Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateBaroness Lloyd of Effra
Main Page: Baroness Lloyd of Effra (Labour - Life peer)Department Debates - View all Baroness Lloyd of Effra's debates with the Department for Science, Innovation & Technology
(2 weeks, 3 days ago)
Lords Chamber
Baroness Lloyd of Effra
That the Bill be now read a second time.
Northern Ireland, Scottish and Welsh legislative consent sought. Relevant document: 3rd Report from the Constitution Committee
The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
My Lords, we are a proudly online nation, embracing interconnectivity in all walks of life. Cloud-based working, the rise of software as a service, the advent of artificial intelligence and more have rocketed the UK forward. They have enabled us to work faster, more efficiently and with more flexibility than ever before.
However, with these advancements come risks. As the technology powering our modern economy has leapt forward, so too have the tools that our adversaries use to extort, disrupt and surveil. Last year, more than 600,000 UK businesses were subject to cyber attacks. This is not only holding businesses back; it is undermining our security. These are criminals and hostile state actors seeking to disrupt the very foundations of our country.
The UK is now the most targeted country in Europe for cyber attacks. It is the duty of this Government to take bold action. We have been clear that all businesses must protect themselves from cyber attacks, but this does not mean regulating every single business. They know their customers and their suppliers, and they are best placed to protect themselves, using the free tools that we have provided.
I commend those who have already signed our Cyber Resilience Pledge, and urge more to do so, committing to take the three simple steps recommended in it: making cyber a board-level responsibility and following the cyber governance code of practice; signing up to the National Cyber Security Centre’s early warning service; and taking a risk-based approach to requiring Cyber Essentials across supply chains. This is our government certification scheme to help organisations improve their cyber resilience. Cyber Essentials works. Organisations with it are 92% less likely to claim on their cyber insurance than those without it. Taking these steps can make a huge difference.
However, where the risks are so great that public safety, the economy or our national security is threatened, it is right that we regulate. The Network and Information Systems—NIS—Regulations 2018 are the UK’s only cross-sector cyber legislation. They apply to operators of essential services in the energy, health, transport, drinking water and digital infrastructure sectors, as well as some digital service providers. The NIS regulations are designed to protect the security and resilience of our most essential services, to keep lights on, to ensure that taps keep running and to protect our NHS. We regulate only where we must, which is why the scope of the NIS regulations is precise. They are a targeted security intervention and the best tool in our arsenal to protect our most essential services. However, the regulations have fallen out of date. If we do not act, the essential services on which we all depend will remain under threat.
That is why we have introduced the Bill. The Cyber Security and Resilience (Network and Information Systems) Bill is a vital opportunity to improve the UK’s defences. In fact, it is the first Bill in British history to have “cyber” in its title. It will update the NIS regulations for the modern age and ensure that the Government can maintain their effectiveness and respond to imminent national security threats.
The objectives behind the Bill are threefold. First, it will safeguard the services on which our people rely most, making our essential and digital services more secure. Secondly, it will deliver a step change in our national security, improving our defences against the cyber attacks that threaten this country. Thirdly, it will better protect our economy. The UK will be a safer and more attractive place for businesses to establish themselves, thrive and grow.
The Bill will achieve these objectives through proportionate and timely measures, which I will speak to in turn. First, the Bill brings more sectors into scope of the NIS regulations. As our economy becomes more interconnected, so do the routes that cyber criminals exploit. For example, data centres in the UK have become critical to nearly all our economic activity and public services. From NHS patient records to financial systems, these vast digital depots are a key part of the modern world. That is why data centres meeting the Bill’s thresholds will be regulated as essential services, ensuring that they take steps to secure their networks.
The Bill also brings large load controllers under regulation. These are organisations that manage significant electricity flows to or from smart appliances. They must be safeguarded to secure our electrical grid and protect consumers using such appliances.
We are also bringing large and medium managed service providers—MSPs—into scope of the NIS regulations. These are organisations offering ongoing services, such as remote IT support or cyber security threat management, to customers. MSPs have deep access into their customers’ systems. As more and more organisations rely on them, MSPs become an increasingly attractive entry point for disruption.
