Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, I am very glad to support all the amendments; I will not read them out again. The noble Baroness, Lady Harding, has already convincingly set out the case. I really hope that the Minister recognises that these amendments are born out of lived experience, which is characteristic of this House and very precious when considering how legislation actually impacts in the world at times of crisis.

The amendment specifically calls for staged incident reporting, to create a drumbeat of information and oversight so that damage can be minimised. Cyber attacks move quickly and are extremely confusing for those involved. Staged incident reporting enables regulators to have a more immediate understanding, so that they can offer support, anticipate spread and learn lessons for strengthening guidance in the future.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

I apologise, I stand to speak to a whole other group of amendments that suffer from the same challenge of needing to be repeated four times, which is why I suggested to the clerks that we degroup them, otherwise we would have got into a real muddle.

This group seeks to address the obligation to report incidents to customers, as the Minister referenced in her remarks earlier. Currently, the Bill requires notification only where a customer is,

“likely to be adversely affected”.

The obligation is to explain the nature of the incident and why the customer is affected. My amendments seek to broaden and deepen that duty. Customers must be notified where an incident has caused or has the potential to cause severe operational damage or financial loss, where I hope my drafting has not fallen prey to the issue that my noble friend Lady Neville-Jones, addressed in Amendment 17. If it has done so, we obviously need to address that.

The duty is extended to cover related natural or legal persons who could suffer considerable damage as a result. The regulated entities must also advise customers on what measures to take in response. Probably most importantly in this group of amendments, the entities must keep customers updated until the incident is resolved, whereas at the moment the Bill only requires them to notify customers once and then leave them hanging, waiting to find out what is going on. Together these amendments would ensure that customers are told promptly what to do and are kept informed throughout the incident until it is resolved. They also follow the NIS2 directive in requiring advice on protective measures and go a little further by making it a requirement to communicate to related persons as well.

Sadly, I have personal experience in this, not from my TalkTalk times but much more recently. I suspect anybody who is on a board or who has chaired a business has experienced this. An organisation that I chair is the customer of a managed service provider that recently experienced an incident. It did not tell us. The incident was to do with some of our staff payroll information, so it was sensitive and important. When it did tell us, it then did not keep us informed about what was going on. So I feel that pain.

I know that some noble Lords may have concerns that we do not want to create panic by endless notification. I absolutely agree. Hence my attempt to define this as severe operational damage. I would very much welcome input between now and Report if we can tighten that wording to make sure that this does not represent lots of unnecessary email alerts telling you that a system three stages back in the tech stack might have been affected. But when your customers’ data has been exposed in a cyber attack through a managed service provider, data centre or digital service that you use, it is entirely reasonable that those companies have a requirement to inform and keep you updated during the incident. That is all that these amendments seek to do. I beg to move.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, for reasons that I do not understand, I do not have my name on these amendments, given all the others from the noble Baroness that I do, but I support them. It is funny, because when I came back from holiday in August, I had no fewer than five emails from companies saying that there had been data breaches in which I was involved, and I had that exact thought—“What now? What do I do? What’s next? How serious?”—and did nothing.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

I am sorry, it is me again. In a break with tradition, we have only one amendment in this group. That is because this amendment would insert a proposed new clause, as opposed to lots of small changes to existing clauses. Amendment 72 is in my name and, once again, I thank the noble Baroness, Lady Kidron, for adding her name.

This proposed new clause seeks to ensure that organisations regulated under the Bill must report any near misses, cyber threats or incidents currently under the thresholds as set out in the Bill that could affect their network and information systems. I am, again, mindful that it is important that this is consistent with the extremely well-made points of my noble friend Lady Neville-Jones in Amendment 17. It is welcome to have discussions on whether the wording is right, because the purpose is to get the near miss, rather than a huge deluge of meaningless reporting.

As it stands, the Bill requires regulated entities to report only what has happened, and only if it crosses a threshold based on factors such as scale, duration and the number of people affected. However, my amendments look to close the gaps in the event of, for example, an attack an organisation has stopped before it has caused major damage, but had the attack had been successful, it would have had a substantial effect across the whole industry. Other examples are where there are very credible warnings of an expected attack that does not occur, or where there is an incident that falls just below the thresholds that could still be significant.

