All 1 Debates between Baroness Ludford and Baroness Berger

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Baroness Ludford and Baroness Berger
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - -

My Lords, this is a group of rather wide scope. I am kicking off. I will also speak to Amendment 168 in my name so as not to speak twice. It is on an entirely different subject from Amendment 79, so we will probably have quite a long debate on this group.

Amendment 79 is about including political parties in this Bill. My honourable friend Victoria Collins MP made the same case in the other place, tabling a proposed new clause to designate political parties as carrying out essential activities. We have discussed, over several days, how cyber security is not just a technical matter confined to server rooms and IT departments; it is a matter of national resilience, economic strength, the functioning of society and, I argue, democratic integrity. On this last count, the Bill is silent.

I remind the Committee that, between August 2021 and October 2022, as we later learned, hostile actors sat undetected inside the systems of the Electoral Commission and exfiltrated copies of the electoral registers—an intrusion the Government attributed to a China state-affiliated actor. There was apparently reconnaissance against the email accounts of parliamentarians who had spoken out against China. So we are hearing of more and more denial-of-service attacks and other incidents affecting critical national infrastructure, which may have some knock-on effect on our democratic structures. Think about what political parties hold: membership lists, canvassing databases covering millions of electors, data on political opinion and special category data of the most sensitive kind—perhaps precisely the material valuable for espionage, transnational repression and targeted disinformation in a campaign period.

Let us think about the kind of defences that are protecting this information. Those of us who have experience of local party activity know that we are normally talking about a small office with a handful of staff and many volunteers, not massive enterprises—and they themselves have been the subject of cyber attacks. We perhaps have quite a weak link at the heart of our democracy.

The National Cyber Security Centre has defending democracy guidance, but this is voluntary, done on an opt-in basis and unenforced; there is no duty to report an incident, no assessment framework, no designated regulator and no floor beneath which a party cannot fall. So there is weakness around the cyber security of political parties and of electoral infrastructure. I am sure that the Minister will tell me that parties are not infrastructure—indeed they are not—but the Bill encompasses data centres and managed service providers on the basis that disruption there would significantly affect the day-to-day functioning of society. If the compromise of a major party’s voter database in the final week of a general election would not meet that test, I struggle to think what would.

Nothing in this amendment invites the Government into the internal affairs of parties; it asks only that the organisations through which the British people exercise their democratic voice are held to a basic standard of resilience. Democracy is essential infrastructure. It is a privilege that we must defend with the utmost priority, and the Bill should reflect that.

I will cover another, completely different matter in my Amendment 168. This amendment was prompted because, probably like others here, in July I had several notifications from either a charity, an arts organisation or an academic organisation—I cannot remember; I think I had four or five altogether—warning me of a data breach. This was a named company—I think it has been in the public domain—called Beacon. It experienced a cyber security incident involving unauthorised access to its systems. I understand it stores data on the membership and customers of a lot of organisations—about 1,000, I read.

This is a probing amendment because I am asking the Government where organisations like this sit. They are variously described as a customer relationship management service provider or a software as a service relationship provider. I do not think they fall into RMSP or RDSP; they are not cloud computing, they are not an online marketplace or search engine and so on. Maybe, arguably, they are a managed service or IT management, support, maintenance or monitoring. I do not know what the precise relationship is between the organisation and the Beacon customer relationship management service provider. I do not really understand it, and the point of the amendment is to find out whether the Government know where it sits in the sphere of cyber and data services. They will often have lots of personal data, including date of birth, contact data, records of donations and memberships, and the booking of events. There is quite a lot where you could profile somebody and find out a lot about them, so it is quite risky to have all of that in unauthorised hands.

I think these breaches triggered reporting duties to the Information Commissioner under the GDPR, but, as far as I know, I do not think that a comparable incident would trigger this Bill’s incident reporting duties. I do not know where these organisations fit, so can the Minister tell me where they live in the ecosystem and what could or should be done to try to increase their support for the organisations that they work for? I beg to move.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I wish to speak to Amendment 81A in my name. I was glad to add my name to Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron. I am sorry that I was unable to speak to them on Tuesday due to some caring responsibilities.

Amendment 81A is all about education. Our British educational institutions sit at the heart of our communities. They are key to developing our children and young people, and helping them grow, supporting them through the most important developments of their lives. This year, the UK was ranked as having the third best public education system in the world, something that we should be so proud of but which we must safeguard. We have seen our education system change rapidly in the past decade. We now have exam results revealed via an app. We have homework set through online portals. I receive it weekly for both of my children. Increasingly, vast amounts of student data is being stored online, including around attainment. If our young people are to be properly supported, that must extend beyond the classroom to the network and information systems now essential to their education—a point only reinforced as universities and colleges continue to further embrace online learning.

Exam results determine a young person’s future opportunities. We all remember just a couple of weeks ago the pictures, the interviews of the young people and the elation of many 16 and 18 year-olds as they received and revealed their GCSE and A-level results. We owe it to the next generation to do everything we can to give them the best possible chances—to protect the integrity of the system that determines their future and to prevent the chaos that could follow if, for example, university place allocation, clearing or accommodation processes could not proceed. Anyone who might have friends or family whose 18 year-olds are currently going through that process knows it is frenetic enough at this time—scrambling to get a place for young people who might not have made their grades, changing universities, changing courses, trying to get a university spot or university accommodation.

We have already seen what chaos looks like on a small scale. Noble Lords perhaps will recall students who sat their A-level physics paper with Cambridge International who had their results voided after just one paper was leaked online, with a substitute mark calculated from other components. That was just one paper from one exam board, and it was still enough to undermine confidence in the results for every student affected. We need to look no further than the terrible experience recently in India where the National Testing Agency’s medical entrance exam results were withdrawn after a paper was leaked. It triggered mass protests and, tragically, at least 21 reported suicides among students who had sat the exam. If a single compromised paper can cause that level of devastation, we cannot afford to leave our education system exposed to a compromise on a grand scale.

Amendment 81A would establish that the education sector is an essential activity by requiring the Secretary of State to make regulations under Part 3 of the Bill. This would bring within scope any institution that provides primary, secondary, further or higher educational and vocational training. It includes exam boards involved in setting, marking or awarding and grades, higher education admission bodies, and any body that is essential to the provision of primary or secondary education that holds substantial volume of student or staff data. The obligations would require that education bodies take appropriate and proportionate technical and organisational measures to manage risks to the security of their network and information systems. The bodies must: take appropriate and proportionate measures to prevent and minimise the impact of cyber incidents, with a view to ensuring continuity of service; have regard to the state of the threat; ensure that they have a high level of security appropriate to the risk; and have regard to any relevant guidance issued by their regulator.