Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateBaroness Northover
Main Page: Baroness Northover (Liberal Democrat - Life peer)Department Debates - View all Baroness Northover's debates with the Department for Science, Innovation & Technology
(2Â months, 2Â weeks ago)
Lords ChamberMy Lords, I too thank the noble Baroness for introducing the Bill. From these Benches we welcome the Bill, but we feel that in a number of ways it does not go far enough. Hostile state actors, organised crime and others are increasingly targeting our systems at every level with potentially catastrophic effects, as previous speakers have said. Attacks on our energy networks, water supplies, transport systems, financial infrastructure and digital services are becoming more frequent. It is clearly vital that organisations that deliver essential services have high standards of cyber security and that they should report serious incidents promptly and transparently. We also recognise that the coverage of those who need to report in this way should be widened. However, is the Bill ambitious enough?
I serve on the House of Lords Select Committee on National Resilienceâthere is at least one other speaker in the debate who also serves on that Select Committeeâand I will draw here from some of the evidence that has been submitted to us. We were, of course, part of the EU arrangements until Brexit, and this is yet another area we needed to address after that. That resulted in the 2018 regulations, which this Bill seeks to update. The post-Brexit arrangements seem to have complicated putting in place clear primary legislation. The Minister in the Commons noted that Brussels is pressing ahead with its own updates âwhile we lag behindâ. He stated that this
âprocedural quirk has left essential UK services more exposed, which perhaps tells us something about why the UK has such appalling figures compared with some of our EU counterparts, as hackers and cyber criminals exploit gaps in our dated lawsâ.â[Official Report, Commons, 6/1/26; col. 179.]
We do indeed have the worst record in Europe for such attacks. I would argue, from submissions we received to our Select Committee, that it makes most sense for us to be aligned with the EU regulations. It has been put to us that this would mean that organisations do not need to answer to two sets of regulations in Europe. It is clear that this would assist us anyway, given that the EU regulations cover a wider range of areas, which it makes little sense to overlook as the Government appear to be doing. As it was put to us by ISC2,
âthe government may have missed an opportunity to have the same taxonomy of CNI across jurisdictions. For example, the EUâs NIS2 directive on cybersecurity includes manufacturing, public administration and food production ⌠These sectors are critical for the UKâs national and economic resilience. Under the proposed regime manufacturers operating across the UK and the EU, when victim of a cybersecurity incident in the UK, will be mandated to reportâ
this to EU authorities but not to the UK.
One of the submissions notes that the Bill is narrow in scope:
âlarge parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Governmentâs approach to ⌠these unregulated sectors relies primarily on voluntary governance mechanisms, including its new Cyber Governance Code of Practiceââ
although we have seen that yet. The submission argues:
âWithout stronger incentives, measurement and accountability, there is a risk that this ⌠will not deliver consistent or meaningful improvementsâ.
It warns:
âThis creates a disconnect between the regulated NIS economy and the wider, unregulated economy, despite risks flowing directly between themâ.
We know the wide, deep and prolonged effect of cyber attacks on M&S, JLR and Synnovis, yet JLR and M&S will be out of the scope of the Bill, as the Commons Minister himself noted. Surely, we need to take a whole-of-economy approach. We should surely include the public sector, and economically significant sectors such as retail and manufacturing.
In evidence to our Select Committee, UK Defence First also argued that the potential loss of control of satellite communications is a âsevereâ national risk and that the Bill should
âexplicitly treat space assets as critical national infrastructureâ.
Could the Minister comment?
DSIT has estimated that significant cyber attacks on businesses cost the UK almost ÂŁ15 billion in 2024. The National Cyber Security Centre reported that nationally significant cyber incidents had more than doubled in a year. As ISC2 says:
âIt is no longer a question of if an organisation will be attacked, but whenâ.
