(4Â weeks ago)
Grand CommitteeMy Lords, I intervene in support of the amendment in the name of the noble Baroness, Lady Northover. I do not want the Liberal Democrats to be on their own, so I hear the call from the noble Lord, Lord Clement-Jones. It brings me back to the coalition days, when I and the noble Baroness, Lady Northover, were once Ministers in the same department—so my support is heartfelt.
I support the substance of the amendment. As the noble Baroness, Lady Northover, says, it may not necessarily be the right amendment but the spirit behind it is absolutely one that the Government should recognise. I was a bit concerned when the noble Baroness was outlining the intention behind the amendment whether it could perhaps be seen as a burden on business, particularly when we talk about small businesses and the need to audit their cyber preparedness. However, to recall my contribution at Second Reading, I said at the time that, although we tend to debate cyber in the Chamber and other places as a great threat that we need to address, it is also a fantastic economic opportunity. I should declare that I am an adviser to a company called Digital Futures, which trains software developers. We do not train them in cyber but obviously the need to build up a skilled workforce in cyber is absolutely essential.
The noble Baroness, Lady Northover, referred to the patchwork of qualifications that exist in this area. It seems to me that the Government have a clear opportunity and a clear role to guide us through the maze and to put the National Cyber Security Centre on a statutory footing to give it the ultimate role in deciding the appropriate qualifications in cyber and to begin a sustained campaign to show young people, people returning to the workforce or people who are considering a new career that there is a route through to recognised, well set out cyber qualifications that will contribute to the national economy and our cyber resilience. I therefore wholeheartedly back this amendment.
My Lords, I very much hope that the Government will accept the amendment in the name of the noble Baroness, Lady Northover. It strikes me as a practical and important contribution to the Bill.
In addition to the points that have already been made by noble colleagues, there is one more thought to be added: one of the weaknesses of the present marketplace in which these skills are operating is the cost and affordability of advice and help for SMEs on security issues. It is costly—security does not come cheap. Many of these small businesses that nevertheless provide sophisticated services are up against it when it comes to making an adequate profit to stay in business. Therefore, a source of guidance and help, of the kind that is being suggested by this structure, would make a real contribution to not only the viability of these small firms but the general security of cyber security services.
We should never forget that these SMEs feed into the bigger ones. Often, it is an outlying service being provided to a bigger provider that is the cause of a fault or of an essential service proving insecure. Helping SMEs in this way would not only make them more secure but make the market generally more secure. This is a very important and helpful amendment, which I hope the Government will accept.
My Lords, the campaign to reform the Computer Misuse Act is at least 10 years old, not just five. We—including me—have been working to try to get the provision that is contained in the amendment before us from the noble Lord, Lord Clement-Jones. I endorse every single word that he said; he put the case precisely as it needed to be set out. It is absolutely anomalous that we still have this legislation on the statute book, and we need an update to it.
We need to put our researchers, and those who help to protect us and keep us safe, in a safe position themselves, which they are not at the moment. They are subject to potential criminal prosecution, which is stupid and a great disincentive to doing what needs to be done. I very much hope that the Minister will be persuaded to take this opportunity—not to reject it—to put a clause, even if it needs modification to a form that the Government approve of, in this legislation.
My Lords, I will speak briefly in support of the amendment from the noble Lord, Lord Clement-Jones, which he so comprehensively set out. I did not mention this at Second Reading because I thought it was so self-evidently sensible that this needed to be fixed. I should know better, having been in this place for a decade, than to assume that something will happen just because it is self-evidently sensible.
The last three days in Committee have been rather depressing—my noble friend Lord Vaizey is lucky he was not here last week, although he managed to give an excellent speech that suggested he had at least been following us in Hansard or on TV—because it has been so clear that the most important issues are not being addressed in the Bill. This seems like something simple to fix. There are much bigger issues, such as the complete gaping hole of the absence of AI and the huge complexity of all the different regimes that the noble Lord, Lord Birt, set out. I am of the view that you cannot wait for the perfect, and there is a real risk that we are letting perfect be the enemy of the good. This is a straightforward and sensible proposal that I think the Government previously agreed with, but it was just not the right time. Surely, now is the time for us to do things rather than keep kicking the can down the road.
