Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Bennett of Manor Castle Excerpts
Baroness Bennett of Manor Castle Portrait Baroness Bennett of Manor Castle (GP)
- View Speech - Hansard - -

My Lords, it is a great pleasure to follow the noble Baroness, Lady Kidron. I will come back to her points about digital sovereignty. I also thank the Minister for introducing this Bill.

I have been reflecting back. I am approaching my eighth year in your Lordships’ House, and we have come a long way. About seven years ago, I was standing behind the Bar and a Member of your Lordships’ House who shall remain nameless sidled up to me and said: “They’re talking about catfishing. I gather that doesn’t mean being beside a river with a rod”. I said, “No, you’re right. Well done, well worked out”. We have come a long way. But, of course, the world has changed an enormous amount in those eight years and the message from all corners of your Lordships’ House today is that the Government are not keeping up. Your Lordships’ House will have to do its best to keep up for them and push the Government in those ways.

In her introduction, the Minister talked about data centres being a key part of the modern world. Their security is very reliant on water and energy supplies, just as all our security is being impacted by their consumption of those supplies. Something we have not really talked about yet, but need to think about a lot, is that we tend to think about these information systems and networks as being up in the cloud, but of course they are very much physically down to earth and dependent on all our natural physical systems. That cannot be forgotten.

I will focus mostly on two areas of concern that are missing or inadequately covered in this Bill in terms of our network and information systems. In Trafalgar Square at this moment, there is literally a Trojan horse—a reminder, in mythological form, to beware of Greeks bearing gifts, at least if they have just been besieging your city. I put it to the Government that this is a parallel that they should be considering: beware of Silicon Valley tech bros bearing shiny undeliverable promises, with large lobbying budgets and frighteningly undemocratic values, and that bear allegiance to a state with doubtful levels of democracy and consistency. I also want to respond directly to the noble Lord, Lord Birt, who spoke about the risks of volunteer-run, open-source software. Of course, it is very possible to question which is the greater risk: a Silicon Valley tech bro or a whole lot of people who are trying to work for the common good. We might debate that as we go along.

As the noble Baroness, Lady Kidron, identified, we are talking about digital sovereignty. I draw the attention of your Lordships’ House to an amendment tabled by my honourable friend Siân Berry in the other place, which was not debated there, calling for the Government to have a digital sovereignty strategy. It proposed that the Government should have and maintain such a strategy and

“set out the Government’s assessment of the risks to … network and information systems arising from … dependence on hardware, software, or digital services that may be subject to foreign interference”

of the kind that the noble Baroness, Lady Kidron, referred to, in terms of AI systems;

“extra-territorial legal requirements that may be imposed on non-domiciled suppliers;”

and

“vulnerabilities, undue control, or supply-chain dependency on foreign states or entities”.

I am sure everyone in your Lordships’ House knows what I am talking about, but I will pick one example as a case study: the company whose place in our society, and the values of its founders, owners and leaders, are a great cause for concern in Parliament and with the public. I am talking, of course, about Palantir. Last month, the Science, Innovation and Technology Committee warned that

“it’s not the only company capable of providing the ‘middleware’ required by public bodies”.

The committee also identified Microsoft and Amazon Web Services. Let us focus on this: you do not even need the fingers of one hand to count the absolutely central suppliers here. The committee said such dependencies were putting us

“‘at the mercy’ of foreign actors”,

and it very explicitly called for the Government to exercise the 2027 break clause in the NHS Federated Data Platform contract—ideally to develop an in-house replacement. That is one sovereign issue.

A second sovereign issue faces towards a more obvious international danger that the Government will not, I hope, deny. As debated in the other place, this is the need for critical safeguard in this field for an anti-transnational repression amendment. I happen to know that the noble Lord, Lord Alton of Liverpool, who cannot be with us today unfortunately, intends to table an amendment as we progress this legislation. At the moment, this Bill creates a dangerous loophole. It permits the sharing of highly sensitive network and information systems data with overseas authorities, without checking whether those authorities operate within a system that guarantees legal standards and human rights. There needs to be a rule that says, “Let’s check and think before we share”.

It is important to say that this would not be an actor-specific measure; it would be a universal principle-based safeguard that would apply to any regime, anywhere in the world, that rejects the rule of law. It would require the Secretary of State to actively consult subject matter experts and civil society groups to identify compromised jurisdictions. We have to be realistic about the state of the world now. Authoritarian states have a long and troubling track record of using international structures, such as Interpol notices for example, to mask political persecution under the guise of criminal justice.

I should declare at this point that, until recently, I was co-chair of the All-Party Parliamentary Group on Hong Kong, and I will focus briefly on the issue of China. UN special rapporteurs have pointed out the issues there. We cannot assume that so-called safe third countries will protect dissidents. Countries such as Spain have authorised extraditions to China, Cyprus has accepted individual “assurances”, and countries such as Hungary and Serbia are deepening judicial co-operation with Beijing. The UK has suspended its formal treaty with Hong Kong, but recent proposed changes to the Extradition Act 2003 open the door to case-by-case ad hoc arrangements. NIS data includes IP addresses, digital fingerprints and user-level logs, so the concern is not just about extradition but that this would allow authoritarian states to identify dissidents in the UK. We know that transnational repression against dissidents has been a great and growing to diaspora communities and human rights defenders.

This Bill needs a lot of work, as many people have said. There is really foundational work here that needs to be done.