Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Northover Excerpts
Baroness Northover Portrait Baroness Northover (LD)
- View Speech - Hansard - -

My Lords, I too thank the noble Baroness for introducing the Bill. From these Benches we welcome the Bill, but we feel that in a number of ways it does not go far enough. Hostile state actors, organised crime and others are increasingly targeting our systems at every level with potentially catastrophic effects, as previous speakers have said. Attacks on our energy networks, water supplies, transport systems, financial infrastructure and digital services are becoming more frequent. It is clearly vital that organisations that deliver essential services have high standards of cyber security and that they should report serious incidents promptly and transparently. We also recognise that the coverage of those who need to report in this way should be widened. However, is the Bill ambitious enough?

I serve on the House of Lords Select Committee on National Resilience—there is at least one other speaker in the debate who also serves on that Select Committee—and I will draw here from some of the evidence that has been submitted to us. We were, of course, part of the EU arrangements until Brexit, and this is yet another area we needed to address after that. That resulted in the 2018 regulations, which this Bill seeks to update. The post-Brexit arrangements seem to have complicated putting in place clear primary legislation. The Minister in the Commons noted that Brussels is pressing ahead with its own updates “while we lag behind”. He stated that this

“procedural quirk has left essential UK services more exposed, which perhaps tells us something about why the UK has such appalling figures compared with some of our EU counterparts, as hackers and cyber criminals exploit gaps in our dated laws”.—[Official Report, Commons, 6/1/26; col. 179.]

We do indeed have the worst record in Europe for such attacks. I would argue, from submissions we received to our Select Committee, that it makes most sense for us to be aligned with the EU regulations. It has been put to us that this would mean that organisations do not need to answer to two sets of regulations in Europe. It is clear that this would assist us anyway, given that the EU regulations cover a wider range of areas, which it makes little sense to overlook as the Government appear to be doing. As it was put to us by ISC2,

“the government may have missed an opportunity to have the same taxonomy of CNI across jurisdictions. For example, the EU’s NIS2 directive on cybersecurity includes manufacturing, public administration and food production … These sectors are critical for the UK’s national and economic resilience. Under the proposed regime manufacturers operating across the UK and the EU, when victim of a cybersecurity incident in the UK, will be mandated to report”

this to EU authorities but not to the UK.

One of the submissions notes that the Bill is narrow in scope:

“large parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Government’s approach to … these unregulated sectors relies primarily on voluntary governance mechanisms, including its new Cyber Governance Code of Practice”—

although we have seen that yet. The submission argues:

“Without stronger incentives, measurement and accountability, there is a risk that this … will not deliver consistent or meaningful improvements”.


It warns:

“This creates a disconnect between the regulated NIS economy and the wider, unregulated economy, despite risks flowing directly between them”.


We know the wide, deep and prolonged effect of cyber attacks on M&S, JLR and Synnovis, yet JLR and M&S will be out of the scope of the Bill, as the Commons Minister himself noted. Surely, we need to take a whole-of-economy approach. We should surely include the public sector, and economically significant sectors such as retail and manufacturing.

In evidence to our Select Committee, UK Defence First also argued that the potential loss of control of satellite communications is a “severe” national risk and that the Bill should

“explicitly treat space assets as critical national infrastructure”.

Could the Minister comment?

DSIT has estimated that significant cyber attacks on businesses cost the UK almost ÂŁ15 billion in 2024. The National Cyber Security Centre reported that nationally significant cyber incidents had more than doubled in a year. As ISC2 says:

“It is no longer a question of if an organisation will be attacked, but when”.


ISACA, a global professional association focused on this area, emphasises:

“Digital service providers, particularly cloud infrastructure, also represent a growing concentration of systemic risk. The financial sector is increasingly reliant on a small number of cloud providers, creating potential single points of failure across critical services. For example, evidence presented to the Treasury Committee highlighted that 73% of UK cloud services are provided by just three providers”.


ISACA also warns:

“Cyber risk is inherently systemic, meaning disruption is rarely confined to a single organisation or sector, but is increasingly transmitted through supply chains, shared infrastructure and third-party dependencies”,


which the Minister made reference to. According to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain.