(1Â month ago)
Grand CommitteeMy Lords, in moving Amendment 17, I will also speak to Amendment 28, which is closely related. Amendment 17 is in part a probing amendment about what constitutes an incident and the circumstances in which reporting is obligatory. It does not affect the amendment that I think the Government will move immediately afterwards.
As drafted, Clause 15 gives the very strong impression that an incident “capable of having” an adverse effect on security must be reported. If this is the case, it constitutes a much wider definition of what should be reported than if it were described as an incident “likely to have” an adverse effect. I think it is a widely held view—it is certainly the case in the industry and a point with which I agree—that “likely to have” would be far too wide a definition and would lead to extensive overreporting and an undue and unnecessary burden on regulators. Looking at the drafting, I asked myself what was the point of the “capable of having” definition in Clause 15.
I shall put forward a hypothesis. It would be very helpful if the Minister could confirm that it is a correct understanding of the existing draft, and that it does not mean that all incidents capable of having an adverse effect on security will need to be reported. Is it right to say that the definition in Clause 15 of what constitutes an “incident” applies across the whole of the regulations, and therefore feeds into security as well as reporting duties? That is to say, firms have a preventive duty to defend against what could be and what could happen, as well as what is likely to happen. That is a preventive duty. Can the Minister confirm that the phrase “capable of having” means that firms should have adequate preventive policies, but it is not—this is where the point comes in—the trigger for an incident to be reported, because in each case this requires it to have affected or be affecting the system?
I am making a distinction between “capable of having”, which applies to a duty to pursue preventive policies, and the trigger of the duty to report, which lies not in the phrase “capable of having” but in “likely to have”. Then there are examples of what I am saying in the regulations, and I can cite them: Regulation 11(3)(a), on page 21 at line 35; Regulation 12A(2)(a), on page 26; and Regulation 14E(2)(a), on page 29 at line 27. If the Minister can confirm that, within existing structures, what I have said is correct—there are no circumstances in which “capable of having” would be the reporting trigger—that would be a very helpful clarification. I will listen closely to the Minister’s reply on this point.
There is a “however”: there is a snag when it comes to the introduction of data centres, and that is the object of my Amendment 28. Data centres sit outside the existing structures that I have just talked about but, as yet in the drafting, there are no reporting trigger regulations for them. It is intended that the data centres should be, in future, big players in the system, so it matters that there is a gap in our information about the circumstances in which they would have a duty to report. It is an odd anomaly. New Regulation 11A(3)—on page 23, from lines 13 and 14 onwards—makes reportable
“an incident which could have had … a significant”
effect, whether or not it had any impact at all or anything was affected. As there is no list of factors for judging what constitutes a significant attack in the Bill, it makes it quite difficult to interpret.
For the operators of essential digital services and managed service providers, such factors are set out expressly in the new regulations in the Bill. However, they are absent for data centres. Why is this the case? What is the rationale for what appears an anomaly? It means that, when reporting an incident, a data centre has to do so when any of the following have had, or were likely to have,
“a significant impact on the operation or security of the network and information systems relied on to provide the data centre service … a significant impact on the continuity of the data centre service … or … any other impact, in the United Kingdom or any part of it, which is significant”.
These are very wide definitions of liability to report, and the discrepancy between them and those applying to other operators seems neither sensible from a security point of view nor fair for different business circumstances, as there will be all sorts of different businesses using data centres.
Although I hope that this will not be the case, I fear that the Government may say that the thresholds and factors for all categories of business will be set out in secondary legislation and subject to consultation. I ask the Minister to think hard about the adequacy of that reply. We are talking here about a penalty-backed duty, which is the core element of the Bill; it is not some minor point. It would seem a poor legislative approach in a foundational Bill for a new regime to fail to define the factors leading to a penalty for a significant segment of providers, when there are indicators in the Bill for other categories of provider. Those other players have different, less demanding and more sensible terms for a trigger for reporting. If data centre regulations need to be different from those for the other players that I have mentioned and the rest of the market, can the Minister explain why? It is the kind of complexity that will give the sectoral approach to regulation a controversial reputation, because it immediately raises the issue of making different rules for people who are apparently, in practice, in the same category. I hope that is not the case and that the issue can be resolved by remedying the drafting.
