All 1 Debates between Lord Clement-Jones and Baroness Berger

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Lord Clement-Jones and Baroness Berger
Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I will speak quickly. I was just checking my records, particularly on Amendment 167. It was just under a year ago that I completed the FT board director programme, which was specifically around cyber risk for boards. In a room of around 50 people, we had a tabletop exercise on a real-life scenario about what one should do in the event of a very serious cyber crisis and cyber risk. I was struck by a number of things. In the room were people with vast waves of expertise and experience, none of whom was a technology expert. All said that no other members of their board had attended training like this. They were there because, having completed a board director programme, it piqued their interest, as it did mine, it was freely on offer and they decided to attend.

Having gone through that session, we covered things such as the regulatory experience, issues around how to challenge management in the event of one of these incidents, how you need to test organisational resilience, how you need to look at the risks involved, and how to respond decisively and to have the expertise and understanding to do so. It was very clear to me, even during that half-day exercise, that that training was not sufficient for me as a board director and member to be able to fulfil that role.

Having gone through that experience, I think for many reasons that this amendment is so important to ensure that boards across this country—be they private boards, FTSE boards or boards of regulated companies—can do their jobs effectively. In this world, which is extending—I echo the points made about AI—it is even more imperative that we have this amendment to ensure that boards are able to fulfil their roles effectively.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, this has been a really useful debate, particularly because it has distilled all the considerable board experience—and, indeed, board training experience—around this Committee. I very much hope that the Minister listened to it with interest.

Amendment 74 in the name of the noble Baroness, Lady Morgan, moved by the noble Baroness, Lady Kidron, would align the UK with the EU’s NIS2 framework. It would introduce personal civil liability for senior executives who deliberately or carelessly neglect cyber duties. My noble friend Lady Ludford’s Amendment 167 would mandate board-level oversight and technical training. In our view, to build national resilience, cyber security must become a fiduciary director’s personal responsibility. As the noble Baroness, my noble friend and the noble Lord, Lord Arbuthnot, have said, this change is long overdue and would be additional to other existing sectors. We need to learn from experience in the way mentioned by the noble Baroness, Lady Harding; I very much hope that we will do so in the course of the Bill.

Together, these two amendments target arguably the single greatest cultural—the noble Baroness, Lady Kidron, rightly emphasised “culture”—and behavioural failure in UK cyber security today: the persistent treatment of cyber security by company boards as a delegated technical IT issue rather than a core personal and fiduciary leadership responsibility. The Government’s approach to corporate cyber governance has been almost entirely passive to date, I am afraid. Ministers have relied on voluntary guidance, such as the Cyber Governance Code of Practice, hoping that boards would voluntarily prioritise digital resilience.

The proof of this policy failure is undeniable. My noble friend quoted the Cyber Security Breaches Survey, which showed that board-level ownership of cyber risk has declined over the past three years. Of course, if boards neglect cyber security, that carries massive public costs, as seen in the recent major supply chain disruptions where, although company directors face strict personal legal liabilities under company law for signing off on financial accounts, they are permitted to treat systemic cyber vulnerabilities—vulnerabilities that can wipe hundreds of millions of pounds from the economy and paralyse critical national supply chains—with complete personal legal impunity.

My noble friend also reminded us of the catastrophic real-world cost of this boardroom neglect in the automotive sector, where a supply chain breach at Jaguar Land Rover cost an estimated ÂŁ500 million, halted production lines for four months and forced the Government to step in with a ÂŁ1.5 billion loan guarantee. We have seen the same in retail, also mentioned by my noble friend: the cyber attack on Marks & Spencer cost ÂŁ300 million and contributed to a 99% collapse in pre-tax profits.

Amendment 74 would provide the direct legislative teeth that the Bill is missing by introducing personal civil liability for senior executives. It would amend the NIS regulations to establish that, where a regulated entity fails to comply with core risk management duties, and that failure was committed with the consent, connivance or deliberate or careless neglect of a senior executive, the regulator may impose a personal civil penalty.

--- Later in debate ---
Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I support the principles behind these amendments. A point was raised by the noble Baroness, Lady Ludford, and I wish to make the point in a different way. Many reasons have been shared during this debate, which I share. The noble Baroness, Lady Ludford, referred to the questions asked by Chi Onwurah MP in the other place. It is interesting because I submitted a very similar Question just before the end of the summer in July. I asked:

“what proportion of the computing and cloud services used by government departments are provided by suppliers that are … headquartered outside the UK, or … subject to the jurisdiction of a government outside the UK”.

