Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Lord Forbes of Newcastle Portrait Lord Forbes of Newcastle (Lab)
- View Speech - Hansard - -

My Lords, the Bill sits squarely within the wider national security and preparedness agenda to which this House has repeatedly returned in recent months since the publication of the strategic defence review. We have spoken often about the interlocking nature of modern threats: geopolitical instability, climate shocks, pressure on critical infra- structure and the growing complexity of our digital systems. The Bill is therefore not a narrow technical measure; it is a national security Bill, and it deserves to be treated as such.

Every essential service in the United Kingdom, whether that be our energy grids, water systems, transport networks, hospitals or financial services, now depends on digital infrastructure. The boundary between physical and digital security has dissolved. A cyber attack on a hospital is not an IT problem; it is a threat to life. A breach in a water company’s control systems is not a data incident; it is a public health emergency. A compromise in a major data centre or managed service provider can cascade and cause chaos across the economy in minutes.

In recent years, we have seen how ransomware attacks have disrupted patient care or student learning, how supply-chain vulnerabilities have exposed critical national infrastructure, and how hostile actors—some criminal, some state-linked—have sought to test the resilience of our systems to destruction. The economic costs run into billions. The strategic cost is greater still: weakened confidence, reduced competitiveness and a nation continually forced into reactive crisis management rather than forward-looking preparedness. Resilience is not a cost; it is a foundation stone of our national strength. And the Bill is a necessary step in strengthening that foundation.

The existing Network and Information Systems Regulations, introduced in 2018, were an important milestone, but the digital ecosystem has changed beyond recognition in the years since. Cloud computing, large-scale data centres, outsourced managed services and complex supply chains now underpin almost every aspect of our national life. The regulatory perimeters and safeguards put in place almost a decade ago have not kept pace with the reality of modern risks.

The Bill addresses that gap. It expands the scope of regulation to include data centres, managed service providers and critical suppliers. Crucially, it recognises that vulnerabilities often sit not in the front-line operators but in the third-party services on which they depend. It strengthens incident reporting by ensuring that regulators receive timely, accurate information and that customers are informed when their services or data may be affected. It introduces statutory codes of practice, giving clarity to industry and consistency to regulators, and provides modern enforcement and cost-recovery powers, enabling regulators to act decisively when standards are not met.

Crucially, the Bill requires the Secretary of State to publish a statement of strategic priorities for cyber resilience. This is a significant and very welcome development. It aligns regulators, industry and public services around a shared national mission. It ensures that our approach to cyber resilience is not fragmented or reactive but coherent, strategic, and future-focused.

The Bill is not simply about technology; it is about people. Cyber incidents disrupt lives through cancelled hospital appointments, delayed trains, compromised personal data, businesses being unable to trade and local authorities unable to deliver essential services. The public rightly expect that the systems they rely on every day are secure. The Bill helps us to continue to meet those expectations. It also fits squarely within the broader preparedness agenda that many of us in your Lordships’ House have championed since the gracious Speech. We have argued consistently for a whole-system approach to resilience: one recognising that national security considerations are not confined to the worlds of defence or intelligence, but include the stability of our infrastructure, the integrity of our supply chains and the confidence of our citizens. Cyber resilience is now as fundamental as physical resilience. The two cannot be separated.

We have also emphasised the importance of place-based resilience. Local authorities, NHS trusts, utility companies and regional industries all depend on secure digital systems. A cyber incident in one part of the country can have national consequences. Strengthening digital resilience strengthens local resilience, and vice versa.

We also continue to make the economic case. Secure systems underpin investment, innovation and job creation. They are essential to the competitiveness of our industries and the stability of our financial markets. In a world where digital infrastructure is as critical as roads or railways, cyber resilience is now an economic imperative. Cyber resilience is, and must be, a shared responsibility. Government, regulators, industry, public services and communities all have a role to play. The Bill strengthens the framework within which that shared responsibility can be exercised, so it is timely and necessary, but it is not sufficient.

Legislation alone cannot deliver the resilient digital nation we need to become. We must understand the current limitations of our sovereign digital capabilities and take urgent steps to address this major vulnerability. We must invest in skills, innovation and the capacity of regulators. We must support industry to meet higher standards, and foster a culture of preparedness: one that anticipates risk rather than waiting for crisis.

I end with a brief reference to the motto of my home city of Newcastle upon Tyne. I am not a Latin speaker, so I apologise if my pronunciation offends any of your Lordships who are. “Fortiter defendit triumphans”—triumphing by brave defence—emblazoned across our city’s crest, celebrates the victories it won in the 1600s against marauding invaders. It symbolises the city’s ability to withstand such assaults through its collective spirit of preparedness and fortitude. The lesson I believe we can draw from the history of Newcastle for this modern age is that by strengthening the digital sinews that hold our country together, we strengthen the country itself. In the very act of doing so, we cast a defensive shadow against those who seek to do us harm and, ultimately, we reduce the risk of attack in the first place. The Bill is an important step in that direction, and I am pleased to support it today in your Lordships’ House.