1 Baroness Berger debates involving the Department for Digital, Culture, Media & Sport

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I also support Amendments 74 and 167. My experience is that boards that tell you that their cyber security is really good are the ones you should be most worried about. Boards that are really worried about it and can tell you where they think they are exposed might be in a slightly better place. There are too many organisations that will tell you that they are fine. Boards that are not doing what is set out in Amendment 167 are in trouble. It is entirely appropriate, and I fully support that amendment.

On Amendment 74, I would just like to draw a thread between the financial services senior management regime, what we have learned in the Online Safety Act and Tuesday’s debate about whether frontier AI models are included in the scope of the Bill. We have learned from the financial services senior management regime that when you make individual human beings accountable, they change. There is no doubt that the senior management regime in financial services has served to move the dial on the culture in financial services, and all previous attempts have failed.

Through the Online Safety Act, we have learned that various companies—not ones regulated by this Bill—have not taken seriously fines from Ofcom and simply refused to obey. We are living through an era when the tech sector wants to believe that it is exceptional and that laws from individual countries do not apply to it. It is therefore very important that we put into the Bill liability for senior executives, precisely because of what we have learned: in a sector that is doing it, you get culture change. In other digital legislation, where we do not have this, regulators’ decisions have actively been flouted. This is even more important if the Minister were to accept the amendments we debated on Tuesday—the noble Lord, Lord Tarassenko, has arrived just in time—because I firmly believe that the single most important part of regulating AI is holding the creators of the model accountable for their actions. Given that the biggest cyber security threats we face are the actions of agentic AI, I want to be able to build the framework that enables us to hold the managers and leaders developing those models, who currently say that this has nothing to do with them, accountable for their actions. I may be stretching it a bit, but I hope that Amendment 74 would be the beginnings of a framework that would enable us to hold senior tech titans to account.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - -

My Lords, I will speak quickly. I was just checking my records, particularly on Amendment 167. It was just under a year ago that I completed the FT board director programme, which was specifically around cyber risk for boards. In a room of around 50 people, we had a tabletop exercise on a real-life scenario about what one should do in the event of a very serious cyber crisis and cyber risk. I was struck by a number of things. In the room were people with vast waves of expertise and experience, none of whom was a technology expert. All said that no other members of their board had attended training like this. They were there because, having completed a board director programme, it piqued their interest, as it did mine, it was freely on offer and they decided to attend.

Having gone through that session, we covered things such as the regulatory experience, issues around how to challenge management in the event of one of these incidents, how you need to test organisational resilience, how you need to look at the risks involved, and how to respond decisively and to have the expertise and understanding to do so. It was very clear to me, even during that half-day exercise, that that training was not sufficient for me as a board director and member to be able to fulfil that role.

Having gone through that experience, I think for many reasons that this amendment is so important to ensure that boards across this country—be they private boards, FTSE boards or boards of regulated companies—can do their jobs effectively. In this world, which is extending—I echo the points made about AI—it is even more imperative that we have this amendment to ensure that boards are able to fulfil their roles effectively.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, this has been a really useful debate, particularly because it has distilled all the considerable board experience—and, indeed, board training experience—around this Committee. I very much hope that the Minister listened to it with interest.

Amendment 74 in the name of the noble Baroness, Lady Morgan, moved by the noble Baroness, Lady Kidron, would align the UK with the EU’s NIS2 framework. It would introduce personal civil liability for senior executives who deliberately or carelessly neglect cyber duties. My noble friend Lady Ludford’s Amendment 167 would mandate board-level oversight and technical training. In our view, to build national resilience, cyber security must become a fiduciary director’s personal responsibility. As the noble Baroness, my noble friend and the noble Lord, Lord Arbuthnot, have said, this change is long overdue and would be additional to other existing sectors. We need to learn from experience in the way mentioned by the noble Baroness, Lady Harding; I very much hope that we will do so in the course of the Bill.

Together, these two amendments target arguably the single greatest cultural—the noble Baroness, Lady Kidron, rightly emphasised “culture”—and behavioural failure in UK cyber security today: the persistent treatment of cyber security by company boards as a delegated technical IT issue rather than a core personal and fiduciary leadership responsibility. The Government’s approach to corporate cyber governance has been almost entirely passive to date, I am afraid. Ministers have relied on voluntary guidance, such as the Cyber Governance Code of Practice, hoping that boards would voluntarily prioritise digital resilience.

