All 1 Debates between Lord Reay and Lord Clement-Jones

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Lord Reay and Lord Clement-Jones
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I cannot possibly compete with the Shakespearean seven stages—as opposed to ages—of the noble Baroness, Lady Kidron. We support Amendment 72 in its entirety. Voluntary reporting is the bit of the amendment that we particularly like. Our national security services and sectoral competent authorities desperately need early upstream visibility of emerging threat patterns before a full-blown systemic crisis unfolds. In the cyber domain, the precursors to the catastrophic attack—the subtle network probes, the exploratory reconnaissance and near misses—often appear weeks before a critical system is actually breached.

At present, the Bill creates a bit of an all-or-nothing trap. If any entity experiences a sophisticated near miss that fails to cross the statutory threshold of an active disruptive breach, it has a powerful legal incentive to keep quiet. It fears that, if it approaches a regulator voluntarily, it will expose itself to regulatory scrutiny, compliance investigations and potential enforcement action. In our view, including a dedicated statutory framework into the NIS regulations specifically for the voluntary notification of near misses, sub-threshold anomalies and early-stage cyber threats would be a significant beneficial addition to the Bill. In effect, it would establish a safe harbour for intelligence sharing.

As the recent “Analogue 72” green paper powerfully argued, we must move away from a culture of fear and silence in this area and we must encourage continuous proactive information flows between our critical infrastructure operators and the NCSC. We strongly support this amendment.

Lord Reay Portrait Lord Reay (Con)
- Hansard - -

My Lords, I thank my noble friend Lady Harding of Winscombe for her amendment, to which the noble Baroness, Lady Kidron, has added her name. We believe that this is a straightforward amendment. If we are to tackle cyber attacks seriously and to create a generally resilient cyber system, we should not simply stop at the reporting of incidents that happen. A key way of ensuring that we build not just a responsive but a preventive cyber system is by knowing what potential risks exist and who is attempting to commit cyber attacks, even if they have not done so yet. This is a reasoned amendment that places a requirement only on those already considered regulated persons, with the opportunity for others not regulated to report voluntarily. I hope that the Minister will agree.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I will speak to this very strategic group of amendments. I use that word again because the noble Baroness, Lady Kidron, made it quite clear from the outset that that is exactly what we lack: a clear national strategy. I pay tribute to her tenacity in tabling Amendment 83, following what I thought was an extremely useful debate on the last day before we went into recess. That is still very much top of mind at the moment, as the Minister can see from the contributions today. If we had another debate today, I do not think we would feel any greater assurance than we did on the day of that debate.

I also thank my noble friend Lady Ludford for having tabled Amendment 166, which is along very much the same lines. We have at the moment, particularly in the public sector—I thought the noble Baroness, Lady Berger, put this extremely well—near total and escalating digital dependence on foreign technology monopolies and foreign jurisdictions. It is quite prevalent in Whitehall. There is a kind of ignorance about the geopolitical reality that so much of what might be described as the digital stack is owned, operated and controlled from abroad. I will come on to our procurement policies shortly.

Amendment 83 defines the pillars of true digital sovereignty. It would tackle extreme market concentration. As we have heard, three American technology giants— Amazon, Google and Microsoft—control a staggering 73% of the cloud computing and enterprise hosting supporting our UK financial sector and public services. If an AWS region or Microsoft Azure network suffers a systemic failure, three-quarters of the City of London and vast swathes of government administration are instantly paralysed. Concentrating our critical national infrastructure into a handful of corporate choke points is the very antithesis of national resilience.

Secondly, it directly confronts foreign extraterritorial legal exposure. Because our critical public data is predominantly hosted on foreign cloud architectures, that data remains legally exposed to foreign statutory instruments, most notably the US CLOUD Act, and is subject to sudden unilateral geopolitical shifts. As my noble friend Lady Ludford said, we saw a chilling preview of this vulnerability only recently when the US Administration temporarily cut off European and UK financial institutions from accessing Anthropic’s AI model, Claude Mythos. Whatever the rights and wrongs of Mythos and its capabilities—we have a pretty good idea of what the wrongs were from what the AI Security Institute had to say—suppose that we had adopted this powerful model in a cyber defensive role; if an ally can pull the plug on front-line cyber security tools overnight, we do not possess true digital sovereignty. If a foreign ally can pull the plug on critical cutting-edge technology at a moment’s notice, we do not have true national resilience but a dangerous dependency.

My noble friend Lady Ludford’s Amendment 166 would force the Government to publish a formal digital sovereignty strategy within 12 months, assessing foreign reliance and reforming public procurement to prioritise secure home-grown UK technology. In fact, both amendments would tackle a glaring failure of current government procurement. The UK possesses world-leading academic institutions and an exceptional cyber security start-up ecosystem. But we suffer from a chronic scale-up failure. Time and again, major public contracts, such as the recent NHS and defence platforms, are automatically handed to dominant foreign tech giants such as Palantir, rather than nurturing and scaling home-grown British technology.

Proposed subsection (2)(c) of Amendment 83 and my noble friend Lady Ludford’s Amendment 166 would provide the solution. They would legally require the Government to use public procurement as a strategic lever to prioritise secure, interoperable and sovereign UK-developed technologies. That is how we build long-term sovereign capacity on our own soil, create high-wage tech jobs and prevent our best innovations being swallowed up by our international competitors.

In an era of contested supply chains, autonomous AI warfare and geopolitical instability, a nation that cannot secure its own digital foundation cannot truly govern itself. I very much hope that the Government will take heed of these amendments, even if they do not take them on board in this Bill. The former Secretary of State for DSIT is on the record as being very much in favour of digital sovereignty, and I hope that that carries through into the current Government.

Lord Reay Portrait Lord Reay (Con)
- Hansard - -

My Lords, I thank all noble Lords who have added their names to the amendments and who have spoken in this debate. Both amendments in this group are underpinned by the same principle that national security and national technological capabilities deserve a unified plan—not one that targets some sectors and entities and not others, but a holistic plan that brings together all sectors and industries into a single framework. His Majesty’s Opposition therefore support the intention behind the amendments.

However, at risk of repetition, the Government could avoid the need for these propositions. They could do away with your Lordships’ worries if they would commit, as mentioned by my noble friend Lord Camrose, to publishing a national cyber action plan within a set timeframe, and commit to including national digital sovereignty as part of that plan. In light of Tuesday’s debate on AI, we request a review and update of the previous Government’s AI White Paper to ensure that AI regulation and cyber regulation are aligned. They need to operate in lockstep, and this Bill is an appropriate place to do it. It is evident that national sovereignty and a reduced reliance on foreign technology is vital to ensuring national wholesale cyber security. I commend these amendments in their aims to achieve that, and I look forward to the Minister’s reply.