In addition, it is reported that many SMEs may perceive that they are too small to be a target, yet government research has found that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for small businesses, a cyber incident can be existential: roughly 60% of SMEs that fall victim to a cyber attack go out of business in six months. It is all very well, as the noble Earl just indicated, being outside regulation here if our SMEs simply go to the wall as a result of inadequate preparation and protection.

Evidence to our Select Committee suggests that skills shortages are a key challenge for companies, especially SMEs and those in the public sector. Is that why the Government have not included them here? That leaves our economy wide open; that is surely not the right answer. Cyber education, training, apprenticeships and investment in skills must accompany regulatory reforms, and the regulators themselves will need to be properly resourced so that they can deal with their new responsibilities. We know that public bodies have often found themselves dependent on ageing digital systems, with the risks from that.

We also need to recognise the need for the highest level of leadership in this area in companies and other organisations. It cannot simply be left to IT departments: cyber security must now be a major consideration at board level. We also need leadership from the Government, working with allies on intelligence sharing, common standards, co-ordinated responses to hostile activity, and co-operation on investigation. We know we face increasing attacks from rogue states: it is spoken of now as being low-level warfare, and we have seen the effect in many other countries as democracies are under attack.

In conclusion, although we welcome the Bill, we are seriously concerned about its limitations. A start would be to align with the EU, which already recognises that a whole-of-economy approach is the right one. I look forward to the Minister’s response.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Northover Excerpts
Moved by
99: After Clause 42, insert the following new Clause—
“Cyber security competence: functions of the UK Cyber Security Council(1) The UK Cyber Security Council is to exercise the functions described in subsection (2) and is accountable to the Secretary of State for the exercise of those functions.(2) The functions are—(a) to validate and accredit professional qualifications, standards and titles for cyber security professionals employed by regulated persons,(b) to monitor the supply of, and demand for, qualified cyber security professionals across the sectors regulated under this Act and the NIS Regulations, and(c) to audit whether, and to what extent, regulated persons employ or have access to appropriately certified cyber security professionals.(3) For the purposes of this section, “regulated person” has the same meaning as in Chapter 3 (see section 30).(4) A regulatory authority (as defined in section 24) must have regard to the information and standards provided by the Council under this section when exercising its functions.(5) The Secretary of State must by regulations made by statutory instrument make further provision about the exercise of the Council’s functions under this section, including provision about its accountability for the exercise of the functions described in subsection (2).(6) A statutory instrument containing regulations under this section may not be made unless a draft of the instrument has been laid before and approved by a resolution of each House of Parliament.”Member’s explanatory statement
This new clause would give the UK Cyber Security Council statutory functions to validate qualifications, to monitor the supply of and demand for cyber security professionals in the areas covered by the Bill, and to audit whether regulated organisations employ certified professionals—a “competence mandate” for the regime.
Baroness Northover Portrait Baroness Northover (LD)
- Hansard - -

My Lords, all the amendments that I have put down to the Bill are derived from evidence we received on the National Resilience Select Committee. I am sorry that I was not here last week to address those that came up then, and I am very grateful to my noble friend Lord Clement-Jones for presenting them for me.

Several members of the Select Committee, including me, were in Finland last week looking at its preparedness for attack. Finland has faced the threat from its long border with Russia throughout the history of its country, and its preparedness on a whole-of-society basis is extremely impressive. Although we do not have a long border with Russia to focus our minds, we know that cyber attacks can immediately undermine our whole society and economy. One of the things we heard on our Select Committee is that not only are many companies unprepared for cyber attacks but that there is a shortage of skills in this area.

This amendment is seeking to move things forward. The proposed new clause would

“give the UK Cyber Security Council statutory functions to validate qualifications, to monitor the supply of and demand for cyber security professionals in the areas covered by the Bill, and to audit whether regulated organisations employ certified professionals—a ‘competence mandate’ for the regime”.

I have received some useful information from the sector, which welcomes my attempt to try to ensure that we have sufficient cyber professionals and that there is a mechanism by which they are certified. There are analogies with the certification of medical professionals, for example. Their certification is conducted independently, and I recognise the importance of that. What I am arguing for here is the principle and not necessarily the route suggested by my amendment. How this is best done can be further discussed between Committee and Report.