The intention of this amendment—unlike in my other two groups, it is quite a probing amendment to see if we can work together to capture the spirit of this—is to close a reporting gap where significant incidents may not be reported simply because of the way we have drawn up the definitions in the Bill.

As in the other two groups that I have led, this follows the EU NIS2 directive, although the NIS2 directive creates a voluntary rather than a mandatory reporting provision for this. My view is that the taboo for going public on cyber attacks is so great that voluntary reporting is not the way to do this. It is better for all organisations to know the black and white of what they can do, what they should do and what they do not have to do. In some sectors, certainly the one I worked in—telecoms—there is a fair amount of voluntary sharing. But even there, there is such a taboo about speaking to your regulator about a problem that this needs to be made this mandatory rather than voluntary. Other than that, this seeks to replicate what is in the EU NIS2 directives. With that—I think noble Lords have probably heard enough of me—I beg to move.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, I support Amendment 72 and I have signed it. I recognise the probing nature of this, but I also recognise the problem it seeks to address. The knowledge that a cyber threat or cyber attack has failed may be incredibly important intelligence because, on the whole, someone trying to create a cyber threat will not retire after the first time that it did not work out; they will try somewhere else, so the intelligence element of this is so crucial.

Some of the people in cyber security talk about seven stages of cyber attack. The first stage is reconnaissance: you are just having a look round and trying to identify vulnerabilities. The second stage is weaponisation: you are developing the means to target that weakness, which can be as simple as an email. It is not until the third stage that the attack begins. But there are still three or four more stages, each of which can provide a barrier and each of which can be the place at which the attack stops. It is not uncommon for attackers to carry out multiple attempts to find or exploit a vulnerability, or indeed to do a small-scale attack in order to then do something larger down the line. In all these cases, there is something absolutely critical for the regulator and possibly the enforcement community to know.

--- Later in debate ---
Moved by
74: After Clause 21, insert the following new Clause—
“Liability of senior executivesAfter regulation 18 of the NIS Regulations insert—“Liability of senior executives(1) This regulation applies where a designated competent authority or the Information Commission has reasonable grounds to believe that—(a) a person that is a body corporate, a partnership (including a Scottish partnership) or an unincorporated body has failed to comply with a duty referred to in regulation 17(1), (2), (2ZA) or (2ZB), and(b) the failure was committed with the consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly. (2) The competent authority or the Information Commission may serve a notice of intention to impose a penalty on the senior executive(s) if it considers that a penalty is warranted having regard to the facts and circumstances of the case.(3) Before serving a senior executive(s) notice, the authority or the Information Commission must inform the senior executive(s), in such form and manner as it considers appropriate having regard to the facts and circumstances of the case, of—(a) the alleged failure and the office’s alleged consent, connivance or neglect, and(b) how and by when representations may be made in relation to the alleged failure and any related matters.(4) A senior executive(s) notice must be in writing and must specify the following—(a) the reasons for serving the notice;(b) the alleged failure or failures and the senior executive(s) alleged consent, connivance, neglect or carelessness which are the subject of the notice;(c) any remedial actions required;(d) the amount of the penalty and the number of penalties which the authority or the Information Commission is minded to impose.(5) The authority or the Information Commission may, after considering any representations made in accordance with paragraph (3)(b), serve a penalty notice on the officer with a final penalty decision if satisfied that a penalty is warranted having regard to the facts and circumstances of the case.(6) A penalty imposed under this regulation must be of an amount which the authority or the Information Commission determines is appropriate and proportionate in the circumstances, having regard to the matters mentioned in regulation 18(6) for each infringement individually.(7) If the authority or the Information Commission is satisfied that no further action is required, having considered any representations submitted in accordance with paragraph (3)(b), it must inform the senior executive(s) in writing as soon as reasonably practicable.(8) In this regulation “senior executive(s)”—(a) in relation to a body corporate, means a CEO, director, manager, secretary or other similar senior executive of the body, or a person purporting to act in any such capacity;(b) in relation to a partnership, means a partner or a person having control or management of the partnership business, or a person purporting to act in any such capacity;(c) in relation to an unincorporated body other than a partnership, means a member of its governing body, or a person purporting to act in any such capacity.””Member’s explanatory statement
This amendment seeks to create provision in the Bill for executives or senior managers to be held responsible for failure to comply or report on the measures placed upon regulated bodies within the Bill.
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, Amendment 74 is in my name and those of the noble Baronesses, Lady Morgan and Lady Ludford. The noble Baroness, Lady Morgan, is very sorry that she cannot be in the Committee this afternoon but she particularly wanted me to thank the Minister for their helpful meeting last week. This amendment and Amendment 167 in the name of the noble Baroness, Lady Ludford, relate to the governance of regulated bodies that will be caught under this Act. The reason for this legislation is to reflect the rapidly changing cyber environment and to strengthen areas of current vulnerabilities of those organisations providing services critical to societal or economic life.