Noble Lords will remember last April’s cyber attack on M&S. It involved a managed service provider being socially engineered, with attackers being able to gain access and compromise systems. We need to close this gap. But these regulations must be proportionate and targeted. Large and medium MSPs comprise fewer than one in 10 of the MSPs active in the UK but account for around 97.6% of the UK’s MSP revenue, so small and micro MSPs will be exempt from this measure. By targeting regulation where the risk and reach are greatest, we will protect almost all MSP customers without burdening small businesses.
In limited circumstances, small and micro-businesses supply critical goods or services to the essential and digital services on which we rely. The Bill therefore enables businesses, including smaller companies, supplying critical goods or services to be designated as “critical suppliers”. This is designed to combat the cyber risks stemming from increasingly complex supply chains.
Members may be aware of the 2024 attack on Synnovis, a pathology provider to some NHS trusts. Criminals thousands of miles away deployed ransomware and made Synnovis’s files unusable, delaying 11,000 appointments. This demonstrates the ripple effect that a compromised supply chain can have on the services at the ends. Duties that critical suppliers will be subject to will be set out in secondary legislation.
I turn to our 12 NIS regulators, whose sectoral expertise is critical to protecting our essential and digital services. These regulators are often operating with one hand tied behind their backs. They do not have the information, resources or levers necessary to properly fulfil their duties. For instance, organisations need only tell their regulator about an incident once it has already caused significant disruption. Under the Bill, they will have to report more types of breaches, to their regulator and the NCSC, within 24 hours and provide a full report within 72 hours. This includes incidents such as pre-positioning and ransomware, where an incident may not cause immediate damage but poses a real threat to the UK economy or society.
This will not only enable the NCSC to support those affected more quickly and warn others but allow the Government to better understand the threat landscape. Furthermore, the Bill requires digital and managed service providers and data centres to inform their customers about reportable incidents that are likely to adversely affect them. This way, customers can take appropriate steps to protect themselves.
However, effective reporting must be matched by consistency. Our 12 regulators cover all NIS sectors and the UK’s four nations. We must utilise their sectoral expertise but ensure that the rules are applied consistently. We cannot allow any sector to become an easy target. This Bill enables government to designate a single set of strategic priorities, as well as objectives tied to them, that regulators must seek to achieve. This will complement the security and resilience requirements, to come in secondary legislation, setting clear, consistent expectations and putting good practice on a firmer footing.
The Secretary of State will be required to consult the regulators on a draft of the statement before designating it. In addition, the Bill gives regulators new powers to recover their full regulatory costs from the organisations that they oversee. This includes enforcement costs, ensuring that this is not conducted to the detriment of a regulator’s books. Regulators must consult on how these fees will be calculated and publish a yearly statement to show how these funds were used.
The Bill also raises the maximum penalty enforceable for regulatory breaches while simplifying the penalty bands for easier, more consistent application. Regulators must consider all circumstances of a case before setting a penalty. This is not designed to punish companies but to incentivise their compliance. The ideal scenario is no penalties at all.
We are also fixing legacy issues concerning information sharing, so regulators can better understand what can and cannot be shared and with whom. All information shared must meet a specified purpose or require permission to be shared and be relevant and proportionate to the purpose for which it is shared. This Bill unties our regulators’ hands, giving them the information, resources and powers that they need to hold the line. That is what effective regulation should look like.
Finally, the Bill contains some important measures to enable future resilience, ensuring that the NIS regulations remain effective into the future. This Bill introduces a targeted, essential set of delegated powers to enable the NIS regulations to keep pace with the ever-changing cyber landscape. These include powers by which the Government can bring new services or sectors into scope of the regulations, so long as they meet the Bill’s strict criteria, or make regulations to further mitigate the risks from security and operational compromises. In the majority of cases, these delegated powers will be subject to consultation and the affirmative procedure will apply. Today’s threats were unimaginable in 2018, so we must not legislate as though today’s threats will stand still. These are carefully targeted, and it would be remiss not to take this opportunity to provide for careful, proportionate delegated powers. In almost all cases of these powers, the Government must consult on any changes. Parliament will still have the final say over legislation made under these powers. Our delegated powers memorandum contains greater detail.
