All 3 Debates between Lord Birt and Lord Londesborough

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Lord Birt and Lord Londesborough
Lord Londesborough Portrait Lord Londesborough (CB)
- Hansard - - - Excerpts

My Lords, I support Amendment 100, in the name of the noble Baroness, Lady Northover. I spoke in support of this type of amendment at Second Reading and I still support its intentions, but I will give it an added twist. The question in my mind is where this resource for SMEs should sit and whether it should have any statutory powers or simply be an information and advisory centre.

There is no doubt that cyber security is needed—and here is another scary statistic—because 96% of all successful cyber attacks in the UK are perpetrated on SMEs, which represent soft targets for hackers. I suggest—here I take noble Lords back to day 1 of Committee— that this resource should sit within the office for cyber resilience proposed by the noble Lord, Lord Clement-Jones, and my noble friend Lord Birt. Indeed, this is yet another example of the need to establish a body like an OCR, given the disturbingly fragmented approach to cyber security in this Bill.

Where can we sensibly draw the line between SMEs across all sectors and the rest of the business world? For instance, advice given to a medium-sized company with, say, 200 staff will overlap hugely with that given to a company with 2,000 staff. In the minds of the hackers and the ransomware merchants there is very little distinction. I argue that our economy needs a coherent, joined-up approach, run by a single competent authority with statutory teeth, for the benefit of SMEs and other companies and sectors.

I am afraid that, as it stands, this Bill is a recipe for chaos. Cooks and broth would be a kind analogy—there is barely any room in the kitchen for the number of departments, teams, councils, centres and agencies involved. The last count I heard was 30 or so, but I believe a few more have cropped up since.

Lord Birt Portrait Lord Birt (CB)
- Hansard - -

I think we all share the sympathy that the noble Baroness, Lady Northover, has identified SMEs need. There are 5.7 million SMEs in the UK and many of them—indeed, most of them—will purchase what are relatively complex platforms. The noble Lord, Lord Londesborough, is extremely experienced in the SME sector; I have less experience than him, but I do have some. Hardly any of them will be able to employ anybody who is able to understand either the complexity of the platform that they have purchased or the highly dynamic threats to that platform that exist. There are many ways in which we need to raise our game and to help.

I personally think that, at least in the short term, the most important thing, which we have not discussed enough so far, is to require providers to supply safe products and, moreover, when they become vulnerable—which happens all the time, often unexpectedly—to patch those products for their customers immediately. The providers have a level of sophistication that the customers do not, and we have insufficiently focused on that in our discussion so far.

The second thing to mention—this is not really part of the Bill—is that the Government’s Cyber Essentials programme is very sound. The Minister quoted a figure the other day, which I forget, but only a trivial number of businesses have signed up and taken the pledge. This needs much more publicity and much more dynamism from within government to raise the understanding of the level of threat that SMEs face.

Lord Birt Portrait Lord Birt (CB)
- Hansard - -

My Lords, I will also speak to all the other amendments in my name, which are all supported by the noble Lord, Lord Londesborough, and some by others of your Lordships.

The Bill in its present form, as others have already said, is extraordinarily limited in scope and ambition—well short, for example, of the scope of the EU’s own NIS2 and its Cyber Resilience Act. One likely and highly unwelcome consequence of this shortfall is that, if the Bill passes in its present form, the UK will be even less well defended than our equivalents in Europe and even more of an attractive target for the bad actors than we are now.

Taken together, my amendments would, first, create a single regulator, the “Office for Cyber Resilience”, or OCR; secondly, they would extend the scope of the Bill to all services that have a material impact on the UK’s economy, society or defence and security; thirdly, they would place obligations on technology suppliers, barely discussed so far, to provide safe services; fourthly, they would require relevant bodies to adjust to threats from new and emerging technologies; fifthly, they would ensure that we have sufficient and appropriately qualified cyber professionals; and, sixthly, they would enable new organisations to be brought under the auspices of the Bill as circumstances change.

Why a single regulator? Because the threat we face, as we have heard all afternoon, is enormous, from state actors, from organised criminal gangs and even from obsessive teenagers. Since Second Reading, I have been made personally aware of multiple attempted hacks; some, on the public record, have succeeded, and some have been mentioned already. In July, after Second Reading, Lewis, the self-proclaimed teenage founder of cyber criminal group ExfilSquad, stole 607,000 records from the Department for Education, declaring it “stupid easy”. Such an attack is not at present within the scope of the Bill. In late July, the police national legal database was breached, exposing data on 100,000 police officers and criminal justice professionals. That is also not in scope. In August, as the noble Viscount, Lord Colville, mentioned, customers of Manchester, Stansted and East Midlands airports had their email addresses, phone numbers, vehicle registrations and postcodes stolen in an attack that is also not in scope.