The proof of this policy failure is undeniable. My noble friend quoted the Cyber Security Breaches Survey, which showed that board-level ownership of cyber risk has declined over the past three years. Of course, if boards neglect cyber security, that carries massive public costs, as seen in the recent major supply chain disruptions where, although company directors face strict personal legal liabilities under company law for signing off on financial accounts, they are permitted to treat systemic cyber vulnerabilities—vulnerabilities that can wipe hundreds of millions of pounds from the economy and paralyse critical national supply chains—with complete personal legal impunity.

My noble friend also reminded us of the catastrophic real-world cost of this boardroom neglect in the automotive sector, where a supply chain breach at Jaguar Land Rover cost an estimated £500 million, halted production lines for four months and forced the Government to step in with a £1.5 billion loan guarantee. We have seen the same in retail, also mentioned by my noble friend: the cyber attack on Marks & Spencer cost £300 million and contributed to a 99% collapse in pre-tax profits.

Amendment 74 would provide the direct legislative teeth that the Bill is missing by introducing personal civil liability for senior executives. It would amend the NIS regulations to establish that, where a regulated entity fails to comply with core risk management duties, and that failure was committed with the consent, connivance or deliberate or careless neglect of a senior executive, the regulator may impose a personal civil penalty.

--- Later in debate ---
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - - - Excerpts

My Lords, this is a group of rather wide scope. I am kicking off. I will also speak to Amendment 168 in my name so as not to speak twice. It is on an entirely different subject from Amendment 79, so we will probably have quite a long debate on this group.

Amendment 79 is about including political parties in this Bill. My honourable friend Victoria Collins MP made the same case in the other place, tabling a proposed new clause to designate political parties as carrying out essential activities. We have discussed, over several days, how cyber security is not just a technical matter confined to server rooms and IT departments; it is a matter of national resilience, economic strength, the functioning of society and, I argue, democratic integrity. On this last count, the Bill is silent.

I remind the Committee that, between August 2021 and October 2022, as we later learned, hostile actors sat undetected inside the systems of the Electoral Commission and exfiltrated copies of the electoral registers—an intrusion the Government attributed to a China state-affiliated actor. There was apparently reconnaissance against the email accounts of parliamentarians who had spoken out against China. So we are hearing of more and more denial-of-service attacks and other incidents affecting critical national infrastructure, which may have some knock-on effect on our democratic structures. Think about what political parties hold: membership lists, canvassing databases covering millions of electors, data on political opinion and special category data of the most sensitive kind—perhaps precisely the material valuable for espionage, transnational repression and targeted disinformation in a campaign period.

Let us think about the kind of defences that are protecting this information. Those of us who have experience of local party activity know that we are normally talking about a small office with a handful of staff and many volunteers, not massive enterprises—and they themselves have been the subject of cyber attacks. We perhaps have quite a weak link at the heart of our democracy.

The National Cyber Security Centre has defending democracy guidance, but this is voluntary, done on an opt-in basis and unenforced; there is no duty to report an incident, no assessment framework, no designated regulator and no floor beneath which a party cannot fall. So there is weakness around the cyber security of political parties and of electoral infrastructure. I am sure that the Minister will tell me that parties are not infrastructure—indeed they are not—but the Bill encompasses data centres and managed service providers on the basis that disruption there would significantly affect the day-to-day functioning of society. If the compromise of a major party’s voter database in the final week of a general election would not meet that test, I struggle to think what would.

Nothing in this amendment invites the Government into the internal affairs of parties; it asks only that the organisations through which the British people exercise their democratic voice are held to a basic standard of resilience. Democracy is essential infrastructure. It is a privilege that we must defend with the utmost priority, and the Bill should reflect that.

I will cover another, completely different matter in my Amendment 168. This amendment was prompted because, probably like others here, in July I had several notifications from either a charity, an arts organisation or an academic organisation—I cannot remember; I think I had four or five altogether—warning me of a data breach. This was a named company—I think it has been in the public domain—called Beacon. It experienced a cyber security incident involving unauthorised access to its systems. I understand it stores data on the membership and customers of a lot of organisations—about 1,000, I read.

