Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateBaroness Kidron
Main Page: Baroness Kidron (Crossbench - Life peer)Department Debates - View all Baroness Kidron's debates with the Department for Digital, Culture, Media & Sport
(1 month, 1 week ago)
Grand CommitteeMy Lords, I am very glad to support all the amendments; I will not read them out again. The noble Baroness, Lady Harding, has already convincingly set out the case. I really hope that the Minister recognises that these amendments are born out of lived experience, which is characteristic of this House and very precious when considering how legislation actually impacts in the world at times of crisis.
The amendment specifically calls for staged incident reporting, to create a drumbeat of information and oversight so that damage can be minimised. Cyber attacks move quickly and are extremely confusing for those involved. Staged incident reporting enables regulators to have a more immediate understanding, so that they can offer support, anticipate spread and learn lessons for strengthening guidance in the future.
I apologise, I stand to speak to a whole other group of amendments that suffer from the same challenge of needing to be repeated four times, which is why I suggested to the clerks that we degroup them, otherwise we would have got into a real muddle.
This group seeks to address the obligation to report incidents to customers, as the Minister referenced in her remarks earlier. Currently, the Bill requires notification only where a customer is,
“likely to be adversely affected”.
The obligation is to explain the nature of the incident and why the customer is affected. My amendments seek to broaden and deepen that duty. Customers must be notified where an incident has caused or has the potential to cause severe operational damage or financial loss, where I hope my drafting has not fallen prey to the issue that my noble friend Lady Neville-Jones, addressed in Amendment 17. If it has done so, we obviously need to address that.
The duty is extended to cover related natural or legal persons who could suffer considerable damage as a result. The regulated entities must also advise customers on what measures to take in response. Probably most importantly in this group of amendments, the entities must keep customers updated until the incident is resolved, whereas at the moment the Bill only requires them to notify customers once and then leave them hanging, waiting to find out what is going on. Together these amendments would ensure that customers are told promptly what to do and are kept informed throughout the incident until it is resolved. They also follow the NIS2 directive in requiring advice on protective measures and go a little further by making it a requirement to communicate to related persons as well.
Sadly, I have personal experience in this, not from my TalkTalk times but much more recently. I suspect anybody who is on a board or who has chaired a business has experienced this. An organisation that I chair is the customer of a managed service provider that recently experienced an incident. It did not tell us. The incident was to do with some of our staff payroll information, so it was sensitive and important. When it did tell us, it then did not keep us informed about what was going on. So I feel that pain.
I know that some noble Lords may have concerns that we do not want to create panic by endless notification. I absolutely agree. Hence my attempt to define this as severe operational damage. I would very much welcome input between now and Report if we can tighten that wording to make sure that this does not represent lots of unnecessary email alerts telling you that a system three stages back in the tech stack might have been affected. But when your customers’ data has been exposed in a cyber attack through a managed service provider, data centre or digital service that you use, it is entirely reasonable that those companies have a requirement to inform and keep you updated during the incident. That is all that these amendments seek to do. I beg to move.
My Lords, for reasons that I do not understand, I do not have my name on these amendments, given all the others from the noble Baroness that I do, but I support them. It is funny, because when I came back from holiday in August, I had no fewer than five emails from companies saying that there had been data breaches in which I was involved, and I had that exact thought—“What now? What do I do? What’s next? How serious?”—and did nothing.
I am sorry, it is me again. In a break with tradition, we have only one amendment in this group. That is because this amendment would insert a proposed new clause, as opposed to lots of small changes to existing clauses. Amendment 72 is in my name and, once again, I thank the noble Baroness, Lady Kidron, for adding her name.
This proposed new clause seeks to ensure that organisations regulated under the Bill must report any near misses, cyber threats or incidents currently under the thresholds as set out in the Bill that could affect their network and information systems. I am, again, mindful that it is important that this is consistent with the extremely well-made points of my noble friend Lady Neville-Jones in Amendment 17. It is welcome to have discussions on whether the wording is right, because the purpose is to get the near miss, rather than a huge deluge of meaningless reporting.
