(4Â weeks ago)
Grand CommitteeMy Lords, I declare my interest as a chief engineer working for AtkinsRéalis. I shall speak to Amendment 82.
In our debate on group 3, a lot of good points were made about one specific technology related to cyber: AI. However, as the noble Lord, Lord Birt, said in the debate on the previous group, quantum is the other area that needs attention as a specific technology. When I started here around seven years ago, I never thought that I would one day be talking about quantum mechanics in your Lordships’ House.
I recently heard the story of Heisenberg and his discovery of the uncertainty principle, almost 100 years ago in 1927. He was out in a park late one night, after a long argument with Niels Bohr, and he saw a row of street lights. He saw a person walking in between the street lights late at night. He would see them go past one light—you would be able to observe them—and then they would disappear into the darkness and they would then reappear at the next light. He realised that he could use that analogy for the behaviour of the electron: as it was being measured, it was there as a particle, but, when it was not being measured, it had to be considered probabilistically because you do not know where it is. In the same way, with a quantum computer, the value of the qubit, as it is called, is locked in only when it interacts with a measurement device.
This extraordinary powerful technology is now emerging. As an example, the Willow chip, which has recently been developed by Google, completed a benchmark calculation in five minutes. It would have taken the fastest classical computer in the world 10 septillion years—that is 10 with 24 zeros, I believe—to complete it. According to the Parliamentary Office of Science and Technology and the NCSC, in less than 10 years—perhaps even sooner than that—we could have a cryptographically relevant quantum computer that uses Shor’s algorithm to decrypt all communications that rely on the RSA algorithm on which we have relied for decades for all of our bank transactions, state-level communications and so on. This is an area of technology that is moving extremely quickly, and it is not just one about which we will have to worry at some point in the future. So-called “harvest now, decrypt later” attacks could be used to decrypt sensitive information in the future.
That brings me to the amendment. It is quite a simple, straightforward one, which goes forward from the discussions on how, given the changing nature of these technologies, it is perhaps not appropriate to have specific technologies and timelines in the Bill. However, as the Minister has already brought out, the statement of strategic priorities is a powerful tool to ensure national join-up, including across those regulators within the remit of the Bill.
We have 12 regulators and each one could approach quantum crypto—so-called post-quantum cryptography—differently. There will be huge benefits in really ensuring that regulators work from the same national signal rather than inventing their own PQC expectations individually. That would also allow them, if it can be brought out in the statement of strategic priorities, to plan their inspections, guidance, skills and capacity around the NCSC timelines, which is a plan ranging from 2028 discovery and initial plan through to 2035 when post-quantum crypto implementation is completed. That will also help with all those newly in-scope firms that will be coming within the remits of this legislation, giving the regulators a legitimate basis to raise post-quantum crypto with those new organisations early on.
I read back the Minister’s remarks at Second Reading, when she said that quantum crypto
“would be considered as part of that requirement by regulated entities, but would not necessarily be singled out as a specific technology in the regulation so that we keep these regulations up to date and matched to the cyber risks that individual entities face”.—[Official Report, 14/7/26; col. 622.]
I believe that this amendment would help strengthen and deliver exactly that. With that, I look forward to hearing from the Minister on her thoughts about this approach.
My Lords, I will speak to this substantial and rather disparate group of amendments, including Amendments 93 to 95 in my name, Amendment 10 tabled by my noble friend Lady Ludford, and a number of other amendments in the names of other noble Lords, including that of the noble Lord, Lord Arbuthnot, who, sadly, is in the Chamber as well.
Under Amendment 10, comprehensively introduced by my noble friend Lady Ludford, we would ensure that digital service providers manage risk arising from AI-driven fraud which, as she explains, represents over 40% of reported crime in England and Wales. I thought she made an extremely convincing case and I very much hope that the Minister takes what she said to heart and adds the very few words that are required to make this Bill much more secure with regard to the kind of phishing activity that she described.
As regards the various amendments relating to skills, beginning with the workforce and competence deficit, in its latest 2025-26 workforce study, ISC2 reveals that 52% of UK cyber professionals identify skills shortages as their single greatest obstacle to regulatory compliance, with 58% of organisations facing critical skills shortages. Regulation without competence is what might be described as pure compliance theatre. That is why, on these Benches, we strongly support Amendment 15 in the name of the noble Lord, Lord Arbuthnot, which would place a direct statutory duty on regulated organisations to ensure that their security leads possess verified competence, alongside Amendment 114 from the noble Lord, Lord Holmes, which would require the Secretary of State to define the objective qualifications and independent criteria for appointing skilled persons.
We also see critical implementation blind spots in distributed infrastructure. In July, as documented in the “Analogue 72” Green Paper, which I have mentioned before, a small UK electricity generator was taken offline for four days following a suspected state-sponsored cyber attack. Because it fell below the statutory reporting size threshold, local responders had zero visibility of the disruption. If small distributed energy assets are paralysed, the compound threat to local grids is severe.
Amendment 82 tabled by the noble Lord, Lord Ravensdale, rightly addresses quantum decryption. I am afraid that, if we are not careful, we are back in the territory of technology agnosticism. I think that across the Committee we have a fundamental disagreement with the Government about that. Hostile states are actively executing “harvest now, decrypt later” operations. By requiring the Secretary of State to incorporate NCSC post-quantum cryptography timelines into strategic priorities, we would mandate preparation for quantum-resistant encryption across all critical sectors. We very much support the amendment tabled by the noble Lord, Lord Ravendale.
Amendment 93 in my name would introduces mandatory eight-week public consultations before secondary regulations or codes of practice are issued, protecting industry and SMEs from closed-door administrative creep. I think that is the kind of area where the Minister could give further assurance.
Amendment 94 in my name would establish a statutory presumption of conformity for organisations achieving ISO/IEC 27001 or Cyber Essentials Plus certification. This safe harbour would eliminate legal ambiguity, reward gold-standard cyber hygiene and free regulatory resources to focus on high-risk, non-compliant entities, while preserving the regulator’s right of rebuttal. As the Minister can imagine, this has considerable industry support.
In Clause 40, my Amendment 95 would shorten the legislative cycle from five years to three years. We also support the alternative in Amendment 95A from the noble Lord, Lord Arbuthnot, which probes an even tighter two-year window, and his Amendment 95B, which I have signed, which would ensure that future statutory reviews must explicitly assess third-party and supply-chain dependencies originating outside the regulatory perimeter. Furthermore, we support the noble Lord, Lord Arbuthnot, in his proposed new Clauses 174C and 174D mandating competency standards and annual workforce strategies—we are just sorry that he is not here and able to speak to those amendments—alongside Amendment 92B from the noble Viscount, Lord Camrose, requiring large businesses to report transparently on their cyber resilient plans.
We have not heard from the noble Viscount regarding the other Conservative Front Bench proposals, but we are sympathetic to the need to review information sharing and analysis centres, ISACs, under Amendment 169 and to expect clear regulatory funding plans under Amendment 174. Furthermore, holding the Government to their commitment under the National Audit Office’s 2025 report and the Cyber Action Plan, under Amendment 170, is important. However, we are less supportive of Amendments 173 and 175, which attempt to make commencement of the entire Act conditional on publishing the National Cyber Action Plan. In our view, that would potentially create a dangerous delay, holding our national resilience hostage to Whitehall paperwork when our hospitals and utilities need protection today.