The National Cyber Security Centre reported that nationally significant cyber incidents have more than doubled in a year. According to its survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain. Evidence to our Select Committee suggests that skills shortages are a key challenge here, especially for SMEs and those in the public sector. It is clear that cyber education, training and apprenticeships, and so on, must accompany these reforms.

The Bill places greater responsibility on organisations to identify and manage cyber risk. However, beyond those technological solutions, these obligations will require skilled professionals to carry them out. The Bill refers to the appointment of a “skilled person” in the context of a national security directive but does not delve into what constitutes a skilled person. I realise that this will change over time, but there should be ways of addressing this.

Neither does the Bill acknowledge the role of skilled persons in delivering its wider objectives. Those in the field have called on the Government to amend the Bill to require organisations to access a cyber security workforce that is qualified to recognise professional standards. We know that this skills shortage exists, weakening our national resilience. One report showed that 87% of organisations experienced at least one consequence due to skills need, so it is becoming strategically important to address this. The Government should use the Bill as an opportunity to professionalise the sector by committing to a cyber security workforce and skills strategy, and mandating that regulators and regulated entities use suitably skilled people for the purposes of compliance with the regulation.

Recognised professional qualifications and certifications anchored in international standards should be required so that we and the regulators are reassured that the work is being carried out to a certain standard. The UK Cyber Security Council was granted royal chartered status to establish a self-regulating, politically independent professional body, structured on proven models of other professional bodies such as the GMC. The UK needs to transition from a fragmented patchwork of varying certifications to a unified national standard of professional competence and ethical conduct.

Therefore, the Bill should recognise the council as the authority for setting and maintaining these standards. Given that the Bill aims to enhance the security and resilience of the UK and the critical sectors that underpin our economy, that needs to be assisted by a suitably skilled workforce to implement it. Of course we need to take further action to make sure that we train people, but this amendment is designed to help move this forward by ensuring that those in this area are sufficiently skilled. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I was hoping that there would be other contributors—there will be a double-banking on this amendment.

I support Amendment 99, tabled by my noble friend. Throughout our deliberations on this Bill, the Government have placed enormous emphasis on imposing tough, outcomes-based statutory duties on operators and suppliers across our critical infrastructure, but we must confront an uncomfortable truth: we can pass the most sophisticated cyber security regulations in the world but, if our economy lacks the trained, qualified human beings required to design, implement and maintain those defences, those regulations remain completely meaningless. Without a professional workforce capability, this Bill merely codifies what ISC2 has rightly termed “compliance theatre”—an expensive box-ticking exercise that produces mountains of paperwork without making our national networks one bit safer.

Look at the scale of the crisis facing our domestic cyber workforce. In its landmark 2025-26 cyber security workforce study, ISC2 revealed that 52% of UK cyber security professionals identify severe skills shortages as their single greatest barrier to complying with cyber regulations. Further, 58% of organisations reported a critical or significant skills deficit, with an astonishing 87% suffering direct operational consequences from missed system patches and delayed vulnerability remediation to active security oversights. Across the civilian economy, the UK currently faces an 88% shortage of certified cyber practitioners. In an environment of such extreme scarcity, how on earth do the Government expect regulated water utilities, transport operators and medium-sized managed service providers to fulfil the heavy duties created by this Bill?

Amendment 99, from my noble friend, would provide a structural solution to this workforce crisis by placing the UK Cyber Security Council on a formal statutory footing. Crucially, as she explained, this connects directly to the definition of a skilled person under Clause 43. If the Government are serious about raising our national resilience floor, they must recognise that human competence is just as vital as technological hardware. By embedding the UK Cyber Security Council’s competence mandate in primary legislation, Amendment 99 would ensure that our cyber laws are backed by the skilled workforce needed to defend us.

I strongly urge the Minister to accept this amendment. By professionalising our cyber workforce, we would elevate this Bill from more than a compliance exercise to a genuine national capability.