In exceptional cases, even secondary legislation is too slow. Right now, if our intelligence community becomes aware of a NIS incident that threatens our national security, the Government have no emergency power within the NIS regulations to protect our people. This Bill provides powers for the Secretary of State to direct regulators and regulated entities where national security is threatened. This could entail instructing a sector to follow new guidance in response to a crisis or requiring an organisation to take technical steps to remove an intruder from a network. These are essential last-resort levers. The Bill has strong safeguards to ensure that they are used accordingly and only where strictly necessary for national security.
This Bill is about protecting the foundations of a modern economy. Growth cannot flourish where essential services are vulnerable, where businesses are exposed to disruption and where hostile actors can exploit weaknesses. We are not choosing between security and growth; we are recognising that one depends on the other. This will help secure the services that our people rely on, give businesses the confidence to invest and grow and strengthen our national security in an increasingly dangerous world. I beg to move.
Baroness Lloyd of Effra (Lab)
I thank noble Lords for their insightful and wide-ranging content, and I am pleased to hear the broad support for the Bill. I also thank the Minister in the other place and the parliamentarians who engaged with your Lordships and others ahead of the Bill’s introduction. The dialogue has been shaped by pragmatism and a genuine interest in protecting our people and businesses. Should I not be able to respond in the allocated time to all the very many specific points that were raised today, I will make sure that I review Hansard carefully and reply to noble Lords accordingly, placing copies in the Library.
The noble Viscount, Lord Camrose, raised an excellent point about the scope of the Bill and the many other government actions and activities to equip our businesses to tackle cyber threats. I agree that the national cyber action plan is the right place to set out exactly how this is all put together, but today I cannot provide noble Lords a date for the publication of the national cyber action plan.
As other noble Lords did, I started writing down the names of all the noble Lords who raised the question of scope—and I too decided that it was probably better to say “everybody”. This is a very pertinent question. Cyber security and resilience are a shared responsibility. The Government and the NCSC provide a range of tools for all parts of the economy, and it is for all organisations to make use of those to enhance their protections. We have invited all businesses, charities and other organisations to sign the Cyber Resilience Pledge and take the three tangible actions that can help boost their resilience to cyber attacks. For many organisations, this will be a significant step in their defences, and regulation will not be necessary nor proportionate.
Under the Bill, we have chosen to regulate where disruption to services—hospitals, drinking water, and cloud service providers—would mean that people and businesses are left with little or no easy alternatives. The significant steps we are taking in the Bill are reflective of the digital nature of our economy today and the risks we encounter. I recognise and share the sentiment of exploring other parts of the economy that would benefit from being under these regulations in the future, and I assure the House that I have asked my officials to work with other government departments to consider what additional services could be brought into scope in future. At the same time, this work needs to be undertaken with thorough consideration for a range of factors, such as the threats posed to such services by hostile actors and the potential impact they could have on the wider economy, as well as the overall value of the sector. We need to take into account the important points that noble Lords have made about proportionate regulation. I confirm to the noble Baroness, Lady Neville-Jones, that, were we to extend these regulations to further sectors, that would follow consultation.
The noble Baronesses, Lady Northover, Lady Neville-Jones and Lady Ludford, and the noble Lords, Lord Londesborough and Lord Clement-Jones, raised an important point about the government cyber action plan. It is crucial that our Government and public sector are covered. The government cyber action plan, which was published in January, will transform cyber security and resilience across government and the entire public sector by 2030. It will enable us to achieve the same outcomes that we want to achieve for services regulated under the Bill: clear and robust requirements, better incident reporting, and stronger accountability and transparency. The plan sets out accountability structures to ensure that cyber risks at all levels of government are actively owned and effectively managed. I assure your Lordships that we will continue to work with Parliament to ensure proper oversight of the plan’s implementation.
The extension to local government is also covered under the overarching strategy of the Government’s cyber action plan. I say to my noble friend Lady Alexander of Cleveden that MHCLG is taking action to strengthen local authorities’ cyber resilience, backed by £20 million of cyber grant funding and technical support, because it is incredibly important that local authorities are prepared and enhance their cyber action.
On the question about the food and retail sector, raised by the noble Lords, Lord Holmes of Richmond and Lord Taylor of Warwick, and the noble Baronesses, Lady Northover, Lady Ludford and Lady Harding of Winscombe, probably among others, it is very important that the sector enhances its cyber resilience. The food sector is unusual among critical sectors because of its high levels of diversity. There are approximately 20,000 small and medium-sized food manufacturers in the UK alone, and many more farms, distribution services, retailers and other types of businesses that form the UK’s food supply chain. Given the lack of a single point of failure, we think there are more proportionate levers to pull than bringing food into the scope of the NIS regime.