To sum up, in addition to my request for a clear statement from the Minister about the trigger for a duty to report in existing structures being related to the likelihood of an adverse effect on security and not on capability, I hope she will also take seriously the need to level the playing field for data centres on this issue and remedy what seems an important defect in the drafting of the Bill. I beg to move.
My Lords, I will speak to this core group of amendments on incident reporting, in particular to Amendment 165, standing in my name, while addressing the other amendments in this group. First, Amendment 17, which was very cogently set out by the noble Baroness, Lady Neville-Jones, addresses what has emerged as one of the most contentious technical faultlines, in our view, across Part 2 of this Bill: the statutory threshold that triggers mandatory incident reporting to the designated competent authority, the NCSC. As the Bill is drafted, Clause 15 fundamentally widens the reporting net by redefining a reportable incident to include any event that is merely “capable of having” an adverse effect on the security of network and information systems, as the noble Baroness described.
While one can readily understand the cyber security community’s desire for complete visibility, in practice, the phrase “capable of having” is an operational disaster. In the daily reality of enterprise networking, thousands of automated port scans, routine phishing lures and perimeter firewall probes occur every hour. Almost every single one of these low-level events is technically capable of having an adverse effect, if multiple defensive layers were to fail simultaneously. By forcing businesses to notify regulators under threat of £17 million penalties whenever an event is merely “capable” of causing harm, the Government will unleash an administrative tsunami of defensive reporting.
Rather than enhancing national security, this compliance overload will drown NCSC analysts in background noise, making it far harder to detect sophisticated state-sponsored attacks. Amendment 17, in our view, would resolve this by replacing “capable of having” with the objective standard of “likely to have”. This would restore the established probability threshold used across UK regulatory frameworks, ensuring that mandatory notifications are reserved strictly for genuine material threats where there is a real likelihood of operational compromise.
This issue is compounded by the Government’s own drafting amendments, specifically Amendments 19, 36 and 44, which replicate the ultra-broad definition of compromise throughout parts 2 and 3. By removing “users” from Clause 15 and redefining data compromise to cover any event affecting data stored or processed on a system, the Government are dramatically expanding the notification net to include technical data anomalies that cause zero destruction or loss to actual customers. Combining this sweeping definition of data compromise with the low “capable of having” trigger will hugely affect responsible operators. It will force critical suppliers and small digital providers to spend their limited resources filling in compliance paperwork, rather than actively defending their infrastructure.
We risk creating a reporting system that captures everything and understands nothing. We must have objective reporting thresholds. By accepting the noble Baroness’s Amendment 17, restoring the “likely to have” test, we would ensure that mandatory reporting delivers high-quality actionable threat intelligence, rather than an unmanageable flood of routine notifications.
Under the new reporting regime, hundreds of incidents will be notified to regulators and the NCSC, but at present the Bill lacks any mechanism to ensure that aggregate intelligence is shared with Parliament or industry. Under Amendment 165 in my name, I propose that the Government lay an annual anonymised report before Parliament, detailing incident volumes, sector breakdowns and principal attack vectors. This would provide software developers and CNI operators with the situational awareness needed to harden defences.
My Lords, I have listened carefully to what the Minister has said. I had hoped that we would get greater clarity; I fear that the fog has increased. I entirely accept the point that companies have a general duty to take as many preventive measures as they can to increase security. That is a different matter, it seems, from what should trigger the reporting duty. Precisely what the Minister has laid out leads to a situation of an overload of reporting of items that do not require that kind of treatment.
I am extremely concerned that the industry fears—and it has a real point—that it will be caused to be active in areas which lead the regulators to be swamped and which reduces the real level of security, because it is doing things that it does not really need to. For those of us who are willing to contemplate a system of regulation that allows for differentiation between sectors—in other words, a sectoral approach—it is the kind of thing that will lead to a terrible muddle. I am unhappy about the response that has been given to that general point. It strengthens the cause of those who say that we should have one general regulator and that it should set the rules.
Secondly, on the question of data centres, I cannot understand that a data centre could alter the rules under which companies, if they happen to be located in a data centre, are operating and doing their business. I fear that this is an issue to which we will have to return on Report, because as things stand we are not heading in the right direction. I beg leave to withdraw the amendment.
My Lords, I strongly support the drift of both amendments spoken to by the noble Baronesses, Lady Kidron and Lady Ludford. As I said the other day, I have sat on many boards with many distinguished people that contained a variety of experience in many jurisdictions, but I have not often come across a board that contains anyone with a pronounced understanding of technology, let alone the extremely narrow but deep area of complexity that is cyber security.