--- Later in debate ---
Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness for her amendment, in particular her focus on the importance of the skills and competence of the UK cyber security professionals on whom we all rely and our economy will continue to rely. As the noble Lord, Lord Vaizey, said, an important aspect here is the spirit behind the noble Baroness’s amendment, with its focus on the skill set and professionalisation of these individuals, which we wholeheartedly agree is incredibly important.

I will focus on the council itself for a moment. It is an independent, royal chartered body that unites government, industry and other sectors to boost the professionalism of the entire cyber sector. The council does important work that already encompasses the majority of functions named in the amendment. It sets professional standards and maintains a register of the UK’s accredited cyber professionals. It establishes pathways for cyber professionals—experienced and new entrants—to have an easier route into quality cyber roles.

We disagree that there is a necessity to put this on a statutory footing. The Government consider the council to be akin to other professional bodies in the UK. Although there are some professional bodies with a statutory role and oversight by either government or Parliament, it is standard practice in technical fields for an organisation to be recognised through a royal charter and afforded operational independence from government. This includes the Engineering Council and the Science Council. Going down the route that the amendment proposes would undermine the council’s independence, and that could affect its relationship with the sector.

That is a separate point from the importance of the need to professionalise the cyber sector and the Government’s strong support for that. Indeed, the Government have committed to funding the UK Cyber Security Council over the spending review period until it becomes self-sustainable, working closely with stakeholders across the profession and wider workforce. We believe that professional standards, accreditation and professional titles in cyber security will improve our cyber resilience.

Moreover, to the points raised by the noble Lords, Lord Clement-Jones and Lord Markam, and others, the adequacy of skilled persons remains important. The Government’s TechFirst programme is helping to build the pipeline of talent for all frontier technologies and is available to all secondary schools across the UK. This month, approximately 1,300 undergraduate and master’s students are starting in the TechFirst scholarship programme, including over 300 students on a cyber security pathway.

On the question about how the Government monitor the adequacy of this, the Government publish annual data on the state of the UK cyber security workforce which shows that the supply of cyber skills is increasing. There is currently a net annual shortfall of approximately 3,800 people in the UK’s cyber security market. For the second year running, the workforce gap has remained markedly lower than our previous estimates, now 3,800, compared to 11,100 in 2023 and 14,100 in 2022. Focusing on the skills pipeline is incredibly important and something that the Government are backing.

Equally, the Government agree with the noble Baroness that regulatory authorities must have regard to the information and standards provided by the council. Indeed, we stated the need to align with council standards in the Government Cyber Action Plan. The Government have already worked with regulators to embed cyber security accreditation and professional standards into their guidance. We want to go further, which is why we intend to use the Bill’s powers to introduce security and resilience requirements in secondary legislation. These are designed to be consistent with the NCSC’s cyber assessment framework, and we propose that these requirements will address relevant training, skills and professional standards. We will consult on these proposals later in the year to ensure that the industries, large and small, covered by the regulated sectors will be able to feed back on this, as will the regulators which will be responsible in this area.

To the questions on SMEs raised by the noble Baroness, Lady Neville-Jones, whether inside or outside, whether they are or are not regulated entities, SMEs have access to NCSC and cyber resilience centres. I am sure that we will go on shortly, in the context of the noble Baroness’s subsequent amendment, to discuss further support that we can provide to those SMEs.

We are very committed to the role and function of the UK Cyber Security Council as a wide-reaching and effective independent body, and we continue to support skills development in the UK. As such, we are not convinced that there is a need to put the council on a statutory footing at this stage.

Baroness Northover Portrait Baroness Northover (LD)
- Hansard - -

I thank the Minister for her thoughtful reply and I thank other noble Lords for their support here. Clearly, we are all seeking to move in the same direction. There is a challenge and risks here that are incredibly important. Whether this is the right way forward, we will have to see.

I am very grateful to those organisations that fed into our Select Committee, which led me to table this amendment. This is an area that we will need to return to before Report, to look carefully at whether the drivers that the Minister has mentioned are sufficient. But at this stage, I beg leave to withdraw the amendment.

