AI: Human Extinction

Lord Clement-Jones Excerpts
Tuesday 15th September 2026

(1 week, 6 days ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

My noble friend raises a number of interesting points. It is true that we need to address this internationally. AI clearly crosses national borders. It is not like previous forms of new technology. We need to find the way forward in getting the balance right. We have been using our opportunity to lead internationally in having those conversations across borders as one of the leaders in AI safety.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I declare an interest as a consultant to DLA Piper on AI regulation and policy. Just two weeks ago, the Government resisted a proposal from Members right across this House to introduce an AI kill switch into cyber legislation on the grounds that the Government were “technology agnostic”. How agnostic does the Minister feel today?

Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

I presume that the noble Lord is referring to the amendment tabled to the Cyber Security and Resilience (Network and information Systems) Bill. One of the things that we have done is introduce the Bill and the guidance to work through that. I know that my noble friend Lady Lloyd will be happy to talk further with the noble Lord about this. One of the issues with a kill switch is that it would be impossible for Britain simply to turn AI off. Another issue is the extent of people’s concerns about whether a kill switch could or would work, but I know my noble friend Lady Lloyd would be delighted to speak further to the noble Lord.

Moved by
92C: Clause 37, page 62, line 24, leave out subsection (7)
Member’s explanatory statement
This probing amendment would remove the power for the Secretary of State to amend this Act by regulations so as to change the consultation and parliamentary scrutiny requirements applying to a code of practice. It responds to the recommendation of the Delegated Powers and Regulatory Reform Committee in its 7th Report.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I think that we are in the final furlong. In moving my Amendment 92C, I will also speak to the closely aligned Amendment 95C under my name. These amendments raise a profound and non-negotiable constitutional principle. They respond directly to the almost always authoritative recommendations of the Delegated Powers and Regulatory Reform Committee in its seventh report of this Session and are strongly supported by the principles laid down by the Select Committee on the Constitution in its third report. Together, these amendments seek to delete two deeply objectionable provisions that represent a classic example of secondary legislation creep—provisions where the Executive are seeking a blank cheque to unilaterally rewrite the rules.

Amendment 92C targets Clause 37 and seeks to leave out subsection (7). Under the Bill as drafted, Clause 37(7) grants the Secretary of State the unilateral power to make regulations to amend the Act to change and potentially dilute the consultation and parliamentary scrutiny requirements that apply to a code of practice. This is a Henry VIII power of quite an extensive kind. In the Government’s original delegated powers memorandum of November 2025, the department, as it then was, argued that this power was necessary to allow flexibility in case a 40-day parliamentary scrutiny period became, in its words, “unfeasible” or

“a detriment to the quality of … a code”.

But as the Delegated Powers Committee correctly noted in its seventh report, the rules governing how Parliament scrutinises the Executive must be set by Parliament in primary legislation; they should not be subject to the administrative convenience of a Minister. Allowing a Minister to use secondary legislation to alter or weaken the very procedural safeguards that this House has debated is not constitutionally correct. The committee’s recommendation is clear and unambiguous: subsection (7) must be removed.

That brings me to Amendment 95C, which seeks to leave out Clause 40(5). Clause 40 requires the Secretary of State to lay a report before Parliament on the operation of this cyber security legislation. However, subsection (5) grants the Secretary of State the power to amend this primary legislation via regulations to change the matters to be covered in those same reports. Again, in their original November 2025 memorandum, the Government defended this by claiming that they needed flexibility to ensure that reports could be expanded over time as technology matures.

With the greatest respect, that argument is entirely spurious. If the Government merely wish to report on more things, they are already fully entitled to include voluntary supplementary chapters in their reports. But by granting themselves a statutory power to amend the legal requirements of Clause 40, they are taking the power to delete or dilute the core mandatory reporting obligations that Parliament has put in the Bill. They would, in effect, be legally empowered to write their own report cards, deciding behind closed doors what they must disclose to Parliament and what they can quietly omit, including critical scrutiny over how they have used the vast delegated powers under Clause 29(1).

The Delegated Powers Committee was again clear. This power is inappropriate, lacks coherent justification and should be deleted from the Bill. The Select Committee on the Constitution too, in its third report, expressed serious anxieties about the overall design of the legislation. It warned that this is a framework Bill that relies far too heavily on secondary regulations to establish the actual perimeters of national cyber resilience.

When a Bill already delegates such sweeping unprecedented powers to the Executive, amplified by the amendments to introduce a parallel high-risk vendor framework, laid on 24 August and discussed on the first day of this Committee, it is doubly important that the statutory channels of parliamentary oversight remain supreme. We cannot allow the Government to use secondary regulations to dismantle the guardrails that keep them accountable. I urge the Minister to accept these common-sense, committee-backed corrections and agree to delete Clause 37(7) and Clause 40(5) before Report. I beg to move.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Clement-Jones, for opening the final day of Committee. For a Bill of such importance, I am surprised at the speed of our progress. However, if quantity has been low, quality has more than compensated.

I agree with the noble Lord that this Committee deserves rather more justification from the Government as to the need for the powers they are granting themselves. The Delegated Powers and Regulatory Reform Committee described the Clause 37(7) power as “unusual” and “novel”, capable of watering down requirements for consultation as it is not constrained by set criteria. The Government’s justification thus far for this power is that it allows them to

“prioritise the content of the code of practice, rather than arbitrary requirements”.

It sounds to me rather as if the Government’s position is that they see any set requirements for consultations and codes of practice as arbitrary. If that is the case—I would appreciate clarification from the Minister—I have to agree with the committee’s description that the position is “quite extraordinary”.

By the way, I noted this morning that the Chancellor of the Duchy of Lancaster has demanded an end to the culture of consultation. I fear that that will be quite a wrench for the former DSIT and its functions, it having launched four new consultations on a single day in July without having responded to the more than 11,000 responses to the AI and copyright consultation. We are already unclear about the machinery of government for that former department. Can the Minister tell us whether its existing and planned consultations will continue or whether today’s announcement represents a fundamental change of approach?

It is not clear why the power conferred by Clause 40(5) has to be sufficiently broad to allow the Government to water down the contents of reports on network and information systems. Could it not be amended, as the committee has recommended, so that the power cannot be used to reduce the requirements to report? It is not unreasonable to question whether the Government really need these extensive powers. Your Lordships’ Committee deserves at least more justification than the Government describing set criteria as arbitrary. I appreciate the need for flexible and adaptive approaches to legislating for fast-moving technologies, but that must come with accountability and I am not sure that we have the balance right at this point. I look forward to the Minister’s response.

Baroness Ramsey of Wall Heath Portrait Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
- Hansard - - - Excerpts

I thank the noble Lord for his Amendments 92C and 95C, and note that these amendments were recommended by the Delegated Powers and Regulatory Reform Committee in its report of 17 July. Some noble Lords may be aware that, until very recently, I was the chair of that committee. I am wondering how best to describe myself: am I gamekeeper turned poacher or poacher turned gamekeeper? I had better let noble Lords decide at the end of my responses.

These delegated powers were included to prevent a scenario where procedure takes priority over the best possible products, whether that be a code of practice or a report on the legislation. The delegated powers will not allow Ministers to bypass Parliament. They are about ensuring that government can respond quickly and effectively to new threats and new technologies that could undermine our national security. The law has always been slower than innovation, and it is unlikely to catch up unless we change our approach. Ministers must provide clear justification and carry out assessments before regulations are laid before Parliament.

On the code of practice, we anticipate that any code will be updated from time to time to remain effective, in line with the latest recommended good practice, evolving threat information and emerging technologies. Any revisions and reissues of a code of practice must first be consulted on with relevant stakeholders before they are effective.

On consultations, it might be above my pay grade to comment so soon after the Chancellor of the Duchy of Lancaster has commented, but I am sure that my noble friend the Minister will have a further response to that at some point, possibly in writing.

I assure noble Lords that the Government are carefully considering the committee’s recommendations and the views of noble Lords today, and will reflect accordingly ahead of Report. My noble friend the Minister will respond formally to the Delegated Powers and Regulatory Reform Committee in the usual manner ahead of Report.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I thank the Minister for her response, which was the reverse of the usual ministerial response—the sting was not in the tail but at the beginning. The end was much more conciliatory, given that she said the Government will consider taking on board the DPRRC’s recommendations before Report. I very much hope they do. At this stage in Committee, of course, nothing gets decided, but I assure the Minister that, if this continues, and the Government do not respond in some shape or form to both those pretty solid recommendations from the committee, we will bring this back on Report.

When I say that the sting was in the beginning of the response, I mean that it was a bit surprising, given that the Minister has been the chair of the committee and knows the seriousness with which we all take its recommendations. A huge amount of work goes into the detail, and she knows how much store we place on the recommendations. I hope that she will use all her influence to make sure that the Government introduce before Report something along the lines of what I have produced. In the meantime, I beg leave to withdraw Amendment 92C.

--- Later in debate ---
Baroness Northover Portrait Baroness Northover (LD)
- Hansard - - - Excerpts

My Lords, all the amendments that I have put down to the Bill are derived from evidence we received on the National Resilience Select Committee. I am sorry that I was not here last week to address those that came up then, and I am very grateful to my noble friend Lord Clement-Jones for presenting them for me.

Several members of the Select Committee, including me, were in Finland last week looking at its preparedness for attack. Finland has faced the threat from its long border with Russia throughout the history of its country, and its preparedness on a whole-of-society basis is extremely impressive. Although we do not have a long border with Russia to focus our minds, we know that cyber attacks can immediately undermine our whole society and economy. One of the things we heard on our Select Committee is that not only are many companies unprepared for cyber attacks but that there is a shortage of skills in this area.

This amendment is seeking to move things forward. The proposed new clause would

“give the UK Cyber Security Council statutory functions to validate qualifications, to monitor the supply of and demand for cyber security professionals in the areas covered by the Bill, and to audit whether regulated organisations employ certified professionals—a ‘competence mandate’ for the regime”.

I have received some useful information from the sector, which welcomes my attempt to try to ensure that we have sufficient cyber professionals and that there is a mechanism by which they are certified. There are analogies with the certification of medical professionals, for example. Their certification is conducted independently, and I recognise the importance of that. What I am arguing for here is the principle and not necessarily the route suggested by my amendment. How this is best done can be further discussed between Committee and Report.

The National Cyber Security Centre reported that nationally significant cyber incidents have more than doubled in a year. According to its survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain. Evidence to our Select Committee suggests that skills shortages are a key challenge here, especially for SMEs and those in the public sector. It is clear that cyber education, training and apprenticeships, and so on, must accompany these reforms.

The Bill places greater responsibility on organisations to identify and manage cyber risk. However, beyond those technological solutions, these obligations will require skilled professionals to carry them out. The Bill refers to the appointment of a “skilled person” in the context of a national security directive but does not delve into what constitutes a skilled person. I realise that this will change over time, but there should be ways of addressing this.

Neither does the Bill acknowledge the role of skilled persons in delivering its wider objectives. Those in the field have called on the Government to amend the Bill to require organisations to access a cyber security workforce that is qualified to recognise professional standards. We know that this skills shortage exists, weakening our national resilience. One report showed that 87% of organisations experienced at least one consequence due to skills need, so it is becoming strategically important to address this. The Government should use the Bill as an opportunity to professionalise the sector by committing to a cyber security workforce and skills strategy, and mandating that regulators and regulated entities use suitably skilled people for the purposes of compliance with the regulation.

Recognised professional qualifications and certifications anchored in international standards should be required so that we and the regulators are reassured that the work is being carried out to a certain standard. The UK Cyber Security Council was granted royal chartered status to establish a self-regulating, politically independent professional body, structured on proven models of other professional bodies such as the GMC. The UK needs to transition from a fragmented patchwork of varying certifications to a unified national standard of professional competence and ethical conduct.

Therefore, the Bill should recognise the council as the authority for setting and maintaining these standards. Given that the Bill aims to enhance the security and resilience of the UK and the critical sectors that underpin our economy, that needs to be assisted by a suitably skilled workforce to implement it. Of course we need to take further action to make sure that we train people, but this amendment is designed to help move this forward by ensuring that those in this area are sufficiently skilled. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I was hoping that there would be other contributors—there will be a double-banking on this amendment.

I support Amendment 99, tabled by my noble friend. Throughout our deliberations on this Bill, the Government have placed enormous emphasis on imposing tough, outcomes-based statutory duties on operators and suppliers across our critical infrastructure, but we must confront an uncomfortable truth: we can pass the most sophisticated cyber security regulations in the world but, if our economy lacks the trained, qualified human beings required to design, implement and maintain those defences, those regulations remain completely meaningless. Without a professional workforce capability, this Bill merely codifies what ISC2 has rightly termed “compliance theatre”—an expensive box-ticking exercise that produces mountains of paperwork without making our national networks one bit safer.

Look at the scale of the crisis facing our domestic cyber workforce. In its landmark 2025-26 cyber security workforce study, ISC2 revealed that 52% of UK cyber security professionals identify severe skills shortages as their single greatest barrier to complying with cyber regulations. Further, 58% of organisations reported a critical or significant skills deficit, with an astonishing 87% suffering direct operational consequences from missed system patches and delayed vulnerability remediation to active security oversights. Across the civilian economy, the UK currently faces an 88% shortage of certified cyber practitioners. In an environment of such extreme scarcity, how on earth do the Government expect regulated water utilities, transport operators and medium-sized managed service providers to fulfil the heavy duties created by this Bill?

Amendment 99, from my noble friend, would provide a structural solution to this workforce crisis by placing the UK Cyber Security Council on a formal statutory footing. Crucially, as she explained, this connects directly to the definition of a skilled person under Clause 43. If the Government are serious about raising our national resilience floor, they must recognise that human competence is just as vital as technological hardware. By embedding the UK Cyber Security Council’s competence mandate in primary legislation, Amendment 99 would ensure that our cyber laws are backed by the skilled workforce needed to defend us.

I strongly urge the Minister to accept this amendment. By professionalising our cyber workforce, we would elevate this Bill from more than a compliance exercise to a genuine national capability.

Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - - - Excerpts

My Lords, I intervene in support of the amendment in the name of the noble Baroness, Lady Northover. I do not want the Liberal Democrats to be on their own, so I hear the call from the noble Lord, Lord Clement-Jones. It brings me back to the coalition days, when I and the noble Baroness, Lady Northover, were once Ministers in the same department—so my support is heartfelt.

I support the substance of the amendment. As the noble Baroness, Lady Northover, says, it may not necessarily be the right amendment but the spirit behind it is absolutely one that the Government should recognise. I was a bit concerned when the noble Baroness was outlining the intention behind the amendment whether it could perhaps be seen as a burden on business, particularly when we talk about small businesses and the need to audit their cyber preparedness. However, to recall my contribution at Second Reading, I said at the time that, although we tend to debate cyber in the Chamber and other places as a great threat that we need to address, it is also a fantastic economic opportunity. I should declare that I am an adviser to a company called Digital Futures, which trains software developers. We do not train them in cyber but obviously the need to build up a skilled workforce in cyber is absolutely essential.

The noble Baroness, Lady Northover, referred to the patchwork of qualifications that exist in this area. It seems to me that the Government have a clear opportunity and a clear role to guide us through the maze and to put the National Cyber Security Centre on a statutory footing to give it the ultimate role in deciding the appropriate qualifications in cyber and to begin a sustained campaign to show young people, people returning to the workforce or people who are considering a new career that there is a route through to recognised, well set out cyber qualifications that will contribute to the national economy and our cyber resilience. I therefore wholeheartedly back this amendment.

--- Later in debate ---
Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

I think we all share the sympathy that the noble Baroness, Lady Northover, has identified SMEs need. There are 5.7 million SMEs in the UK and many of them—indeed, most of them—will purchase what are relatively complex platforms. The noble Lord, Lord Londesborough, is extremely experienced in the SME sector; I have less experience than him, but I do have some. Hardly any of them will be able to employ anybody who is able to understand either the complexity of the platform that they have purchased or the highly dynamic threats to that platform that exist. There are many ways in which we need to raise our game and to help.