The question of AI was raised by the noble Earl, Lord Effingham, the noble Viscount, Lord Colville of Culross, the noble Baroness, Lady Kidron, and my noble friend Lady Berger. The Government are committed to protecting our national security against the risks posed by advanced AI models, and our AI Security Institute is world leading and one of a small group of organisations with access to Anthropic’s Claude Mythos model before its release. As for addressing the risks of cyber attacks facilitated by AI, it is true that AI capabilities are moving very fast, but strong cyber fundamentals still work. Our advice, and that of the NCSC, is to ensure that organisations get the basics right and that they are managing risks at board level. There is extensive guidance on this from the Government and from the NCSC.
As for whether AI is in scope, the Bill does not specifically bring large language models or AI companies into scope, but where organisations in scope use AI models and systems, those organisations will need to take appropriate and proportionate steps to manage the risks to these from hackers. For example, if an LLM is used as part of the day-to-day software available to staff in a hospital, and is therefore part of the network and information systems, it would be considered in scope.
On the example given by the noble Baroness, Lady Kidron, of how this would happen, the Bill grants the Secretary of State the power to direct entities if the compromise of the relevant NIS or the threat of one gives rise to a national security risk. This could, for example, require an entity to cease using and to isolate an AI model. These powers are a backstop to an effective cyber security regime, enabling the Government to act swiftly in the face of unexpected national security threats, but they are also designed to be proportionate, recognising the need for stability among regulated entities and the importance of proper accountability.
Many noble Lords reflected on the need for effective implementation and the importance of consultation and secondary legislation. There will indeed be secondary legislation and guidance and a business adjustment period for the Bill. To answer the question posed by the noble Baroness, Lady Neville-Jones, this will probably be for the period up to 2028, when we expect the duties to come into force.
On the questions about incident reporting raised by the noble Earl, Lord Effingham, the noble Lord, Lord Ravensdale, and the noble Baronesses, Lady Northover and Lady Harding of Winscombe, we have heard the clear ask from businesses to minimise the time they spend filling in different reporting templates following an attack. We understand the pressure that institutions can be under in the midst of an attack, and we want to make sure that they can prioritise the technical response. We are exploring all options and will look closely at other regimes in the UK and the new template used by EU member states for the NIS2 reporting, reflecting questions posed by noble Lords about where we are looking at the EU regime.
We do not believe that there is a risk of overreporting, but we will provide further clarity by setting out thresholds in secondary legislation following consultation. That will set out when an incident is considered to have had, or to be likely to have had, a significant impact—a question posed by the noble Lords, Lord Holmes of Richmond and Lord Ravensdale.
On the questions raised by the noble Baroness, Lady Bennett of Manor Castle, the ability to share information with like-minded countries is important if we are to make cyber security a global effort. But the Bill does not mandate information sharing across borders, and there are important safeguards around the sharing of information for the purpose of prosecuting a crime. I followed the debate on this topic in the other place, and I would be happy to meet with those interested in this topic to discuss it further.
Noble Lords raised the question of the balance between a single consistent approach and being attuned to sector-specific issues. One of the ways in which we are going to pursue consistency and provide clarity on what is expected is through the new security and resilience requirements for regulated entities, which will be set out in secondary legislation. These will set out the clear and consistent steps that regulated entities will need to take to mitigate their security risks. On the questions posed by the noble Lords, Lord Arbuthnot, Lord Birt and Lord Ravensdale, these will be high-level, outcomes-based requirements that will be consistent with the NCSC’s cyber assessment framework, including requirements on board responsibility and governance, supply chain and incident reporting and recovery, as well as requirements around testing and exercising protective security. These proposals will be technology- and sector-agnostic, and take an all-hazards approach to ensure resilience in the face of an evolving threat landscape and emerging technologies. They reflect the requirement for regulated entities to have regard to state-of-the-art technology when assessing the risks they face.