As it stands, the Bill requires regulated entities to report only what has happened, and only if it crosses a threshold based on factors such as scale, duration and the number of people affected. However, my amendments look to close the gaps in the event of, for example, an attack an organisation has stopped before it has caused major damage, but had the attack had been successful, it would have had a substantial effect across the whole industry. Other examples are where there are very credible warnings of an expected attack that does not occur, or where there is an incident that falls just below the thresholds that could still be significant.
The intention of this amendment—unlike in my other two groups, it is quite a probing amendment to see if we can work together to capture the spirit of this—is to close a reporting gap where significant incidents may not be reported simply because of the way we have drawn up the definitions in the Bill.
As in the other two groups that I have led, this follows the EU NIS2 directive, although the NIS2 directive creates a voluntary rather than a mandatory reporting provision for this. My view is that the taboo for going public on cyber attacks is so great that voluntary reporting is not the way to do this. It is better for all organisations to know the black and white of what they can do, what they should do and what they do not have to do. In some sectors, certainly the one I worked in—telecoms—there is a fair amount of voluntary sharing. But even there, there is such a taboo about speaking to your regulator about a problem that this needs to be made this mandatory rather than voluntary. Other than that, this seeks to replicate what is in the EU NIS2 directives. With that—I think noble Lords have probably heard enough of me—I beg to move.
My Lords, I support Amendment 72 and I have signed it. I recognise the probing nature of this, but I also recognise the problem it seeks to address. The knowledge that a cyber threat or cyber attack has failed may be incredibly important intelligence because, on the whole, someone trying to create a cyber threat will not retire after the first time that it did not work out; they will try somewhere else, so the intelligence element of this is so crucial.
Some of the people in cyber security talk about seven stages of cyber attack. The first stage is reconnaissance: you are just having a look round and trying to identify vulnerabilities. The second stage is weaponisation: you are developing the means to target that weakness, which can be as simple as an email. It is not until the third stage that the attack begins. But there are still three or four more stages, each of which can provide a barrier and each of which can be the place at which the attack stops. It is not uncommon for attackers to carry out multiple attempts to find or exploit a vulnerability, or indeed to do a small-scale attack in order to then do something larger down the line. In all these cases, there is something absolutely critical for the regulator and possibly the enforcement community to know.
My Lords, Amendment 74 is in my name and those of the noble Baronesses, Lady Morgan and Lady Ludford. The noble Baroness, Lady Morgan, is very sorry that she cannot be in the Committee this afternoon but she particularly wanted me to thank the Minister for their helpful meeting last week. This amendment and Amendment 167 in the name of the noble Baroness, Lady Ludford, relate to the governance of regulated bodies that will be caught under this Act. The reason for this legislation is to reflect the rapidly changing cyber environment and to strengthen areas of current vulnerabilities of those organisations providing services critical to societal or economic life.
As we have discussed, regulators will be given powers to designate critical suppliers whose disruption could have a significant impact on essential services. As we have discussed in previous groups, many of us think the Bill does not go far enough in setting out who those critical suppliers are. We are going to see similar amendments in other forthcoming Bills that make provision for senior manager liability when new responsibilities are legislated. This is something that we have been through in other Bills: the only way to change the culture of an organisation is to start at the top.
I am sure that boards will grumble when they accept new duties, but they will keep their regulators happy were they to be in sight of the law. What really makes the difference to successful implementation is knowing that if it can be proven—I shall read out proposed new subsection (1)(b)—that
“the failure was committed with a consent or connivance of, or is reasonably attributable to any neglect on the part of, a senior executive or group of senior executives, deliberately or carelessly”,
that individual will be held responsible. I point noble Lords to recent court cases in the area of social media, where disclosure has repeatedly shown that senior executives knew of harm or stood in the way of harm mitigation for years. The idea that this might capture an unwilling or unwitting senior executive is shown clearly not to be the case by what I have just read out.