I personally think that, at least in the short term, the most important thing, which we have not discussed enough so far, is to require providers to supply safe products and, moreover, when they become vulnerable—which happens all the time, often unexpectedly—to patch those products for their customers immediately. The providers have a level of sophistication that the customers do not, and we have insufficiently focused on that in our discussion so far.

The second thing to mention—this is not really part of the Bill—is that the Government’s Cyber Essentials programme is very sound. The Minister quoted a figure the other day, which I forget, but only a trivial number of businesses have signed up and taken the pledge. This needs much more publicity and much more dynamism from within government to raise the understanding of the level of threat that SMEs face.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I too support Amendment 100, in the name of my noble friend Lady Northover, and will add my support to the very useful speeches from the noble Lords, Lord Vaizey, Lord Birt and Lord Londesborough. I entirely agree with the noble Lord, Lord Vaizey, about the need to inject a sense of urgency into this. The noble Lords, Lord Birt and Lord Londesborough, asked some very fair questions, which went back to some of the debate we had on a single regulator and product liability, all of which are relevant to the kinds of duties that SMEs are under.

I welcome what the Minister had to say about the Government’s consciousness of the needs of SMEs, but this amendment would provide a blueprint for a much better form of support for SMEs. They account for 99% of all private sector businesses but, as the NCC Group and industry experts have repeatedly warned, they represent what might be described as the soft underbelly of our national supply chains. They are the prime targets for cyber criminals seeking a backdoor into critical infrastructure.

It is completely unrealistic to expect a 60-person small supplier to bear the same heavy compliance overheads as a multinational utility. A single ransomware attack can permanently destroy a small firm. Hostile state actors and ransomware syndicates are no longer focusing exclusively on attacking the fortified perimeters of FTSE 100 utilities or government departments; instead, they deliberately target smaller, resource-poor suppliers and niche contractors embedded in tier 2 or tier 3 of critical supply chains, using them as an easy, undefended backdoor into our critical national infrastructure.

Under the expanded critical supplier provisions in Clause 12 and the managed services duties in Clause 9, thousands of medium-sized businesses and specialised tech vendors will now be pulled directly into the statutory NIS regime, facing severe regulatory requirements under threat of multi-million pound penalties. However, as the Government’s own impact assessments acknowledge, there is a staggering what might be called resource asymmetry across UK businesses. A 50-person specialised component manufacturer or regional logistics provider does not have a dedicated chief information security officer or possess a 24/7 security operations centre and cannot afford to hire elite forensic incident response teams on £500-an-hour retainers. When a sophisticated ransomware attack hits a small business, it is frequently an existential event that forces insolvency.

During Committee stage in the Commons, when my honourable friend Freddie van Mierlo MP brought forward this proposal, the Minister in the Commons rejected it on the grounds that the Government already provide voluntary advice online. A downloadable PDF checklist on GOV.UK is not an incident response service. When a small critical supplier is locked out of its servers by a Russian ransomware gang at 2 o’clock on a Sunday morning, a generic website checklist is completely useless. It does not need advice to check its passwords; it needs an active, human, technical first responder to help it contain the malware, isolate compromised systems and safely recover its data.

Amendment 100 would bridge this capability gap by mandating a dedicated national support service modelled directly, as my noble friend explained, on the proven and globally respected Australian Cyber Security Centre’s framework. In Australia, the federal Government provide small and medium-sized businesses with free direct phone-in emergency technical support, active breach triage and hands-on recovery assistance. It has achieved extraordinary success in hardening Australia—

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

To continue, if the state is going to impose heavy, legally binding supply chain security duties on small businesses, backed by turnover-based fines, the state has a moral and strategic obligation to provide the operational tools needed to meet those standards. By establishing a free, Australian-style digital safety net under Amendment 100, we would turn the Bill from a purely punitive compliance exercise into a genuine co-operative national partnership for cyber resilience, and I urge the Minister to accept this vital common-sense amendment.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness, Lady Northover, for her amendment and, needless to say, I support the intention behind it. It is clearly right that, having placed several new duties on businesses and their vendors, the Government consider how to ensure that they are able to carry them out. This is particularly the case for SMEs, which are often far less resilient, less well-resourced and more vulnerable to cyber attacks than their larger counterparts. But, when thinking through this idea, I was trying to come up with some sort of framework to estimate the costs of such a provision, and I just could not arrive at a satisfactory estimate, except that they would be very considerable, particularly given the urgency, complexity and difficulty of incident response.

As I think the noble Lord, Lord Clement-Jones, and others mentioned, providing advice on a government website is cheap and useful, but providing urgent incident response is far from cheap. That begs the question: would it be funded by the companies benefiting from this directly or the taxpayer? I am not sure that either is wholly satisfactory. The actual costs of running such a programme will depend largely on how it would operate and the terms of service it would offer. I am very grateful to the noble Baroness, Lady Northover, for pointing to the Australian example; I confess that I was unaware of it before and would be interested to know what service it provides and to what level. It is incredibly hard to estimate how it will operate and what terms of service it will offer. The rate of cyber attacks is non-linear, the scale, nature and complexity of each attack will vary significantly and the number of staff needed or resources available for a response at any one time would necessarily be volatile and unpredictable.

--- Later in debate ---
Moved by
148A: After Clause 52, insert the following new Clause—
“Appeals against decisions under section 50(1) A person may appeal to the Upper Tribunal against—(a) a confirmation decision given to the person under section 50;(b) a decision under section 50 to require the person to pay a penalty;(c) the amount of a penalty which the person is required to pay under section 50.(2) An appeal under this section must be brought before the end of the period of 28 days beginning with the day on which notice of the decision appealed against was given to the person, or within such longer period as the Upper Tribunal may allow.(3) The Upper Tribunal must determine an appeal under this section on the merits and by reference to the matters before it, and not by applying the principles that would be applied by a court on an application for judicial review.(4) On an appeal under this section the Upper Tribunal may—(a) confirm, vary or cancel the decision appealed against,(b) substitute for that decision any decision that the Secretary of State could have made, or(c) remit the matter to the Secretary of State with such directions as the Upper Tribunal considers appropriate.(5) Where an appeal is brought under subsection (1)(b) or (c), the requirement to pay the penalty is suspended until the appeal is determined, withdrawn or abandoned.(6) Tribunal Procedure Rules must make provision, for the purposes of proceedings under this section, about—(a) securing that information is not disclosed where disclosure would be contrary to the interests of national security,(b) the holding of proceedings, or of parts of proceedings, in the absence of a party or a party’s legal representative, and(c) the appointment of a person to represent the interests of a party in proceedings, or parts of proceedings, from which that party and that party’s legal representative are excluded.(7) Nothing in this section affects any right to apply for judicial review.”Member’s explanatory statement
This new clause would provide a right of appeal to the Upper Tribunal, on the merits, against a confirmation decision or a financial penalty imposed under section 50, with provision for the protection of national security material. It implements the recommendation of the Constitution Committee in its 3rd Report.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, Amendment 148A stands in my name on the Marshalled List. This amendment would address a profound, structural and deeply disturbing gap in the judicial oversight and democratic accountability of the Bill. It represents a direct implementation of the authoritative recommendation of the Select Committee on the Constitution, in its third report of this Session.

Under Clause 50, the Secretary of State, acting as the direct enforcement authority for national security directions, is empowered to issue a unilateral confirmation decision that potentially imposes hugely significant financial penalties on non-compliant organisations. Under Clause 49, these penalties can reach a peak of up to £17 million or 10% of global turnover for commercial undertakings. Even for non-undertakings—such as our cash-strapped NHS trusts, local government authorities, or educational bodies—the penalty can be a crushing £17 million, with daily ongoing fines of up to £100,000 per day. Yet, under the Bill as currently drafted, the Government expect us to accept that the only avenue of legal recourse for an affected organisation to challenge these business-destroying fines is judicial review in the High Court.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I resume with Amendments 174A and 174B, which were introduced by the noble Lord, Lord Markham. They would require the Secretary of State to create a register of “foreign powers” that pose a threat to UK cyber security, to review this register and to lay the report in Parliament. This is intended to inform the use of the powers granted under Part 4 of the Bill. The noble Lord is right that hostile foreign actors pose a clear risk to our essential services. National security is the first responsibility of any Government, which is why we are addressing these risks actively, including through the Bill.

The Bill will grant the Secretary of State important new powers to issue national security directions to regulated entities or regulators, where their compromise poses a national security risk. We will seek to strengthen the Government’s national security toolkit further, to protect our supply chains from hostile actors. That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.

Any decision to use the powers in the Bill will be informed by expert national security advice, including from GCHQ. The direction powers provide a strategic case-by-case basis to safeguarding our national security, irrespective of the specific actor. As a result, a country-specific approach lacks the nuance required to assess and respond comprehensively to all relevant risks. We also need to proceed responsibly in how we categorise and present these risks in the public sphere.

That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber risks where it is appropriate to do so. As the noble Lord, Lord Markham, set out, the NCSC annual report highlights risks posed by foreign actors; we work with the NCSC to mitigate these risks.

I note that noble Lords have confronted this question before, notably during the passage of the Telecommunications (Security) Act, where there was cross-party support for vendors to be assessed on a case-by-case basis, rather than by designating nations themselves as hostile actors. I hope that, in that vein, noble Lords are reassured that the Government have the tools to act strategically, acting on the right intelligence where hostile states seek to do us harm.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I thank the Minister for her response and the noble Lords, Lord Vaizey and Lord Markham, for their contributions. I cannot help feeling that the approach to this by the noble Lord, Lord Vaizey, is coloured by his history as a Minister. I can understand that because I saw the frustration within Ofcom over the type of judicial review. It was a particular type of judicial review: it was not a full merits-based appeal, but it allowed merits to be considered as part of the judicial review process. Subsequently, that was changed, which has probably calmed the way in which appeals are carried on.

However, in this particular case, although he said that he was not sighted as to the secrecy aspects of this, it was quite interesting to hear what the noble Lord, Lord Markham, had to say. He started by saying that he supported the amendment, then—rather coloured, I think, by the response of the noble Lord, Lord Vaizey—he did a bit of a U-turn halfway through what was a speech originally written in support. I am sure that he knows in his heart that this is the right one.

Really, the argument in this case is expediency versus justice. I think that choosing expediency, especially in the light of what the Constitution Committee had to say, would be extremely inadvisable. I was encouraged by the fact that the Minister is producing a memorandum in response to the Constitution Committee; we all wait with bated breath for when that arrives. In the meantime, I beg leave to withdraw my amendment.

Amendment 148A withdrawn.
--- Later in debate ---
Moved by
164: After Clause 58, insert the following new Clause—
“Computer Misuse Act 1990: statutory defence for cyber security activities(1) The Secretary of State must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 (unauthorised access to computer material) for persons carrying on legitimate cyber security activities is necessary or desirable to improve the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.(2) The review under subsection (1) must consider, in particular—(a) the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith,(b) the conditions and safeguards (including as to authorisation, proportionality and reporting) that any such defence should contain, and(c) the approaches taken in other jurisdictions.(3) On concluding the review, the Secretary of State must lay before Parliament a report which sets out—(a) the findings and conclusions of the review, and(b) whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so.”Member’s explanatory statement
This new clause seeks to place a statutory duty on the Secretary of State to review, within 12 months, whether a statutory defence under section 1 of the Computer Misuse Act 1990 for good-faith cyber security researchers and vulnerability testing is needed to improve the UK’s cyber resilience, and to report to Parliament.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, Amendment 164 is in my name and, I am delighted to say, that of the noble Lord, Lord Arbuthnot of Edrom. Sadly, he is tied up next door with matters of national security—I hope that I am not giving away any secrets—and is unable to speak to this amendment, but I value the support that he has given as a long-standing campaigner for changes to the Computer Misuse Act.

This amendment addresses a long-standing, globally recognised and increasingly dangerous absurdity in our criminal law: the fact that our primary cyber crime statute, the Computer Misuse Act 1990, criminalises the very cyber security professionals who are actively working to defend our country. The Computer Misuse Act is now 36 years old. It was drafted in 1990—an era before the world wide web had entered public consciousness, when less than 0.5% of the British public had ever sent an email and when the entire concept of proactive, ethical vulnerability research was completely unimagined. Because the Act was drafted at such a primitive stage of the digital revolution, it contains a blanket, indiscriminate prohibition on all unauthorised access to computer material. In its current form, it draws no legal distinction whatever between a malicious hacker, backed by a hostile foreign state and seeking to sabotage our critical national infrastructure, and an ethical, good-faith cyber security researcher—a “white hat” hacker, if you like—seeking to discover and responsibly disclose vulnerabilities before criminals can exploit them.

The real-world consequence of this statutory blind spot is that British cyber defenders are forced to operate with one hand tied behind their backs. Consider the day-to-day operational reality: if an ethical researcher in the UK scans an internet-facing network, identifies a critical zero-day vulnerability that leaves an NHS hospital dataset or a municipal water control system exposed, and takes the basic technical steps necessary to verify the flaw, they have technically committed a criminal offence under Section 1 of the 1990 Act. They face prosecution and imprisonment, even if their actions were undertaken entirely in good faith, strictly in the public interest and followed by immediate responsible disclosure to the National Cyber Security Centre or the affected operator.

I and others have received overwhelmingly passionate representations from the CyberUp campaign, representing what might be described as the elite of our domestic cyber security industry. Alongside the Criminal Law Reform Now Network and the NCC group, its evidence is stark. It says that the chilling effect of the Computer Misuse Act is actively undermining our national cyber resilience. Leading UK cyber security companies are routinely forced to prohibit their researchers conducting proactive threat intelligence gathering and vulnerability research on UK-based infrastructure because the legal risks are unacceptable. When British researchers identify an active cyber threat originating abroad, they are legally constrained from investigating the command and control servers if doing so involves touching a remote system without explicit owner authorisation.

Meanwhile, our international competitors have moved ahead. The United States updated its Department of Justice charging policies explicitly to protect good-faith security research. Countries such as Portugal, France and Australia have established clear and legal safe harbours for ethical cyber defenders. As a direct result, British cyber talent and commercial investment are migrating overseas to jurisdictions where proactive defence is recognised as a public good, rather than a criminal act.

During the Bill’s passage in the other place and during our Second Reading debate, the Government’s response was to agree with the principle of reform while arguing that this Bill is not the appropriate vehicle. Ministers pointed to an ongoing Home Office review and suggested that reform must wait for a hypothetical future security Bill. We have been waiting for the outcome of that Home Office review for more than five years; it was kicked into the long grass of Whitehall interdepartmental delays while our critical network remained under siege.

There is potentially a contradiction at the heart of the Government’s strategy on this issue. On one hand, Ministers are using this Bill to impose sweeping new legal duties and heavy, turnover-based penalties on operators to secure their networks; on the other hand, the Government continue to criminalise the very security professionals and ethical researchers whom these operators must hire to test and harden their systems.

Amendment 164 would resolve this contradiction cleanly, decisively and safely. It seeks to insert a direct substantive statutory defence into Sections 1 and 3 of the CMA. An individual charged under the Act would have a complete legal defence if they can prove that their conduct was reasonable for the detection or prevention of crime, or that they were carrying on legitimate cyber security activities, specifically defined in the Bill as vulnerability research, penetration testing, threat intelligence-gathering or a responsible disclosure necessary to safeguard system security.

Crucially, this amendment would not create a free-for-all or a loophole for malicious actors. It would empower the Secretary of State to approve a statutory code of practice, setting out the precise standards, rules of engagement and reporting protocols that constitute legitimate, good-faith cyber security activity. Anyone who acts outside those clear standards remains fully subject to criminal prosecution. Let us also consider the significant economic dividend of this reform. Independent economic modelling from the CyberUp Campaign demonstrates that introducing a statutory defence for legitimate cyber security activities would add 9,500 high-skilled, high-wage jobs and generate £2.5 billion in additional revenue for the UK economy.