I asked that specifically in the wake of recent events and the debate we had in July.

The Answer came back on Tuesday. I accept that the Question asked by Chi Onwurah MP was specifically about AWS, but I was asking about all services hosted outside the UK. The Answer was:

“This information is not held centrally. Individual government departments are responsible for managing their own commercial arrangements for computing and cloud services and would need to confirm the proportion of services provided by suppliers headquartered outside the UK”.


The Government do not know how much they are collectively relying on other countries for our key government digital infrastructure. Our Government’s critical systems, public services and citizens’ data are increasingly reliant on foreign-hosted clouds and data centres. While the Answer refers to “commercial arrangements”, I think it is about much more than that. This is a question of our national security and resilience. I believe we urgently need a digital sovereignty strategy to ensure that we know the answers to these questions, that we can act on them and that we can prevent any future challenges happening to ensure that we are as resilient as we should be.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I will speak to this very strategic group of amendments. I use that word again because the noble Baroness, Lady Kidron, made it quite clear from the outset that that is exactly what we lack: a clear national strategy. I pay tribute to her tenacity in tabling Amendment 83, following what I thought was an extremely useful debate on the last day before we went into recess. That is still very much top of mind at the moment, as the Minister can see from the contributions today. If we had another debate today, I do not think we would feel any greater assurance than we did on the day of that debate.

I also thank my noble friend Lady Ludford for having tabled Amendment 166, which is along very much the same lines. We have at the moment, particularly in the public sector—I thought the noble Baroness, Lady Berger, put this extremely well—near total and escalating digital dependence on foreign technology monopolies and foreign jurisdictions. It is quite prevalent in Whitehall. There is a kind of ignorance about the geopolitical reality that so much of what might be described as the digital stack is owned, operated and controlled from abroad. I will come on to our procurement policies shortly.

Amendment 83 defines the pillars of true digital sovereignty. It would tackle extreme market concentration. As we have heard, three American technology giants— Amazon, Google and Microsoft—control a staggering 73% of the cloud computing and enterprise hosting supporting our UK financial sector and public services. If an AWS region or Microsoft Azure network suffers a systemic failure, three-quarters of the City of London and vast swathes of government administration are instantly paralysed. Concentrating our critical national infrastructure into a handful of corporate choke points is the very antithesis of national resilience.

Secondly, it directly confronts foreign extraterritorial legal exposure. Because our critical public data is predominantly hosted on foreign cloud architectures, that data remains legally exposed to foreign statutory instruments, most notably the US CLOUD Act, and is subject to sudden unilateral geopolitical shifts. As my noble friend Lady Ludford said, we saw a chilling preview of this vulnerability only recently when the US Administration temporarily cut off European and UK financial institutions from accessing Anthropic’s AI model, Claude Mythos. Whatever the rights and wrongs of Mythos and its capabilities—we have a pretty good idea of what the wrongs were from what the AI Security Institute had to say—suppose that we had adopted this powerful model in a cyber defensive role; if an ally can pull the plug on front-line cyber security tools overnight, we do not possess true digital sovereignty. If a foreign ally can pull the plug on critical cutting-edge technology at a moment’s notice, we do not have true national resilience but a dangerous dependency.

My noble friend Lady Ludford’s Amendment 166 would force the Government to publish a formal digital sovereignty strategy within 12 months, assessing foreign reliance and reforming public procurement to prioritise secure home-grown UK technology. In fact, both amendments would tackle a glaring failure of current government procurement. The UK possesses world-leading academic institutions and an exceptional cyber security start-up ecosystem. But we suffer from a chronic scale-up failure. Time and again, major public contracts, such as the recent NHS and defence platforms, are automatically handed to dominant foreign tech giants such as Palantir, rather than nurturing and scaling home-grown British technology.

Proposed subsection (2)(c) of Amendment 83 and my noble friend Lady Ludford’s Amendment 166 would provide the solution. They would legally require the Government to use public procurement as a strategic lever to prioritise secure, interoperable and sovereign UK-developed technologies. That is how we build long-term sovereign capacity on our own soil, create high-wage tech jobs and prevent our best innovations being swallowed up by our international competitors.

In an era of contested supply chains, autonomous AI warfare and geopolitical instability, a nation that cannot secure its own digital foundation cannot truly govern itself. I very much hope that the Government will take heed of these amendments, even if they do not take them on board in this Bill. The former Secretary of State for DSIT is on the record as being very much in favour of digital sovereignty, and I hope that that carries through into the current Government.