ISACA, a global professional association focused on this area, emphasises:
âDigital service providers, particularly cloud infrastructure, also represent a growing concentration of systemic risk. The financial sector is increasingly reliant on a small number of cloud providers, creating potential single points of failure across critical services. For example, evidence presented to the Treasury Committee highlighted that 73% of UK cloud services are provided by just three providersâ.
ISACA also warns:
âCyber risk is inherently systemic, meaning disruption is rarely confined to a single organisation or sector, but is increasingly transmitted through supply chains, shared infrastructure and third-party dependenciesâ,
which the Minister made reference to. According to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain.
In addition, it is reported that many SMEs may perceive that they are too small to be a target, yet government research has found that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for small businesses, a cyber incident can be existential: roughly 60% of SMEs that fall victim to a cyber attack go out of business in six months. It is all very well, as the noble Earl just indicated, being outside regulation here if our SMEs simply go to the wall as a result of inadequate preparation and protection.
Evidence to our Select Committee suggests that skills shortages are a key challenge for companies, especially SMEs and those in the public sector. Is that why the Government have not included them here? That leaves our economy wide open; that is surely not the right answer. Cyber education, training, apprenticeships and investment in skills must accompany regulatory reforms, and the regulators themselves will need to be properly resourced so that they can deal with their new responsibilities. We know that public bodies have often found themselves dependent on ageing digital systems, with the risks from that.
We also need to recognise the need for the highest level of leadership in this area in companies and other organisations. It cannot simply be left to IT departments: cyber security must now be a major consideration at board level. We also need leadership from the Government, working with allies on intelligence sharing, common standards, co-ordinated responses to hostile activity, and co-operation on investigation. We know we face increasing attacks from rogue states: it is spoken of now as being low-level warfare, and we have seen the effect in many other countries as democracies are under attack.
In conclusion, although we welcome the Bill, we are seriously concerned about its limitations. A start would be to align with the EU, which already recognises that a whole-of-economy approach is the right one. I look forward to the Ministerâs response.
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateBaroness Northover
Main Page: Baroness Northover (Liberal Democrat - Life peer)Department Debates - View all Baroness Northover's debates with the Department for Digital, Culture, Media & Sport
(3Â weeks ago)
Grand CommitteeMy Lords, all the amendments that I have put down to the Bill are derived from evidence we received on the National Resilience Select Committee. I am sorry that I was not here last week to address those that came up then, and I am very grateful to my noble friend Lord Clement-Jones for presenting them for me.
Several members of the Select Committee, including me, were in Finland last week looking at its preparedness for attack. Finland has faced the threat from its long border with Russia throughout the history of its country, and its preparedness on a whole-of-society basis is extremely impressive. Although we do not have a long border with Russia to focus our minds, we know that cyber attacks can immediately undermine our whole society and economy. One of the things we heard on our Select Committee is that not only are many companies unprepared for cyber attacks but that there is a shortage of skills in this area.
This amendment is seeking to move things forward. The proposed new clause would
âgive the UK Cyber Security Council statutory functions to validate qualifications, to monitor the supply of and demand for cyber security professionals in the areas covered by the Bill, and to audit whether regulated organisations employ certified professionalsâa âcompetence mandateâ for the regimeâ.
I have received some useful information from the sector, which welcomes my attempt to try to ensure that we have sufficient cyber professionals and that there is a mechanism by which they are certified. There are analogies with the certification of medical professionals, for example. Their certification is conducted independently, and I recognise the importance of that. What I am arguing for here is the principle and not necessarily the route suggested by my amendment. How this is best done can be further discussed between Committee and Report.
The National Cyber Security Centre reported that nationally significant cyber incidents have more than doubled in a year. According to its survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain. Evidence to our Select Committee suggests that skills shortages are a key challenge here, especially for SMEs and those in the public sector. It is clear that cyber education, training and apprenticeships, and so on, must accompany these reforms.
The Bill places greater responsibility on organisations to identify and manage cyber risk. However, beyond those technological solutions, these obligations will require skilled professionals to carry them out. The Bill refers to the appointment of a âskilled personâ in the context of a national security directive but does not delve into what constitutes a skilled person. I realise that this will change over time, but there should be ways of addressing this.
