Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Alex Sobel Excerpts
Matt Western Portrait Matt Western (Warwick and Leamington) (Lab)
- View Speech - Hansard - - - Excerpts

It is a pleasure to follow the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). I concur with the points he made on Jimmy Lai and Jagtar Singh Johal and, more widely, about the internet of things. I think of Norway and Denmark, which suddenly realised that hundreds of buses they had imported from China had kill switches, meaning that their entire public transport networks could potentially have been disabled, just like that. That is the reality of these new technologies, and we need to face up to it and have our eyes wide open in the contracts and deals that we sign.

On Second Reading five months ago, I welcomed the Cyber Security and Resilience (Network and Information Systems) Bill, but even in the short time since then, the world has become an ever more dangerous place, and the cyber-threat has only intensified. I commend the Government on their hard work in the intervening period, and in my remarks today I want to focus on the cyber-threat landscape, my two amendments—new clause 21 and amendment 28—and the need for a national conversation on national security, which of course includes cyber-security.

Let me start with the cyber-threat landscape. The UK is the most cyber-attacked nation in Europe and the third most cyber-attacked nation globally, with three in four businesses having suffered a cyber-attack in the past year. My hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah) talked about the attacks on Jaguar Land Rover, Marks & Spencer, the Co-op and others. Having spoken with those businesses with the Joint Committee on the National Security Strategy and individually, I know of the scale of the impact that was felt within their operation and how affected they were by these attacks. It is unimaginable, even for the most seasoned business and industry leaders, to suddenly find themselves under such attack, and the repercussions for the economy have been very significant.

In April, the CEO of the National Cyber Security Centre, Richard Horne, laid out the scale of cyber-attacks: on average, the NCSC deals with around four nationally significant incidents a week—that is not the hundreds of incidents that are occurring every day, but the really serious, significant ones. The threat of cyber-attacks will only intensify. Continued state-backed cyber-attacks from Russia, China and Iran, either directly or via proxies, are being fuelled by technological advancements in AI and quantum computing, increasing the complexity and sheer volume of such attacks. The reality is that major cyber-attacks are no longer rare one-offs but an operational reality facing every business and organisation—public and private—across the UK, as they are globally. It is important that we secure our systems to make them more robust and deter such attacks, so that those who wish to do us harm will go after others. It is in this context that the Bill has been introduced, and it takes serious, robust steps to increase the resilience of the UK.

However, given the escalating threat picture, I continue to have concerns about the scope and breadth of the Bill. That is why I have tabled new clause 21 and amendment 28, which I hope the Minister will reconsider. New clause 21 would bring those in the food supply chain within the scope of the NIS regulations and regulate them as “operators of essential services”, while excluding smaller businesses, to avoid an unnecessary administrative burden. I understand that the Minister addressed this on Second Reading, explaining that essential services would only include those sectors

“the failure of whose network and information systems poses imminent threat to life to the British public.”—[Official Report, 6 January 2026; Vol. 778, c. 225.]

I would gently suggest that the collapse or disruption of the food supply chain would pose an imminent threat to life. I say that in an honest and not patronising way. Those of us who have had conversations behind the scenes about what happened during the pandemic, and Opposition Members who were far closer to that when in government, will realise that the health threat was one element, but the collapse of society—not just the economy, but society—with the potential for civil unrest and rioting, due to the lack of food and toilet rolls on shelves and so on, would have been the most urgent and pressing issue. It is worth noting that the European Union’s NIS2 directive does include food distribution in its regulation, so it is feasible and recognised internationally as important. The Bill does grant the Secretary of State powers to bring in new sectors. Could the Minister reassure me that the Department will give this due consideration today and in the future?

Secondly, amendment 28 would ensure that relevant managed service providers do not provide services to manage the technology systems for a number of customers that exceeds a critical risk threshold within the same sector or subsector. The rationale behind this is simple: it is about building resilience and ensuring that if one RMSP fails or is breached, a whole sector is not hamstrung by it. I can envision a situation whereby one particular RMSP dominates a large category or small subsector that may be a crucial part of a supply chain, thereby crippling the whole chain. Indeed, my hon. Friend the Member for Newcastle upon Tyne Central and West cited the UK Government’s dependency on AWS and Microsoft as an example. Will the Minister please consider that?