This is a probing amendment because I am asking the Government where organisations like this sit. They are variously described as a customer relationship management service provider or a software as a service relationship provider. I do not think they fall into RMSP or RDSP; they are not cloud computing, they are not an online marketplace or search engine and so on. Maybe, arguably, they are a managed service or IT management, support, maintenance or monitoring. I do not know what the precise relationship is between the organisation and the Beacon customer relationship management service provider. I do not really understand it, and the point of the amendment is to find out whether the Government know where it sits in the sphere of cyber and data services. They will often have lots of personal data, including date of birth, contact data, records of donations and memberships, and the booking of events. There is quite a lot where you could profile somebody and find out a lot about them, so it is quite risky to have all of that in unauthorised hands.

I think these breaches triggered reporting duties to the Information Commissioner under the GDPR, but, as far as I know, I do not think that a comparable incident would trigger this Bill’s incident reporting duties. I do not know where these organisations fit, so can the Minister tell me where they live in the ecosystem and what could or should be done to try to increase their support for the organisations that they work for? I beg to move.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - -

My Lords, I wish to speak to Amendment 81A in my name. I was glad to add my name to Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron. I am sorry that I was unable to speak to them on Tuesday due to some caring responsibilities.

Amendment 81A is all about education. Our British educational institutions sit at the heart of our communities. They are key to developing our children and young people, and helping them grow, supporting them through the most important developments of their lives. This year, the UK was ranked as having the third best public education system in the world, something that we should be so proud of but which we must safeguard. We have seen our education system change rapidly in the past decade. We now have exam results revealed via an app. We have homework set through online portals. I receive it weekly for both of my children. Increasingly, vast amounts of student data is being stored online, including around attainment. If our young people are to be properly supported, that must extend beyond the classroom to the network and information systems now essential to their education—a point only reinforced as universities and colleges continue to further embrace online learning.

Exam results determine a young person’s future opportunities. We all remember just a couple of weeks ago the pictures, the interviews of the young people and the elation of many 16 and 18 year-olds as they received and revealed their GCSE and A-level results. We owe it to the next generation to do everything we can to give them the best possible chances—to protect the integrity of the system that determines their future and to prevent the chaos that could follow if, for example, university place allocation, clearing or accommodation processes could not proceed. Anyone who might have friends or family whose 18 year-olds are currently going through that process knows it is frenetic enough at this time—scrambling to get a place for young people who might not have made their grades, changing universities, changing courses, trying to get a university spot or university accommodation.

We have already seen what chaos looks like on a small scale. Noble Lords perhaps will recall students who sat their A-level physics paper with Cambridge International who had their results voided after just one paper was leaked online, with a substitute mark calculated from other components. That was just one paper from one exam board, and it was still enough to undermine confidence in the results for every student affected. We need to look no further than the terrible experience recently in India where the National Testing Agency’s medical entrance exam results were withdrawn after a paper was leaked. It triggered mass protests and, tragically, at least 21 reported suicides among students who had sat the exam. If a single compromised paper can cause that level of devastation, we cannot afford to leave our education system exposed to a compromise on a grand scale.

Amendment 81A would establish that the education sector is an essential activity by requiring the Secretary of State to make regulations under Part 3 of the Bill. This would bring within scope any institution that provides primary, secondary, further or higher educational and vocational training. It includes exam boards involved in setting, marking or awarding and grades, higher education admission bodies, and any body that is essential to the provision of primary or secondary education that holds substantial volume of student or staff data. The obligations would require that education bodies take appropriate and proportionate technical and organisational measures to manage risks to the security of their network and information systems. The bodies must: take appropriate and proportionate measures to prevent and minimise the impact of cyber incidents, with a view to ensuring continuity of service; have regard to the state of the threat; ensure that they have a high level of security appropriate to the risk; and have regard to any relevant guidance issued by their regulator.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The cyber action plan is a very thorough document. It sets out a plan over many years to improve the cyber resilience of the Government and the public sector, which I think we all agree is absolutely needed. The fact that incidents are still occurring in the public sector reinforces the need to act. We will publish the cyber action plan and, as I mentioned two days ago, I will keep the Committee and the House updated on progress on that.

