Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Lord Ravensdale Portrait Lord Ravensdale (CB)
- View Speech - Hansard - -

My Lords, I declare my interest as a chief engineer working for AtkinsRéalis and I support the Bill. Given the threats that we are facing, strengthening the cyber security of the UK is vital. I think that the flexible, risk-based approach taken within the Bill is the right one.

Noble Lords have made many of the broader points already, so I will focus on a few narrower points. My remarks are really centred around the impact on economic growth and the need for proportionate regulation, because this legislation supports growth through, first, increasing our cyber resilience. The noble Baroness, Lady Northover, gave the example of the £15 billion cost of cyber attacks in 2024: that is a significant fraction of our GDP, around 0.5%.

I am also glad that the noble Lord, Lord Vaizey, brought up our world-leading cyber industry: the Bill represents a great opportunity for one of our key industries. However, there are threats to that growth agenda within the Bill, particularly through how larger corporates and SMEs will be affected, and we need to tread extremely carefully here. Business already has to deal with much burdensome regulation, as the noble Earl, Lord Effingham, set out. As ever in legislation, we need to think about those unintended consequences. To this end, there are three points I want to make.

Looking at some of the detail of the Bill, my first point is around supply chains. Clause 12 rightly brings in the concept of “critical suppliers” and ensures that supply chains are within the scope of the regulations. However, given the ambiguity of the criteria for designation, there is a risk that a significant number of SMEs could be affected, perhaps unintentionally, by this legislation, so I would be grateful if the Minister would set out what steps the Government are taking to ensure that the “critical supplier” designation is restricted to suppliers posing genuine systemic risks to the UK economy. Terms such as “potential to cause disruption”, which is the wording used in the Bill, are qualitative, and there are no hard quantitative thresholds in the Bill. The risk, of course, is that a significant number of SMEs could be bought within scope, stifling those businesses with unnecessary regulation. We need to ensure that is proportionate.

Secondly, going through the Bill and continuing on this theme, we come to Clause 15, on reporting. To expand on what the Minister set out at the start, Clause 15 expands the definition of “a reportable incident” to include those capable of having

“an adverse effect on … network and information systems”.

The risk is that this could lead to overreporting, as even a minor phishing email could be deemed to be capable of having “an adverse effect”, and then we could perhaps see overreporting overwhelming systems and bringing the risk that genuine threats could get through. So, I would also be grateful if the Minister could tell us how the Government will ensure that the “capable of having an adverse effect” threshold does not lead to overreporting of low-level incidents.

Thirdly, we have heard a lot of talk about AI in this debate, and perhaps a little less about quantum. I want to bring up quantum as a specific aspect, as the noble Lord, Lord Birt, referred to. I appreciate that there is a difficult balance here. This is a framework Bill, and it is perhaps not appropriate to set out specific technologies or technology impacts in it. However, the threat of quantum computers using algorithms like Shor’s algorithm to crack current public key crypto, such as RSA, enabling “harvest now, decrypt later” attacks on sensitive data, is something that will come, sooner or later, and quantum computing is evolving astonishingly quickly. The Parliamentary Office of Science and Technology, POST, where I am vice-chair of the board, has set out around a 10-year timescale for when a quantum computer will be able to break conventional encryption, and that aligns with the National Cyber Security Centre, which has already set out that organisations must complete migration to post-quantum crypto by 2035. I would be grateful for the Minister’s thoughts on how this could perhaps be strengthened within the Bill. For example, could there be something in the statement of strategic priorities in Clause 25 to help to join together the regulators in terms of the focus that is required on quantum cryptography? I would be very grateful for the Minister’s thoughts on that key area too.

In general, as I said, I support the Bill and I look forward to working with the Minister and her team as we move towards Committee.