As we have discussed, regulators will be given powers to designate critical suppliers whose disruption could have a significant impact on essential services. As we have discussed in previous groups, many of us think the Bill does not go far enough in setting out who those critical suppliers are. We are going to see similar amendments in other forthcoming Bills that make provision for senior manager liability when new responsibilities are legislated. This is something that we have been through in other Bills: the only way to change the culture of an organisation is to start at the top.

I am sure that boards will grumble when they accept new duties, but they will keep their regulators happy were they to be in sight of the law. What really makes the difference to successful implementation is knowing that if it can be proven—I shall read out proposed new subsection (1)(b)—that

“the failure was committed with a consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly”,

that individual will be held responsible. I point noble Lords to recent court cases in the area of social media, where disclosure has repeatedly shown that senior executives knew of harm or stood in the way of harm mitigation for years. The idea that this might capture an unwilling or unwitting senior executive is shown clearly not to be the case by what I have just read out.

I understand that the Minister and the noble Baroness, Lady Morgan, also discussed this in the context of financial services and a regime introduced after the 2008 financial crash with the very intention of changing the culture of financial service businesses and focusing senior minds on the damage those businesses can do if they do not meet their responsibilities. A more recent example is the introduction of the consumer duty by the Financial Conduct Authority, which required relevant boards to appoint an individual consumer duty champion, something that the noble Baroness, Lady Morgan, was involved in. I also point to the Building Safety Act that was a response to the Grenfell Tower disaster.

I am hoping that the Government are sympathetic to this amendment, but if they find themselves unable to be sympathetic, I would be interested also to hear the Minister’s thoughts on whether we could require the relevant regulator to introduce a named senior manager regime, which indeed we did in the Online Safety Act.

The final point I make is that the senior manager must be senior. The intention behind the amendment is to change the culture of an organisation to ensure preventive action is taken to avoid penalties. As I said at the outset, culture change starts at the top. The services covered in the Bill are, by definition, considered by Ministers to be critical to national life, which means that the most senior governing body should be discussing them and responsible for them. While day-to-day management may be delegated, overall oversight and responsibility should sit at the top. For that reason, I support—as I know the noble Baroness, Lady Morgan, supports—Amendment 167, tabled by the noble Baroness, Lady Ludford. Her proposed new clause would focus the minds of those at the most senior levels of organisations caught by the Bill, and I really hope that the Government support this ambition. I beg to move.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - - - Excerpts

My Lords, I am pleased to speak to Amendment 167 and grateful for the support from the noble Baroness, Lady Kidron—the support is mutual, as I co-signed her amendment. The two amendments are complementary, because Amendment 74 is about the liability of senior executives while Amendment 167 is about board oversight of an individual executive, responsibility and accountability. I was interested to hear the noble Baroness refer not only to financial and consumer conduct but to building safety as areas where such responsibility exists.