Aside from my two amendments, it is clear that the Bill, in itself, is not the only answer to our cyber-resilience; multiple approaches are needed. Given that the Bill does not include large swathes of the economy or local government, it is even more important that we explain to businesses and the public the very real threats that we face. That brings me to my final point, which is on the need for a national conversation on national security. We can have the best crafted and tightest legislation and regulation, but unless we have a real cultural shift and acknowledgment of the cyber-threat and its impacts, from board level to entry-level positions, all of this will be wasted. I once again encourage the Department and the whole machinery of government to go further and faster in explaining the threat posed and the steps we can all take to boost resilience, because resilience starts with the mobile phone in our pocket, and cyber-security is only as strong as its weakest link.

The Joint Committee on the National Security Strategy, which I chair, has begun its inquiry into building national resilience through a national conversation. It is clear from the evidence we have heard from Taiwan, the Netherlands and other European nations I have spoken to that we need to explain the threat to people, build a stronger cultural sense of resilience and explain that we all have a role to play; it is not simply the state’s responsibility. I will update the House on our findings in due course, and I hope the Minister and the Government will find that useful when considering their plans for national resilience.

To conclude, this Bill is a substantial and serious step forward in protecting the UK from cyber-attacks. It makes us more resilient and strengthens our collective security, but there are areas where I encourage the Government to be more ambitious—namely, by bringing the food supply chain into the essential services classification, as Europe is doing; setting critical risk thresholds for RMSPs; and expanding the scope of the Bill to encompass more of the economy.

Alex Sobel Portrait Alex Sobel (Leeds Central and Headingley) (Lab/Co-op)
- View Speech - Hansard - -

It is a pleasure to follow such esteemed colleagues. My only declaration before I start my speech is that I hold a degree in information systems from the University of Leeds.

I have been sat here for the last two hours looking at the memorial plaque for Jo Cox, 10 years after the horrific day that we lost Jo. I was a West Yorkshire candidate alongside Jo in the run-up to the 2015 election. It is to my huge detriment that I never got to serve with her here. Today is such a difficult day for so many colleagues. I know that Jo would have dearly liked to see many of the things that Labour is doing in government. It is incumbent on us to try to push forward all the things that Jo strived for, to make this place better, to make the country better and to make the world better.

Let me now turn to cyber-security. Data centres are warehouse-like facilities that house the information technology equipment upon which almost all digital activity relies. The UK Government say that they

“underpin almost all economic activity and innovation, including the development of AI and other technology, public service delivery”

and modern-day communications. Europe’s largest data centre market is Greater London, where most of the UK data centres are concentrated. There are four types of data centre, one being AI data centres, which are facilities specialised for the high-performance computing needs of AI development and AI models. Having data centres based in the UK allows our Government to regulate them, such as by requiring them to meet cyber-security standards and reduce their environmental impact, which is obviously very important.

Data centres are an essential part of our critical national infrastructure. They have a huge environmental impact so must be managed carefully, but the benefits of having them on our home turf is that we can regulate them. In our current state of hybrid war with Russia, it is vital to protect those data centres from any nefarious actors or cyber-warfare, and to strengthen their protections against cyber-attacks spawned by AI. Otherwise, the impact on public safety, the economy and society could be catastrophic.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I will give way to my hon. Friend the Member for Leeds Central and Headingley in the first instance and then to my hon. Friend the Member for Dunfermline and Dollar.

Alex Sobel Portrait Alex Sobel
- Hansard - -

There is obviously a level of complexity here in relation to the data centre, AI development and the network in the UK and more broadly. Will the Minister therefore commit to a meeting with me and my hon. Friend the Member for Cowdenbeath and Kirkcaldy (Melanie Ward) to discuss this matter further?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I would be delighted to.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

As ever, I would be delighted to work with the Chair of the Select Committee on a range of technology questions, including this one.

I am delighted with the support that this House has shown for the intention and principles of the Bill, and I am grateful for Members’ consistent, principled scrutiny.

Alex Sobel Portrait Alex Sobel
- Hansard - -

On the amendment from the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith), I think we have made some progress with the Minister, but it is clear that trying to isolate the issues around fair trial from other matters is complex. Repeating my earlier call, will the Minister meet me, the right hon. Member for Chingford and Woodford Green and others who signed his amendment to explore the complexities of this after the debate?