Amendment 99 withdrawn.
Moved by
100: After Clause 42, insert the following new Clause—
“National cyber security support service for small and medium-sized enterprises (1) The Secretary of State must, by regulations, make provision for the establishment and operation of a national cyber security support and incident response service for relevant small and medium-sized enterprises (SMEs), for the purpose of improving the security and resilience of their network and information systems.(2) The service established under this section must—(a) be free at the point of use, and(b) provide, in particular following a cyber incident affecting a relevant SME—(i) advice and technical assistance,(ii) incident response support, and(iii) guidance on recovery and remediation.(3) For the purposes of this section, a relevant SME is a small or medium-sized enterprise which is—(a) an operator of an essential service,(b) a relevant digital service provider,(c) a relevant managed service provider, or(d) a critical supplier,within the meaning of the NIS Regulations.(4) In establishing and operating the service the Secretary of State must have regard to comparable national cyber security support services operated in other jurisdictions.” Member's explanatory statement
This new clause would require the Secretary of State to establish a national, free-at-the-point-of-use cyber security support and incident response service for relevant SMEs, modelled on comparable overseas services such as the small-business support provided by the Australian Cyber Security Centre.
Baroness Northover Portrait Baroness Northover (LD)
- Hansard - -

My Lords, this amendment again comes out of the evidence submitted to our National Resilience Select Committee.

It has been reported that many SMEs think that they are too small to be a target. However, as was reported at Second Reading, government research shows that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for many small businesses, a cyber incident can be existential and that roughly 60% of SMEs that fall victim to a cyber attack go out of business within six months.

In this amendment, I therefore seek to address the position of SMEs. Coming from the insurance sector, the Association of British Insurers feels that the Bill is narrow in scope and that

“large parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Government’s approach to … these unregulated sectors relies primarily on voluntary governance mechanisms”,

including their new Cyber Governance Code of Practice. It feels that, without stronger incentives, measurement and accountability, there is a risk that it will not deliver consistent improvements. That is obviously concerning a number of people.

There are warnings—we know this—that cyber risk is inherently systemic. Disruption is rarely confined to a single organisation or sector but is increasingly transmitted through supply chains. As I mentioned in the previous group, according to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risks presented by the wider supply chain, so how do we bring in greater protection in a way that, as the noble Baroness, Lady Neville-Jones, and the noble Lord, Lord Vaizey, have just mentioned, does not overwhelm SMEs?

This proposed new clause would require the Secretary of State to establish a national, free-at-point-of-use cyber security support incident response service for relevant SMEs, modelled on comparable overseas services, such as the small business support provided by the Australian Cyber Security Centre.

The ABI notes that the Bill rightly focuses on building resilience in our critical national infrastructure and that more must therefore be done to address the cyber resilience of SMEs. Not surprisingly, it is concerned about cyber insurance. It points out that the take-up of cyber insurance among UK SMEs is very low—somewhere between 10% and 40%—and argues that cyber insurance can help prevent and alleviate the impact of cyber attacks for SMEs. But, obviously, there is a cost to that. As cyber risks continue to grow, SMEs are typically more vulnerable and less well placed than larger businesses to respond to cyber threats due to overstretched resources, including IT and potential security and skills gaps.

We have to be careful to make sure that reporting is not too onerous for SMEs. It is suggested, for example, that maybe their reporting timelines should be not as short as those for bigger companies, and that there should be better clarification of what is an actual or suspected cyber incident, so that things which are not as significant do not, as it were, clog up the system. However, I think everybody agrees that we need to make sure that SMEs are better supported.

I welcome the fact that the Government have set up some support in this area. There is a cyber action toolkit, which was launched in March 2026 and includes a helpline, and a cyber adviser scheme, which offers a free 30-minute session. There is also a small business guide for response and recovery. But when you look at what they are suggesting, they are pushing companies towards the commercial market, so there is going to be a cost to that, and, down the line, towards fraud analysis and law enforcement. We know how challenging that is in so many areas, so it does not necessarily seem the most helpful or robust system.