We cannot build a resilient nation by preserving laws written for the floppy disk era. In an age of automated AI exploits and state-sponsored ransomware, we must unchain our cyber defenders. We have been here before, and the Government’s arguments for delay have run completely out of road. During our debates and correspondence on the then Crime and Policing Bill and, previously, the then Data (Use and Access) Bill, the Government repeatedly acknowledged the strength of our case. The noble Lord, Lord Katz, stood at the Dispatch Box and conceded that the Computer Misuse Act is dangerously outdated and that the Home Office were actively preparing a statutory defence under Section 1 to protect ethical cyber security researchers. Indeed, in correspondence following those debates, Ministers confirmed that engagement with industry and system owners was well advanced, but their stock excuse for resisting our amendments was always the same: “This is the wrong legislative vehicle. Wait for the upcoming cyber security legislation”. Well, here we are—this is the cyber security and resilience Bill. If primary cyber legislation cannot fix the statute that actively criminalises our front-line cyber defenders, what on earth can?

When the Government updated law enforcement powers under the Crime and Policing Act to seize domains and IP addresses, Ministers were quick to assure us that police powers are tightly bound by the Police and Criminal Evidence Act 1984 and statutory exemptions under Section 10 of the CMA. Yet independent security researchers, who discover over half of all critical system vulnerabilities before hostile state actors can weaponise them, enjoy zero statutory protections. They are left entirely at the whim of prosecutorial discretion and the threat of catastrophic legal action. The review of the noble Lord, Lord Vallance, recommended this defence three years ago. The CyberUp Campaign and techUK have drafted the ethical safeguards. In correspondence, Ministers have told us that they agree in principle. It is time to honour those commitments and put a direct statutory defence in this Bill. I urge the Minister to support this vital amendment. I beg to move.

Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - - - Excerpts

My Lords, I strongly support the amendment from the noble Lord, Lord Clement-Jones, whether technically or in spirit. He is right to point out how outdated the Computer Misuse Act is and that its blanket prohibition on undertaking cyber security activities without any public interest defence is ridiculous.

The noble Lord’s amendment goes to the heart of the frustrations that have been expressed in debates on this Bill, particularly at Second Reading; sadly, I was not able to attend Committee last week, but I imagine they were reiterated again. This is an incremental and technical Bill that clears up some important anomalies. Time and time again, noble Lords have raised the point that it is missing the bigger picture. Now that we live in a digital age when absolutely everything depends on digital infrastructure, it seems to be absolutely extraordinary that we are not taking a much bigger view on updating our legislation, institutions, resources and skill base, to make this core infrastructure fit for purpose. It seems extraordinary to me that the Computer Misuse Act has not been touched for 36 years. It is well out of date. It may well be that there are other elements of it that have to be looked at.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.

The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.

The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I thank the Minister for that response. The noble Lord, Lord Vaizey, said that we know what the Minister will say: that it will be in a future piece of legislation. To that extent, we are pleased that at least we have a commitment to it, but this has been going on for an awfully long time. We tabled amendments during the passage of the Crime and Policing Act and the Data (Use and Access) Act. There has been plenty of time for the Home Office, or any other department to address this—DSIT could have taken this by the scruff of the neck—because it is such an egregious aspect of the current legislation.

I am pleased to hear that the Minister has read the correspondence. I hope she did not fall asleep while doing so; it is pretty interminable. She may well find that we come back to this on Report because, as she said at the beginning, feelings are running high about it. It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.

I thank noble Lords who have spoken today and demonstrated support across the board. On a light-hearted note, I say to the noble Lord, Lord Tarassenko, that of course Claude said that; it is trained on my speeches. As the noble Baroness, Lady Harding, said, this is self-evidently sensible. The trouble is, it is self-evident to us, but we despair sometimes, and the perfect must not be the enemy of the good. As the noble Baroness, Lady Neville-Jones, said, the objective is to put researchers in a safe position.

Finally, the noble Lord, Lord Vaizey, exhorted me to make sure that we have a date and a timeline. When will the national security Bill come forward? We saw it in the King’s Speech but I have had no contact from anybody in the Home Office about what they might insert in the Bill. I do not know whether anybody in this Committee has had notice of when a Bill might come forward. I think the Minister recognises the sheer impatience that most of us feel in this field, and I very much hope that, between Committee and Report, we can get some more clarity in this area for the benefit of all those researchers. In the meantime, I beg leave to withdraw the amendment.

Amendment 164 withdrawn.
--- Later in debate ---
The amendment proposes a requirement for the Secretary of State to consult on achieving the minimisation of identifiable data, while looking at deletion and at what needs to be kept. It is seen as constructive. Again, if there are other suggestions, I am happy to talk about the best ways of going about this, but I very much hope that all noble Lords will see that it is a sensible and pragmatic approach to try to deal with a problem. It would remove a lot of the juicy targets—for want of better words—from a potential attack vector in the first place. I beg to move.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, despite the fact that this is the last group, it is a really important area and this amendment rightly reflects that. We strongly support Amendment 174E. It would introduce a fundamentally elegant and highly necessary cyber security principle that the Bill has otherwise completely ignored: that of data minimisation and the proactive reduction of what is called our national data attack surface.

The most sophisticated cyber defence system in the world cannot protect data that has already been stolen. Conversely, the most ruthless ransomware gang or hostile state-sponsored actor cannot compromise data that was never collected or which has already been securely deleted. In the realm of digital defence, we must move past the narrow defensive mindset of simply building thicker walls around our databases. We must begin to ask a more fundamental strategic question: why are we keeping these massive, un-anonymised and highly vulnerable data honeypots in the first place?

The empirical evidence from our public sector is deeply alarming. We have received detailed and coruscating briefings from the Centre for Long-Term Resilience and our technical authorities. The National Audit Office’s January 2025 report on government cyber resilience revealed that approximately 28% of government technology is legacy software, leaving our public bodies highly vulnerable to attack.

Consider the catastrophic ransomware attack on the British Library in October 2023. When the library refused to pay a ransom of 20 bitcoins, the Rhysida ransomware group released 600 gigabytes of stolen customer and staff data on to the dark web. The library’s own subsequent post-mortem was clear: its reliance on legacy applications and older network designs substantially and unnecessarily increased the volume of sensitive customer data sitting on the network. This was data hoarding, plain and simple, and the price was paid by the British citizens whose personal details are now permanently compromised.

Consider the hack by ExfilSquad, when normal teenagers living with their parents managed to breach a public database, leaking the sensitive personal details of 100,000 police officers and staff on the dark web, alongside data from the Ministry of Defence and the Department for Education. How did they do it? They did not deploy supercomputers or advanced zero-day exploits, they simply exploited a basic, misconfigured Power Pages database. The hackers’ own boast on the dark web was chilling. They said the data was accessible without any authentication whatever.

Why are these databases so large? Because our public bodies routinely collect and indefinitely retain vast, sprawling, unanonymised datasets, from birth certificates and benefit records to housing benefits and electoral roles, without any systematic statutory drive to minimise or anonymise them. That is why the Association of British Insurers and the NCSC both advise that data encryption and data minimisation are critical to reducing the leverage that a threat actor has in ransomware attacks. By rendering exfiltrated data unreadable through encryption—or better yet, non-existent through deletion—we take away the hackers’ ammunition.

While the Bill focuses heavily on the administrative paper exercise of incident reporting, it remains completely silent on the contents of the databases themselves. Amendment 174E would provide a strategic corrective. It would legally oblige the Secretary of State to open a public consultation within one month of the Bill’s passing to evaluate the cyber-resilience benefits of minimising data collection and increasing data anonymisation across our public bodies. By forcing our public sector to lead by example, this amendment could begin the vital work of shifting the UK towards a genuine resilience-by-design model. It would reduce our vulnerability, harden our national defences and protect the digital lives of our citizens. I urge the Minister to accept this vital safeguard.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security. 

Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.

Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.

As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on.

I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

My Lords, in moving Amendment 17, I will also speak to Amendment 28, which is closely related. Amendment 17 is in part a probing amendment about what constitutes an incident and the circumstances in which reporting is obligatory. It does not affect the amendment that I think the Government will move immediately afterwards.

As drafted, Clause 15 gives the very strong impression that an incident “capable of having” an adverse effect on security must be reported. If this is the case, it constitutes a much wider definition of what should be reported than if it were described as an incident “likely to have” an adverse effect. I think it is a widely held view—it is certainly the case in the industry and a point with which I agree—that “likely to have” would be far too wide a definition and would lead to extensive overreporting and an undue and unnecessary burden on regulators. Looking at the drafting, I asked myself what was the point of the “capable of having” definition in Clause 15.

I shall put forward a hypothesis. It would be very helpful if the Minister could confirm that it is a correct understanding of the existing draft, and that it does not mean that all incidents capable of having an adverse effect on security will need to be reported. Is it right to say that the definition in Clause 15 of what constitutes an “incident” applies across the whole of the regulations, and therefore feeds into security as well as reporting duties? That is to say, firms have a preventive duty to defend against what could be and what could happen, as well as what is likely to happen. That is a preventive duty. Can the Minister confirm that the phrase “capable of having” means that firms should have adequate preventive policies, but it is not—this is where the point comes in—the trigger for an incident to be reported, because in each case this requires it to have affected or be affecting the system?

I am making a distinction between “capable of having”, which applies to a duty to pursue preventive policies, and the trigger of the duty to report, which lies not in the phrase “capable of having” but in “likely to have”. Then there are examples of what I am saying in the regulations, and I can cite them: Regulation 11(3)(a), on page 21 at line 35; Regulation 12A(2)(a), on page 26; and Regulation 14E(2)(a), on page 29 at line 27. If the Minister can confirm that, within existing structures, what I have said is correct—there are no circumstances in which “capable of having” would be the reporting trigger—that would be a very helpful clarification. I will listen closely to the Minister’s reply on this point.

There is a “however”: there is a snag when it comes to the introduction of data centres, and that is the object of my Amendment 28. Data centres sit outside the existing structures that I have just talked about but, as yet in the drafting, there are no reporting trigger regulations for them. It is intended that the data centres should be, in future, big players in the system, so it matters that there is a gap in our information about the circumstances in which they would have a duty to report. It is an odd anomaly. New Regulation 11A(3)—on page 23, from lines 13 and 14 onwards—makes reportable

“an incident which could have had … a significant”

effect, whether or not it had any impact at all or anything was affected. As there is no list of factors for judging what constitutes a significant attack in the Bill, it makes it quite difficult to interpret.

For the operators of essential digital services and managed service providers, such factors are set out expressly in the new regulations in the Bill. However, they are absent for data centres. Why is this the case? What is the rationale for what appears an anomaly? It means that, when reporting an incident, a data centre has to do so when any of the following have had, or were likely to have,

“a significant impact on the operation or security of the network and information systems relied on to provide the data centre service … a significant impact on the continuity of the data centre service … or … any other impact, in the United Kingdom or any part of it, which is significant”.

These are very wide definitions of liability to report, and the discrepancy between them and those applying to other operators seems neither sensible from a security point of view nor fair for different business circumstances, as there will be all sorts of different businesses using data centres.

Although I hope that this will not be the case, I fear that the Government may say that the thresholds and factors for all categories of business will be set out in secondary legislation and subject to consultation. I ask the Minister to think hard about the adequacy of that reply. We are talking here about a penalty-backed duty, which is the core element of the Bill; it is not some minor point. It would seem a poor legislative approach in a foundational Bill for a new regime to fail to define the factors leading to a penalty for a significant segment of providers, when there are indicators in the Bill for other categories of provider. Those other players have different, less demanding and more sensible terms for a trigger for reporting. If data centre regulations need to be different from those for the other players that I have mentioned and the rest of the market, can the Minister explain why? It is the kind of complexity that will give the sectoral approach to regulation a controversial reputation, because it immediately raises the issue of making different rules for people who are apparently, in practice, in the same category. I hope that is not the case and that the issue can be resolved by remedying the drafting.

To sum up, in addition to my request for a clear statement from the Minister about the trigger for a duty to report in existing structures being related to the likelihood of an adverse effect on security and not on capability, I hope she will also take seriously the need to level the playing field for data centres on this issue and remedy what seems an important defect in the drafting of the Bill. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I will speak to this core group of amendments on incident reporting, in particular to Amendment 165, standing in my name, while addressing the other amendments in this group. First, Amendment 17, which was very cogently set out by the noble Baroness, Lady Neville-Jones, addresses what has emerged as one of the most contentious technical faultlines, in our view, across Part 2 of this Bill: the statutory threshold that triggers mandatory incident reporting to the designated competent authority, the NCSC. As the Bill is drafted, Clause 15 fundamentally widens the reporting net by redefining a reportable incident to include any event that is merely “capable of having” an adverse effect on the security of network and information systems, as the noble Baroness described.

While one can readily understand the cyber security community’s desire for complete visibility, in practice, the phrase “capable of having” is an operational disaster. In the daily reality of enterprise networking, thousands of automated port scans, routine phishing lures and perimeter firewall probes occur every hour. Almost every single one of these low-level events is technically capable of having an adverse effect, if multiple defensive layers were to fail simultaneously. By forcing businesses to notify regulators under threat of £17 million penalties whenever an event is merely “capable” of causing harm, the Government will unleash an administrative tsunami of defensive reporting.

Rather than enhancing national security, this compliance overload will drown NCSC analysts in background noise, making it far harder to detect sophisticated state-sponsored attacks. Amendment 17, in our view, would resolve this by replacing “capable of having” with the objective standard of “likely to have”. This would restore the established probability threshold used across UK regulatory frameworks, ensuring that mandatory notifications are reserved strictly for genuine material threats where there is a real likelihood of operational compromise.

This issue is compounded by the Government’s own drafting amendments, specifically Amendments 19, 36 and 44, which replicate the ultra-broad definition of compromise throughout parts 2 and 3. By removing “users” from Clause 15 and redefining data compromise to cover any event affecting data stored or processed on a system, the Government are dramatically expanding the notification net to include technical data anomalies that cause zero destruction or loss to actual customers. Combining this sweeping definition of data compromise with the low “capable of having” trigger will hugely affect responsible operators. It will force critical suppliers and small digital providers to spend their limited resources filling in compliance paperwork, rather than actively defending their infrastructure.

We risk creating a reporting system that captures everything and understands nothing. We must have objective reporting thresholds. By accepting the noble Baroness’s Amendment 17, restoring the “likely to have” test, we would ensure that mandatory reporting delivers high-quality actionable threat intelligence, rather than an unmanageable flood of routine notifications.

Under the new reporting regime, hundreds of incidents will be notified to regulators and the NCSC, but at present the Bill lacks any mechanism to ensure that aggregate intelligence is shared with Parliament or industry. Under Amendment 165 in my name, I propose that the Government lay an annual anonymised report before Parliament, detailing incident volumes, sector breakdowns and principal attack vectors. This would provide software developers and CNI operators with the situational awareness needed to harden defences.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

May I interrupt the Minister before she moves on to the next set of amendments? I do not intend to ambush her as regards her amendments this time around, but I seek an assurance, given that there seems to be quite a philosophical difference between her amendments today and those put forward by the noble Baroness, Lady Neville-Jones. There is considerable industry concern about the disproportionality involved. I seek an assurance from the Minister that, between Committee and Report, she will actively consult on the impact of this part of the Bill—Clause 15—and not just when it is in black-letter form. There is quite a lot of concern from many industry voices. It is incumbent on the Government to listen to those voices on the impact of this reporting structure and these duties before they go ahead in a way that many of us believe will not be helpful for the running of these businesses.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

We have already undertaken some consultation and I am happy to commit to contact affected businesses and business organisations and have further conversations between now and Report. Perhaps if I progress a little more, I may be able to answer some of the questions that may have given rise to some of this but, equally, there are different rationales for some different thresholds in the Bill, which, again, I am just about to come on to. I will set out the rationale for those because I think that they are well motivated and are linked to the risk profile that we see in the country and the connectedness of certain regulated entities in the country.