I am simultaneously involved in the Public Office (Accountability) Bill—the Hillsborough law—which will introduce a duty of ethical conduct, candour and transparency on public authorities and public officials. Perhaps what some of these other sectors have in common is that it has been an after-the-event thought that maybe boards and senior executives ought to have some kind of responsibility in this area. If we have had a catastrophe, often with a great deal of harm created—such as Hillsborough—maybe it would be a good idea if the people at the top, who are often extremely highly paid, took some interest in the area, rather than regarding it as some sort of lowly service, rather like cleaning the loos in the HQ building. I know it is now routine to refer to examples such as Jaguar Land Rover and Marks & Spencer, but there have been huge financial effects of cyber attacks. This is not some negligible issue; cyber security ought to be a core responsibility for senior people.

I am sitting close to the noble Baroness, Lady Harding, who today has referred to her own personal experience—we all remember it. I am sure it was painful for her and very public. She has actually been through it, so nobody knows better what it can be like when you have a big cyber data breach or cyber attack. It really is long past due that this ought to be a top responsibility of boards, directors and senior executives. Yet we understand—I think I get this from my noble friend Lord Clement-Jones—that the Government’s own Cyber Security Breaches Survey reveals that board-level ownership of cyber risk in the UK has declined from 38% to 27% over the past three years. It is going precisely in the wrong direction.

I do not think I need to persuade anyone here of how important it is for senior people in an organisation to be aware and carry not only responsibility, awareness and accountability but liability, so that it hits where it hurts if something goes wrong. Personally, it seems pretty much a no-brainer, and I hope the Minister will agree.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

The noble Lord, Lord Clement-Jones, has done a lot of my work for me. I thank everyone who contributed. I was really struck by the expertise in this Room. We started this afternoon by talking about the importance of lived experience. I say very strongly to the Minister that I have been in the House long enough to see Acts of Parliament pass, be regulated and fail because we did not really understand how they were going to hit when they were in the world.

The comments on this group are really worth listening on, particularly those on Amendment 167. I say both to the noble Viscount, Lord Camrose, and to the Minister that there is such a high bar of connivance in Amendment 74. There is no accident. The words are “deliberately”, “knowingly”, et cetera—I read them out as part of my introduction. I will take up the noble Viscount’s offer to come to speak to him and persuade him, and I ask the Minister to really think about this, because we have heard that culture does not change without an incentive. This is an incentive to say that if you are seen to grossly mislead and undermine the regulation, then you are liable. That is what good law does. I beg leave to withdraw the amendment.

Amendment 74 withdrawn.
--- Later in debate ---
Moved by
83: After Clause 28, insert the following new Clause—
“Digital Sovereignty Strategy (relevant network and information systems)(1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems.(2) The Strategy must—(a) set out the Government’s assessment of the risks to relevant network and information systems arising from or related to—(i) dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference,(ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers,(iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities,(iv) inadvertent or deliberate extraction or training on UK datasets without licence or permission, and(v) foreign actors’ access to UK sovereign data assets and data held in trust on behalf of the public including, but not limited to, the National Health Service, the British Broadcasting Corporation, the Meteorological Office, security and surveillance assets, defence assets, education assets, and assets from museums and other cultural institutions;(b) set out the technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems in the UK;(c) set out the Government’s approach to mitigating the risks identified under paragraph (b); (d) include an assessment of—(i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems,(ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems,(iii) the skills, capabilities, and capacity of UK-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems,(iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems,(v) options for international collaboration in the production of open source components used in relevant network and information systems,(vi) options to prioritise procurement from UK-based businesses, services and suppliers used in relevant network and information systems,(vii) capital markets and pension funds holding capital in UK-based relevant network and information systems, and(viii) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems.(3) The Secretary of State must, within the Strategy, set out a Digital Sovereignty Dashboard used to measure the technological sovereignty of the UK in relation to relevant network and information systems, including relating to—(a) infrastructure, including infrastructure concentration,(b) data-jurisdiction exposure,(c) value of information and cultural assets of the United Kingdom, and(d) dependency on foreign states.(4) In preparing the Digital Sovereignty Dashboard, the Secretary of State must consult—(a) the Office for National Statistics,(b) the Competition and Markets Authority,(c) the National Cyber Security Centre,(d) the AI Security Institute, and(e) any other persons the Secretary of State deems relevant.(5) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security.(6) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen.(7) In this section—“Digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend;“open source” has the meaning given to it in the definition published by the Open Source Initiative;“relevant network and information system” means a network and information system belonging to—(a) an operator of an essential service, (b) a relevant digital service provider,(c) a relevant managed service provider, or(d) a critical supplier,within the meaning of the NIS Regulations.”Member’s explanatory statement
This new clause would require the Secretary of State to prepare, maintain, and lay before Parliament a Digital Sovereignty and Resilience Strategy addressing risks to relevant network and information systems from foreign ownership, interference, and technological dependence. The Strategy would include a Digital Sovereignty Dashboard, which would provide evidence on UK procurement, innovation and resilience and keep an up-to-date understanding of emerging risk.
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, Amendment 83, in my name and those of the noble Baroness, Lady Ludford, and the noble Lords, Lord Holmes and Lord Tarassenko, would require the Secretary of State to publish and maintain a digital sovereignty strategy. Before the Recess, many of us participated in a debate on digital sovereignty, and the level of agreement across the Chamber was absolutely overwhelming about the importance of UK national sovereignty and the current threats to it from our current arrangements with the tech sector, particularly US-based behemoths. The same sentiment is articulated by Amendment 166 in the name of noble Baroness, Lady Ludford, and it is a sentiment shared in the other place, where Conservatives, Liberal Democrats and Greens all tabled similar Motions.

