(4Â weeks, 1Â day ago)
Grand CommitteeMy Lords, I thank my noble friend Lady Harding of Winscombe for her amendment, to which the noble Baroness, Lady Kidron, has added her name. We believe that this is a straightforward amendment. If we are to tackle cyber attacks seriously and to create a generally resilient cyber system, we should not simply stop at the reporting of incidents that happen. A key way of ensuring that we build not just a responsive but a preventive cyber system is by knowing what potential risks exist and who is attempting to commit cyber attacks, even if they have not done so yet. This is a reasoned amendment that places a requirement only on those already considered regulated persons, with the opportunity for others not regulated to report voluntarily. I hope that the Minister will agree.
Baroness Lloyd of Effra (Lab)
My Lords, I thank the noble Baroness for raising this question about the requirement for regulated entities to report cyber threats, near misses and sub-threshold incidents within a 72-hour deadline.
I turn first to the question of voluntary reporting, which we touched on a little in the context of discussing the industry groupings on Tuesday and the trust groups that exist and are often facilitated by the NCSC. These are incredibly valuable groups. We absolutely encourage voluntary reporting, whether through those groups or other industry bodies. There is a question about whether putting such groups and mechanisms on a statutory footing helps or hinders that objective, because we need to engender the confidence to share information, as the noble Baroness and others mentioned. There is a question about whether that is within the regulatory perimeter, as it were, and whether it encourages that or not. I am happy to come back to that on Report.
I turn to the question of reporting sub-threshold incidents. The amendment concerns incidents that have been successfully contained or have proved ineffective, incidents that fall somewhere below the current reporting thresholds and any potential circumstance or event that could, if it occurred, affect a regulated entity’s systems or the users of a service provided through these systems. We discussed that in the context of data centres. Let me answer the question from the noble Baroness, Lady Kidron. In the discussion on data centres, I was speaking about near misses. We made the point highlighted by the noble Baroness, Lady Neville-Jones: near misses and those types of incidents would be captured for data centres, given the particular role they play in our digital infrastructure.
The extension of similar requirements—although, as we read it, they are much broader requirements—to all regulated entities would increase regulatory reporting very significantly. The noble Baroness, Lady Neville-Jones, made the point right at the beginning—although it could have possibly been someone else—about the ability of our regulators to effectively utilise the threat intelligence and manage it so that it can be conveyed into actionable advice and trend data. These are the considerations that we take.
Another consideration is that the entities that have more sophisticated surveillance and mitigations may be able to identify attacks more effectively. We would not want to set up a situation where there were any perverse incentives in the system for those who have very adept surveillance and assessments away from reporting or developing that.
Even though I heard very clearly that the motivation is that the amendment is just to catch to those incidents that just fall below, our reading of it is that it would be much wider, and it may indeed have some other effects. At this stage, I would not support the amendment as drafted.
My Lords, I thank all noble Lords who have added their names to the amendments and who have spoken in this debate. Both amendments in this group are underpinned by the same principle that national security and national technological capabilities deserve a unified plan—not one that targets some sectors and entities and not others, but a holistic plan that brings together all sectors and industries into a single framework. His Majesty’s Opposition therefore support the intention behind the amendments.
However, at risk of repetition, the Government could avoid the need for these propositions. They could do away with your Lordships’ worries if they would commit, as mentioned by my noble friend Lord Camrose, to publishing a national cyber action plan within a set timeframe, and commit to including national digital sovereignty as part of that plan. In light of Tuesday’s debate on AI, we request a review and update of the previous Government’s AI White Paper to ensure that AI regulation and cyber regulation are aligned. They need to operate in lockstep, and this Bill is an appropriate place to do it. It is evident that national sovereignty and a reduced reliance on foreign technology is vital to ensuring national wholesale cyber security. I commend these amendments in their aims to achieve that, and I look forward to the Minister’s reply.
Baroness Lloyd of Effra (Lab)
I thank noble Lords for continuing the debate with which we ended the previous session: the very important topic of the technological and digital sovereignty of the UK. That is very important to this Government and we are taking action on it. It possibly has not been focused on enough in past years but, across many areas, that is what we are doing.
We are clear that we need a coherent approach and a clear direction. We obviously need to take into account that technologies and markets evolve, and the core of that approach was set out in the modern industrial strategy and the Digital and Technologies Sector Plan. That set out the direction of travel, and the Government will continue to consider how our priorities are best articulated.
Our objective, as I articulated at the end of July, is not complete independence but strategic resilience through a combination of domestic capability, diversified international partnership and targeted management of critical dependencies. This allows us to access the best of global markets while capitalising on our domestic capabilities. That is why we already have in place a range of regulatory and non-regulatory frameworks that enable us to embed those objectives through existing industrial, technological and resilience strategies. I will talk to some of those now.
For essential services in scope of the network and information systems regime, such as drinking water, health and energy, all entities are required to manage and mitigate the risks posed to their systems that deliver essential services. This includes the risks set out in the amendment of the noble Baroness, Lady Ludford.
On market concentration, which the noble Baroness, Lady Kidron, and the noble Lord, Lord Clement-Jones, referred to, the CMA is acting. It concluded an investigation into the cloud services market in July last year, highlighting competition issues arising from market concentration. It has since announced packages of actions to improve competition in cloud services. This work has directly informed our thinking, as we develop a more strategic approach to how the public sector procures cloud services.