I turn to the amendments tabled by the noble Baroness, Lady Neville-Jones, and her questions to me on the link between the definitions and whether they apply beyond incident reporting. They apply to the security duties within the Bill, which means that regulated entities have a duty to prevent or minimise the impact of incidents. The amendments from the noble Baroness would limit this and reduce their security and resilience. We think that not every incident should be reportable but that organisations need to take appropriate and proportionate steps to mitigate the risks before, during and after a broader set of incidents.

On the second part of the noble Baroness’s amendments and her second question, the Government have recognised that the reporting threshold for data centres is broader than that for other regulated entities under the Bill. This reflects the distinctive role and risk profile of data centres. They are the physical infrastructure underpinning digital services across the economy and the public sector. Unlike the virtual cloud layer, for instance, they combine cyber, physical, personal and operational technology risks. This is particularly important in collocation facilities where infrastructure belonging to numerous customers is concentrated in one location. Then they need physical access to the premises and information about facilities or operational systems. A single incident could therefore exploit both physical and digital vulnerabilities, potentially affecting the confidentiality, integrity or availability of services belonging to multiple customers and sectors. The consequences may also extend beyond the facility’s immediate geographic location, because the hosted service can support users and central services elsewhere. That is the rationale for having this threshold applying to data centres.

To come on to the questions raised, including by the noble Lord, Lord Clement-Jones, on the use of the phrase “capable of”, and the points made in the amendment from the noble Baroness, Lady Neville-Jones, replacing “could have had” or “capable of having” with “likely to have” would exclude some incidents because their eventual impact was uncertain or successfully contained. It would also constrain the security duties, as I mentioned. In reference to the incident reporting definitions introduced by Clause 15, the subsequent detail sets out how the notification of incidents applies in each regulated sector, except for data centres. That is how the definition is made for regulated sectors other than data centres.

There are a lot of safeguards in the Bill to ensure that reporting remains proportionate. It is intended to capture significant near misses, not routine scanning, unsuccessful low-level attacks or ordinary operational events, and clear guidance will ensure that the industry understands this threshold. As the noble Baroness, Lady Neville-Jones, pointed out, we will set this out in secondary legislation and that will allow the consultation to take place that the noble Lord, Lord Clement-Jones, emphasised is so important—we agree with that. We have undertaken extensive engagement to date and will continue to do so.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I rise to introduce a large number of amendments, for which I apologise: Amendments 18 to 23, 25 to 31, 33 to 39, 41 to 47 and 49 and 50.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

Full house. Fear not—it is not as complex as it seems. These amendments, which I have introduced, and I am grateful for the support of the noble Baroness, Lady Kidron, and my noble friend Lord Holmes of Richmond, seek to strengthen the staged reporting requirements of the four different groups of entities, so each change must be repeated four times. Because of the way in which the Bill is drafted, I was unable to introduce the change just once; I had to put in each micro phrase, hence so many amendments. The aim is to strengthen the staged reporting requirements for operators of essential services, data centres, relevant digital service providers and relevant managed service providers, so everything is multiplied by four.

The Bill, as it stands, requires only an initial report within 24 hours and a full notification within 72 hours of an incident. My amendments would add two further stages: an intermediate report which is capped at 14 days after the incident has first been notified, or sooner if the relevant regulator requires, and a final report within one month. In all four cases, the reports must be given without undue delay, so that regulated entities cannot use the timeframes as an excuse to delay until the end of the time period.

These amendments are in line with the EU’s NIS2 directive. The reason why I have introduced them, as I said at Second Reading, is that I have lived this. I absolutely understand what the fog feels like. In the first moment when you have been attacked, you do not understand what has happened: you do not know who is attacking you, you do not know what they could have stolen, you do not know where they have gone, but you do know that it is serious. That is your first report. You start to understand, 72 hours later, quite how awful it could be. That is your second report, where you start to get real data, because your teams have worked all night, usually all around the world, to try to work out where the malign actors have gone. But it is really only after a couple of weeks that you have a proper sense of what has happened.

I recognise that my experience is, obviously, 10 years old, but quite recently I had a long conversation with some of the leaders at Marks & Spencer. The thing that scared me most was that it seemed so similar to my experience 10 years ago and that this basic process is likely to be the same. So we need the requirement to properly update whatever you learn two weeks on, and then a month later the fog starts to clear and you have a proper sense of the real scale of the problem.

The reason why we need to put this in legislation is that, throughout that entire period, all the incentives for you, as a corporate leader, are not to say anything. This is the biggest corporate taboo. Your board will be encouraging you not to tell everyone, the public will be telling you not to tell everyone and there is a real risk, unless you are forced to, that you just make it easier for the blackmailers to do their work. My personal experience was of being blackmailed during this process. Obviously, at the time, there were none of these regulations. I can tell your Lordships that there were so many voices saying, “Why don’t you just shut up? You don’t know what’s going on yet. Keep quiet”. Yet if, in the fog, you share this information with regulators and with law enforcement agencies, that is how the law can prevail. It is how regulators can work out what is happening and how they can warn others who might be affected. It is how the law enforcement agencies can do their work to try to find the bad guys.

This really matters if we want the rule of law to exist in the digital world, because the incentives, even for entirely well-meaning and upstanding leaders of corporations—and government departments, dare I say—are to keep quiet. We need to put these reporting requirements in the Bill. All the amendments would do is bring our own legislation in line with the NIS2 framework. To be honest, many of these companies and these incidents are likely to need to be reported in Europe at the same time as they are in the UK. As my noble friend Lady Neville-Jones said, there is a real primacy on keeping things simple. The more we can mirror and have exactly the same reporting requirements, the easier it will be when you are in that terrifying moment when you realise that you have a serious incident. I beg to move.

--- Later in debate ---
Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - - - Excerpts

My Lords, good can come out of bad events. The experience, as well as the speech, of my noble friend Lady Harding is one such good aspect. If it combines with bringing us into line with European practice, which so many businesses already have to follow, so much the better. I hope the Minister will be as sympathetic as she possibly can to my noble friend’s amendments.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I very strongly support this set of amendments on the staged notification of incidents. This is a significant group of amendments from the noble Baroness, Lady Harding, and so well supported by the noble Baroness, Lady Kidron, and the noble Lord, Lord Holmes; he has illustrated this extremely well. As has been described, the noble Baroness, Lady Harding, has a great deal of experience. She brings an invaluable perspective to this Committee, having led a major telecommunications provider through one of the most high-profile corporate cyber breaches in British history. She speaks from real experience and understands very clearly what happens inside an organisation in the immediate aftermath of a severe attack. We should listen extremely carefully to what she has to say.

In those critical opening hours, incident response teams and forensic engineers are working under an intense fog of war, so to speak, actively fighting to contain the malware, to isolate compromised servers and to protect customer data. We cannot expect an organisation to produce an exhaustive, multivariable forensic post-mortem within the first few hours of a fast-moving operational crisis. Yet, as Clause 15 currently stands, the reporting pipeline that follows the initial notification is left thin and unstructured. The noble Baroness’s amendments fix this with three-stage architecture, which is mirrored clause by clause across each category of regulated entity: operators of essential services, data centres, relevant digital service providers and relevant managed service providers.

I will not add much more, as noble Lords have already spoken extremely eloquently. Cyber incidents do not likely conclude on the day a final report falls due. Where an incident is still live at the point that the final report is owed, the entity must instead give a progress report on the information known to date, followed by the final report within one month of the incident ceasing. That seems to me to be a very sensible and realistic accommodation of how live incidents unfold.

Finally, I turn to the amendments tabled by the noble Lord, Lord Ashcombe, although I do not see him here in Committee. They would extend the deadline for the full notification from 72 hours to 30 days. I understand the underlying concerns, as 72 hours can be an unforgiving window in which to complete a full investigation and analysis. However, it is the amendments from the noble Baroness, Lady Harding, that deliver what we need. Intermediate reporting exists precisely so that the authorities are not left in the dark for weeks at a time. Taken together, the noble Baroness’s amendments replace a single blunt deadline with a structured, predictable reporting line, which gives business clarity on exactly what is required and when, while ensuring that the NCSC and our competent authorities receive high-quality, structured intelligence, rather than a single, rushed snapshot. As she said, this is the kind of staged discipline that the EU’s NIS2 directive already reflects and which this Bill should emulate.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

As per the points made by other noble Lords, this is a prime example of when you realise how valuable it is to have in this House and, in particular, in this Committee people who have lived experience. Because of that, this is a well thought out set of proposals; I thank my noble friend Lady Harding for bringing them before us, and I thank my noble friend Lord Holmes and the noble Baroness, Lady Kidron, for supporting them.

These amendments mirror a lot of what I saw from the other side when I was the Health Minister and we had the problems with Synnovis and testing. That is where I am coming from: you realise that you need some real teeth because, even though you have public bodies such as the NHS, which you think would listen to the Minister on certain requirements, that that does not always follow. The point made by my noble friend Lady Harding about everyone telling you to keep quiet applies to state organisations just as much as it does to private companies. Having teeth is an important part of all this and of making things happen.

The staged approach has been mentioned. In your first 72 hours, it is all about wanting just to get the information out there. One of my questions—I will come on to the rest in a minute—is: what are we doing on our side with that information? We must make sure that it is being used valuably and used to alert others. Only later on, around the 30-day mark, do you get into the “lessons learned” stage. So staged reporting would be a very sensible and well thought out approach.

That brings me on to another point; I would be grateful if the Minister could address it. If we are requiring businesses to provide such information to the Government very quickly, what will they get back? The strong justification for rapid incident reporting is surely that the NCSC can aggregate the intelligence, identify common attack vectors and vulnerabilities, and rapidly warn other organisations before they, too, are attacked. Obviously, that is the difference between regulatory reporting and genuine national cyber defence. I would be grateful if the Minister could explain the planning and what will happen operationally when one of these early notifications is received. How quickly will the information be assessed? How quickly will actionable intelligence be disseminated to other potentially vulnerable organisations? What obligations will there be on the Government and the regulators to ensure that the information provided by one organisation improves the resilience of everyone else?

Of course, there is a wider point here. Throughout our consideration of the Bill, we need to guard against measuring success by the number of organisations regulated or the number of reports submitted. Rather, the real test is whether fewer attacks succeed, whether we identify attacks faster, whether organisations can recover more quickly and whether intelligence from one attack prevents the next one. That is the outcomes we want this regime to achieve.

I hope that the Minister will look seriously at the principles behind these amendments, and in particular at whether we can achieve a reporting structure that gives the Government the information they genuinely need quickly while allowing organisations to concentrate their scarce cyber expertise on the thing that matters most: defeating the attack.

--- Later in debate ---
I am not entirely sure whether the amendments in the name of the noble Lord, Lord Ashcombe, were spoken to, but, as a precautionary measure, I resist the suggestion to extend the timeframe for submitting the full incident notification. His amendments would require the full notification to be submitted within 30 days of a regulated entity becoming aware of an incident, rather than the current deadline of 72 hours. This change would mean that regulated entities would provide no information to their regulators following the initial notification issued within 24 hours, which could create a worrying gap between the regulator’s and the NCSC’s awareness of the incident. Maintaining the rhythm set out in the Bill would mitigate that risk.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, before the noble Baroness, Lady Harding, stands up, I heard what the Minister had to say about consulting across sectors. I was reminded that, at Second Reading, I mentioned the fact that the law firm with which I am associated, DLA Piper, was subjected to a NotPetya ransomware attack back in 2017. What the Minister said is completely at odds with not only what the noble Baroness, Lady Harding, said, but the experience that we had in the way that we needed to understand how these events unfold. It would be really helpful to know from the Minister, or for her to publish, the sectors where the Government have had those discussions and which parts of industry have agreed that this is an appropriate form of incident reporting.

What we are trying to do, throughout the Bill, is to ground it in what is practical. At the moment, despite the fact that we are letting through some government amendments, it seems that we are heading in the wrong direction with this clause. It is going to be disproportionate in the way that it impacts on business and is not even going to be fit for purpose, despite the disproportionality. It is just not going to work.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I think we all agree that we want a proportionate and clear regime. The noble Lord supports further incident reporting here—additional stages of incident reporting. In our impact assessment, we clearly set out the implications of that in its cost to business and so on. We will come on shortly to discuss potentially broadening the scope of incidents that would be reported. We have not been able to quantify that potential impact, as a sort of counterfactual, because we are only just discussing that.

--- Later in debate ---
Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, I support all these amendments. They bring the customer perspective well into focus, which the Bill is currently chronically insufficient on, in my view. As the noble Baroness, Lady Harding, identified, if these amendments do not quite get to the precision of it, how will the Government bring something forward that will do the trick perfectly? This is a critically significant element which is currently not within the Bill. On an allied point, which has already been nodded to, I ask the Minister, since the Bill’s drafting seems to like “likely to”, and, in earlier additions “capable of”, why would there not be coherence through the Bill as to the type of legal construction that is being used throughout? Surely, that would not only be beneficial and more precise, but it would give greater clarity to all those who have to engage with the issues therein.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I, too, support these customer notification amendments tabled by the noble Baroness, Lady Harding of Winscombe. As I have said, the noble Baroness brings vital lived experience, in more ways than I thought, from the front line of corporate crisis response. When a major cyber breach occurs, vague statutory requirements to notify customers

“as soon as reasonably practicable”

lead to corporate delay. Amendment 58 would replace this with a strict statutory 24-hour notification clock, while Amendment 65 would establish explicit harm triggers and require providers to provide actionable remediation advice to affected customers. Look at what Amendments 60 and 65, in particular, would achieve across Clause 16.

Under Amendment 65, notification would be explicitly triggered whenever an incident causes or threatens severe operational disruption, substantial financial loss or material harm to downstream users. Furthermore, Amendment 71 would place a positive duty on the provider to advise customers on immediate remediation steps that they can take. In the cyber realm, time is the attacker’s greatest ally. If a hospital, bank or small supplier is informed within 24 hours that their cloud or managed service provider has been breached and given technical instructions on how to isolate their systems, they can prevent contagion before it paralyses their operations. We must ensure that customer notification is prompt and meaningful, empowering downstream businesses to isolate compromised systems before contagion spreads, so we very strongly support these amendments.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I, too, thank my noble friend Lady Harding of Winscombe for tabling this important set of amendments, which we welcome, and for clarifying the refinements of the grouping process, which had slightly eluded me up to that point. As with the previous group, this would amend four key areas of, on this occasion, customer reporting. It would tighten the timing to notify customers; widen the incidents expected to be reported by removing the adverse impact criterion; add extra reporting triggers; and add an “advice on remedies” duty.

Of course, businesses should be supported in the case of cyber attacks and our priority must be preventing, containing and controlling such incidents, but this cannot come at the expense of the customers that businesses serve and depend on. Customers deserve to know when a firm they depend on is targeted, even if such an attack does not necessarily directly adversely affect them. They deserve to be informed promptly and they deserve to be informed of potential remedies.

It is worth saying that there is a welcome side effect to doing so, based on the premise that behaviours are the best guard against cyber attack. Constantly being aware that cyber attacks are going on will improve behaviours. As was said earlier, the goal is not to create panic but, on a continuum between insouciance and panic, we must imbue a point closer to concern more widely in the population to keep people aware that we are constantly at risk of being hacked. On these Benches we feel these are wise, pragmatic and helpful changes. I certainly hope the Minister agrees.

--- Later in debate ---
Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, I support this amendment, particularly in terms of its probing nature and what work can potentially be done between Committee and Report in this respect. It is really about the question of mandation. There should not be any question of a voluntary requirement. This is something that is not about the individual organisation, business or entity. It goes broader than that. It is about the community, the greater good and the country. The fact of a near miss says nothing about the severity of intent and the intel that can thus be gleaned to benefit at that point across the sector, the community, the country and beyond. Mandation has to be the standard for this provision.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I cannot possibly compete with the Shakespearean seven stages—as opposed to ages—of the noble Baroness, Lady Kidron. We support Amendment 72 in its entirety. Voluntary reporting is the bit of the amendment that we particularly like. Our national security services and sectoral competent authorities desperately need early upstream visibility of emerging threat patterns before a full-blown systemic crisis unfolds. In the cyber domain, the precursors to the catastrophic attack—the subtle network probes, the exploratory reconnaissance and near misses—often appear weeks before a critical system is actually breached.

