All 1 Debates between Lord Birt and Lord Russell of Liverpool

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Lord Birt and Lord Russell of Liverpool
Lord Russell of Liverpool Portrait Lord Russell of Liverpool (CB)
- Hansard - - - Excerpts

My Lords, I echo the words of the noble Baroness, Lady Kidron: in the previous group, we probably would not have had anything like that debate if a clear strategy were indeed in place.

I will speak very briefly and in the context of other countries’ views of the safety and security of doing business with the UK and UK entities. Part of the backdrop is an attempt by His Majesty’s Government to try to do a reset with the EU, not least because of the problems we are having with our erstwhile colonial possessions across the Atlantic. We need to be viewed as a safe haven for the security of our business and data. If we look at what the EU, for all its bureaucratic idiosyncrasies, has been doing with NIS2, in many instances that is an extremely good model for us when looking comprehensively at the different sectors that need to be involved. NIS2 covers energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ISP services, public administration, space, postal services, waste management, chemicals, food, manufacturing, research and other critical parts of the economy. The EU is ahead of us and has done a great deal of groundwork; if we were to talk to the EU, we could benefit hugely without reinventing the wheel.

It is imperative not only that we give noble Lords and parliamentarians a feeling that we know what we are doing and where we are going but that other countries currently doing, or thinking of doing, business or more business with us have faith in the security of our data and cyber security infrastructure. If I were looking to invest in a company, that is an area I would look at very carefully—but, frankly, at the moment, I would not feel very confident.

Lord Birt Portrait Lord Birt (CB)
- Hansard - -

My Lords, these amendments are highly pertinent. We simply must ensure that non-UK providers of services in this sector are firmly and wholly within the scope of the Bill—they are only partly in scope. For noble Lords who were not at Second Reading, I read out a coruscating report by the American Government that damned Microsoft for its poor cyber security. I am sure that it is not true across the whole of Microsoft, but in that particular instance it manifestly was.

I observe that our previous debate was absolutely excellent; it uniformly focused on organisations in the UK that are providing services. There was a danger that somebody hearing that debate might think that all those organisations are themselves responsible for breaches. The data on whether breaches chiefly occur through failures in organisations mentions the absence of multifactor authentication or that they are caused by failures in the quality and design of the services that those organisations consume. By the way, the organisations consume literally hundreds and hundreds of services, and the reality is that it is a huge challenge for organisations to ensure that all the services that they buy are secure. We might say that it is a near impossibility. Again, it is absolutely vital that we keep providers firmly within the scope of the Bill—I am not saying that they are not there, but they are certainly not there in their totality—and, dare I say, firmly under regulation.