Education is an incredibly important sector, and the Department for Education takes an active approach to supporting the sector. This includes the Cyber Security Hub, providing schools in England with guidance, while the standards for schools and colleges help institutions to understand their cyber security requirements. Colleges have been required to meet cyber essentials since 2024, with more than 80% of colleges now meeting this requirement.

I come to the question of MHCLG and local government. The department is also taking meaningful steps and working with local authorities to increase their cyber defences. This includes the rollout of the cyber assessment framework for local government, which would be the equivalent to what is required in the cyber Bill, and the recently proposed revisions to the best value statutory guidance to set new expectations for local authorities on cyber resilience. That best-value duty provides an immediate and proportionate route to improving through existing governance and accountability mechanisms. In addition, MHCLG is supporting councils directly.

The question of electoral infrastructure and political parties, raised in Amendments 79 and 81D, is also incredibly important, as noble Lords have set out. The Government work with the NCSC to mitigate risks there. MHCLG specifically works with local authorities to strengthen their electoral cyber resilience and ensure electoral data is adequately protected. The Joint Election Security and Preparedness Unit has responsibility for co-ordinating election security. The MHCLG digital electoral services team maintains robust incident response arrangements to protect electoral systems and citizen data. As the noble Baroness, Lady Ludford, mentioned, the NCSC also has a broad package of support for political parties, candidates and elected representatives. This includes regular engagement with parties, which can access the NCSC’s active cyber defence services, as well as NCSC providing tailored advice to parties and candidates.

I have set all that out because the motivation behind bringing these matters into scope is to engender further action. I want to emphasise that further action is happening, whether or not it is within the scope of the regulatory perimeter.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - -

The Minister pointed to three examples of where education is considering issues around cyber security, specifically in schools and only 80% of colleges. One of the concerns I outlined in my contribution was around the examining bodies for both our secondary schools and universities. There was no mention of universities. Can I understand a bit more about how they are currently being considered, if they are not going to be included within the scope of this Bill?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The general approach is that the lead government department has responsibility for ensuring cyber security in the areas that it covers. I will need to write to my noble friend specifically on exam boards and examining authorities. I know that the DfE supports bodies that support higher education and further education, but for further details, I will come back to her.

More broadly, I am happy to talk further with noble Lords between now and Report, and perhaps after, on the approach to assessing what should be within the regulatory perimeter and at what speed that can be advanced.

--- Later in debate ---
Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - -

My Lords, I support the principles behind these amendments. A point was raised by the noble Baroness, Lady Ludford, and I wish to make the point in a different way. Many reasons have been shared during this debate, which I share. The noble Baroness, Lady Ludford, referred to the questions asked by Chi Onwurah MP in the other place. It is interesting because I submitted a very similar Question just before the end of the summer in July. I asked:

“what proportion of the computing and cloud services used by government departments are provided by suppliers that are … headquartered outside the UK, or … subject to the jurisdiction of a government outside the UK”.

I asked that specifically in the wake of recent events and the debate we had in July.

The Answer came back on Tuesday. I accept that the Question asked by Chi Onwurah MP was specifically about AWS, but I was asking about all services hosted outside the UK. The Answer was:

“This information is not held centrally. Individual government departments are responsible for managing their own commercial arrangements for computing and cloud services and would need to confirm the proportion of services provided by suppliers headquartered outside the UK”.


The Government do not know how much they are collectively relying on other countries for our key government digital infrastructure. Our Government’s critical systems, public services and citizens’ data are increasingly reliant on foreign-hosted clouds and data centres. While the Answer refers to “commercial arrangements”, I think it is about much more than that. This is a question of our national security and resilience. I believe we urgently need a digital sovereignty strategy to ensure that we know the answers to these questions, that we can act on them and that we can prevent any future challenges happening to ensure that we are as resilient as we should be.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I will speak to this very strategic group of amendments. I use that word again because the noble Baroness, Lady Kidron, made it quite clear from the outset that that is exactly what we lack: a clear national strategy. I pay tribute to her tenacity in tabling Amendment 83, following what I thought was an extremely useful debate on the last day before we went into recess. That is still very much top of mind at the moment, as the Minister can see from the contributions today. If we had another debate today, I do not think we would feel any greater assurance than we did on the day of that debate.