At present, the Bill creates a bit of an all-or-nothing trap. If any entity experiences a sophisticated near miss that fails to cross the statutory threshold of an active disruptive breach, it has a powerful legal incentive to keep quiet. It fears that, if it approaches a regulator voluntarily, it will expose itself to regulatory scrutiny, compliance investigations and potential enforcement action. In our view, including a dedicated statutory framework into the NIS regulations specifically for the voluntary notification of near misses, sub-threshold anomalies and early-stage cyber threats would be a significant beneficial addition to the Bill. In effect, it would establish a safe harbour for intelligence sharing.

As the recent “Analogue 72” green paper powerfully argued, we must move away from a culture of fear and silence in this area and we must encourage continuous proactive information flows between our critical infrastructure operators and the NCSC. We strongly support this amendment.

Lord Reay Portrait Lord Reay (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend Lady Harding of Winscombe for her amendment, to which the noble Baroness, Lady Kidron, has added her name. We believe that this is a straightforward amendment. If we are to tackle cyber attacks seriously and to create a generally resilient cyber system, we should not simply stop at the reporting of incidents that happen. A key way of ensuring that we build not just a responsive but a preventive cyber system is by knowing what potential risks exist and who is attempting to commit cyber attacks, even if they have not done so yet. This is a reasoned amendment that places a requirement only on those already considered regulated persons, with the opportunity for others not regulated to report voluntarily. I hope that the Minister will agree.

--- Later in debate ---
Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I will speak quickly. I was just checking my records, particularly on Amendment 167. It was just under a year ago that I completed the FT board director programme, which was specifically around cyber risk for boards. In a room of around 50 people, we had a tabletop exercise on a real-life scenario about what one should do in the event of a very serious cyber crisis and cyber risk. I was struck by a number of things. In the room were people with vast waves of expertise and experience, none of whom was a technology expert. All said that no other members of their board had attended training like this. They were there because, having completed a board director programme, it piqued their interest, as it did mine, it was freely on offer and they decided to attend.

Having gone through that session, we covered things such as the regulatory experience, issues around how to challenge management in the event of one of these incidents, how you need to test organisational resilience, how you need to look at the risks involved, and how to respond decisively and to have the expertise and understanding to do so. It was very clear to me, even during that half-day exercise, that that training was not sufficient for me as a board director and member to be able to fulfil that role.

Having gone through that experience, I think for many reasons that this amendment is so important to ensure that boards across this country—be they private boards, FTSE boards or boards of regulated companies—can do their jobs effectively. In this world, which is extending—I echo the points made about AI—it is even more imperative that we have this amendment to ensure that boards are able to fulfil their roles effectively.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, this has been a really useful debate, particularly because it has distilled all the considerable board experience—and, indeed, board training experience—around this Committee. I very much hope that the Minister listened to it with interest.

Amendment 74 in the name of the noble Baroness, Lady Morgan, moved by the noble Baroness, Lady Kidron, would align the UK with the EU’s NIS2 framework. It would introduce personal civil liability for senior executives who deliberately or carelessly neglect cyber duties. My noble friend Lady Ludford’s Amendment 167 would mandate board-level oversight and technical training. In our view, to build national resilience, cyber security must become a fiduciary director’s personal responsibility. As the noble Baroness, my noble friend and the noble Lord, Lord Arbuthnot, have said, this change is long overdue and would be additional to other existing sectors. We need to learn from experience in the way mentioned by the noble Baroness, Lady Harding; I very much hope that we will do so in the course of the Bill.

Together, these two amendments target arguably the single greatest cultural—the noble Baroness, Lady Kidron, rightly emphasised “culture”—and behavioural failure in UK cyber security today: the persistent treatment of cyber security by company boards as a delegated technical IT issue rather than a core personal and fiduciary leadership responsibility. The Government’s approach to corporate cyber governance has been almost entirely passive to date, I am afraid. Ministers have relied on voluntary guidance, such as the Cyber Governance Code of Practice, hoping that boards would voluntarily prioritise digital resilience.

The proof of this policy failure is undeniable. My noble friend quoted the Cyber Security Breaches Survey, which showed that board-level ownership of cyber risk has declined over the past three years. Of course, if boards neglect cyber security, that carries massive public costs, as seen in the recent major supply chain disruptions where, although company directors face strict personal legal liabilities under company law for signing off on financial accounts, they are permitted to treat systemic cyber vulnerabilities—vulnerabilities that can wipe hundreds of millions of pounds from the economy and paralyse critical national supply chains—with complete personal legal impunity.

My noble friend also reminded us of the catastrophic real-world cost of this boardroom neglect in the automotive sector, where a supply chain breach at Jaguar Land Rover cost an estimated £500 million, halted production lines for four months and forced the Government to step in with a £1.5 billion loan guarantee. We have seen the same in retail, also mentioned by my noble friend: the cyber attack on Marks & Spencer cost £300 million and contributed to a 99% collapse in pre-tax profits.

Amendment 74 would provide the direct legislative teeth that the Bill is missing by introducing personal civil liability for senior executives. It would amend the NIS regulations to establish that, where a regulated entity fails to comply with core risk management duties, and that failure was committed with the consent, connivance or deliberate or careless neglect of a senior executive, the regulator may impose a personal civil penalty.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.

I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.

That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.

I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.

To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.

I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, can I just check something before the noble Baroness, Lady Kidron, rises? The Minister has uttered some very warm words about the responsibilities of directors, but am I right in thinking that in nothing of what she said is there any intent for the Bill to create a legal liability that compels directors in the way that these two amendments do, or any form of personal financial fiduciary duty on a director? What she is arguing for, despite the warm words, is, essentially, a voluntary scheme.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

We will consult on the security and resilience requirements that will come out of the Bill. They will contain a requirement on board governance and those expectations will be set out as a result of the Bill. The regulators and others enforcing the Bill will take that into account in their enforcement regime.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I am sorry to press, but the Minister is saying that these are expectations. Will she write to us? There is a huge lack of clarity in the middle of those warm words. We take encouragement from the fact that the Government want to see boards take responsibility, but where are the teeth?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Obviously, we have not yet gone out to consultation on the security and resilience requirements; we will do that after the Bill passes. I can certainly update on the process, the expectation and how that links with the enforcement duties in further detail.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

The Minister is also going to have to point out the power under which the Government are going to act to actually fix that liability, or make sure that the guidance, or whatever it is, is complied with, because we are talking about the power and the duties in primary legislation. It is all very well for the Government to say, “We’re going to produce guidance”, but unless there is something in the Bill that permits that and makes sure that the Government can make it stick, we are all going to feel dissatisfied.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.

--- Later in debate ---
Lord Russell of Liverpool Portrait Lord Russell of Liverpool (CB)
- Hansard - - - Excerpts

My Lords, just quickly, I will back up the noble Baroness, Lady Ludford, on Amendment 168. I, like many other noble Lords, have been involved with a variety of charities that were impacted by the cyber security breach at Beacon CRM, which has about 1,500 charities that store an enormous amount of personal data. I looked at its website, and perhaps this will emphasise to the Minister the problem that we face. This is what this website, which had a major security breach in the past, says about its security:

“The secure choice for security-conscious charities. Beacon has all of the security certifications and features that you should expect from your CRM, and we’re adding more all the time”.


It says that it is ISO 27001:2022 certified and Cyber Essentials Plus certified and that

“Cyber Essentials Plus is the highest level of certification in the UK government’s Cyber Essentials scheme, and includes a technical audit of the Beacon team’s endpoint devices”.

It says that it has “World-class infrastructure” and that it is “A UK-based system”. If I was a potential customer of Beacon reading all that, I would feel a very false sense of security about the level of knowledge and defence that its systems have. That is clearly not the case. There is a clear, major mismatch between the degree of confidence that organisations such as Beacon have in their own cyber security and the reality of how feeble and weak they actually are. Before this happens again and again, it would be helpful to look at this more closely and see whether we need to do more.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, the noble Lord, Lord Birt, was right to remind us that we perhaps need something rather more generic and comprehensive when we are assessing whether a particular sector should be brought into the Bill, but that does not mean that we should not use this group of amendments to illustrate that the Bill at the moment is not nearly comprehensive enough in the way it is structured and the sectors that it contains.

The Bill remains stubbornly wedded to what we might call the traditional 2018 five utilities model: water, energy, transport, health and core telecoms. But we have moved on from that world. Today, systemic digital risk does not respect what might be called 20th century arbitrary utility boundaries for critical national infrastructure. An adversary seeking to disrupt our society or blackmail the UK does not need to compromise a power station; it can strike our democratic institutions, food distribution networks, university research labs, orbital satellites or software supply chains.

Amendment 79, tabled by my noble friend Lady Ludford, designates services supporting registered political parties as essential activities. Hostile state actors, from Russian GRU units to Chinese state-sponsored espionage networks, are actively targeting our political parties. As my honourable friend and my noble friend have argued strongly, political parties are a vital part of our constitutional machinery, yet they operate on shoestring budgets with high staff turnovers, heavily reliant on consumer-grade IT and voluntary workers, while holding vast tranches of confidential voter files, donor databases and what we might call strategic policy intelligence. If a hostile power exfiltrates or manipulates a major political party’s systems, the threat is not just a commercial data breach but the subversion of our electoral integrity and democratic sovereignty. To leave our political parties outside statutory NCSC cyber standards is an indefensible democratic blind spot that Amendment 79 would decisively rectify.

Amendment 80, tabled by my noble friend Lady Northover, who sadly cannot be present, addresses the fact that the Bill remains frozen in that 2018 world. It will bring critical manufacturing, industrial food production and large-scale food distribution networks under statutory cyber resilience duties. Our contemporary manufacturing and retail logistics networks are no longer purely mechanical operations; they are vast, hyper-automated cyber-physical systems. They run on automated warehouse robotics, internet-connected telemetry and algorithmic just-in-time delivery pipelines.

Consider the manufacturing of critical transport equipment. When Jaguar Land Rover suffered a catastrophic supply chain cyber breach, the damage was not confined to a single company balance sheet. Production lines were frozen for four months, hundreds of component manufacturers were dragged to the brink of collapse and the economic fallout cost between £1.6 billion and £2.1 billion, making it the costliest cyber attack in British history and forcing the state to step in with loan guarantees. In an economy that depends to a large extent on vehicle transport and haulage equipment, leaving critical automotive and transport manufacturing outside statutory NIS protections is an invitation to systemic economic blackmail.

Even more acute is the vulnerability of our food supply. Modern food processing and supermarket distribution operate with less than 48 hours of inventory buffer. When Marks & Spencer was hit by a major ransomware incident, it cost £300 million to remediate and wiped 99% from its statutory pre-tax profits. As I said earlier, if a hostile state or sophisticated ransomware syndicate executes a co-ordinated attack against the central routeing software of two major distribution operators, supermarket shelves across our cities would begin emptying within two days.

Amendment 80 provides a clear, proportionate statutory safeguard. It includes an explicit turnover threshold of £12 million, ensuring that local bakeries, independent farmers and small shops face zero regulatory burden. It targets solely the industrial food processors and large-scale distributors whose distribution would threaten the daily functioning of society. In doing so, it aligns the UK with the EU’s NIS2 directive, which has already brought food production, processing and critical manufacturing under statutory cyber obligations. Our European neighbours recognise that you cannot have national resilience if your food supply can be halted by a single malicious click, so why are this Government leaving Britain’s food supply chain completely exposed?

That brings me to Amendment 81, also in the name of my noble friend Lady Northover, which designates the space and satellite sector as an essential activity under Part 3. The omission of the space sector from primary cyber security legislation in 2026 is nothing short of extraordinary. The space sector is formally identified in the Government’s own industrial strategy as a core national growth driver. Yet the Bill treats orbital infrastructure as if it were entirely invisible. Our entire critical national infrastructure, from financial transaction timestamps across the City of London and automated container port logistics, to emergency blue-light dispatch, cellular networks and high-voltage grid synchronisation, relies absolutely on satellite positioning, navigation and timing—PNT.

Ground-truth economic studies demonstrate that a five-day blackout of satellite positioning systems would inflict a staggering £5.2 billion direct loss on the UK economy. Furthermore, the UK possesses world-leading capability in earth observation and small satellite manufacturing, with sovereign launch facilities advancing at SaxaVord. But satellites, ground uplink stations and space telemetry are dual-use systems. As the House of Lords special inquiry committee on space, which I sat on, has heard throughout its evidence sessions, satellite communications and orbital command links are under relentless, daily cyber probing, jamming and spoofing by hostile state adversaries. An exploit deployed against the satellite operator’s ground command software can sever communications, blind environmental monitoring or hijack commercial orbital satellites.

Amendment 81 would rectify this strategic blind spot. It would place a statutory requirement on the Secretary of State, within six months, to make regulations bringing the space sector into scope as an essential activity. It specifically covers the operation of space objects and launch facilities, satellite communications, earth observation and critical PNT services, while requiring the Government to designate an appropriate regulatory authority such as the CAA or Ofcom to supervise compliance.

Before moving on to my own amendments, I welcome Amendment 81A, moved by the noble Baroness, Lady Berger, covering the education sector. Our world-class universities are the engines of the UK science and technology prowess, holding billions of pounds of cutting-edge IP, defence research and quantum computing prototypes. They are under relentless cyber espionage assault from foreign adversaries, while centralised bodies such as UCAS and qualification boards, as the noble Baroness said, hold sensitive data on millions of young people. Bringing education into scope under Part 3 is an urgent national security necessity.

I have tabled new amendments—Amendments 81B, 81C and 81D—which address the single most gaping, indefensible and dangerous structural failure of the Bill: the complete and absolute exclusion of central government, public authorities, local councils and our core democratic electoral infrastructure from the scope of our national cyber security perimeters. How can we claim to be building a genuinely cyber resilient nation when the public administration itself is left out entirely in the cold? I wish I had more time to expand on those three amendments, but I will content myself with hoping that the Minister will have considered those amendments and will come back with a positive response. Of course, we strongly look forward to an answer to my noble friend Lord Russell of Liverpool’s questions on Amendment 168.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank noble Lords for raising so many aspects of the scope of the Bill. I recognise the sentiment among noble Lords today about the importance of expanding its scope. Our approach has been to target regulatory requirements on a select number of essential services, while using non-regulatory but effective measures to improve the cyber security and resilience of the wider economy.

As I set out at Second Reading, I have asked my officials to work across government to consider what additional services would merit being brought into scope of the regime in future. This will allow us to make a holistic and considered approach. To ensure our assessment is appropriately prioritised, I would first like to focus on the CNI sectors not already covered by the NIS regime.

I share the intent behind the objective from the noble Viscount, Lord Camrose—which the noble Lord, Lord Markham, spoke to—that the process to expand the scope of the regime should be rigorous and evidence based. As set out in the Bill, for something to be defined as a new essential activity under its powers, the Secretary of State must be satisfied that the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is reserved for the most vital activities in our nation. To the point raised by the noble Lord, Lord Birt, I believe that that is a clear test. In reaching a decision, the relevant departments would need to carry out a risk assessment and any economic assessments, and consider whether inclusion is proportionate. This is part of normal policy development. After that, proposals would be subject to consultations and the affirmative procedure.

The noble Viscount proposed in his amendment that assessment for inclusion be carried out on an entity-by-entity basis, which obviously differs from the sectoral approach we have taken thus far. Setting out the detail that would need to be published according to the amendment could lead to a release of information about individual companies that could pose commercial or national security risks, due to their criticality. I think that the sectoral approach is better. As others have said today, looking at a systemic approach to the sectors is the right way to look at what is in the statutory approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I am sorry to interrupt the Minister, but clarification along the way would be very helpful. She has asked her officials to see what other sectors should be brought in and has given an indication of the kind of test, but we are dealing with a bit more fog here. Is she promising us something in primary legislation or will it appear in secondary legislation? Will it just be something that government policy will cover, and we will have no say on the kinds of sectors that should be included?