Neither does the Bill acknowledge the role of skilled persons in delivering its wider objectives. Those in the field have called on the Government to amend the Bill to require organisations to access a cyber security workforce that is qualified to recognise professional standards. We know that this skills shortage exists, weakening our national resilience. One report showed that 87% of organisations experienced at least one consequence due to skills need, so it is becoming strategically important to address this. The Government should use the Bill as an opportunity to professionalise the sector by committing to a cyber security workforce and skills strategy, and mandating that regulators and regulated entities use suitably skilled people for the purposes of compliance with the regulation.
Recognised professional qualifications and certifications anchored in international standards should be required so that we and the regulators are reassured that the work is being carried out to a certain standard. The UK Cyber Security Council was granted royal chartered status to establish a self-regulating, politically independent professional body, structured on proven models of other professional bodies such as the GMC. The UK needs to transition from a fragmented patchwork of varying certifications to a unified national standard of professional competence and ethical conduct.
Therefore, the Bill should recognise the council as the authority for setting and maintaining these standards. Given that the Bill aims to enhance the security and resilience of the UK and the critical sectors that underpin our economy, that needs to be assisted by a suitably skilled workforce to implement it. Of course we need to take further action to make sure that we train people, but this amendment is designed to help move this forward by ensuring that those in this area are sufficiently skilled. I beg to move.
My Lords, I was hoping that there would be other contributorsâthere will be a double-banking on this amendment.
I support Amendment 99, tabled by my noble friend. Throughout our deliberations on this Bill, the Government have placed enormous emphasis on imposing tough, outcomes-based statutory duties on operators and suppliers across our critical infrastructure, but we must confront an uncomfortable truth: we can pass the most sophisticated cyber security regulations in the world but, if our economy lacks the trained, qualified human beings required to design, implement and maintain those defences, those regulations remain completely meaningless. Without a professional workforce capability, this Bill merely codifies what ISC2 has rightly termed âcompliance theatreââan expensive box-ticking exercise that produces mountains of paperwork without making our national networks one bit safer.
Look at the scale of the crisis facing our domestic cyber workforce. In its landmark 2025-26 cyber security workforce study, ISC2 revealed that 52% of UK cyber security professionals identify severe skills shortages as their single greatest barrier to complying with cyber regulations. Further, 58% of organisations reported a critical or significant skills deficit, with an astonishing 87% suffering direct operational consequences from missed system patches and delayed vulnerability remediation to active security oversights. Across the civilian economy, the UK currently faces an 88% shortage of certified cyber practitioners. In an environment of such extreme scarcity, how on earth do the Government expect regulated water utilities, transport operators and medium-sized managed service providers to fulfil the heavy duties created by this Bill?
Amendment 99, from my noble friend, would provide a structural solution to this workforce crisis by placing the UK Cyber Security Council on a formal statutory footing. Crucially, as she explained, this connects directly to the definition of a skilled person under Clause 43. If the Government are serious about raising our national resilience floor, they must recognise that human competence is just as vital as technological hardware. By embedding the UK Cyber Security Councilâs competence mandate in primary legislation, Amendment 99 would ensure that our cyber laws are backed by the skilled workforce needed to defend us.
I strongly urge the Minister to accept this amendment. By professionalising our cyber workforce, we would elevate this Bill from more than a compliance exercise to a genuine national capability.
The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
My Lords, I thank the noble Baroness for her amendment, in particular her focus on the importance of the skills and competence of the UK cyber security professionals on whom we all rely and our economy will continue to rely. As the noble Lord, Lord Vaizey, said, an important aspect here is the spirit behind the noble Baronessâs amendment, with its focus on the skill set and professionalisation of these individuals, which we wholeheartedly agree is incredibly important.