During the debate, I identified four areas in which the UK has surrendered its leverage to make its own decisions. We surrendered our political leverage by deferring to the power of US tech; we surrendered our economic leverage by placing UK businesses at a structural disadvantage and entering into expansive and extractive contracts; we surrendered our technological capability as we failed to invest in UK capacity and businesses; and we ensured our strategic vulnerability by depending on foreign companies for key infrastructure. Together, these weaken our economy, our security, our safety and, above all, our autonomy: the ability to choose. I doubt that any single government strategy put us in this position, but it reveals a lack of strategy that we find ourselves here.

Amendment 83 would set out a requirement for the Secretary of State to establish a digital sovereignty strategy. Proposed new subsection (2)(a) would require an assessment of the risks to networks and information systems from

“dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, extra-territorial legal requirements that may be imposed on non-domiciled suppliers”—

such as cloud providers through the US CLOUD Act—

“vulnerabilities, undue control, or supply-chain dependency on foreign states or entities”,

the use of

“UK datasets without license or permission”

and vulnerabilities to valuable data assets that belong to the British public, including those related to the NHS, BBC, and Met Office. The rest of proposed new subsection (2) sets out further requirements to assess the risk of

“technological developments, market concentration or strategic dependencies”

and give consideration to vital elements of sovereignty, including open source technology and assets, talent procurement, capital markets and international collaboration with mid-sized partners whom we retain leverage with.

Finally, proposed new subsections (3) and (4) call for the development of a dashboard enabling the measurement of digital sovereignty. I am working with computer scientists at the British Computing Society who are developing a prototype for this and I urge the Government to look at this work and consider developing it, for their own procurement purposes and to provide it as a tool for the wider business community.

I set that out in some detail because I rather suspect that, if we had a proper strategy across the nation, we would not have had the conversation that we just had in our debate on the previous grouping. Sovereignty is now firmly on the agenda. This is partly due to the export ban on Anthropic and Claude Fable 5 introduced by President Trump in June, but stories highlighting our sovereign vulnerability across the digital stack predate that event and have continued since.

Dependency is not built overnight. It is the result of a systemic and concerted effort by entrenched big tech companies across many years to make themselves indispensable to the UK state, businesses and society, and of successive UK Governments failing to invest in our businesses, communities and people and choosing always to buy oven-ready tech, irrespective of the economic, societal and individual costs.