For instance, the Minister is the Space Minister. Do we have an indication that space, or any of the key activities within space, will be included? Do we have any white smoke from the department as to whether that sector will be included? Will we hear by Report what sectors might be included? It is all a bit vague, and that does not give us a great deal of assurance.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I was referring to the process by which sectors can be brought into scope of the Bill, as set out in it and using the powers in the Bill. That would follow the process I just mentioned, which would be subject to consultation and the affirmative procedure. That is the process that I am referring to.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

But the powers are further down the track; they are under secondary legislation. I am assuming the Minister is promising that the Secretary of State will set out the criteria by which a new sector is brought in. Is that right? Do we have any indication, apart from what the Minister has said today in response to the noble Lord, Lord Markham, as to what those criteria will be?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I have highlighted a few of those criteria regarding the extent to which the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. Obviously, we already have the list of critical national infrastructure. We need to go through a whole process, as others have mentioned. We would need to make our assessment and then consult with industry on that, so there is a process to go through here. That process of consultation and talking to industry, or any affected sector, is absolutely critical. I am absolutely happy to update noble Lords and engage further ahead of Report on this.

In terms of the report referenced in Amendment 92A, I do not think we would need a statutory obligation to bring this report back, as set out. I mentioned the focus on entities rather than sectors, and it is better to look at the sectoral approach.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, if the Minister could commit to adding that to the conversations we are bound to have to have between now and Report—

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am not only committing; I am offering, so I am happy to have the noble Lord confirm that that would be good. I am absolutely offering that as part of the engagement ahead of Report.

I have heard the numerous areas that have been raised for inclusion in the Bill. We should look in a methodical and sensible way at these and at the implications—as we have previously discussed—for the obligations that will placed on any entities that come within the scope of the Bill, such as incident reporting, board accountability and so on, so that we do this in a very sensible manner. That is why this is the right approach to take.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, at the risk of irritating the Minister even further, it is great to hear of some of this activity, but that is not the same as bringing it under the terms of the Bill.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.

Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.

Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.

Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.

This brings me on to Amendment 81A—

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Let me work backwards here. The noble Baroness makes a very good point: the services delivered at local level often mirror those at central government level. At the moment, we are consulting on the question of the best value duty to give additional prominence. One of the issues with mapping these requirements into local government is that many different services are indeed provided. We may need to come back to that in more detail.

The government cyber unit now resides within DCMS. The team has transferred over and is up and running; I have spoken to them many times recently. The unit is very active in progressing the government cyber action plan as per the timetable and the target plan.

On the question about the approach to looking at other sectors to bring in, that is why I mentioned at Second Reading that I had already asked my officials to work across government to consider what additional services would merit being brought in. I mentioned earlier today that focusing on CNI services not already covered by the NIS regime would be the right place to start.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, will the Minister show some greater enthusiasm for her own regulatory scheme? I hope that the criteria that she adopts within the department as to whether certain sectors are going to be brought in will be about not only the criticality of the services but the need for transparency on the incidents themselves. We have had this whole debate about notification being beneficial so that organisations such as the NCSC actually know what is going on, that we the public know what is going on and the level of threat, and that our intelligence services are fully apprised.

The noble Baroness, Lady Neville-Jones, was entirely right on critical sectors, such as space. If there is no duty of notification on, say, a satellite manufacturer or something, we will all be in the dark. The Government rightly introduced this Bill to introduce greater transparency and duties on some very important sectors. We simply want to make sure that we capture all the important sectors and that they are all subject to the duty. This shying away from the Government’s own framework seems completely contrary.

--- Later in debate ---
Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I support the principles behind these amendments. A point was raised by the noble Baroness, Lady Ludford, and I wish to make the point in a different way. Many reasons have been shared during this debate, which I share. The noble Baroness, Lady Ludford, referred to the questions asked by Chi Onwurah MP in the other place. It is interesting because I submitted a very similar Question just before the end of the summer in July. I asked:

“what proportion of the computing and cloud services used by government departments are provided by suppliers that are … headquartered outside the UK, or … subject to the jurisdiction of a government outside the UK”.

I asked that specifically in the wake of recent events and the debate we had in July.

The Answer came back on Tuesday. I accept that the Question asked by Chi Onwurah MP was specifically about AWS, but I was asking about all services hosted outside the UK. The Answer was:

“This information is not held centrally. Individual government departments are responsible for managing their own commercial arrangements for computing and cloud services and would need to confirm the proportion of services provided by suppliers headquartered outside the UK”.


The Government do not know how much they are collectively relying on other countries for our key government digital infrastructure. Our Government’s critical systems, public services and citizens’ data are increasingly reliant on foreign-hosted clouds and data centres. While the Answer refers to “commercial arrangements”, I think it is about much more than that. This is a question of our national security and resilience. I believe we urgently need a digital sovereignty strategy to ensure that we know the answers to these questions, that we can act on them and that we can prevent any future challenges happening to ensure that we are as resilient as we should be.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I will speak to this very strategic group of amendments. I use that word again because the noble Baroness, Lady Kidron, made it quite clear from the outset that that is exactly what we lack: a clear national strategy. I pay tribute to her tenacity in tabling Amendment 83, following what I thought was an extremely useful debate on the last day before we went into recess. That is still very much top of mind at the moment, as the Minister can see from the contributions today. If we had another debate today, I do not think we would feel any greater assurance than we did on the day of that debate.

I also thank my noble friend Lady Ludford for having tabled Amendment 166, which is along very much the same lines. We have at the moment, particularly in the public sector—I thought the noble Baroness, Lady Berger, put this extremely well—near total and escalating digital dependence on foreign technology monopolies and foreign jurisdictions. It is quite prevalent in Whitehall. There is a kind of ignorance about the geopolitical reality that so much of what might be described as the digital stack is owned, operated and controlled from abroad. I will come on to our procurement policies shortly.

Amendment 83 defines the pillars of true digital sovereignty. It would tackle extreme market concentration. As we have heard, three American technology giants— Amazon, Google and Microsoft—control a staggering 73% of the cloud computing and enterprise hosting supporting our UK financial sector and public services. If an AWS region or Microsoft Azure network suffers a systemic failure, three-quarters of the City of London and vast swathes of government administration are instantly paralysed. Concentrating our critical national infrastructure into a handful of corporate choke points is the very antithesis of national resilience.

Secondly, it directly confronts foreign extraterritorial legal exposure. Because our critical public data is predominantly hosted on foreign cloud architectures, that data remains legally exposed to foreign statutory instruments, most notably the US CLOUD Act, and is subject to sudden unilateral geopolitical shifts. As my noble friend Lady Ludford said, we saw a chilling preview of this vulnerability only recently when the US Administration temporarily cut off European and UK financial institutions from accessing Anthropic’s AI model, Claude Mythos. Whatever the rights and wrongs of Mythos and its capabilities—we have a pretty good idea of what the wrongs were from what the AI Security Institute had to say—suppose that we had adopted this powerful model in a cyber defensive role; if an ally can pull the plug on front-line cyber security tools overnight, we do not possess true digital sovereignty. If a foreign ally can pull the plug on critical cutting-edge technology at a moment’s notice, we do not have true national resilience but a dangerous dependency.

My noble friend Lady Ludford’s Amendment 166 would force the Government to publish a formal digital sovereignty strategy within 12 months, assessing foreign reliance and reforming public procurement to prioritise secure home-grown UK technology. In fact, both amendments would tackle a glaring failure of current government procurement. The UK possesses world-leading academic institutions and an exceptional cyber security start-up ecosystem. But we suffer from a chronic scale-up failure. Time and again, major public contracts, such as the recent NHS and defence platforms, are automatically handed to dominant foreign tech giants such as Palantir, rather than nurturing and scaling home-grown British technology.

Proposed subsection (2)(c) of Amendment 83 and my noble friend Lady Ludford’s Amendment 166 would provide the solution. They would legally require the Government to use public procurement as a strategic lever to prioritise secure, interoperable and sovereign UK-developed technologies. That is how we build long-term sovereign capacity on our own soil, create high-wage tech jobs and prevent our best innovations being swallowed up by our international competitors.

In an era of contested supply chains, autonomous AI warfare and geopolitical instability, a nation that cannot secure its own digital foundation cannot truly govern itself. I very much hope that the Government will take heed of these amendments, even if they do not take them on board in this Bill. The former Secretary of State for DSIT is on the record as being very much in favour of digital sovereignty, and I hope that that carries through into the current Government.

Lord Reay Portrait Lord Reay (Con)
- Hansard - - - Excerpts

My Lords, I thank all noble Lords who have added their names to the amendments and who have spoken in this debate. Both amendments in this group are underpinned by the same principle that national security and national technological capabilities deserve a unified plan—not one that targets some sectors and entities and not others, but a holistic plan that brings together all sectors and industries into a single framework. His Majesty’s Opposition therefore support the intention behind the amendments.

However, at risk of repetition, the Government could avoid the need for these propositions. They could do away with your Lordships’ worries if they would commit, as mentioned by my noble friend Lord Camrose, to publishing a national cyber action plan within a set timeframe, and commit to including national digital sovereignty as part of that plan. In light of Tuesday’s debate on AI, we request a review and update of the previous Government’s AI White Paper to ensure that AI regulation and cyber regulation are aligned. They need to operate in lockstep, and this Bill is an appropriate place to do it. It is evident that national sovereignty and a reduced reliance on foreign technology is vital to ensuring national wholesale cyber security. I commend these amendments in their aims to achieve that, and I look forward to the Minister’s reply.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for continuing the debate with which we ended the previous session: the very important topic of the technological and digital sovereignty of the UK. That is very important to this Government and we are taking action on it. It possibly has not been focused on enough in past years but, across many areas, that is what we are doing.

We are clear that we need a coherent approach and a clear direction. We obviously need to take into account that technologies and markets evolve, and the core of that approach was set out in the modern industrial strategy and the Digital and Technologies Sector Plan. That set out the direction of travel, and the Government will continue to consider how our priorities are best articulated.

Our objective, as I articulated at the end of July, is not complete independence but strategic resilience through a combination of domestic capability, diversified international partnership and targeted management of critical dependencies. This allows us to access the best of global markets while capitalising on our domestic capabilities. That is why we already have in place a range of regulatory and non-regulatory frameworks that enable us to embed those objectives through existing industrial, technological and resilience strategies. I will talk to some of those now.

For essential services in scope of the network and information systems regime, such as drinking water, health and energy, all entities are required to manage and mitigate the risks posed to their systems that deliver essential services. This includes the risks set out in the amendment of the noble Baroness, Lady Ludford.

On market concentration, which the noble Baroness, Lady Kidron, and the noble Lord, Lord Clement-Jones, referred to, the CMA is acting. It concluded an investigation into the cloud services market in July last year, highlighting competition issues arising from market concentration. It has since announced packages of actions to improve competition in cloud services. This work has directly informed our thinking, as we develop a more strategic approach to how the public sector procures cloud services.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I point out to the Minister that not all is rosy in that particular cloud services garden. The CMA failed to designate those major US hyperscalers as having strategic market status, which, for many of us, was a rather extraordinary outcome.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It has announced a series of measures, including actions from Microsoft and Amazon, to support greater choice for UK businesses and the public sector.

On my noble friend Lady Berger’s question, it is true that cloud spend is distributed across departments and managed through a range of departmental contracts and commercial arrangements. We have established a cross-government cloud consumption dashboard to improve the visibility of cloud usage across the public sector, and we are working with both suppliers and departments to further improve the quality and completeness of our cloud infrastructure spend data to provide a joined-up view today and for the future. That is something that the Government are acting on.

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

My Lords, I will also speak to the other amendments in my name in this group. I thank noble Lords for their constructive engagement on this topic over the Summer Recess. I particularly thank the noble Viscount, Lord Camrose, and his colleagues for sending their questions in advance. I will seek to address those in my opening remarks.

This package of amendments introduces new powers that will enable the UK to address vendor-related cyber risks in our critical infrastructure. The principal new clause introduces a new direction power. It enables the Secretary of State to direct entities in scope of the power where they are using, or may potentially use, vendor-supplied goods, services or facilities in connection with their network and information systems that could create national security risks.

It is becoming increasingly clear that there are axes of cyber risks that the Government need to address. These risks arise from goods or services supplied by another company being harnessed as tools for sabotage, surveillance or espionage. But they also exist where goods or services constitute critical points of failure due to their defective design or vulnerabilities. Noble Lords would have had some sense of these risks from debates during this Bill—in particular, discussions about remote access in embedded products such as cellular modules and the scope for hostile interference and control.

GCHQ has also raised escalating concerns about supply-chain vulnerabilities in the wider geopolitical context. The director of GCHQ explicitly called out those risks in her annual lecture in May this year when discussing the challenges posed by a relationship with China and the threats posed by Russian cyber operations. That is why we have tabled Amendment 102 to tackle decisively these risks and protect our national security. Our intention is to limit the use of this power to operators of essential services in the first instance, although we will review the case for bringing other entities into scope in the future.

Supplementary amendments contain the mechanisms needed to operationalise the power. They enable the Secretary of State to set statutory timeframes for decision-making, to specify and update which entities are in scope of the vendor-related direction power and to introduce mandatory procurement screening should this ever be considered necessary to protect national security. They also introduce a power to bring more entities into scope of the existing direction power in Clause 43.

The powers to bring entities into scope of this framework are rightly restricted. To be brought into scope, the Secretary of State or Chancellor of the Duchy of Lancaster must be satisfied that the entity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is consistent with the Bill’s definition of essential activity in Clause 24. Either Minister can exercise the power. It has been drafted like this to accommodate machinery of government changes.

The decision to introduce the amendments has not been taken lightly. The Bill already includes important national security powers to direct regulated entities whose systems have been compromised, or which are at risk of being compromised, by hostile actors. This new power allows the Government to act before vendors become embedded in supply chains and before taking action becomes costly and disruptive. It will give operators greater confidence in their procurement planning and avoid the need for costly interventions down the line.

Crucially, we are not proposing to introduce these powers in isolation. They will be part of a broader framework which will also include procurement guidance for operators and a voluntary referral route into government where operators have identified potentially risky procurements. The voluntary self-referral route will enable the Government to assist operators with vendor-related concerns, provide them with guidance on how to proceed and, where necessary, inform decisions about the issuing of a direction.

We intend to consult on the implementation of the framework in due course. This will include the criteria for referral and how the mechanism will work in practice. In the event that this Government ever determined a mandatory referral scheme was necessary, we would intend to consult on the definition of a “qualifying transaction” before laying the necessary secondary legislation. However, I emphasise that it is not our current intention to set up a mandatory scheme.

Ultimately, we expect this wider framework will minimise the need for formal interventions using the new powers. However, it is crucial that the power is in place as a backstop to guarantee the Government’s ability to protect the UK’s national security. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I assume that there are no Back-Bench contributions at this point, so I will speak on behalf of the Liberal Democrats to this very significant group of amendments tabled by the Minister as recently as 24 August. I thank her for her introduction today and for her brief meeting shortly after their tabling.

At the outset, from these Benches we express our strong concern about the timing and the sheer scale of the Government’s package of new amendments. To drop 65 amendments of this nature on the eve of Committee, which will completely reshape the architecture of this Bill, after its passage through the Commons, is a major challenge to effective parliamentary scrutiny. The Minister’s letter, also dated 24 August, came alongside these 65 new amendments, so we have had very little time to consider them. As far as I can see, a full Ministerial Statement did not accompany them; we had to rely on the coverage of Computer Weekly to understand the Government’s motives.