There will have been, since we all last met, many more successful breaches that we simply do not know about, many with a highly adverse impact on the organisations concerned. We need a single regulator because we need a singular focus, not a fragmented one. We need to amass all relevant knowledge in one place about the perpetrators and the vulnerabilities. We need a singular focus on how to respond to minimise attacker success.

We should extend the scope of the Bill because it focuses only narrowly on a very small fraction of the economy, the 12 national infrastructure sectors, each with its own regulator, and because the overwhelming bulk of the high-performing private sector is excluded from the Bill, including M&S and JLR. The damage to our economy can only grow. Moreover, I can see no good reason why the Government themselves, or any part of the public sector—the NHS has just been mentioned—should enjoy a carve-out and should not be brought into scope too. I note that the EU’s NIS2 does just that, with limited exceptions.

My amendment on scope proposes that services that have a material impact on society, the economy or our defence and security should be deemed essential and should have an annual, independently conducted cyber resilience audit alongside the annual, independently conducted financial audit they all have now. For those concerned, rightly, about a possible burden on SMEs, I point out that there are around 6 million private sector businesses in the UK, but that 8,000 with more than 250 employees—less than one-fifth of 1% of the total—produce around half of all private sector turnover, so that only a tiny fraction of businesses would be included within the regulatory orbit of the OCR as I have defined it.

Why place obligations on suppliers? Because while some breaches occur because of poor practice within recipient organisations—falling for scams or failing to introduce multi-factor authentication, for example—at least an equivalent number of breaches result from providers selling insufficiently robust services or not closing down vulnerabilities speedily once they become apparent. In July, the supplier of a service to over 1,000 UK charities and non-profit organisations was breached and personal details and donations paid by multiple donors were stolen—a supplier not in scope.

Cars were once sold absent of all safety functionality—seat belts, airbags and the like—but Ralph Nader put an end to all that, thank goodness. The EU has the Cyber Resilience Act. We need an OCR to ensure that the UK’s modern technology suppliers provide safe-to-use and secure services. Why arm the OCR with the power to require relevant bodies to adjust to threats from new and emerging technologies? I think we have just had the answer to that question in spades, from quite a few devastating contributions—for me, the most affecting was from the noble Lord, Lord Tarassenko. New technologies like agentic AI pose an existential threat now. We all appear to agree about that. They are already escaping their minders and practicing trickery. They are in effect unregulated, but they simply must be—I only hear agreement on that question.

The only slight note of caution that I strike is that technology is changing all the time, so we cannot have a Bill which has such an amount of detail in it. I think it was the noble Viscount, Lord Camrose, who suggested it should be more principle-based. We cannot have something with lots of fine detail in it because things will change. Only one person so far has mentioned quantum technology, which will potentially have an even bigger impact down the line than AI. The UK, by the way, has the second highest number of quantum start-ups of any country in the world, second only to the United States.

Why give the OCR a role in the oversight of training and qualifying cyber professionals? Plainly, there are other ways of skinning this particular cat. However, I note how very poor all Governments have been over time in strategic skill planning—viz dentists, for instance. The previous Government’s founding of the Cyber Security Council was a valuable innovation. It is early days but, since its inception, it has qualified 1,761 professionals, 570 in the highest “chartered” category. Purely informal estimates, however, indicate that. across the UK economy as a whole, we will need something like 50,000 to -60,000 qualified cyber professionals, and the sooner we have them, the better.

We have a long road ahead, and with an OCR defined as the “powerhouse” of cyber security and abreast of the scale and nature of offending and vulnerabilities, it would be best placed to vouchsafe that the Cyber Security Council’s qualification standards are bang up to date. I suggest it should report annually on whether the numbers are sufficient and whether we are on track to produce the scale of cyber professionalism that both the public and private sectors will require.

Finally, why enable the OCR to recommend to the Secretary of State the expansion of the definition of an “essential service” to be brought under OCR regulation? Government can be a slow-moving, bureaucratic tangle and an independent, informed and focused regulator with just one job to do is much more likely to act with due urgency and identify vulnerable but critical and essential services that need to be brought under scope.

