deferring to the power of US tech; we surrendered our economic leverage by placing UK businesses at a structural disadvantage and entering into expansive and extractive contracts; we surrendered our technological capability as we failed to invest in UK capacity and businesses; and we ensured our strategic vulnerability by depending on foreign companies for key infrastructure. Together, these weaken our economy, our security, our safety and, above all, our autonomy: the ability to choose. I doubt that any single government strategy put us in this position, but it reveals a lack of strategy that we find ourselves here.

Amendment 83 would set out a requirement for the Secretary of State to establish a digital sovereignty strategy. Proposed new subsection (2)(a) would require an assessment of the risks to networks and information systems from

“dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, extra-territorial legal requirements that may be imposed on non-domiciled suppliers”—

such as cloud providers through the US CLOUD Act—

“vulnerabilities, undue control, or supply-chain dependency on foreign states or entities”,

the use of

“UK datasets without license or permission”

and vulnerabilities to valuable data assets that belong to the British public, including those related to the NHS, BBC, and Met Office. The rest of proposed new subsection (2) sets out further requirements to assess the risk of

“technological developments, market concentration or strategic dependencies”

and give consideration to vital elements of sovereignty, including open source technology and assets, talent procurement, capital markets and international collaboration with mid-sized partners whom we retain leverage with.

Finally, proposed new subsections (3) and (4) call for the development of a dashboard enabling the measurement of digital sovereignty. I am working with computer scientists at the British Computing Society who are developing a prototype for this and I urge the Government to look at this work and consider developing it, for their own procurement purposes and to provide it as a tool for the wider business community.

I set that out in some detail because I rather suspect that, if we had a proper strategy across the nation, we would not have had the conversation that we just had in our debate on the previous grouping. Sovereignty is now firmly on the agenda. This is partly due to the export ban on Anthropic and Claude Fable 5 introduced by President Trump in June, but stories highlighting our sovereign vulnerability across the digital stack predate that event and have continued since.

Dependency is not built overnight. It is the result of a systemic and concerted effort by entrenched big tech companies across many years to make themselves indispensable to the UK state, businesses and society, and of successive UK Governments failing to invest in our businesses, communities and people and choosing always to buy oven-ready tech, irrespective of the economic, societal and individual costs.

Just as dependence is not built overnight, neither can sovereignty be reclaimed overnight; nor is it a zero-sum game in which every part of the stack can or should be replaced. None the less, to restore any independence at all, we require an equally systematic and concerted approach to build where we can, to buy only products and services that adhere to our laws, to recognise our unique skills and assets, and to work co-operatively with other like-minded countries. That begins with a strategy that establishes a clear route for government and is fed into experts, free from lobbying and scrutinised by Parliament—which is the very purpose of the amendment in front of us. I beg to move.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I shall speak to my Amendment 166. It offers an alternative route to the same destination, although the amendment in the name of the noble Baroness, Lady Kidron, is probably superior because it is fuller and more comprehensive; I readily concede that. Her amendment would add an important element—a digital sovereignty dashboard prepared by the Office for National Statistics, the Competition and Markets Authority, the National Cyber Security Centre and the AI Security Institute—so that we can measure whether anything is changing. The cross-party agreement on this matter, which the noble Baroness referenced, is important and might help persuade the Minister of the force of the argument.

The Competition and Markets Authority puts Amazon Web Services and Microsoft together at between 70% and 80% of the UK’s public cloud market. That is not only a duopoly but a digital sovereignty issue. In its report Rewiring the State, which was published in June, the Science, Innovation and Technology Committee in the other place found that major departments, including HMRC and the NHS, were locked into multiyear agreements that further entrench those dependencies. The National Audit Office has found no shared strategic approach across government towards the handful of very large suppliers that now dominate these markets and are, to a large extent, American. Research done by the British cloud provider Civo found that 83% of UK IT leaders believe that geopolitics threatens their ability to control their data, while only 35% know precisely where that data resides.

I have a history, as a Member of the European Parliament, of being involved in all the arguments about transatlantic data transfer and what happens to the data when it is in the US; this was all in the wake of the war on terror, Guantanamo and so on. We are back in that territory, I guess. It is not just about the economic side of non-national control; it is also about your vulnerability to decisions—including, sometimes, decisions that you do not like—about what happens to the data.

Moved by
10: Clause 8, page 7, line 36, at end insert—
“(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,”.”Member's explanatory statement
This amendment would explicitly include risks arising from fraud as one of the risks to the security of network and information systems that relevant digital service providers must identify and manage.
--- Later in debate ---
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I apologise for not having been much around earlier, but I am also involved in the Hillsborough Bill in the Chamber.

Amendment 10 stands in my name and that of my noble friend Lord Clement-Jones. It would insert just five words into Regulation 12 of the 2018 regulations so that the risks which a relevant digital service provider must identify and manage explicitly include risks arising from fraud. The amendment might create no new duty if the duty is already encompassed in Clause 8, but it settles a question that the Bill currently leaves open. When an online marketplace, search engine or cloud provider—or a software or digital platform, under Amendment 7 from the noble Lord, Lord Birt—sits down with its regulator and asks which risks it is expected to manage, is fraud definitely on the list? At present, nobody can say so with confidence, and the answer matters a great deal because of who Clause 8 applies to. Relevant digital service providers are online marketplaces, search engines, cloud computing services and, possibly, digital and software platforms. These are not incidental to fraud in this country. They are increasingly where it begins.