The Government have quietly established a major parallel high-risk vendor regime. Under Amendments 102 and 103, the Secretary of State—and now, crucially, under Amendment 101, the Chancellor of the Duchy of Lancaster—are granted unilateral powers to issue vendor-related directions. They can legally order an organisation to prohibit, restrict, remove, disable or modify any software, hardware or digital facility supplied by a designated high-risk vendor. Furthermore, under Amendment 105 they are given the power to establish a mandatory referral scheme, legally forcing companies to submit technology procurement contracts to the Cabinet Office for security clearance before signing.

Let us look closely at the operational mechanism in Amendment 103, which ISC2 has rightly highlighted. The proposed new clause mandates that a company appoints a “skilled person” to oversee compliance and, under subsection (5) of the proposed new clause, permits the Secretary of State to rely on a list of persons published by GCHQ. I ask the Minister: what is this list? Is it public or classified? What objective criteria will govern inclusion? How will conflicts of interest be avoided, and how will independent professional competence be assured? To create statutory compliance roles backed by secret lists is entirely unacceptable.

Under Amendment 108, the Secretary of State can make regulations bringing any specific company into the scope of the Clause 43 directions without bringing them into the NIS regulations as a whole. Under Amendment 127, the Government will insert an emergency “made affirmative” procedure allowing regulations and vendor bans to take effect immediately without prior parliamentary debate. Furthermore, under Amendment 148 the Secretary of State can prohibit a company disclosing that they have received a direction or are in consultation, backed by civil penalties of up to £10 million or £50,000 per day.

There is also a second critical implication—the backdoor regulation of advanced artificial intelligence systems. At Second Reading, the Minister assured the House that advanced AI systems and LLMs were out of scope. These amendments appear to reverse that position. Under Amendment 108, any entity providing essential goods or services can be specified. As our critical infrastructure increasingly integrates agentic AI models, such as GPT-5 or Anthropic’s Mythos, these developers become points of supply chain risk concentration. It seems that, under Amendment 102, the Government can designate AI developers as high-risk vendors and mandate pre-procurement vetting. Is that the case and, if so, why not say so?

The Government will no doubt resist the transparent, legally bounded emergency shutdown power proposed by Amendment 84, with its High Court backstops and seven-day parliamentary reporting, yet here the Government demand sweeping, secretive executive powers to ban software, veto procurement and gag businesses with zero judicial checks. These Benches cannot give these 65 government amendments a free pass. I remind the Minister that, in Grand Committee, unanimity is required for amendments to carry. We insist that the Government come back on Report with strict guardrails and clear limits on executive market intervention without parliamentary consent before these new powers can be exercised.

Quite apart from that, both the Constitution Committee and the Delegated Powers and Regulatory Reform Committee had something to say about the existing powers in the Bill, but neither committee has had a chance to look at these amendments. I am sure that they will have comments to make in due course.

Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, I apologise for not speaking before the Liberal Front Bench, but the great news for everybody in Grand Committee is that I am not the Conservative Front Bench. That is good to know. I declare my relevant technology interests as adviser to the Crown Estate and to Simmons & Simmons LLP.

I have just a few questions for the Minister, most of which revolve around what was known when the Bill was in the Commons and what has become known since it was in your Lordships’ House at Second Reading that have required this raft of amendments to come forward over August. The Minister, in her opening, described defective by design; this is an interesting principle, which could have broad applicability, but, as the noble Lord, Lord Clement-Jones, said, we were clearly told at Second Reading that AI and all therein were not in the scope of this Bill. Does this raft of government amendments change that fundamentally? Is it a nod or hint to it? Is this a large, fundamental change in the Government’s policy approach to large language models and enhanced AI, as covered by this raft of proposed amendments?

Is the Minister’s view that changes to the machinery of government will not be complete and clear by the time the Bill completes its passage through your Lordships’ House, hence the need for the reference to the Secretary of State or the Chancellor of the Duchy of Lancaster? Is there a broader issue on that point, worth the Committee considering, on how the shuffling of departmental deckchairs ahead of the Summer Recess is going down? How long will this take to be settled? Could the Minister update the Grand Committee on what is happening with clarity on where every last element of science, innovation and technology policy now rests? Do they all have a clear, identified home and ministerial responsibility?

In later groups we will come on to talk about AI and the deafening silence on AI—until this raft of amendments. Perhaps the Minister would like to comment, in responding, on whether the Government have had a significant change of direction on these technologies, as illustrated by these amendments, or whether they have not. Thus, what will the Government’s response be when these issues are discussed in later groups, compared to the response that they gave at Second Reading?

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I will need to write to the noble Lord on that specific question of how GCHQ’s powers are executed in respect of operational decisions such as this. I am aware that in other areas they are within Secretary of State responsibility, whether they are exercised by a Secretary of State, advised by GCHQ or whether, as the noble Lord suggests, they are actually undertaken by GCHQ.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I thank the Minister for her gracious, intended withdrawal of Amendment 1, and I am sure we will have a much better debate on Report as a result, particularly once we have had a chance to read her remarks on both interventions today. However, I hope she will agree with me, especially in terms of what she said about being technology agnostic through the Bill, that we will have a much better debate as we come to talk about specific AI issues as a result of not having already incorporated those in the Bill. So, all the way around we will have a much better debate about the proper shape of the Bill as a result of those amendments being withdrawn.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

With that, I believe now is the time where I beg to leave to withdraw Amendment 1.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I support Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron, to which I have added my name. I will not repeat too much all her comments on our learning from the Online Safety Act that small does not mean low risk. However, it should not be a surprise that those of us who championed that amendment to the then Online Safety Bill have again put our names to it. We have learned the hard way that, in online safety, risk can come from the smallest providers.

I have learned it personally. I retired from TalkTalk 10 years ago and I remember, what must have been 11 years ago—I promise this is not a cyber attack story—a mapping exercise across all the telcos, mobile and fixed, looking at our even then incredibly complex data centre networks across Europe. I am sure this has all changed and is much more complex, but I remember discovering, as a result of that exercise, that all of us were routing traffic through the same small data centre in central Europe and none of us was aware that we were doing so. These networks are expanding so fast and data centres and managed service providers are growing so fast that it is impossible for people to retain perfect knowledge 100% of the time, so a small provider really can be a node that brings down the whole network. It is not just in child safety that we have learned that small can mean very risky; it is also the case in the world of physical digital infrastructure, which we have known for some time in telecoms. That is why these amendments are so important.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, these amendments confront us immediately with some of the Bill’s most fundamental potential structural weaknesses—the danger of a static, arbitrary and pre-digital scope. The Government appear to have conceded this point already by tabling those infamous 65 high-risk vendor amendments in the previous group. Let us look first at Amendment 3 in the name of the noble Baroness, Lady Kidron, which I would have signed if there had been room.

As drafted, the Bill brings data centres into scope, relying entirely on rigid physical megawatt thresholds—specifically a rated IT load of 1 megawatt, or 10 megawatts for enterprise facilities. In the modern cloud ecosystem, physical power load is a crude and unreliable proxy for risk. A highly dense, interconnected facility drawing under 1 megawatt can host the critical patient records of multiple NHS trusts, emergency dispatch telemetry or core local government routing directories. If that facility is compromised, the societal and economic devastation will be catastrophic, regardless of how much electricity it pulls from the grid—the noble Baroness drew the parallels with NHS data centres.

Amendment 3 would provide the essential statutory fix. It would empower Ofcom to apply a risk-based designation that looks beyond physical power to evaluate the customer base, data sensitivity and critical interconnectivity. I listened with considerable interest and sympathy to what the noble Baronesses, Lady Kidron and Lady Harding, had to say about parallels with the Online Safety Act, which is engraved on our hearts.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, we have had some excellent speeches in this group. I hope that the Minister has taken on board some of the points made by people who really know what they are talking about in the AI field. I will speak to my Amendment 84 and in strong support of the amendments tabled by the noble Lord, Lord Tarassenko, and the noble Baroness, Lady Kidron.

--- Later in debate ---
The question of how far you take the powers of the state and the powers of the regulator seems to me to be an area for discussion. It would be good to see some agreement between the private sector and the regulators about what needs to be regulated and what should be left to business. I think that is an area for further discussion, but I think we need something which is not quite either of these two extremes that are being proposed: the complete regulation of everything and done by only one regulator.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I first congratulate the noble Lord, Lord Birt, on what is a really comprehensive vision expressed in this group of amendments. I speak in strong support of those amendments, on which both he and the noble Lord, Lord Londesborough, have spoken so cogently. Together, they address one of the most glaring defects of the architecture of this Bill: the fragmented, inefficient model of 12 separate sectoral regulators. I think that the noble Baroness, Lady Neville-Jones, asked the right questions about how to co-ordinate and how to be fair, but I am afraid I come to very different answers and to the same conclusion as the noble Lord, Lord Birt. Cyber threats are sector-agnostic. Malicious code and supply chain exploits do not respect the boundary between Ofwat, Ofgem or the CAA. Expecting 12 separate bodies to recruit scarce elite cyber forensic talent is a fantasy that results in weak, uneven enforcement.

Furthermore, multi-sector businesses face duplicative compliance obligations across separate competent authorities in the current scheme. Under Amendments 7, 9 and 11, the noble Lord, Lord Birt, would correctly widen the definition of digital service providers to include the creators, distributors and managers of software and digital platforms. As the Synnovis pathology attack proved so catastrophically to London hospitals, our critical infrastructure is entirely dependent on third party software code. If we do not bring software and platform providers into scope under Clauses 7 and 8, we leave the front door wide open to cyber crime. Amendment 88, in the name of the noble Lord, Lord Birt, which I actually prefer to my own Amendment 87, would replace this maze of regulators with a unified, specialised body, the office for cyber resilience. The OCR would centralise enforcement, establish common auditing baselines and maintain sector-specific expertise under a single roof.

Amendments 76 and 77 would ensure that, when the Secretary of State specifies new essential activities under Part 3, they must act on the expert recommendations of the OCR, targeting any activity whose disruption carries severe economic, societal or national security impacts. I entirely agree with what the noble Lord, Lord Holmes, had to say and think, sadly, that we would all benefit from a bit of musical accompaniment.

This structural foundation would enable a vital reform suggested by the noble Lord, Lord Birt: Amendment 89 would establish a register requiring software and platform providers to certify products as safe by design; and Amendment 91 would introduce annual independent cyber resilience audits modelled on statutory financial audits.

Under Amendment 90, the OCR would work hand in glove with the UK Cyber Security Council to validate and enforce workforce competence standards across all regulated entities. I remind your Lordships that Amendment 99, in the name of my noble friend Lady Northover, has been degrouped but is relevant to the relationship between the potential OCR and the UK Cyber Security Council.

This is a comprehensive but significant group of amendments that hang together extremely well. I urge the Government to look very closely at what could be a really effective scheme of regulation.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Birt, for introducing this debate and all noble Lords who have spoken. I appreciate the rigorous strategic thinking that the noble Lords, Lord Birt and Lord Londesborough, have put into the proposal for an office for cyber resilience, but I will try to keep my remarks to the principle of a single regulator.

As others have set out very powerfully, I see the appeal of having a single regulator: it is easy to issue directives, to store data and information centrally, to take a systemic approach overall and to better manage the hiring of scarce, skilled resources. That said, as my noble friend Lady Neville-Jones pointed out, it is important to see the value of sectoral regulators supported by a centre-of-excellence model. More sector-specific expertise, more direct communication with the industry and more flexible approaches are all easier to achieve with smaller, more specific regulators. At a sufficient level of abstraction, it almost does not matter which of those models you go for; it is about having resourced, skilled and empowered people performing monitoring and enforcement activities, regardless of the body under which they sit.

More broadly, the point is that, while differences between a more centralised or more sectoral approach are worthy of debate—I do not think we would ever hit the extremes of either of those—what actually matters is ensuring that, whichever route the Government choose to take us, they make certain that the regulators are adequately resourced and that they exist within a wider strategy.

I am not sure, and look forward to finding out, whether the first of those is the case. The Government have chosen the more sectoral approach, but we do not yet know how the regulators are going to be resourced and what additional resourcing needs will be needed to cope with the increased responsibilities that will be laid at their door. I look forward to hearing from the Minister on how the regulators are going to be funded, how the funding needs will be calculated and how they are going to be supported in this significant expansion of their role.

The second point is that the regulators should exist as a part of a wider strategy, which is not currently the case. I apologise to noble Lords for banging on about this, but it is very difficult to get the past the hole in the Bill in the shape of a wider national cyber strategy. Whether the regulators are many or one matters little without the bigger picture into which they fit. In an ideal world, we would review the overall cyber strategy and then debate what regulatory structures might be appropriate to deliver it but, for now, sadly, that is not the world that we are in.

The Secretary of State—or, indeed, the Chancellor of the Duchy of Lancaster; it is not reassuring that we still do not know which one—must commit to publishing the national plan, after which we can assess the efficacy of its many parts.

--- Later in debate ---
Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - - - Excerpts

My Lords, I declare my interest as a chief engineer working for AtkinsRéalis. I shall speak to Amendment 82.

In our debate on group 3, a lot of good points were made about one specific technology related to cyber: AI. However, as the noble Lord, Lord Birt, said in the debate on the previous group, quantum is the other area that needs attention as a specific technology. When I started here around seven years ago, I never thought that I would one day be talking about quantum mechanics in your Lordships’ House.

I recently heard the story of Heisenberg and his discovery of the uncertainty principle, almost 100 years ago in 1927. He was out in a park late one night, after a long argument with Niels Bohr, and he saw a row of street lights. He saw a person walking in between the street lights late at night. He would see them go past one light—you would be able to observe them—and then they would disappear into the darkness and they would then reappear at the next light. He realised that he could use that analogy for the behaviour of the electron: as it was being measured, it was there as a particle, but, when it was not being measured, it had to be considered probabilistically because you do not know where it is. In the same way, with a quantum computer, the value of the qubit, as it is called, is locked in only when it interacts with a measurement device.

This extraordinary powerful technology is now emerging. As an example, the Willow chip, which has recently been developed by Google, completed a benchmark calculation in five minutes. It would have taken the fastest classical computer in the world 10 septillion years—that is 10 with 24 zeros, I believe—to complete it. According to the Parliamentary Office of Science and Technology and the NCSC, in less than 10 years—perhaps even sooner than that—we could have a cryptographically relevant quantum computer that uses Shor’s algorithm to decrypt all communications that rely on the RSA algorithm on which we have relied for decades for all of our bank transactions, state-level communications and so on. This is an area of technology that is moving extremely quickly, and it is not just one about which we will have to worry at some point in the future. So-called “harvest now, decrypt later” attacks could be used to decrypt sensitive information in the future.

That brings me to the amendment. It is quite a simple, straightforward one, which goes forward from the discussions on how, given the changing nature of these technologies, it is perhaps not appropriate to have specific technologies and timelines in the Bill. However, as the Minister has already brought out, the statement of strategic priorities is a powerful tool to ensure national join-up, including across those regulators within the remit of the Bill.

We have 12 regulators and each one could approach quantum crypto—so-called post-quantum cryptography—differently. There will be huge benefits in really ensuring that regulators work from the same national signal rather than inventing their own PQC expectations individually. That would also allow them, if it can be brought out in the statement of strategic priorities, to plan their inspections, guidance, skills and capacity around the NCSC timelines, which is a plan ranging from 2028 discovery and initial plan through to 2035 when post-quantum crypto implementation is completed. That will also help with all those newly in-scope firms that will be coming within the remits of this legislation, giving the regulators a legitimate basis to raise post-quantum crypto with those new organisations early on.

I read back the Minister’s remarks at Second Reading, when she said that quantum crypto

“would be considered as part of that requirement by regulated entities, but would not necessarily be singled out as a specific technology in the regulation so that we keep these regulations up to date and matched to the cyber risks that individual entities face”.—[Official Report, 14/7/26; col. 622.]

I believe that this amendment would help strengthen and deliver exactly that. With that, I look forward to hearing from the Minister on her thoughts about this approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I will speak to this substantial and rather disparate group of amendments, including Amendments 93 to 95 in my name, Amendment 10 tabled by my noble friend Lady Ludford, and a number of other amendments in the names of other noble Lords, including that of the noble Lord, Lord Arbuthnot, who, sadly, is in the Chamber as well.