Just as dependence is not built overnight, neither can sovereignty be reclaimed overnight; nor is it a zero-sum game in which every part of the stack can or should be replaced. None the less, to restore any independence at all, we require an equally systematic and concerted approach to build where we can, to buy only products and services that adhere to our laws, to recognise our unique skills and assets, and to work co-operatively with other like-minded countries. That begins with a strategy that establishes a clear route for government and is fed into experts, free from lobbying and scrutinised by Parliament—which is the very purpose of the amendment in front of us. I beg to move.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - - - Excerpts

My Lords, I shall speak to my Amendment 166. It offers an alternative route to the same destination, although the amendment in the name of the noble Baroness, Lady Kidron, is probably superior because it is fuller and more comprehensive; I readily concede that. Her amendment would add an important element—a digital sovereignty dashboard prepared by the Office for National Statistics, the Competition and Markets Authority, the National Cyber Security Centre and the AI Security Institute—so that we can measure whether anything is changing. The cross-party agreement on this matter, which the noble Baroness referenced, is important and might help persuade the Minister of the force of the argument.

The Competition and Markets Authority puts Amazon Web Services and Microsoft together at between 70% and 80% of the UK’s public cloud market. That is not only a duopoly but a digital sovereignty issue. In its report Rewiring the State, which was published in June, the Science, Innovation and Technology Committee in the other place found that major departments, including HMRC and the NHS, were locked into multiyear agreements that further entrench those dependencies. The National Audit Office has found no shared strategic approach across government towards the handful of very large suppliers that now dominate these markets and are, to a large extent, American. Research done by the British cloud provider Civo found that 83% of UK IT leaders believe that geopolitics threatens their ability to control their data, while only 35% know precisely where that data resides.

I have a history, as a Member of the European Parliament, of being involved in all the arguments about transatlantic data transfer and what happens to the data when it is in the US; this was all in the wake of the war on terror, Guantanamo and so on. We are back in that territory, I guess. It is not just about the economic side of non-national control; it is also about your vulnerability to decisions—including, sometimes, decisions that you do not like—about what happens to the data.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Going back to the point made by the noble Lord in an earlier intervention, the Bill is a substantive Bill that substantially increases coverage of the digital infrastructure on which much of our economy relies. That is a very important point. As I mentioned at the start of my remarks just now, the question of whether the Bill is the right place to articulate the breadth of many of the issues that have been raised is, indeed, a good one. I am not sure that it is the right place to articulate all the very good questions that have been asked, because some are much more wide-ranging than the scope of the Bill.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, I thank all who have spoken for their excellent contributions. I will make three quick points. First, in the course of the afternoon, I opened the Explanatory Notes, which is always a bit of a danger. I just want to put on the record that paragraph 2 states:

“These reforms are intended to better protect the services and other activities that are essential to the day-to-day functioning of society in the UK, and the economy, through safeguarding relevant network and information systems (the systems that allow computers and other devices to communicate with each other) and their surrounding environment”.


I do not think that the Bill, as it stands, does that job, and the last two groups have absolutely illustrated that.

The second thing that I would like to say to the Minister, and I absolutely recognise all the things that she mentioned, is that I did find myself counting, and it was 11. We do not have a strategy. It is 11, but it does not cover the scope of what we are discussing; it does not even cover the scope of security.

The third thing, which I am slightly loath to say but will now say, because otherwise we will get nowhere, is that I have been in the room with Ministers when they have indicated directly that they cannot do something because of America’s desire—absolutely categorically, yeah? That is the bit that we did not get from the Minister. Sovereignty is about being able to impose and choose our laws, and to decide what we can and cannot do and what we are willing to risk and give up for it.

I am not saying that it is easy, but I think everybody in the Committee has been completely reasonable in saying that we are not trying to replace the stack; we are trying to talk about chokeholds and we are trying to be strategic. What we are really trying to do is make the country safe and secure and, dare I say, make it respond to its own laws. I do not think that anything that the Minister said has dealt with that fact. It was not asking for much to actually have a think about what strategy is and have a look at how we might get to a better place. Let us have a vision of where we want to go and work out how to get there. Individual things and departments and leaving things out is not the answer.

This is an easy amendment for the Government to say yes to and I hope that, by Report, they will. I beg leave to withdraw the amendment.

Amendment 83 withdrawn.