(3Â weeks, 6Â days ago)
Grand CommitteeMy Lords, I rise early to support the amendment from the noble Baroness, Lady Northover, partly to spare the stress of the noble Lord, Lord Clement-Jones, and also because there is a Liberal Democrat amendment imminent in the Chamber, although we of course will be abstaining—our solidarity with the Liberal Democrats does not extend too far.
However, it does extend to this amendment, which ties in well with the noble Baroness’s earlier amendment concerning qualifications. I was fascinated to hear her referring to the Australian cyber service, which I had not heard about before. I would be fascinated to know more and it would be interesting to hear from the Minister what other lessons there may be for us to learn from similar jurisdictions around the globe. I suspect the Canadians, for example, some of our European partners and some of the south-east Asian nations, such as Singapore or South Korea, will probably have very advanced and sophisticated bureaucracies, if I can put it that way, or institutions looking at the cyber threat.
Again, I shall address, rather than the technical detail of the noble Baroness’s amendment, the spirit in which it is brought and why it fits so well with her earlier amendment. It is about injecting a sense of urgency into how we raise our game in cyber in terms of our economy. When she mentioned the cyber action toolkit, it took me back to the days when I was one of the Cyber Ministers in the coalition Government. My responsibility was towards small businesses, and we launched endless small business toolkits, mainly because we wanted to say that we had launched a small business toolkit. We certainly never put in place any mechanisms for auditing its impact or success, and I think the constant references to about 7% of SMEs now having cyber policies in place may point to my abject failure in that role, and perhaps that of some of my successors.
The more I have listened to this debate, the more it takes me back to my childhood, when we would get leaflets about a possible nuclear conflagration. I know that Ministers and the Government are now telling people to stockpile water and baked beans because of the impact of El Niño, but we know that a cyber attack on the UK would cripple our economy and essential public services, so it is akin, given the geopolitical situation, to a national emergency.
The noble Baroness mentioned the views of the Association of British Insurers. Again, that was part of the toolkit. The feeling was that professional services would drive small businesses towards becoming more skilled in assessing their cyber risks, that you could not get insurance, or indeed cyber insurance, unless you had clear policies to deal with cyber attacks. With professional services firms, you could not necessarily get legal liability insurance for a data breach, which is not necessarily going to cripple your business but will affect your customers and therefore leave you open to liability, unless you could demonstrate that you had proper processes in place to protect your data. There is a whole ecosystem, it seems to me, that needs to be brought to bear to support the uptake of cyber skills and cyber audits by small businesses: we cannot be complacent and assume that 7% is an acceptable figure and that it should be allowed to evolve.
To a certain extent, the noble Baroness’s amendment is about the after-effects: if you suffer a cyber attack then you should be able to call on skilled people, whom we hope will have achieved the kind of recognised qualifications that the noble Baroness talked about earlier. She compared them to doctors but, when I thought about the amendment, I thought more about plumbers and electricians and the technical qualifications that you need to have to do a technical and difficult job.
We also need to look at what happens before. How do we increase the number of small businesses that put in place policies that will protect them from cyber attacks? That involves using the private sector, insurance companies and professional services firms to push forward clear protocols to which small business should be expected to adhere in order to receive the cover that they need to carry on doing business.
My Lords, I support Amendment 100, in the name of the noble Baroness, Lady Northover. I spoke in support of this type of amendment at Second Reading and I still support its intentions, but I will give it an added twist. The question in my mind is where this resource for SMEs should sit and whether it should have any statutory powers or simply be an information and advisory centre.
There is no doubt that cyber security is needed—and here is another scary statistic—because 96% of all successful cyber attacks in the UK are perpetrated on SMEs, which represent soft targets for hackers. I suggest—here I take noble Lords back to day 1 of Committee— that this resource should sit within the office for cyber resilience proposed by the noble Lord, Lord Clement-Jones, and my noble friend Lord Birt. Indeed, this is yet another example of the need to establish a body like an OCR, given the disturbingly fragmented approach to cyber security in this Bill.
Where can we sensibly draw the line between SMEs across all sectors and the rest of the business world? For instance, advice given to a medium-sized company with, say, 200 staff will overlap hugely with that given to a company with 2,000 staff. In the minds of the hackers and the ransomware merchants there is very little distinction. I argue that our economy needs a coherent, joined-up approach, run by a single competent authority with statutory teeth, for the benefit of SMEs and other companies and sectors.
I am afraid that, as it stands, this Bill is a recipe for chaos. Cooks and broth would be a kind analogy—there is barely any room in the kitchen for the number of departments, teams, councils, centres and agencies involved. The last count I heard was 30 or so, but I believe a few more have cropped up since.