I will focus on the council itself for a moment. It is an independent, royal chartered body that unites government, industry and other sectors to boost the professionalism of the entire cyber sector. The council does important work that already encompasses the majority of functions named in the amendment. It sets professional standards and maintains a register of the UKâs accredited cyber professionals. It establishes pathways for cyber professionalsâexperienced and new entrantsâto have an easier route into quality cyber roles.
We disagree that there is a necessity to put this on a statutory footing. The Government consider the council to be akin to other professional bodies in the UK. Although there are some professional bodies with a statutory role and oversight by either government or Parliament, it is standard practice in technical fields for an organisation to be recognised through a royal charter and afforded operational independence from government. This includes the Engineering Council and the Science Council. Going down the route that the amendment proposes would undermine the councilâs independence, and that could affect its relationship with the sector.
That is a separate point from the importance of the need to professionalise the cyber sector and the Governmentâs strong support for that. Indeed, the Government have committed to funding the UK Cyber Security Council over the spending review period until it becomes self-sustainable, working closely with stakeholders across the profession and wider workforce. We believe that professional standards, accreditation and professional titles in cyber security will improve our cyber resilience.
Moreover, to the points raised by the noble Lords, Lord Clement-Jones and Lord Markam, and others, the adequacy of skilled persons remains important. The Governmentâs TechFirst programme is helping to build the pipeline of talent for all frontier technologies and is available to all secondary schools across the UK. This month, approximately 1,300 undergraduate and masterâs students are starting in the TechFirst scholarship programme, including over 300 students on a cyber security pathway.
On the question about how the Government monitor the adequacy of this, the Government publish annual data on the state of the UK cyber security workforce which shows that the supply of cyber skills is increasing. There is currently a net annual shortfall of approximately 3,800 people in the UKâs cyber security market. For the second year running, the workforce gap has remained markedly lower than our previous estimates, now 3,800, compared to 11,100 in 2023 and 14,100 in 2022. Focusing on the skills pipeline is incredibly important and something that the Government are backing.
Equally, the Government agree with the noble Baroness that regulatory authorities must have regard to the information and standards provided by the council. Indeed, we stated the need to align with council standards in the Government Cyber Action Plan. The Government have already worked with regulators to embed cyber security accreditation and professional standards into their guidance. We want to go further, which is why we intend to use the Billâs powers to introduce security and resilience requirements in secondary legislation. These are designed to be consistent with the NCSCâs cyber assessment framework, and we propose that these requirements will address relevant training, skills and professional standards. We will consult on these proposals later in the year to ensure that the industries, large and small, covered by the regulated sectors will be able to feed back on this, as will the regulators which will be responsible in this area.
To the questions on SMEs raised by the noble Baroness, Lady Neville-Jones, whether inside or outside, whether they are or are not regulated entities, SMEs have access to NCSC and cyber resilience centres. I am sure that we will go on shortly, in the context of the noble Baronessâs subsequent amendment, to discuss further support that we can provide to those SMEs.
We are very committed to the role and function of the UK Cyber Security Council as a wide-reaching and effective independent body, and we continue to support skills development in the UK. As such, we are not convinced that there is a need to put the council on a statutory footing at this stage.
I thank the Minister for her thoughtful reply and I thank other noble Lords for their support here. Clearly, we are all seeking to move in the same direction. There is a challenge and risks here that are incredibly important. Whether this is the right way forward, we will have to see.
I am very grateful to those organisations that fed into our Select Committee, which led me to table this amendment. This is an area that we will need to return to before Report, to look carefully at whether the drivers that the Minister has mentioned are sufficient. But at this stage, I beg leave to withdraw the amendment.
My Lords, this amendment again comes out of the evidence submitted to our National Resilience Select Committee.
It has been reported that many SMEs think that they are too small to be a target. However, as was reported at Second Reading, government research shows that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for many small businesses, a cyber incident can be existential and that roughly 60% of SMEs that fall victim to a cyber attack go out of business within six months.
