Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Baroness Harding of Winscombe and Lord Vaizey of Didcot
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, earlier today, the noble Viscount, Lord Colville, and I were saying that we were both quite late down this list and feared that everything would already have been said. That appears to be the case, but, fear not, I will still use my eight minutes.

I support the Bill and I agree with many noble Lords that we also need a much more comprehensive cyber security strategy. Like others, I have some specific suggestions for this specific Bill. My unique contribution, if it is unique, is not that I am an engineer and tech expert, as the noble Lord clearly is. I think that, in health terms, I would be described as an expert by lived experience, in that I suspect I am the only noble Lord today, probably the only noble Lord on the roster, who has actually been a CEO faced with a cyber attack. I have been that CEO whose company has been targeted by a gang of hackers, trying to work out how to navigate the crisis. I have had to go out and communicate to regulators, to customers, to shareholders.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

To Ministers, indeed—to my noble friend himself. In those days, the National Cyber Security Centre did not exist—I am obviously referring to my time as chief executive at TalkTalk. Instead, we were directed to the Metropolitan Police’s hostage negotiation team. They were lovely but unfortunately had no tech experience at all. In fact, we did no better ourselves. The security expert who came to brief the TalkTalk board had just come from Mexico, where he had been trying to get a bank manager back who had been kidnapped.

That was only 11 years ago. At TalkTalk, we took the view that communicating was the only way to help our customers and therefore the only way to save the company, and I stand by that decision now, but not everyone takes that view. I was accused at the time of being hopelessly naive for going out, within 24 and 48 hours, on to the airwaves and saying, “My customers have been attacked and, no, I don’t know exactly what has happened”. That is the timetable in this legislation. Most CEOs I talk to say, first, “God, I’m glad I wasn’t in that situation. That’s my nightmare”. Secondly, they are surprised when I say that, actually, I would communicate earlier if I was in that situation again and not later. Cyber attacks are a modern-day taboo in the business world. Business leaders are terrified of admitting that they have been attacked, and I am afraid that that means that mandating reporting is essential, because, 11 years after I was in that situation, I do not think that that has changed. I think that unless we make it mandatory to report, people will not do it.

I was surprised at the time, in 2015, that had Sainsbury’s or Tesco been hacked, I would not have had to tell anybody—I had just come from Sainsbury’s in my previous job. It is really depressing, 11 years later, to see that retail is still excluded. I cannot quite understand why water is “essential” but food is not. I think that Covid taught us that our food retail supply chain is an essential service, and those who work in it are essential workers.

Managed service providers are in, but generative AI is out. Only a decade ago, that might have been OK, but it is not now. In the other place, the Minister said there are powers in the Bill so that we can get it right in the future. Well, we need to get it right now, and we also need the powers to try to keep up. I am not against giving Ministers the power to keep this live, but that is not an excuse for not being up to date today. As other noble Lords have said, it looks, sadly, as though the EU has got this more right than we have. We should be humble enough to admit that, rather than be afraid and insist on doing the wrong thing.

The other area I have some lived experience in, which, again, has been mentioned by other noble Lords, is the challenge of 12 NIS regulators and the lack of join-up. When the TalkTalk hack happened, we immediately stood up a series of workstreams—the obvious things such as trying to work out what had happened. That is the biggest problem with a cyber attack—you genuinely do not know whether you have been attacked by a nation state or kids in a bedroom. You somehow hope it might be the former, but more often than not it turns out to be the latter. So you have to know what has happened and you have to start communicating before you know what has happened. That is two workstreams. You have to work out how to get your systems back up again. That is another workstream. Even 11 years ago, without any of these additional regulators, we had to have a “communicating with regulators” workstream.

Now, spare a thought for the poor managed service providers. They are companies that serve transport, telecoms, energy and the NHS. I think they might have a full house. If you were a managed service provider that was the victim of an attack, you would probably have to deal with all 12 regulators. Those of us who have been here for a while know that if you give 12 different public sector bodies the ability to define terms, they will define them in 12 different ways and have 12 different forms. That will stop you, in the first day or the first week of a cyber attack, doing the things that you should be doing to try to protect your customers. As an expert through lived experience, I plead with the Minister: join-up is essential. It should not be optional. We all know it is hard to do. If you do not sort it out in the Bill, it will not happen. Please do not make that join-up a forum.

I can take myself back to October 2015 and imagine having to communicate with—as much as I love it—the DCRF. If we had had to convene a meeting of 12 regulators in the heat of the crisis to work out what to do, that would not have helped anybody. So we need either a single regulator, as the noble Lord, Lord Birt, so eloquently set out, or a lead regulator, as I know the Government are looking at in a number of other areas, to try to reduce the burden of regulation. I very much support what my noble friend Lord Effingham said: regulation does look like it is necessary here but we need to be careful that we are not just layering burden upon burden, and doing it 12 times most definitely is.

I feel I have said nothing original at all but have said it possibly from a unique perspective. I am rare among former chief executives who have experienced a cyber attack in that I am willing to talk about it, which is exactly why this legislation is important. But I very much hope that, as with so many tech issues, the Minister will hear that we agree more than we disagree and that we could work together to improve the Bill, as this House is often quite good at doing.