The noble Lord, Lord Arbuthnot, a gentle and much-respected man in the House who is careful with his words, described this Bill at Second Reading as “a muddle”. I fear that that was understatement. This Bill has been too long in the genesis. It completely fails to deal with the world as it has developed, as the most experienced and acute cyber professionals describe it and as the worst of its victims have experienced it. I implore the Minister to recognise that this is not a partisan matter, as has been very clear from our proceedings this afternoon. There are profound reservations across the Committee about the Bill as presently constructed. As the noble Baroness, Lady Kidron, just did, I urge the Minister to use the period between now and the Bill’s next stage to engage widely, open-mindedly and meaningfully with those who wish to improve it. I beg to move.

Lord Londesborough Portrait Lord Londesborough (CB)
- Hansard - - - Excerpts

My Lords, I shall speak to Amendments 7, 9, 11, 76, 77 and 88 to 91 in the name of my noble friend Lord Birt, each of which I have added my name to, and to Amendment 87 in the name of the noble Lord, Lord Clement-Jones.

Football Governance Bill [HL]

Debate between Lord Birt and Lord Londesborough
Lord Birt Portrait Lord Birt (CB)
- View Speech - Hansard - -

There is a potential conflict on both sides. There are many different roles in media but obviously, it is a single role that might be filled here. I would feel very uncomfortable if someone were sitting in both camps, were I to be in the decision-making capacity ever again in a broadcast organisation.

Lord Londesborough Portrait Lord Londesborough (CB)
- View Speech - Hansard - - - Excerpts

My Lords, I shall address Amendment 40 in the names of the noble Lords, Lord Parkinson and Lord Markham.

Before I do, I have remained silent for the last few days, taking in what has been said. I have a problem with Amendment 40, which I will come on to in a moment, but I want to reflect on the role of the regulator and the CEO. We are now on day three in Committee. It is important that both sides—I am trying, as a Cross-Bencher, to act as an honest broker—work productively and do not lose sight of what the majority of us want, which is to establish a new regulator with a clearly defined remit that does not stray into areas of overregulation or overreach.

That is not to say that issues such as environmental sustainability, CSR, women’s football or player welfare are not important; they are, but if we do not focus tightly on the core responsibilities of the regulator, I fear we are going to end up with a very complicated Bill that lacks pragmatism and leaves the regulator, whose salary I will come on to in a moment, in a pretty unworkable and unpopular role, at increasing expense to the football clubs in terms of the licence fees. I am thinking here particularly of the clubs in tiers 3, 4 and 5.

I would like to bring back a bit of financial perspective to this debate. Remember, financial sustainability is really what brought us here. Yes, there is fans’ engagement, but we have rather lost sight of that. The Premier League is the richest and most-watched league in the world, a fantastic creator of jobs and a multibillion-pound generator of exports. However, we have warning lights flashing on our dashboard that we ignore at our peril.

Total debt across the Premier League is fast approaching £4 billion—not the £2 billion that one of your Lordships mentioned on Monday—and that figure comes from the University of Liverpool. Losses across the Premier League are running at close to £1 billion per annum, per season. As we have heard, typically, 16 to 17 of its clubs generate losses, while in the Championship 80% of clubs have negative equity, and not one of those clubs generates an operating profit outside of player trading.

Having said that, I appreciate that we need to strike a balance and not interfere unnecessarily. I have listened carefully, this week and last week, to the noble Baroness, Lady Brady, among others, when she spoke about the danger of overreach and the need to be careful that we do not kill off the ambition, aspiration and calculated risk-taking of clubs—in other words, that we do not kill off the excitement and jeopardy of the game, which of course involves financial risk. That is a really important point.

Taking that into consideration, we need to be disciplined and define the parameters of the IFR with an eye on realism, pragmatism and effectiveness. The Bill runs to 120 pages, with 99 pages of Explanatory Notes. We have 340 amendments, which, thankfully, are reducing—and I think we are still on page 4. That is not a great advert for productivity.

Anyway, that is enough background from me. I return to Amendment 40. We are going to need a CEO of the highest calibre for the regulator, and that CEO is going to have to show great leadership skills and profound and relevant domain experience. Capping his or her salary at ÂŁ172,000 per annum will simply make the recruitment of a high-calibre CEO that much more difficult. I appreciate that we need to control costs, but that is not the area in which to do it.