I hope noble Lords will forgive me for reminding the Committee of what I said on Tuesday: the way to achieve this objective is to require boards, at an appropriate level—I do not mean every board in the land—to have a cyber resilience audit each year, in the way that all major organisations have a very searching financial audit each year for the whole board, even though it may contain people who are there for different reasons: they may have marketing or sector expertise. But believe me, for every single board, when the team of auditors—who have been in the business for weeks and sometimes months—reports, it is listened to, and anything it advises is acted upon. We need to do exactly the same for cyber resilience.
My Lord, this Bill is largely directed at a given segment of the corporate sector. That reminds us, however, that there is a very large swathe of the corporate sector that we are not focusing on directly.
However, in the corporate sector generally, the board has to be interested in all risks, not just financial risks, or whether the book market or the wine market is in good shape; it must be able to protect the business and its shareholders. The board has a duty to the shareholders to do that. This is a very good opportunity to try to raise the level of performance in this area. The record is demonstrably not very good. This is an opportunity to help raise the level of performance and make it clear that if you take on a responsibility as a board director, you will have to be able to help conduct the business of that organisation at the highest possible level. I very strongly support Amendment 167.
Baroness Lloyd of Effra (Lab)
The general approach is that the lead government department has responsibility for ensuring cyber security in the areas that it covers. I will need to write to my noble friend specifically on exam boards and examining authorities. I know that the DfE supports bodies that support higher education and further education, but for further details, I will come back to her.
More broadly, I am happy to talk further with noble Lords between now and Report, and perhaps after, on the approach to assessing what should be within the regulatory perimeter and at what speed that can be advanced.
Can I ask a couple of questions and make one comment? The more we hear about the conversation that is taking place on the Bill, the more anomalous the factors that have been chosen or included in the scheme become. Let me give the example of space. Plenty of us now receive our internet connection via satellite. It is inevitably an intimate part of the networking system of cyber security. What we appear to be told is that some parts of the telecoms and internet world are going to be governed by the Bill, but other parts, which are equally integrated and important, are going to be covered separately by a special different arrangement—they are not included. For example, as I understand what the Minister said about space, it is not going to be included in this Bill. With the greatest possible respect to the Minister, it does not make sense.
My question is: in the period ahead of us, could the Government have another look at the whole question of the scope of the Bill? This seems to be one of the problems that lies between us. As a result, Members are now trying to shove into the Bill all sorts of things on the grounds that they are essential services—some of which clearly need to be there, but for others it is arguable that they do not.
I heard what the Minister said about the action plan. I have read the action plan, and it is a good plan, but it lays a heavy responsibility on a department that no longer exists—DSIT. The function is set out so well and is important to keeping government departments up to the mark, which is going to be done separately. Where is that responsibility now going to sit? It will require a very considerable degree of expertise on the part of those conducting this system of keeping people up to the mark. How is that going to be done?
It seems to me that local government requires something of the same. Government is a whole thing. It is not that some things can be done in central government without regard to their implementation by local government or vice versa. Are the Government going to extend the system that is being mapped out in the action plan for government to local government as well, in order to get the same standard of performance and integrity of systems?
Baroness Lloyd of Effra (Lab)
Let me work backwards here. The noble Baroness makes a very good point: the services delivered at local level often mirror those at central government level. At the moment, we are consulting on the question of the best value duty to give additional prominence. One of the issues with mapping these requirements into local government is that many different services are indeed provided. We may need to come back to that in more detail.
The government cyber unit now resides within DCMS. The team has transferred over and is up and running; I have spoken to them many times recently. The unit is very active in progressing the government cyber action plan as per the timetable and the target plan.
On the question about the approach to looking at other sectors to bring in, that is why I mentioned at Second Reading that I had already asked my officials to work across government to consider what additional services would merit being brought in. I mentioned earlier today that focusing on CNI services not already covered by the NIS regime would be the right place to start.
(1Â month ago)
Grand CommitteeMy Lords, it is a pleasure to speak to this group of amendments; I was certainly delighted to sign those in the name of the noble Lord, Lord Birt. Before turning to the specific subject matter, I say that the point he raised about JLR is germane to our broader discussions this afternoon and goes to the heart of the sense of coherence, or lack thereof, in certain key elements of the Bill.