I understand that the Minister and the noble Baroness, Lady Morgan, also discussed this in the context of financial services and a regime introduced after the 2008 financial crash with the very intention of changing the culture of financial service businesses and focusing senior minds on the damage those businesses can do if they do not meet their responsibilities. A more recent example is the introduction of the consumer duty by the Financial Conduct Authority, which required relevant boards to appoint an individual consumer duty champion, something that the noble Baroness, Lady Morgan, was involved in. I also point to the Building Safety Act that was a response to the Grenfell Tower disaster.
I am hoping that the Government are sympathetic to this amendment, but if they find themselves unable to be sympathetic, I would be interested also to hear the Minister’s thoughts on whether we could require the relevant regulator to introduce a named senior manager regime, which indeed we did in the Online Safety Act.
The final point I make is that the senior manager must be senior. The intention behind the amendment is to change the culture of an organisation to ensure preventive action is taken to avoid penalties. As I said at the outset, culture change starts at the top. The services covered in the Bill are, by definition, considered by Ministers to be critical to national life, which means that the most senior governing body should be discussing them and responsible for them. While day-to-day management may be delegated, overall oversight and responsibility should sit at the top. For that reason, I support—as I know the noble Baroness, Lady Morgan, supports—Amendment 167, tabled by the noble Baroness, Lady Ludford. Her proposed new clause would focus the minds of those at the most senior levels of organisations caught by the Bill, and I really hope that the Government support this ambition. I beg to move.
My Lords, I am pleased to speak to Amendment 167 and grateful for the support from the noble Baroness, Lady Kidron—the support is mutual, as I co-signed her amendment. The two amendments are complementary, because Amendment 74 is about the liability of senior executives while Amendment 167 is about board oversight of an individual executive, responsibility and accountability. I was interested to hear the noble Baroness refer not only to financial and consumer conduct but to building safety as areas where such responsibility exists.
I am simultaneously involved in the Public Office (Accountability) Bill—the Hillsborough law—which will introduce a duty of ethical conduct, candour and transparency on public authorities and public officials. Perhaps what some of these other sectors have in common is that it has been an after-the-event thought that maybe boards and senior executives ought to have some kind of responsibility in this area. If we have had a catastrophe, often with a great deal of harm created—such as Hillsborough—maybe it would be a good idea if the people at the top, who are often extremely highly paid, took some interest in the area, rather than regarding it as some sort of lowly service, rather like cleaning the loos in the HQ building. I know it is now routine to refer to examples such as Jaguar Land Rover and Marks & Spencer, but there have been huge financial effects of cyber attacks. This is not some negligible issue; cyber security ought to be a core responsibility for senior people.
I am sitting close to the noble Baroness, Lady Harding, who today has referred to her own personal experience—we all remember it. I am sure it was painful for her and very public. She has actually been through it, so nobody knows better what it can be like when you have a big cyber data breach or cyber attack. It really is long past due that this ought to be a top responsibility of boards, directors and senior executives. Yet we understand—I think I get this from my noble friend Lord Clement-Jones—that the Government’s own Cyber Security Breaches Survey reveals that board-level ownership of cyber risk in the UK has declined from 38% to 27% over the past three years. It is going precisely in the wrong direction.
I do not think I need to persuade anyone here of how important it is for senior people in an organisation to be aware and carry not only responsibility, awareness and accountability but liability, so that it hits where it hurts if something goes wrong. Personally, it seems pretty much a no-brainer, and I hope the Minister will agree.
Baroness Lloyd of Effra (Lab)
I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.
The noble Lord, Lord Clement-Jones, has done a lot of my work for me. I thank everyone who contributed. I was really struck by the expertise in this Room. We started this afternoon by talking about the importance of lived experience. I say very strongly to the Minister that I have been in the House long enough to see Acts of Parliament pass, be regulated and fail because we did not really understand how they were going to hit when they were in the world.