Under Amendment 10, comprehensively introduced by my noble friend Lady Ludford, we would ensure that digital service providers manage risk arising from AI-driven fraud which, as she explains, represents over 40% of reported crime in England and Wales. I thought she made an extremely convincing case and I very much hope that the Minister takes what she said to heart and adds the very few words that are required to make this Bill much more secure with regard to the kind of phishing activity that she described.

As regards the various amendments relating to skills, beginning with the workforce and competence deficit, in its latest 2025-26 workforce study, ISC2 reveals that 52% of UK cyber professionals identify skills shortages as their single greatest obstacle to regulatory compliance, with 58% of organisations facing critical skills shortages. Regulation without competence is what might be described as pure compliance theatre. That is why, on these Benches, we strongly support Amendment 15 in the name of the noble Lord, Lord Arbuthnot, which would place a direct statutory duty on regulated organisations to ensure that their security leads possess verified competence, alongside Amendment 114 from the noble Lord, Lord Holmes, which would require the Secretary of State to define the objective qualifications and independent criteria for appointing skilled persons.

We also see critical implementation blind spots in distributed infrastructure. In July, as documented in the “Analogue 72” Green Paper, which I have mentioned before, a small UK electricity generator was taken offline for four days following a suspected state-sponsored cyber attack. Because it fell below the statutory reporting size threshold, local responders had zero visibility of the disruption. If small distributed energy assets are paralysed, the compound threat to local grids is severe.

Amendment 82 tabled by the noble Lord, Lord Ravensdale, rightly addresses quantum decryption. I am afraid that, if we are not careful, we are back in the territory of technology agnosticism. I think that across the Committee we have a fundamental disagreement with the Government about that. Hostile states are actively executing “harvest now, decrypt later” operations. By requiring the Secretary of State to incorporate NCSC post-quantum cryptography timelines into strategic priorities, we would mandate preparation for quantum-resistant encryption across all critical sectors. We very much support the amendment tabled by the noble Lord, Lord Ravendale.

Amendment 93 in my name would introduces mandatory eight-week public consultations before secondary regulations or codes of practice are issued, protecting industry and SMEs from closed-door administrative creep. I think that is the kind of area where the Minister could give further assurance.

Amendment 94 in my name would establish a statutory presumption of conformity for organisations achieving ISO/IEC 27001 or Cyber Essentials Plus certification. This safe harbour would eliminate legal ambiguity, reward gold-standard cyber hygiene and free regulatory resources to focus on high-risk, non-compliant entities, while preserving the regulator’s right of rebuttal. As the Minister can imagine, this has considerable industry support.

In Clause 40, my Amendment 95 would shorten the legislative cycle from five years to three years. We also support the alternative in Amendment 95A from the noble Lord, Lord Arbuthnot, which probes an even tighter two-year window, and his Amendment 95B, which I have signed, which would ensure that future statutory reviews must explicitly assess third-party and supply-chain dependencies originating outside the regulatory perimeter. Furthermore, we support the noble Lord, Lord Arbuthnot, in his proposed new Clauses 174C and 174D mandating competency standards and annual workforce strategies—we are just sorry that he is not here and able to speak to those amendments—alongside Amendment 92B from the noble Viscount, Lord Camrose, requiring large businesses to report transparently on their cyber resilient plans.

We have not heard from the noble Viscount regarding the other Conservative Front Bench proposals, but we are sympathetic to the need to review information sharing and analysis centres, ISACs, under Amendment 169 and to expect clear regulatory funding plans under Amendment 174. Furthermore, holding the Government to their commitment under the National Audit Office’s 2025 report and the Cyber Action Plan, under Amendment 170, is important. However, we are less supportive of Amendments 173 and 175, which attempt to make commencement of the entire Act conditional on publishing the National Cyber Action Plan. In our view, that would potentially create a dangerous delay, holding our national resilience hostage to Whitehall paperwork when our hospitals and utilities need protection today.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness, Lady Ludford, for introducing this group. I am generally supportive of the principles she is introducing, and I thank all noble Lords who have spoken in this debate. I particularly enjoyed trying to get my head round ten septillion, however many zeros that was, on that computing.

Moving first to our amendments, I hope that there was something constructive in this debate trying to build on a lot of the things that the noble Lord, Lord Birt, said in the previous group around giving people tools for self-help in a lot of this because we know that the Government cannot be expected to cover every aspect. Starting with the amendment in my name and that of my noble friend Lord Camrose, Amendment 92B builds on a similar principle to that underpinning our support for a voluntary referral scheme, that being that businesses and individuals should, where practical, be self-sufficient and self-accountable with regard to cyber security. The more that businesses are responsible for their own security, the less the state has to look over their shoulders: I think that is of benefit to both parties. Requiring a large business to report its own cyber security and resilience plan provides an impetus. The idea is that you want the board to ask the chief executive and the executive team, “What are you doing in this space?” and hold them to account for the shareholders. If the answer to that is a big fat zero, that would clearly be concerning. That act of informal, nudging pressure—call it whatever you want—would be quite a call to action that any self-respecting chief executive and board would take heed of.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I shall speak in support of this group on designated critical suppliers. I support in particular Amendments 15A and 15B, which were tabled by the noble Lord, Lord Arbuthnot of Edrom; I have signed them both. We are also sympathetic in principle to Amendment 16 in the name of the noble Lord, Lord Ravensdale.

We on these Benches fully support the principle of regulating managed service providers and designated critical suppliers. Because MSPs and key vendors act as trusted bridges into multiple enterprise networks, a single compromised supplier can trigger a systemic, cross-sector shutdown; we saw this in the Collins Aerospace attack, which halted airport check-in systems across Europe. However, we must ensure that our regulatory net is both deep enough to capture hidden systemic risks and precise enough to avoid catching non-critical small businesses.

In our view, Amendments 15A and 15B in the name of the noble Lord, Lord Arbuthnot, achieve the necessary depth. They would empower regulators under Clause 12 to designate critical suppliers that supply essential services or managed service providers through one or more intermediaries. In modern digital architectures, systemic single points of failure often sit at tier 2 or tier 3 in the supply chain. If an essential service materially depends on a sub-tier vendor, regulators must not be blinded by the absence of a direct contract. By pairing Amendments 15A and 15B with Amendment 16 in the name of the noble Lord, Lord Ravensdale, we could ensure that deep supply chain risks are policed, while protecting small innovators from bureaucratic overreach.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend for introducing this group; as it is the final group of the day, I will keep my remarks brief.

Amendments 15A and 15B in the names of my noble friend Lord Arbuthnot and the noble Lord, Lord Clement-Jones, seek to allow regulatory oversight of critical suppliers on whom operators of essential services and relevant service providers depend, be it directly or indirectly. We believe that this must be a reasonable approach. The aim of Clause 12 is to ensure the continued functioning of the central suppliers and providers by providing support for their critical suppliers. Surely whether they are supplied directly or indirectly is of little importance.

Amendment 16 from the noble Lord, Lord Ravensdale, would restrict the designation of critical suppliers to those who present systemic risk rather than a simple single-entity risk. We should seek to minimise government oversight wherever possible, and suppliers should not be designated unless they pose a genuine risk. I am also supportive of the noble Lord’s focus on cross-sectoral consistency and general macroeconomic risks, which is too often something that the Government neglect.

However, I am hesitant to endorse the amendment in its entirety. Having to assess every supplier of every OES, RDSP or RMSP and having to decide whether it meets the systemic threshold have the potential to place an unrealistic administrative burden on designated competent authorities. We are already concerned about the resources that they will need to undertake the changes that the Bill introduces; I am unsure whether we need to ask more of them.

To wrap up, I return to a more general point: the risk to the economy or to national security is a scale, and the legislation that we pass should reflect this. Perhaps the noble Lord, Lord Ravensdale, is correct that the designation of critical suppliers based solely on whom they serve is too permissive, but it is equally as likely that restricting designation to systemic risks would be too restrictive. This highlights—it goes back to earlier groups—that the binary distinction about which we are talking now does not cover the gradation of different types of risk. That is why I come back to the original point that my noble friend Lord Camrose made on adopting, perhaps, the Cyber Monitoring Centre’s severity scale, which offers a template for a more nuanced approach to definitions. I hope that the Minister can commit to reviewing the Bill’s definitions ahead of Report.

UK Streaming and Cinema Sector

Lord Clement-Jones Excerpts
Monday 2nd March 2026

(6 months, 3 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

I have heard that loud and clear, and I will convey the sentiment of the House back to colleagues in DCMS.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I declare an interest as chair of the Authors’ Licensing and Collecting Society. The Minister said that she cannot at this stage rule out certain aspects of what might be contained in the paper due from the Secretary of State this March, but can she rule in the importance of making sure that AI developers must license UK content for the training and grounding of their models?

Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

Our priority is to ensure that the UK is ready for AI-related risks while supporting responsible innovation and long-term growth. We are considering all potential options to deliver on the UK’s ambition. It would be a very foolish and brave Minister to pre-empt a report that has yet to be published, but I look forward to future debates on this matter.

Enterprise Act 2002 (Mergers Involving Newspaper Enterprises and Foreign Powers) Regulations 2025

Lord Clement-Jones Excerpts
Tuesday 22nd July 2025

(1 year, 2 months ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
As someone who believes passionately in the future of our free press, I know which side I am on and that is why I will be voting against the amendment in the name of the noble Lord, Lord Fox. I would urge all others who want to secure a sustainable, optimistic future for our media to do the same.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I strongly support my noble friend Lord Fox’s fatal amendment. When this House welcomed a complete ban on foreign government ownership at the Third Reading of the Digital Markets, Competition and Consumers Bill last March, the then Government proposed a 5% exemption for passive sovereign wealth fund investment. The noble Baroness, Lady Stowell, and the noble Lords, Lord Forsyth, Lord Robertson and Lord Anderson, deserve huge credit for securing this change, alongside the then Minister, the noble Lord, Lord Parkinson.

Yet in a remarkable about-face, this Labour Government propose allowing foreign state-owned investors to hold up to 15% stakes, tripling the previously proposed threshold. As we have heard, 15% is not trivial. Even a 15% stake can provide extraordinary leverage, board representation, veto powers over key decisions and a very real influence over editorial policy.

The Competition and Markets Authority guidance on mergers’ jurisdiction and procedure makes it clear that there is no exhaustive list of relevant factors. Even one board seat may suffice, depending on circumstances. The regulations currently allow multiple foreign states each to acquire a 15% stake. Nothing would stop a consortium of foreign regimes stacking up a controlling interest in a British newspaper. The Government acknowledged this flaw in their letter of 21 July, admitting, as we have again heard, that this will need correcting in the autumn. But why proceed with these regulations when the Government admit that they are fundamentally flawed? The 15% threshold contrasts starkly with international best practice. Australia sets just 5% for media companies.

There has been some argument today, notably from the noble Lord, Lord Black, that our struggling newspaper industry needs foreign investment. Even the Minister talked about existential threats. But if conventional investors are reluctant, as the noble Lords, Lord Fox and Lord Forsyth, say, foreign state investors clearly seek a different return: influence. Should we mortgage editorial independence when the price is erosion of public trust?

The consultation process was deeply problematic, with only four responses, primarily from newspaper groups seeking foreign investors. This hardly justifies tripling the threshold. The Government claim they can intervene if passive investors become active, but how does one monitor passivity and detect influence? As the Secondary Legislation Scrutiny Committee noted, it is an impossible task to determine nuanced changes indicating influence. In matters of press freedom, we must err on the side of caution.

I see that the noble Lord, Lord Black of Brentwood, came out in yesterday’s Telegraph, and today, with all guns blazing. His attack on the Liberal Democrat position fundamentally mischaracterised what the Press Recognition Panel actually does. The PRP is not a statutory media regulator that controls editorial content. It is an independent body that recognises voluntary press regulators, such as Impress, while IPSO deliberately chooses not to seek recognition to avoid meeting proper independent standards. This system protects press freedom by ensuring that regulatory bodies themselves meet robust standards for independence and effectiveness.

The characterisation of this amendment by the noble Lord, Lord Black, as “onerous statutory controls” is the same misleading tactic used by media proprietors to avoid genuine accountability while maintaining maximum commercial freedom. The position of these Benches is entirely consistent: genuine press freedom requires protection from all forms of external influence, whether political interference, proprietorial control or foreign state investment. Our support for Leveson-compliant independent regulation and opposition to foreign state media investment both serve the same principle: to ensure editorial independence from external pressures.

The stakes could not be higher. As the noble Lord, Lord Black, has mentioned, this legislation is clearly drafted to facilitate deals such as the potential takeover of the Telegraph by RedBird Capital, whose Chinese connections are subject to concern. A 5% cap strikes the right balance, allowing for genuine commercial investment while preventing the accumulation of influence that will strangle press freedom. The British public deserve to know—

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- Hansard - - - Excerpts

As ever, the noble Lord has made a good case. He made his point—as did the noble Lord, Lord Forsyth—around what a percentage stake might mean if the returns are not going to be great. What difference is there between 5% and 15% in respect of the argument he is making about influence? If someone wants to invest 5%, surely they are doing it on the same basis as 15%.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

Perhaps the noble Lord has never been on the board of a public limited company. There is a huge difference between a 5% and a 15% ownership stake.

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- Hansard - - - Excerpts

There is a difference, but the argument the noble Lord is making is that people are seeking to get influence rather than a financial return. If you are taking 5%, you are doing so for a financial return. Why would investors not also be looking for a financial return on 15% in just the same way?

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

If a company has a series of 5% ownership stakes it will have a plurality of shareholders and therefore a mix of influence, but if you own a 15% stake you have a much higher share in the company and are probably entitled to a single board member.

Lord Forsyth of Drumlean Portrait Lord Forsyth of Drumlean (Con)
- View Speech - Hansard - - - Excerpts

Is it not that there is a difference between 5% being held by a foreign government and 5% being held by a national wealth fund or something of that kind?

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I entirely agree with the noble Lord. I do not understand why the noble Lord, Lord Knight, is raising what seems to be a pretty obvious issue.

The British public deserve to know that their morning newspaper delivers journalism guided by British values and editorial independence, not the preferences of foreign powers.

Briefly on this House’s conventions: the guidance issued in the 2006 report from the Joint Committee on Conventions—which was mentioned by noble friend Lord Fox—is still current, despite the 2015 Strathclyde review. It concluded:

“On the basis of the evidence, we conclude that the House of Lords should not regularly reject Statutory Instruments, but that in exceptional circumstances it may be appropriate for it to do so. This is consistent with past practice, and represents a convention recognised by the opposition parties”.


Subsequently in March 2007, with strong support from the then Archbishop of Canterbury I succeeded with a fatal amendment that prevented a super- casino being located in east Manchester. Since then, in January 2013, the noble Lord, Lord Bach, succeeded in defeating a legal aid order. I welcome what the noble Baroness, Lady Stowell, had to say about the existence of the convention.

Those were exceptional circumstances and so too are today’s. The ownership of our press is a matter of great public policy importance, and we are fully entitled to defeat these regulations. I urge noble Lords to support my noble friend Lord Fox’s fatal amendment. Let us send a clear message that the integrity of the British press is not negotiable: 5% is sufficient, but 15% is a doorway to influence that, once opened, may prove impossible to close. I commend the amendment to the House.

We on these Benches also oppose the draft Enterprise Act 2002 (Amendment of Section 58 Considerations) Order 2025 and the draft Enterprise Act 2002 (Definition of Newspaper) Order 2025, which have been tabled for approval today. These orders propose extending the ambit of the Enterprise Act to encompass digital media and broadening the definition of “news media” to explicitly include online news, websites and broadcasting. If we were at one on the question of media ownership then this would be a welcome extension. However, expansion at this time, while fundamental concerns regarding foreign ownership of traditional newspapers remain unresolved—or, indeed, are potentially being dangerously broadened—is illogical and dangerous, and we will not support these draft orders.