Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Vaizey of Didcot
Main Page: Lord Vaizey of Didcot (Conservative - Life peer)Department Debates - View all Lord Vaizey of Didcot's debates with the Department for Science, Innovation & Technology
(2 weeks, 6 days ago)
Lords ChamberMy Lords, it is a pleasure to take part in this debate at Second Reading. I am taking part not because I was once hacked but because I was very briefly the Cyber Security Minister—which is almost as surprising as learning that I was once the Minister of Fashion.
Several themes have emerged during this very interesting debate and I always find it interesting to debate a Bill on technology, because the process of legislation is so ponderous and takes so long while digital technology moves so fast. I think there is a recurring theme, of course, that everything is digital. The other thing I always find odd when we debate legislation such as this is how we seem to continue to work in silos. AI has been mentioned so many times and it so important, but I recognise the need for legislation to provide the Government with a framework, just as the Online Safety Act has provided the Government with a framework on which we can move forward on online safety. I am less concerned about executive action and endless consultation; I want the Government to have the powers to move quickly in this important area.
As an opening remark, I will say something perhaps counterintuitive, which is that cyber security as well as being a threat is also a great opportunity. It is very important for us not to lose sight of the fact that the UK is one of the leading countries in the world for cyber security expertise. We have a cluster of great companies built around GCHQ. We must not lose sight as we debate these important issues of the fact that we have world-leading expertise that can contribute to the growth in our economy. When we talk about the defence investment plan, for example, it is important to talk about the huge opportunities we have to create great defence tech companies. Nor should we lose sight of the opportunity to create great British cyber security companies, which goes to the whole debate about potential sovereignty and giving us our own capability.
Let me begin by echoing a number of speeches about how important it is to work in lockstep with our EU partners. It is a piece of irony that this legislation emerges in effect from a European directive that we were beginning to debate when I was the Cyber Security Minister. In fact, the legislation is necessary because we can no longer transpose European legislation directly into British legislation. The noble Baroness, Lady Ludford, mentioned the GDPR, and it is a fact that Brussels can often take the lead in regulation such as this, and that big multinational companies tend to look at the biggest regulatory space in order to adhere to it. So it is important that we are mindful of how Brussels plans to proceed in this area, even if we find areas where we can be more flexible.
People have talked about our bad record in the UK on cyber security on account of cyber security attacks. I suspect that that is because we remain, I think, the most digital nation in the EU, and the English language as well provides us, weirdly, with some kind of vulnerability. But we are at the forefront of cyber security attacks, and it is important that we have the legislation and the bodies capable of responding to them.
Several themes have emerged. When I was the Cyber Security Minister, we began preparations for the National Cyber Security Centre: I thought that was incredibly important. I used to have a mantra that business in particular needed one front door that it could walk through to get the advice and expertise it needed to draw on to protect itself. We have talked constantly in this debate about 12 regulators, and I echo the calls to provide a uniform platform that can read across all the regulators, and they can add on top of that any sector- specific needs they meet.
I also recognise the calls from many noble Lords to say that this is perhaps an artificially constrained Bill, focusing on only a few vital sectors that are important to protect, instead of, as it were, seeing the whole picture and understanding, as many noble Lords have said, that cyber security pervades everywhere. There are so many ways in which we should look to protect ourselves in this age, one of which, of course, is in not losing sight of the hardware. The Minister spoke about software as a service. It is very important to remember that many of our public service providers, for example, still rely on ageing infrastructure, which provides huge vulnerabilities to cyber security attacks. I wonder whether the Government have a strategy to update much of the hardware that is still being used.
I was also interested in the remarks made about how vendors of software should be accountable. That is a very important avenue to explore: perhaps we could introduce kitemarks and audits of software providers to ensure that they are providing cyber-secure software that is as robust as it can be—again, as the noble Baroness said, we can count on the fingers of one hand the main providers of the software that is used in a vast number of businesses—and that they also work with us, as it were, to be on the front line.
It is interesting that this issue has become one of sovereignty. I am fascinated by the debate on the use of Palantir, for example. Personally, I have no problem working with Palantir. I think it provides a vital service, and I hope that the Government will be cautious in listening to the siren calls of people who say “Don’t work with these companies” simply because they disagree with the slightly bizarre views of some of their chief executives. Nevertheless, it perhaps calls for the Government to have a consistent story on this.
One thought that occurred to me during this debate was what has happened to the debate about encryption? This is a dog that no longer seems to be barking. In the last few years, we have had a vigorous debate on potential backdoors to encryption and security services being given, as it were, cyber keys to access encrypted services such as WhatsApp and Signal, and we saw a big pushback from the tech industry on how that would create big cyber vulnerabilities. I wonder whether the Government have come to a settled view on that.
Returning to the theme of the opportunities for the economy, the need to invest in cyber skills in our workforce is absolutely vital. We need to create a cyber workforce and a cyber defence force that work to protect the country, as well as giving companies the kind of skills base they need to make themselves secure. I echo the call from the noble Baroness, Lady Ludford, about boards. I was astonished to read in the House of Lords Library briefing that the number of board members with a responsibility for cyber has apparently fallen. I do not know if that is true, but I wonder whether it is possible to work with business bodies such as the IoD and the CBI to make it a strong corporate governance recommendation that every board should have somebody with a responsibility for cyber.
As I said at the beginning, this is a partnership: it is business, as much as government, that will protect us from cyber. For example, there has been reference to the insurance industry. One of the best ways we can ensure that companies invest in cyber security is to make it mandatory for them to get cyber insurance—which you cannot get unless you put cyber-secure measures in place—and to employ law firms to protect themselves from liability and to put in place important cyber measures.
