Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Moraes
Main Page: Lord Moraes (Labour - Life peer)Department Debates - View all Lord Moraes's debates with the Department for Science, Innovation & Technology
(4 weeks, 1 day ago)
Lords Chamber
Lord Moraes (Lab)
My Lords, it is a pleasure to follow the noble Lord, Lord Holmes. The noble Baroness, Lady Harding, has inspired me, as I am so low down the list—nearly at the end—not to do that thing of saying, “Everything has already been said, but not yet by everyone”, which I was thinking of while she was speaking. I will not do that; I am going to dump my very boring speech, inspired by the noble Baroness, Lady Ludford, who reminded me of what we used to do for a living. This contextualises exactly what the Government are trying to do.
My noble friend the Minister has a very tough job—I will explain a little why I think it is so difficult—but it is a job that we said we would do. We wanted to update the NIS regulation in 2018 and, as the noble Baroness, Lady Neville-Jones, said, to move fast and have some urgency. I know why she said that: I will come on to what the intelligence services are dealing with every single day, with hacking and what the Russians are doing. She knows that, as that is part of her DNA. We have to move fast, and we have to do something. That is exactly what the Government are doing. I want to try to contextualise what they are doing, why this is a national priority and how we can be as constructive as we can in building cyber security and cyber resilience.
A number of noble Lords, including the noble Baroness, Lady Harding, mentioned the EU network and information systems directive, which is very much the context of what we are doing. The noble Baroness, Lady Northover, spoke in some detail about our alignment with it and the noble Baroness, Lady Ludford, had some critical views about where we are in terms of our alignment. This really contextualises the complexity, as well as the urgency, of what we are doing here in the UK.
Noble Lords have said this because there are really only three global regulators doing this now—in the United States, the European Union and China—and they are diverging very badly. China does its own thing. In the United States, you may remember Mark Zuckerberg coming to the EU inquiry, going to Congress and saying, “Well, we need a GDPR, obviously”, but most of the legislation in the United States on cyber is in fact state led. The FTC looks at it, but it is really not national legislation. The EU is one of the few places, whether you like it or not, which has decided that it is a global regulator and that the cyber threat and cyber resilience are very much a global issue.
That does not take away from or dilute in any way some of the things that have been said, for example by the noble Lord, Lord Vaizey, about the United Kingdom’s special position as a country. We have the best intelligence services in the world, which is very relevant to this area. We have GCHQ and all that, and the technologists and companies close to this area, which are some of the best in the world. But the issue is with global regulation, and that is why it is so difficult.
The noble Baroness, Lady Ludford, made exactly the point that I was going to make, except I come to a different conclusion. She talked about the way that the two Ministers, Ian Murray and Kanishka Narayan, seem to be saying two different things. One is saying that we are taking a big hit and that real businesses and people are being hit by cyber breaches; whether or not it is 0.5% of our GDP, it is a big problem for the United Kingdom. Our other Minister said that we need the 12 regulators, to which the noble Lord, Lord Birt, referred, because they have the expertise, and that that is why it is so complicated and if we do anything else it is a huge burden on business. But I believe that both are true.
This is where the complexity of enacting good-quality cyber legislation happens. I know this because, as the noble Baroness, Lady Ludford, will testify, I chaired many of the GDPR legislative trilogues and the ePrivacy trilogues and I had to scrutinise many of the cyber conventions that are part of the EU treaties and body of law. I will cite the latest AI rapporteur—we now have another AI Act forthcoming in the EU because the older Act is out of date, the GDPR is out of data and the ePrivacy legislation is out of date. I said to the AI rapporteur, “You have the latest AI legislation”, and he said, “Yes, it’s a bit like you just jump off the cliff and build your wings on the way down”. Why somebody from Italy was quoting Ray Bradbury I do not know, but it is kind of correct. I know that the Minister has wings already—she has wings and she need not worry; she will be fine—but the point is that you have to move with such speed. The point that the noble Baroness, Lady Neville-Jones, made is that somehow you just have to move. The urgency is great.
The noble Lord, Lord Vaizey, who is not in his place, has inspired me to depart from my notes. He explained very eloquently, having been a Minister at that time, how complicated this is for our current Ministers in government. He talked about encryption and said that we knew that the companies—Microsoft, Facebook, which is now Meta, Reddit, Snap Inc, and all of them—wanted end-to-end encryption and did not want it weakened. Why? Because with strong end-to-end encryption, you deal with cyber threats. At the time, as noble Lords will remember, there were a lot of terrorism threats around, so most enforcement agencies were saying, “No, we need a backdoor to encryption”. That was the prevailing wisdom, and that argument won out. But the companies, in my view, were right. They were talking about the banking system, privacy and all the threats that we now have if we weaken encryption.
The noble Lord, Lord Vaizey, said that because the context here is that it is extremely complex to come up with good cyber security and resilience legislation. The noble Lord, Lord Birt, is so good with his communication that I almost think the OCR is a real thing. That is because he is who he is—he could persuade anyone. Of course, everyone is saying, “Let’s get rid of the 12”, but I caution about the complexity of dealing with cyber threats. I will give one last example about the daily threats we have from foreign actors—this is very different from the corporate threats, some of which come from within the United Kingdom and need a very different response, as we also saw in the European Union.
My time is up, but I just want to contextualise how tough this is going to be. Let us jump off the cliff, build the wings on the way down, get this done and do what we can in Committee, because this is a national priority. Is it perfect? Of course it is not. But we need to get moving, because the threats are very real.