(1Â month ago)
Grand CommitteeMy Lords, it is a pleasure to support these amendments. I have signed all of them, although in doing so I almost got a serious case of electronic RSI. They have the great good fortune of being clear, precise and aligned with existing regulations in other jurisdictions. As my noble friend Lady Harding has already pointed out, many businesses will have operations in multiple jurisdictions. For something as significant as reporting, why would we not follow NIS2 in this respect?
The clarity of the amendments is their strength, even more so when compared with what is currently in the Bill in this respect. What we are trying to achieve from these changes is clear. The 24-hour initial reporting period makes sense: of course it does. As my noble friend Lady Harding pointed out, what one knows at that point is that something is happening and a report is made. In many ways, that is all that needs to be known and all that needs to be reported.
To have a situation as currently set out in the Bill, 24 then 72, means that in that period so much would need to be known to comply with the provisions set out in the Bill that it is just not realistic. This staged approach is both clear and precise. It enables what the purpose of the Bill is all about, which is to support the individual business or entity that is under attack. Crucially, as other noble Lords have said, it puts the power in the collective. As a consequence of one attack, the collective can benefit if there is a sense of commitment to this reporting schedule. That will come only if it is in this stage 4, as clearly set out by my noble friend Lady Harding.
If we want to enable businesses and other entities to really commit to this process—not just be dragged there by force of statute but have it as a means of business as usual, a real cultural change and a commitment to the positivity of this—it has to work for them. This staged process not only does that but, by aligning with NIS, stops this being yet another burden added to business: added unnecessarily and less effectively than what these amendments propose. I very much look forward to the Minister’s response.
My Lords, good can come out of bad events. The experience, as well as the speech, of my noble friend Lady Harding is one such good aspect. If it combines with bringing us into line with European practice, which so many businesses already have to follow, so much the better. I hope the Minister will be as sympathetic as she possibly can to my noble friend’s amendments.
My Lords, I very strongly support this set of amendments on the staged notification of incidents. This is a significant group of amendments from the noble Baroness, Lady Harding, and so well supported by the noble Baroness, Lady Kidron, and the noble Lord, Lord Holmes; he has illustrated this extremely well. As has been described, the noble Baroness, Lady Harding, has a great deal of experience. She brings an invaluable perspective to this Committee, having led a major telecommunications provider through one of the most high-profile corporate cyber breaches in British history. She speaks from real experience and understands very clearly what happens inside an organisation in the immediate aftermath of a severe attack. We should listen extremely carefully to what she has to say.
In those critical opening hours, incident response teams and forensic engineers are working under an intense fog of war, so to speak, actively fighting to contain the malware, to isolate compromised servers and to protect customer data. We cannot expect an organisation to produce an exhaustive, multivariable forensic post-mortem within the first few hours of a fast-moving operational crisis. Yet, as Clause 15 currently stands, the reporting pipeline that follows the initial notification is left thin and unstructured. The noble Baroness’s amendments fix this with three-stage architecture, which is mirrored clause by clause across each category of regulated entity: operators of essential services, data centres, relevant digital service providers and relevant managed service providers.
I will not add much more, as noble Lords have already spoken extremely eloquently. Cyber incidents do not likely conclude on the day a final report falls due. Where an incident is still live at the point that the final report is owed, the entity must instead give a progress report on the information known to date, followed by the final report within one month of the incident ceasing. That seems to me to be a very sensible and realistic accommodation of how live incidents unfold.
Finally, I turn to the amendments tabled by the noble Lord, Lord Ashcombe, although I do not see him here in Committee. They would extend the deadline for the full notification from 72 hours to 30 days. I understand the underlying concerns, as 72 hours can be an unforgiving window in which to complete a full investigation and analysis. However, it is the amendments from the noble Baroness, Lady Harding, that deliver what we need. Intermediate reporting exists precisely so that the authorities are not left in the dark for weeks at a time. Taken together, the noble Baroness’s amendments replace a single blunt deadline with a structured, predictable reporting line, which gives business clarity on exactly what is required and when, while ensuring that the NCSC and our competent authorities receive high-quality, structured intelligence, rather than a single, rushed snapshot. As she said, this is the kind of staged discipline that the EU’s NIS2 directive already reflects and which this Bill should emulate.
My Lords, I have added my name to Amendment 167, in the name of the noble Baroness, Lady Ludford, and I also support Amendment 74. I have done that in the knowledge that it is perfectly possible that the Minister will say that she wants to minimise regulation wherever possible—I get that. But I also get that we have been saying for years now that cyber security should be a board responsibility, that it requires knowledge and that that knowledge requires training. That is what Amendment 167 would provide for. We have been saying that, but very little has actually happened. If we are not to legislate about this, what will make people act? If the noble Baroness, Lady Ludford, is right that board ownership of cyber security has declined, we have to do something.