JLR suffered a serious cyber attack yet it currently would not fall within one of the sectors covered by the Bill. Was that attack significant at a level that should be of concern to the Bill? To look at its economic impact—the definition of which my noble friend Lord Camrose has identified as being somewhat broad, to paraphrase what he said—the JLR attack impacted that quarter’s GDP numbers, thus raising the eyebrows of the markets, the ratings agencies and all international economic observers. I would suggest that the impact was more than material and certainly significant, yet it would fall outside the sectors in the Bill as currently drafted.
That goes to the point at the heart of the need for an OCR or an entity that would perform that function or role. Much of the discussion so far on this group is understandably echoic of the discussion we are having around the need for AI to be taken on by some regulator. As we are discussing the need for AI regulation and legislation, it seems only fair for me to give a nod to the AI authority in my AI regulation Private Member’s Bill—it comes with music every time I announce it, this time from a phone going off; that is multimedia.
The reality is, if the choice of the Government, be it for AI or for cyber, is not to have a single centralised regulator, then the consequences are clear and profound. In no sense is there any chance of clarity, consistency and coherence for businesses and sectors right across our economy and society. When you come to cyber, you should not have to consider whether it is or is not in a sector within the Bill. Is that specific regulator in that sector tooled up or do they have any experience, knowledge or ability to lead when it comes to all the challenges of cyber?
Let us take one obvious example, just for the case of efficiency, effectiveness and economic good management. Say that there is a search out, a recruitment, for a particular cyber professional and it turns out that Ofgem and the FCA are both in the final throes of getting that person. The FCA ends up getting that cyber professional; that is good for the FCA and good for financial services, but less good for Ofgem. How is that in any sense good for the broader economy and society, the UK as a whole, when it comes to protection from and an effective coherent approach to the cyber risks and how we guard against them?
The case for a unifying regulator when it comes to cyber is equal to that for AI. It would enable clarity, consistency and coherence of approach and would be that centre of expertise. There would be horizontal impact across all sectors and it would be delivered effectively and efficiently. That cannot simply be the case just for individual regulators; no matter how well intended or up for it they may be, they simply could not deliver that. Even if one sector did, another sector would not, which would mean that, just by dint of where your business or you as an individual happen to come across a cyber challenge, it would be the luck of the draw as to whichever regulator or professionals were in that field. The case for an individual, central, clear and coherent cyber regulator is clear. I hope that the Minister agrees and I look forward to her response.
My Lords, the last two interventions seemed to raise two issues, not one. The first is the question of how many regulators and the second is their coverage. Who will they regulate? Will they regulate just, say, the public sector, or will they regulate, in effect, the whole of the economy, including retail, business, high street businesses and so on? You can argue a case for any of these approaches: you can try to do too much, and certainly you can fail and do too little.
While I can see the case for a single regulator, my worry is that large organisations like that, with monopoly powers, in the end either tend to fail, because they just do not cope, or become overweening. I do not think that we want either of those two things. I am therefore in favour of something that is more decentralised than that and has more specialised regulators involved, partly because I think the nature of the regulation probably deserves that. However, at the same time, there has to be some degree of co-ordination—in fact, a high degree of co-ordination—between the regulators. They must operate according to the same principles, applied appropriately. They must espouse the same philosophy and must be seen to be fair. Therefore, great divergence and different approaches will equally not work. There needs to be a mechanism for co-ordination, for discussion and for agreement of principles. There also needs to be a thinker there somewhere. I am therefore in favour of some bit of the system being bigger than the rest, so that it inspires a degree of good and recognised co-ordination in the system.
In this recovery regime, will whatever organisations that are to be regulated be levied for the service of regulation that will be provided, or will the revenue come as a result of fines? If that is the case, I hope they will not raise the revenue by finding fault. What is the basis of the cost recovery? It needs to be perceived to be fair, not onerous and not directed at encouraging regulators to regulate for the sake of increasing their income.
Baroness Lloyd of Effra (Lab)
The intent behind the cost recovery model is to provide a fair approach so that regulators, when regulating on cyber, can recover the costs associated with that. Further guidance will be put out on this. I cannot recall the Bill’s exact provisions on fines. I will come back to the noble Baroness on that.