I also thank my noble friend Lady Ludford for having tabled Amendment 166, which is along very much the same lines. We have at the moment, particularly in the public sector—I thought the noble Baroness, Lady Berger, put this extremely well—near total and escalating digital dependence on foreign technology monopolies and foreign jurisdictions. It is quite prevalent in Whitehall. There is a kind of ignorance about the geopolitical reality that so much of what might be described as the digital stack is owned, operated and controlled from abroad. I will come on to our procurement policies shortly.

Amendment 83 defines the pillars of true digital sovereignty. It would tackle extreme market concentration. As we have heard, three American technology giants— Amazon, Google and Microsoft—control a staggering 73% of the cloud computing and enterprise hosting supporting our UK financial sector and public services. If an AWS region or Microsoft Azure network suffers a systemic failure, three-quarters of the City of London and vast swathes of government administration are instantly paralysed. Concentrating our critical national infrastructure into a handful of corporate choke points is the very antithesis of national resilience.

Secondly, it directly confronts foreign extraterritorial legal exposure. Because our critical public data is predominantly hosted on foreign cloud architectures, that data remains legally exposed to foreign statutory instruments, most notably the US CLOUD Act, and is subject to sudden unilateral geopolitical shifts. As my noble friend Lady Ludford said, we saw a chilling preview of this vulnerability only recently when the US Administration temporarily cut off European and UK financial institutions from accessing Anthropic’s AI model, Claude Mythos. Whatever the rights and wrongs of Mythos and its capabilities—we have a pretty good idea of what the wrongs were from what the AI Security Institute had to say—suppose that we had adopted this powerful model in a cyber defensive role; if an ally can pull the plug on front-line cyber security tools overnight, we do not possess true digital sovereignty. If a foreign ally can pull the plug on critical cutting-edge technology at a moment’s notice, we do not have true national resilience but a dangerous dependency.

My noble friend Lady Ludford’s Amendment 166 would force the Government to publish a formal digital sovereignty strategy within 12 months, assessing foreign reliance and reforming public procurement to prioritise secure home-grown UK technology. In fact, both amendments would tackle a glaring failure of current government procurement. The UK possesses world-leading academic institutions and an exceptional cyber security start-up ecosystem. But we suffer from a chronic scale-up failure. Time and again, major public contracts, such as the recent NHS and defence platforms, are automatically handed to dominant foreign tech giants such as Palantir, rather than nurturing and scaling home-grown British technology.

Proposed subsection (2)(c) of Amendment 83 and my noble friend Lady Ludford’s Amendment 166 would provide the solution. They would legally require the Government to use public procurement as a strategic lever to prioritise secure, interoperable and sovereign UK-developed technologies. That is how we build long-term sovereign capacity on our own soil, create high-wage tech jobs and prevent our best innovations being swallowed up by our international competitors.

In an era of contested supply chains, autonomous AI warfare and geopolitical instability, a nation that cannot secure its own digital foundation cannot truly govern itself. I very much hope that the Government will take heed of these amendments, even if they do not take them on board in this Bill. The former Secretary of State for DSIT is on the record as being very much in favour of digital sovereignty, and I hope that that carries through into the current Government.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It has announced a series of measures, including actions from Microsoft and Amazon, to support greater choice for UK businesses and the public sector.

On my noble friend Lady Berger’s question, it is true that cloud spend is distributed across departments and managed through a range of departmental contracts and commercial arrangements. We have established a cross-government cloud consumption dashboard to improve the visibility of cloud usage across the public sector, and we are working with both suppliers and departments to further improve the quality and completeness of our cloud infrastructure spend data to provide a joined-up view today and for the future. That is something that the Government are acting on.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - -

For clarification, that is on the spend, but my question is specifically about where the cloud services are hosted and/or whether they are under the jurisdictions of Governments beyond the UK. It was not just about what money is being spent; it was about who is responsible for it and where it is located.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

That is well noted.

For all digital services, as many noble Lords have pointed out, government departments are required to carry out robust security and resilience assessments in their procurement to ensure that the actions of foreign states or hostile actors cannot disrupt the delivery of public services. In June, the Cabinet Office published procurement policy note 025, Protecting the UKs National Security through Public Procurement, and AI will be one of four key sectors recognised as critical for national security, with new guidance for departments prioritising contracts for British business where necessary to protect our national security.