I understand that people who start, say, a wine business or a book business are probably interested in wine or books, rather than cyber security. If they were interested in cyber security, they would probably start a cyber security business, in which they would probably make a great deal more money. But they have to be interested in cyber security in exactly the same way as they have to be interested in money—hence this proposed new clause, which I support.
My Lords, I strongly support the drift of both amendments spoken to by the noble Baronesses, Lady Kidron and Lady Ludford. As I said the other day, I have sat on many boards with many distinguished people that contained a variety of experience in many jurisdictions, but I have not often come across a board that contains anyone with a pronounced understanding of technology, let alone the extremely narrow but deep area of complexity that is cyber security.
I hope noble Lords will forgive me for reminding the Committee of what I said on Tuesday: the way to achieve this objective is to require boards, at an appropriate level—I do not mean every board in the land—to have a cyber resilience audit each year, in the way that all major organisations have a very searching financial audit each year for the whole board, even though it may contain people who are there for different reasons: they may have marketing or sector expertise. But believe me, for every single board, when the team of auditors—who have been in the business for weeks and sometimes months—reports, it is listened to, and anything it advises is acted upon. We need to do exactly the same for cyber resilience.
(1Â month ago)
Grand CommitteeMy Lords, I apologise for having spent less time in Committee than I would have liked, but I have been speaking on the Public Office (Accountability) Bill. I am grateful to those noble Lords who I suspect have been speaking to amendments on my behalf.
Amendments 15A and 15B are about the designation of critical suppliers. New Regulation 14H says:
“A designated competent authority may designate a person … under this regulation if P supplies goods or services directly to an OES for which the authority is the designated competent authority”.
The Bill expands this regime to cover additional organisations and creates a new framework for designated critical supplies. That is good, and it recognises that essential services depend on organisations that go far beyond the direct infrastructure of the critical organisation itself; everything is dependent on everything else. However, the critical supplier test is focused on suppliers providing goods or services directly to a regulated organisation. That ignores the concept of a supply chain with several tiers of suppliers. These amendments are intended to address that. Therefore, I beg to move.
My Lords, I will speak briefly to my Amendment 16. In my view, the central problem is that, if I am small or medium-sized firm, I cannot currently tell with any confidence whether I am within the scope of the Bill as a critical supplier. Small and medium-sized enterprises are the lifeblood of our economy, and we need to approach with caution any ambiguity around their inclusion in the Bill. I took note of what the Minister said at Second Reading, when she said that:
“They can be regulated if they are designated as critical suppliers, for which there will be a high bar for designation”.—[Official Report, 14/7/26; col. 622.]
That was helpful, but what exactly is that high bar?
To give noble Lords an example of regulation legislation that is not defined, I come back to one noble Lords are likely to be familiar with: the infamous IR35. With that, the uncertainty and costs of getting it wrong were high in the regulation, so firms applied a blanket under which everyone they engaged with had to be inside IR35 and had to be treated as an employee. IR35 addressed a real problem, but the test was judgment-heavy and getting it wrong was expensive. That was why many organisations stopped making case-by-case decisions and applied a blanket policy, which meant that far more were caught by the regulation than was intended. I remember many years ago, as an engineer, spending a lot of time trying to fill in IR35 determinations and not doing engineering, which was a frustration at the time. It led to many issues with finding the right new skilled resource that we required to undertake the work.
I am sure that the Minister will say that the criteria will be set out in secondary legislation, but there will be a long period of uncertainty, and the IR35 example helps illustrate the risks. I took a look at the impact assessment and some of the costs were laid out. For example, if a firm is within the scope of this legislation, it is looking at physical security costs of perhaps £114,000 and cyber security spending—potentially of £190,000 a year. The impact assessment could not say how many SMEs may be designated within this legislation. All of that uncertainty is a cost, because it means that, if firms are uncertain about whether they are going to included, they may delay investment. In fact, they may overprepare; they may take on additional costs, which has wider implications to the UK economy, or they may walk away from public services. They will not want to go for these contracts because of the risk they may fall under this legislation, and that could potentially cause the same grit in the wheel of the economy that was seen in IR35. There is a case here for providing in the Bill at least some additional definition on what a critical supplier is; that is what my amendment intends to do.