In this amendment, I therefore seek to address the position of SMEs. Coming from the insurance sector, the Association of British Insurers feels that the Bill is narrow in scope and that
âlarge parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Governmentâs approach to ⌠these unregulated sectors relies primarily on voluntary governance mechanismsâ,
including their new Cyber Governance Code of Practice. It feels that, without stronger incentives, measurement and accountability, there is a risk that it will not deliver consistent improvements. That is obviously concerning a number of people.
There are warningsâwe know thisâthat cyber risk is inherently systemic. Disruption is rarely confined to a single organisation or sector but is increasingly transmitted through supply chains. As I mentioned in the previous group, according to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risks presented by the wider supply chain, so how do we bring in greater protection in a way that, as the noble Baroness, Lady Neville-Jones, and the noble Lord, Lord Vaizey, have just mentioned, does not overwhelm SMEs?
This proposed new clause would require the Secretary of State to establish a national, free-at-point-of-use cyber security support incident response service for relevant SMEs, modelled on comparable overseas services, such as the small business support provided by the Australian Cyber Security Centre.
The ABI notes that the Bill rightly focuses on building resilience in our critical national infrastructure and that more must therefore be done to address the cyber resilience of SMEs. Not surprisingly, it is concerned about cyber insurance. It points out that the take-up of cyber insurance among UK SMEs is very lowâsomewhere between 10% and 40%âand argues that cyber insurance can help prevent and alleviate the impact of cyber attacks for SMEs. But, obviously, there is a cost to that. As cyber risks continue to grow, SMEs are typically more vulnerable and less well placed than larger businesses to respond to cyber threats due to overstretched resources, including IT and potential security and skills gaps.
We have to be careful to make sure that reporting is not too onerous for SMEs. It is suggested, for example, that maybe their reporting timelines should be not as short as those for bigger companies, and that there should be better clarification of what is an actual or suspected cyber incident, so that things which are not as significant do not, as it were, clog up the system. However, I think everybody agrees that we need to make sure that SMEs are better supported.
I welcome the fact that the Government have set up some support in this area. There is a cyber action toolkit, which was launched in March 2026 and includes a helpline, and a cyber adviser scheme, which offers a free 30-minute session. There is also a small business guide for response and recovery. But when you look at what they are suggesting, they are pushing companies towards the commercial market, so there is going to be a cost to that, and, down the line, towards fraud analysis and law enforcement. We know how challenging that is in so many areas, so it does not necessarily seem the most helpful or robust system.
The reason I mention the Australian cyber resilience service and have looked at what it does is that it goes further than we are now going, and I hope the Government will give thought to extending this in the way that the Australian system does. There is free, tailored, person-to-person support with two functions: helping small businesses assess and build resilience and helping them to recover after an incident, such as account compromise, phishing or ransomware, with case management and device remediation. It is much more supportive than what we currently have in the United Kingdom.
Clearly, much more needs to be done to ensure that SMEs are aware of the risks and do not simply wait until they have been hit, but also that they are actively assisted. That is important for them, but also for the wider economy, given how interlinked we all are. This is clearly an evolving area and I look forward to hearing what the Minister has to say about how we can move this forward, given how significant it is. I beg to move.
Baroness Lloyd of Effra (Lab)
My Lords, I thank the noble Baroness for her amendment and for linking the issue of cyber security with wider questions on national resilience; she is absolutely right to situate it in that space. I also thank her for introducing the topic of the right amount of cyber security support for the SMEs regulated under the Bill; indeed, the discussion has led to SMEs that are not regulated under the Bill.
We know that SMEs require dedicated cyber security support. That is why there are a wide range of free tools, guidance and training to help SMEs implement cyber security measures. These resources are available to any business, not just those regulated under the regime. As the noble Lord, Lord Vaizey, mentioned, this includes the Cyber Action Toolkit, designed to scale nationally to empower millions of small organisations through tailored cyber security advice with NCSC-certified cyber advisers. A number of noble Lords referenced the importance of Cyber Essentials, as well as insurance and incident response. If an SME with a turnover of less than ÂŁ20 million has Cyber Essentials, it also has cyber insurance cover of up to ÂŁ25,000. That incentive is intended to link the process of getting Cyber Essentials with the benefits of insurance. Likewise, SMEs get cyber incident support 24/7 with Cyber Essentials.