On the question posed by the noble Lord, Lord Ravensdale, and others on post-quantum cryptography, and that posed by the noble Lord, Lord Birt, on quantum, these would be considered as part of that requirement by regulated entities, but would not necessarily be singled out as a specific technology in the regulation so that we keep these regulations up to date and matched to the cyber risks that individual entities face.
In addition to how the requirements in the Bill will capture board responsibilities, we recognise that board-level governance is essential to effective cyber risk management, which is why the Cyber Resilience Pledge sets out that making cyber a board responsibility is one of the three clear tangible actions that any organisation can make to boost its resilience. The Government’s forthcoming modernising corporate reporting consultation will seek views on whether the existing risk reporting framework produces sufficient reporting on cyber risk management as an additional step that could be considered.
On the questions about the Secretary of State reporting to Parliament at least every five years, this is a minimum baseline. Additional reports can be published if deemed appropriate.
The noble Earl, Lord Effingham, and the noble Lords, Lord Londesborough and Lord Ravensdale, asked about business burden and the definition of small businesses. We believe that this legislation is targeted and proportionate, only regulating where necessary to protect the most essential services on which we rely. That is why small and micro digital service providers are exempt from the regulations, unless designated as a critical supplier. Small businesses are defined as entities that employ up to 50 people and have an annual turnover or balance sheet of less than €10 million. They are exempt from being an RDSP or an RMSP under the Bill. They can be regulated only if they are designated as critical suppliers, for which there will be a high bar for designation.
My noble friend asked how we can support small businesses. This is a very important part of our approach. The NCSC provides support through the Cyber Action Toolkit and Cyber Essentials, which also includes cyber insurance for those who get the certification. For any organisation that experiences an incident, the Government’s Cyber Incident Signposting Service helps point them towards where the issue should be reported and where appropriate support can be sought.
Questions on regulator capacity and consistency were raised by the noble Lord, Lord Vaizey, and my noble friend Lady Alexander. The framework will drive consistency across sectors through these common security requirements and through the statement of strategic priorities, which will set the objectives that regulators must seek to achieve. Sector-specific guidance from regulators will also remain key to address sectoral nuances and risks, building on a common foundation of good practice.
Many noble Lords raised the importance of building out sovereign capability in the UK, and I note that the Government are committed to pursuing that. I am sure that we will have other opportunities to talk further about tech sovereignty in the coming week in Oral Questions and the forthcoming debate on that subject.
My noble friend Lady Paul of Shepherd’s Bush and the noble Lords, Lord Ashcombe and Lord Arbuthnot, discussed cyber insurance. It can absolutely play an important role as part of a wider approach to cyber resilience, particularly in helping organisations to manage the impacts of cyber resilience and to support recovery. We do not believe that cyber insurance is a replacement for cyber security, but it is definitely part of a wider suite of cyber measures.
Many noble Lords made points about skills, which are incredibly important. We are improving industry understanding of cyber security, we are investing in cyber skills through TechFirst, and we are working with the UK Cyber Security Council to develop professional standards to bring cyber security in line with professions such as engineering and accounting. I also heartily endorse the points made by the noble Lords, Lord Ravensdale and Lord Vaizey, about the strength of the cyber security industry and sector in this country. It is not only strong within this country; it is also exporting to many other parts of the world, building on our strengths.
I note that product security, which was mentioned by many today in the sense of building in requirements, is indeed a feature of our product security and telecoms infrastructure—or PSTI—regime, which is an important complement to what is in the Bill.
Finally, the noble Lord, Lord Clement-Jones, led the charge on the Computer Misuse Act. We highlighted in the King’s Speech that a Bill focused on national security will update that Act and provide law enforcement with the updated powers and capabilities, so they can remain effective in the digital age.
I, too, look forward to Committee. This is an incredibly important Bill. I welcome the high level of engagement from across the House tonight on the practicalities and the details.
This Bill is fundamentally about national security. It will deliver stronger protections against those who want to disrupt our way of life. It will do so with growth at the forefront, focusing first on support and partnership and regulating only where it is necessary. I thank noble Lords and look forward to the Bill’s next stages.
Baroness Lloyd of Effra
That the bill be committed to a Grand Committee, and that it be an instruction to the Grand Committee that they consider the bill in the following order:
Clauses 1 to 22, Schedule 1, Clause 23, Schedule 2, Clauses 24 to 61, Title.