Baroness Lloyd of Effra (Lab)
I thank noble Lords, in particular the noble Lords, Lord Arbuthnot and Lord Ravensdale, for engaging with the incredibly important question of drawing the right scope in the Bill for the designation of those in the supply chain. It is incredibly important that we get this right and take into account the economic and security impact. To begin, let me explain our reading of the amendments and the practical impact they would have.
Amendments 15A and 15B would enable regulators to designate suppliers as critical beyond those which directly supply to regulated entities, if they are materially dependent on that supplier to provide the regulated service. This would extend the scope of the measure to include suppliers further down the chain, even where they have no direct relationship with the regulated entity. In addition, the amendments would introduce an additional assessment of whether a regulated entity is materially dependent on a supplier, which would form part of the designation process. This could create a higher bar for designation of a direct supplier than currently exists in the Bill and could limit designation by excluding suppliers whom it would be reasonable and prudent to include.
The Bill recognises the importance of supply chain security, has considered the risks that supply chains pose and has developed targeted and proportionate measures to address those risks. First, regulated entities are subject to an overarching duty to identify and manage the risks posed to the systems they rely on to provide their services. A core part of this is to consider the risks arising from their supply chains. Secondly, as will be set out in the forthcoming security and resilience requirements, we will require regulated entities to take specific steps to manage their supply chains through an analysis of the risks they could pose, and to include a requirement to put in place contractual obligations on those suppliers to manage the immediate risks and the risks posed further down the supply chain, which may not be in the immediate view of the primary regulated entity. Thirdly, it is recognised that some suppliers in the market are critical to certain sectors and therefore the most proportionate step is to regulate them in their own right and to subject their security posture to the scrutiny of regulators.
This clause is already designed to be a proportionate and targeted measure and is aimed at bringing into scope only those suppliers who are genuinely critical to the regulated entities they supply directly. Finally, as we discussed at the beginning of this Committee, some suppliers may present additional risk and are potentially the vector of attack from hostile actors. That is why we believe that we need to take measured but decisive steps to manage that risk before it crystallises and before those vendors are embedded in critical systems. The amendments would significantly increase the number of potential suppliers that regulators may need to consider for designation and could risk imposing additional burdens on smaller suppliers that may be several layers removed from the regulated service.
On Amendment 16 in the name of the noble Lord, Lord Ravensdale, I agree that a supplier should be designated only where they are genuinely critical to the provision of a regulated service. That is why the Bill includes strict designation criteria that must be met before a supplier can be designated. Importantly, an incident affecting the systems relied on by the supplier could disrupt regulated services in a way that significantly impacts the economy or the functioning of society. The Bill maximises the proportionality of the measure so that only the most critical suppliers to regulated entities are designated. It will also limit the number of small and micro enterprises that are likely to be designated.
The noble Lord’s amendment intends to limit that further. Its intention is to focus on suppliers whose activities being disrupted would cause systemic risk to the UK’s digital ecosystem, economy or essential services, and to prohibit designation if a supplier provides goods or services only to a single operator of essential services, a critical national infrastructure entity or a public authority.
We discussed a little earlier in Committee the risk of small but risky suppliers. Amending the designation criteria to focus on systemic risk to a wider number of entities could potentially leave many of the UK’s most essential services vulnerable to disruption. In fact, the compromise of just one of these providers could still have a significant impact on the economy or functioning of society in the UK or any part of it. Under the noble Lord’s amendments, a supplier that is essential to a single energy provider responsible for a county’s power, an NHS hospital looking after a whole city or a single cloud service provider used nationwide may not be judged as posing a systemic risk if it were disrupted. This would leave these essential end services vulnerable to severe disruption if that supply were compromised, with significant impacts for the huge number of citizens relying on them.
The amendment would also require the Government to issue statutory guidance for regulators on designating critical suppliers. I agree that consistency in the decisions taken by regulators will be crucial to the success of this regime. That is why my department will work with regulators to develop guidance to drive this consistency, and regulators will be required to consult with other regulators before designating suppliers where there is a relevant connection to multiple sectors. As we have discussed before, the statement of strategic priorities will also provide common objectives for regulators, which will further increase alignment between their approaches.
I heard very clearly what noble Lords said in introducing their amendments and the important other contributions during this discussion, which highlight how important it is to strike the right balance for this measure. I believe that the Bill establishes a proportionate and targeted framework that captures genuinely critical suppliers without extending regulation or excluding risks within the supply chain.
My Lords, I listened carefully to what the Minister said. She made some very reasonable points and she may even be right, but I will need to take it away and think about it. In the meantime, I beg leave to withdraw my amendment.