The noble Lords, Lord Vaizey, Lord Londesborough and Lord Birt, talked about the âpushâ. We are indeed encouraging, perhaps not pushing, the private sector to engage its supply chain through the cyber pledge, which is for entities outside the regulated scope. That is one of the key elements of the cyber pledge. Likewise, under the GCAP, the Governmentâs cyber action plan, Cyber Essentials, or equivalent, are needed for government procurements using official data. These are the mechanisms by which we are encouraging large organisations to look at their supply chainsâon the point that the noble Lord, Lord Clement-Jones, made about the interconnectedness of all our organisations todayâand encouraging the uptake of Cyber Essentials with these very tangible benefits.
I was asked a very fair question about the best way to provide cyber support to organisations. I heard at least one noble Lord say that SMEs do not like different provision. I think that many SMEs preferâor, if asked, would requestâlocal trusted advisers, which is exactly what the regional cyber resilience centres offer. They offer free support to SMEs across England and Wales, covering a wide range of services, such as incident response, a business continuity service and support with Cyber Essentials and security training.
The noble Lord, Lord Londesborough, made a point about a central, monolithic model compared with these local or regional models. There is a lot of merit in a regional model that has some common standards but is located much nearer to the SMEs that it serves. I reiterate that small and micro-organisations are exempt from being regulated as relevant digital service providers or relevant managed service providers. They can be regulated only if they are operators of essential services or designated as a critical supplier, for which there is a high bar. On the picture raised by the noble Lord, Lord Clement-Jones, we do not think that a huge number of small enterprises will be in scope of this legislation. All small businesses will benefit from the current provision, but they would not necessarily benefit from the model proposed by the amendment.
The amendment would also require the Secretary of State to have regard to international regimes. We are indeed aware of such schemes, such as the Australian Small Business Cyber Resilience Service. Many of the offerings that that service provides, such as tailored support and practical incident recovery support, already exist in the UK, as I have set out. We learn from international best practice, but we also tailor it to our local economy and the threats we see, to best support and meet the needs of UK businesses and interact with UK regulations.
I hope that I have set out that guidance for small and medium-sized organisations is already available through existing UK support. We are doing more to look at supply chains through discussions with large firms, through the GCAP and through this Bill. We think that a new dedicated service could divert resources from these existing services and potentially impact on their efficacy. On the central point that the noble Baroness started with, we absolutely agree with the importance of providing support to small and medium-sized enterprises under the Bill, ensuring that they have everything they need to be resilient and respond to incidents.
I thank the Minister, and I thank noble Lords for their support. This is clearly an area where we agree that there is a problem; we are very vulnerable in the United Kingdom. What we have in place is clearly not working sufficiently well if 60% of SMEs that are hit by cyber attacks go under. That is the context in which we ought to look at proposals that might seek to address that. We clearly need to take SMEs forward in a way that does not overburden them.
I hear the point about extending insurance cover. We can indeed take more than one track, but there is a cost to not supporting SMEs. If they are going to go under, that will be an economic cost to the country and, if we do not support them, they are likely to be hit by cyber attacks, taking them and others under anyway, with that effect upon our economy. Clearly, the Government agreeâhence putting in place the measures that the Minister has outlined.
I am suggesting, from the evidence we have received, that this needs to go further and faster. We can discuss exactly how, but it is clear that this is an escalating problem and that we need to do more to tackle it. That is on the basis, in particular, of the concerns expressed to the National Resilience Committee on which I serve and which, as I say, gave me the idea of putting this amendment forward. I think that we will need to return to this, because it is a major problem, but, in the meantime, I beg leave to withdraw the amendment.