The comments on this group are really worth listening on, particularly those on Amendment 167. I say both to the noble Viscount, Lord Camrose, and to the Minister that there is such a high bar of connivance in Amendment 74. There is no accident. The words are “deliberately”, “knowingly”, et cetera—I read them out as part of my introduction. I will take up the noble Viscount’s offer to come to speak to him and persuade him, and I ask the Minister to really think about this, because we have heard that culture does not change without an incentive. This is an incentive to say that if you are seen to grossly mislead and undermine the regulation, then you are liable. That is what good law does. I beg leave to withdraw the amendment.
My Lords, Amendment 83, in my name and those of the noble Baroness, Lady Ludford, and the noble Lords, Lord Holmes and Lord Tarassenko, would require the Secretary of State to publish and maintain a digital sovereignty strategy. Before the Recess, many of us participated in a debate on digital sovereignty, and the level of agreement across the Chamber was absolutely overwhelming about the importance of UK national sovereignty and the current threats to it from our current arrangements with the tech sector, particularly US-based behemoths. The same sentiment is articulated by Amendment 166 in the name of noble Baroness, Lady Ludford, and it is a sentiment shared in the other place, where Conservatives, Liberal Democrats and Greens all tabled similar Motions.
During the debate, I identified four areas in which the UK has surrendered its leverage to make its own decisions. We surrendered our political leverage by deferring to the power of US tech; we surrendered our economic leverage by placing UK businesses at a structural disadvantage and entering into expansive and extractive contracts; we surrendered our technological capability as we failed to invest in UK capacity and businesses; and we ensured our strategic vulnerability by depending on foreign companies for key infrastructure. Together, these weaken our economy, our security, our safety and, above all, our autonomy: the ability to choose. I doubt that any single government strategy put us in this position, but it reveals a lack of strategy that we find ourselves here.
Amendment 83 would set out a requirement for the Secretary of State to establish a digital sovereignty strategy. Proposed new subsection (2)(a) would require an assessment of the risks to networks and information systems from
“dependence on hardware, software, or digital products and services that may be subject to foreign influence or interference, extra-territorial legal requirements that may be imposed on non-domiciled suppliers”—
such as cloud providers through the US CLOUD Act—
“vulnerabilities, undue control, or supply-chain dependency on foreign states or entities”,
the use of
“UK datasets without license or permission”
and vulnerabilities to valuable data assets that belong to the British public, including those related to the NHS, BBC, and Met Office. The rest of proposed new subsection (2) sets out further requirements to assess the risk of
“technological developments, market concentration or strategic dependencies”
and give consideration to vital elements of sovereignty, including open source technology and assets, talent procurement, capital markets and international collaboration with mid-sized partners whom we retain leverage with.
Finally, proposed new subsections (3) and (4) call for the development of a dashboard enabling the measurement of digital sovereignty. I am working with computer scientists at the British Computing Society who are developing a prototype for this and I urge the Government to look at this work and consider developing it, for their own procurement purposes and to provide it as a tool for the wider business community.
I set that out in some detail because I rather suspect that, if we had a proper strategy across the nation, we would not have had the conversation that we just had in our debate on the previous grouping. Sovereignty is now firmly on the agenda. This is partly due to the export ban on Anthropic and Claude Fable 5 introduced by President Trump in June, but stories highlighting our sovereign vulnerability across the digital stack predate that event and have continued since.
Dependency is not built overnight. It is the result of a systemic and concerted effort by entrenched big tech companies across many years to make themselves indispensable to the UK state, businesses and society, and of successive UK Governments failing to invest in our businesses, communities and people and choosing always to buy oven-ready tech, irrespective of the economic, societal and individual costs.
Just as dependence is not built overnight, neither can sovereignty be reclaimed overnight; nor is it a zero-sum game in which every part of the stack can or should be replaced. None the less, to restore any independence at all, we require an equally systematic and concerted approach to build where we can, to buy only products and services that adhere to our laws, to recognise our unique skills and assets, and to work co-operatively with other like-minded countries. That begins with a strategy that establishes a clear route for government and is fed into experts, free from lobbying and scrutinised by Parliament—which is the very purpose of the amendment in front of us. I beg to move.