We can see the impact of a lack of action to secure online and cyber spaces. Fraud makes up 44% of all UK crime, and online technologies, especially artificial intelligence, are supercharging that, with a big increase in online-generated fraud and scams. Research by Lloyds Bank found that Meta’s social media sites are a starting point for 76%—three-quarters—of purchase scams in the UK, with the value of losses to UK customers estimated at £66 million in the last year alone. The Government’s fraud strategy does not really focus on the role of social media giants and big tech in the proliferation of online scams, and now the Bill fails to address explicitly the risks that fraud and scams pose to critical infrastructure and organisations. That is very striking when we consider that the Government’s official statistics on cyber security breaches show that phishing attacks—scams—remain by far the most prevalent type of breach or attack in the UK.

The evidence of the impact of fraudulent online activity is not contested and is a huge concern for consumers. UK Finance’s annual fraud report, published in June, records that criminals stole nearly £1.3 billion through payment fraud in 2025, a rise of 4% on the previous year and the second consecutive year of growth. There were more than 4 million confirmed cases in 2025: that is eight people defrauded every minute. Authorised push payment losses rose 19% to £576 million, and around two-thirds of that fraud originated online. Investment fraud was up by 40%.

UK Finance describes fraud as a “national security threat” and I think it is right. The Government’s cyber security breaches survey published in April found phishing to be by far the most prevalent form of breach or attack, experienced by almost four in 10 businesses and rated the most disruptive by seven in 10 of those affected. Among businesses breached, more than half experienced only phishing. Fraud is not parallel to the cyber security threat. For most organisations, fraud is the cyber threat picture.

I anticipate the Minister will tell me that fraud is handled elsewhere: in the Online Safety Act, the reimbursement rules and the fraud strategy. However, I make two points. First, none of those regimes places a security and resilience duty on cloud providers or marketplaces in respect of the systems on which essential activities depend. Secondly, a regulatory architecture in which every regulator assumes that fraud is everybody else’s business is precisely how a gap of this size opens up in the first place.

This amendment was raised in the other place by my honourable friend Victoria Collins MP. The ministerial answer was, in essence, that the words were unnecessary. I would rather have them explicitly in the Bill rather than rely on inference. If the Minister cannot accept the amendment, I ask for two assurances: that the guidance the Information Commissioner must issue under paragraph (4)(a) of Regulation 3 will address fraud risk explicitly, and that the statement of strategic priorities under Clause 25 will name fraud among the risks to which regulators must have regard.

I shall turn to just one other theme in this group; my noble friend Lord Clement-Jones will sweep up at the end in his winding-up speech. I wish to speak to Amendment 15 on workforce competence and skills, as well as on the issues raised in Amendments 174C and 174D, which also refer to cyber security capability. We are all concerned about the shortage of cyber skills and competencies in the workforce, but one place where that has to start is with young people in schools and colleges. I sought to table an amendment calling for the Government to publish a strategy on improving the cyber security awareness and resilience of children and young people through education. Sadly, the PBO ruled it out of scope, but I hope that we might have that issue in mind. If we are going to get the increase in workforce skills and competence on cyber security that we vitally need, we need also to have an eye on developing those skills in our young people, who spend so much of their lives online. I beg to move.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The content of the statement of strategic priorities will be subject to consultation and we will be working with regulators on that. It could include specific risks, whether from quantum or from fraud. What I do not want to do right now is to commit that it will include that, because we are going through a process.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, I thank the Minister for her reply. Her last words gave me a little bit more hope than the rest of her response, to be honest, when she said that the statement of strategic priorities could include specific risks, because it seemed to me that she was otherwise being a bit generic and unspecific—almost above the fray. When I came in on a previous group—and other noble Lords are much more knowledgeable and expert in this field than I am—I picked up some frustration that the feedback from the Government and from the Minister today was a bit vague and not very responsive. All this is happening out there; there are huge cyber threats and there is a feeling that the Government are not really getting to grips with the actualité quite as much as they might.

I understand that the Minister might not be able to say now what will be in the statement of strategic priorities, but what we are searching for is that it will grapple with real problems out there in the economy, in society. I must admit that Amendment 82 from the noble Lord, Lord Ravensdale, on post-quantum cryptography, is somewhat above my pay grade. I wish I was more knowledgeable, but I ain’t. But I understand what he is saying, how real this is: the threat is out there. You just have to read newspapers to get the drift of what is happening. I mentioned that fraud is nearly half of all crime, so these are big issues. I think that what we want from the Government is a feeling that they get it, that there is going to be specificity in the way that they are going to implement this Bill and that they are really going to be on the case of these big threats. The Minister’s last words were a bit more encouraging than some of the rest of what she has been saying. That said, I am sure we will come back to some of these issues on Report, but I beg leave to withdraw my amendment.

Amendment 10 withdrawn.

Maccabi Tel Aviv FC: Away Fans Ban

Baroness Ludford Excerpts
Wednesday 22nd October 2025

(11 months, 1 week ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Ludford Portrait Baroness Ludford (LD)
- View Speech - Hansard - -

My Lords, it seems clear that the main motivation locally was in fact to boycott Israel. None the less, it is necessary to get clear the degree of blame that has been attributed to the fans of Maccabi Tel Aviv. There is an account in the Guardian today which seems seriously distorted. Have the Government got it clear in their own mind, at least for all useful purposes, that while there may well have been bad behaviour, hooliganism and even some racist behaviour by a minority of fans in Amsterdam, the majority of the harm was committed against them and not by them? It is important to capture the picture that the Government have of what happened in Amsterdam, because it has been recycled a lot.

Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

My understanding of what happened in Amsterdam is as the noble Baroness has just outlined. One of the things that I found most appalling about the decision that was made is that it was based on the risk to fans, primarily. In a country where we manage violence associated with football on a regular basis, we cannot have a situation in which it is the risk to fans which means that those fans themselves are barred from a sporting or other public event.