I have not had a chance to support the noble Lord, Lord Clement-Jones, in his 50-year call for ethical hackers to be allowed to hack. I also echo the earlier call to hear the Minister’s views on the rise of bots and their impact on cyber security.
My Lords, earlier today, the noble Viscount, Lord Colville, and I were saying that we were both quite late down this list and feared that everything would already have been said. That appears to be the case, but, fear not, I will still use my eight minutes.
I support the Bill and I agree with many noble Lords that we also need a much more comprehensive cyber security strategy. Like others, I have some specific suggestions for this specific Bill. My unique contribution, if it is unique, is not that I am an engineer and tech expert, as the noble Lord clearly is. I think that, in health terms, I would be described as an expert by lived experience, in that I suspect I am the only noble Lord today, probably the only noble Lord on the roster, who has actually been a CEO faced with a cyber attack. I have been that CEO whose company has been targeted by a gang of hackers, trying to work out how to navigate the crisis. I have had to go out and communicate to regulators, to customers, to shareholders.
To Ministers, indeed—to my noble friend himself. In those days, the National Cyber Security Centre did not exist—I am obviously referring to my time as chief executive at TalkTalk. Instead, we were directed to the Metropolitan Police’s hostage negotiation team. They were lovely but unfortunately had no tech experience at all. In fact, we did no better ourselves. The security expert who came to brief the TalkTalk board had just come from Mexico, where he had been trying to get a bank manager back who had been kidnapped.
That was only 11 years ago. At TalkTalk, we took the view that communicating was the only way to help our customers and therefore the only way to save the company, and I stand by that decision now, but not everyone takes that view. I was accused at the time of being hopelessly naive for going out, within 24 and 48 hours, on to the airwaves and saying, “My customers have been attacked and, no, I don’t know exactly what has happened”. That is the timetable in this legislation. Most CEOs I talk to say, first, “God, I’m glad I wasn’t in that situation. That’s my nightmare”. Secondly, they are surprised when I say that, actually, I would communicate earlier if I was in that situation again and not later. Cyber attacks are a modern-day taboo in the business world. Business leaders are terrified of admitting that they have been attacked, and I am afraid that that means that mandating reporting is essential, because, 11 years after I was in that situation, I do not think that that has changed. I think that unless we make it mandatory to report, people will not do it.
I was surprised at the time, in 2015, that had Sainsbury’s or Tesco been hacked, I would not have had to tell anybody—I had just come from Sainsbury’s in my previous job. It is really depressing, 11 years later, to see that retail is still excluded. I cannot quite understand why water is “essential” but food is not. I think that Covid taught us that our food retail supply chain is an essential service, and those who work in it are essential workers.
Managed service providers are in, but generative AI is out. Only a decade ago, that might have been OK, but it is not now. In the other place, the Minister said there are powers in the Bill so that we can get it right in the future. Well, we need to get it right now, and we also need the powers to try to keep up. I am not against giving Ministers the power to keep this live, but that is not an excuse for not being up to date today. As other noble Lords have said, it looks, sadly, as though the EU has got this more right than we have. We should be humble enough to admit that, rather than be afraid and insist on doing the wrong thing.
The other area I have some lived experience in, which, again, has been mentioned by other noble Lords, is the challenge of 12 NIS regulators and the lack of join-up. When the TalkTalk hack happened, we immediately stood up a series of workstreams—the obvious things such as trying to work out what had happened. That is the biggest problem with a cyber attack—you genuinely do not know whether you have been attacked by a nation state or kids in a bedroom. You somehow hope it might be the former, but more often than not it turns out to be the latter. So you have to know what has happened and you have to start communicating before you know what has happened. That is two workstreams. You have to work out how to get your systems back up again. That is another workstream. Even 11 years ago, without any of these additional regulators, we had to have a “communicating with regulators” workstream.
Now, spare a thought for the poor managed service providers. They are companies that serve transport, telecoms, energy and the NHS. I think they might have a full house. If you were a managed service provider that was the victim of an attack, you would probably have to deal with all 12 regulators. Those of us who have been here for a while know that if you give 12 different public sector bodies the ability to define terms, they will define them in 12 different ways and have 12 different forms. That will stop you, in the first day or the first week of a cyber attack, doing the things that you should be doing to try to protect your customers. As an expert through lived experience, I plead with the Minister: join-up is essential. It should not be optional. We all know it is hard to do. If you do not sort it out in the Bill, it will not happen. Please do not make that join-up a forum.
I can take myself back to October 2015 and imagine having to communicate with—as much as I love it—the DCRF. If we had had to convene a meeting of 12 regulators in the heat of the crisis to work out what to do, that would not have helped anybody. So we need either a single regulator, as the noble Lord, Lord Birt, so eloquently set out, or a lead regulator, as I know the Government are looking at in a number of other areas, to try to reduce the burden of regulation. I very much support what my noble friend Lord Effingham said: regulation does look like it is necessary here but we need to be careful that we are not just layering burden upon burden, and doing it 12 times most definitely is.
I feel I have said nothing original at all but have said it possibly from a unique perspective. I am rare among former chief executives who have experienced a cyber attack in that I am willing to talk about it, which is exactly why this legislation is important. But I very much hope that, as with so many tech issues, the Minister will hear that we agree more than we disagree and that we could work together to improve the Bill, as this House is often quite good at doing.