My Lords, I shall speak to my Amendment 166. It offers an alternative route to the same destination, although the amendment in the name of the noble Baroness, Lady Kidron, is probably superior because it is fuller and more comprehensive; I readily concede that. Her amendment would add an important element—a digital sovereignty dashboard prepared by the Office for National Statistics, the Competition and Markets Authority, the National Cyber Security Centre and the AI Security Institute—so that we can measure whether anything is changing. The cross-party agreement on this matter, which the noble Baroness referenced, is important and might help persuade the Minister of the force of the argument.
The Competition and Markets Authority puts Amazon Web Services and Microsoft together at between 70% and 80% of the UK’s public cloud market. That is not only a duopoly but a digital sovereignty issue. In its report Rewiring the State, which was published in June, the Science, Innovation and Technology Committee in the other place found that major departments, including HMRC and the NHS, were locked into multiyear agreements that further entrench those dependencies. The National Audit Office has found no shared strategic approach across government towards the handful of very large suppliers that now dominate these markets and are, to a large extent, American. Research done by the British cloud provider Civo found that 83% of UK IT leaders believe that geopolitics threatens their ability to control their data, while only 35% know precisely where that data resides.
I have a history, as a Member of the European Parliament, of being involved in all the arguments about transatlantic data transfer and what happens to the data when it is in the US; this was all in the wake of the war on terror, Guantanamo and so on. We are back in that territory, I guess. It is not just about the economic side of non-national control; it is also about your vulnerability to decisions—including, sometimes, decisions that you do not like—about what happens to the data.
Baroness Lloyd of Effra (Lab)
Going back to the point made by the noble Lord in an earlier intervention, the Bill is a substantive Bill that substantially increases coverage of the digital infrastructure on which much of our economy relies. That is a very important point. As I mentioned at the start of my remarks just now, the question of whether the Bill is the right place to articulate the breadth of many of the issues that have been raised is, indeed, a good one. I am not sure that it is the right place to articulate all the very good questions that have been asked, because some are much more wide-ranging than the scope of the Bill.
My Lords, I thank all who have spoken for their excellent contributions. I will make three quick points. First, in the course of the afternoon, I opened the Explanatory Notes, which is always a bit of a danger. I just want to put on the record that paragraph 2 states:
“These reforms are intended to better protect the services and other activities that are essential to the day-to-day functioning of society in the UK, and the economy, through safeguarding relevant network and information systems (the systems that allow computers and other devices to communicate with each other) and their surrounding environment”.
I do not think that the Bill, as it stands, does that job, and the last two groups have absolutely illustrated that.
The second thing that I would like to say to the Minister, and I absolutely recognise all the things that she mentioned, is that I did find myself counting, and it was 11. We do not have a strategy. It is 11, but it does not cover the scope of what we are discussing; it does not even cover the scope of security.
The third thing, which I am slightly loath to say but will now say, because otherwise we will get nowhere, is that I have been in the room with Ministers when they have indicated directly that they cannot do something because of America’s desire—absolutely categorically, yeah? That is the bit that we did not get from the Minister. Sovereignty is about being able to impose and choose our laws, and to decide what we can and cannot do and what we are willing to risk and give up for it.
I am not saying that it is easy, but I think everybody in the Committee has been completely reasonable in saying that we are not trying to replace the stack; we are trying to talk about chokeholds and we are trying to be strategic. What we are really trying to do is make the country safe and secure and, dare I say, make it respond to its own laws. I do not think that anything that the Minister said has dealt with that fact. It was not asking for much to actually have a think about what strategy is and have a look at how we might get to a better place. Let us have a vision of where we want to go and work out how to get there. Individual things and departments and leaving things out is not the answer.
This is an easy amendment for the Government to say yes to and I hope that, by Report, they will. I beg leave to withdraw the amendment.