The reason I mention the Australian cyber resilience service and have looked at what it does is that it goes further than we are now going, and I hope the Government will give thought to extending this in the way that the Australian system does. There is free, tailored, person-to-person support with two functions: helping small businesses assess and build resilience and helping them to recover after an incident, such as account compromise, phishing or ransomware, with case management and device remediation. It is much more supportive than what we currently have in the United Kingdom.

Clearly, much more needs to be done to ensure that SMEs are aware of the risks and do not simply wait until they have been hit, but also that they are actively assisted. That is important for them, but also for the wider economy, given how interlinked we all are. This is clearly an evolving area and I look forward to hearing what the Minister has to say about how we can move this forward, given how significant it is. I beg to move.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness for her amendment and for linking the issue of cyber security with wider questions on national resilience; she is absolutely right to situate it in that space. I also thank her for introducing the topic of the right amount of cyber security support for the SMEs regulated under the Bill; indeed, the discussion has led to SMEs that are not regulated under the Bill.

We know that SMEs require dedicated cyber security support. That is why there are a wide range of free tools, guidance and training to help SMEs implement cyber security measures. These resources are available to any business, not just those regulated under the regime. As the noble Lord, Lord Vaizey, mentioned, this includes the Cyber Action Toolkit, designed to scale nationally to empower millions of small organisations through tailored cyber security advice with NCSC-certified cyber advisers. A number of noble Lords referenced the importance of Cyber Essentials, as well as insurance and incident response. If an SME with a turnover of less than ÂŁ20 million has Cyber Essentials, it also has cyber insurance cover of up to ÂŁ25,000. That incentive is intended to link the process of getting Cyber Essentials with the benefits of insurance. Likewise, SMEs get cyber incident support 24/7 with Cyber Essentials.

The noble Lords, Lord Vaizey, Lord Londesborough and Lord Birt, talked about the “push”. We are indeed encouraging, perhaps not pushing, the private sector to engage its supply chain through the cyber pledge, which is for entities outside the regulated scope. That is one of the key elements of the cyber pledge. Likewise, under the GCAP, the Government’s cyber action plan, Cyber Essentials, or equivalent, are needed for government procurements using official data. These are the mechanisms by which we are encouraging large organisations to look at their supply chains—on the point that the noble Lord, Lord Clement-Jones, made about the interconnectedness of all our organisations today—and encouraging the uptake of Cyber Essentials with these very tangible benefits.

I was asked a very fair question about the best way to provide cyber support to organisations. I heard at least one noble Lord say that SMEs do not like different provision. I think that many SMEs prefer—or, if asked, would request—local trusted advisers, which is exactly what the regional cyber resilience centres offer. They offer free support to SMEs across England and Wales, covering a wide range of services, such as incident response, a business continuity service and support with Cyber Essentials and security training.

The noble Lord, Lord Londesborough, made a point about a central, monolithic model compared with these local or regional models. There is a lot of merit in a regional model that has some common standards but is located much nearer to the SMEs that it serves. I reiterate that small and micro-organisations are exempt from being regulated as relevant digital service providers or relevant managed service providers. They can be regulated only if they are operators of essential services or designated as a critical supplier, for which there is a high bar. On the picture raised by the noble Lord, Lord Clement-Jones, we do not think that a huge number of small enterprises will be in scope of this legislation. All small businesses will benefit from the current provision, but they would not necessarily benefit from the model proposed by the amendment.

The amendment would also require the Secretary of State to have regard to international regimes. We are indeed aware of such schemes, such as the Australian Small Business Cyber Resilience Service. Many of the offerings that that service provides, such as tailored support and practical incident recovery support, already exist in the UK, as I have set out. We learn from international best practice, but we also tailor it to our local economy and the threats we see, to best support and meet the needs of UK businesses and interact with UK regulations.

I hope that I have set out that guidance for small and medium-sized organisations is already available through existing UK support. We are doing more to look at supply chains through discussions with large firms, through the GCAP and through this Bill. We think that a new dedicated service could divert resources from these existing services and potentially impact on their efficacy. On the central point that the noble Baroness started with, we absolutely agree with the importance of providing support to small and medium-sized enterprises under the Bill, ensuring that they have everything they need to be resilient and respond to incidents.

Baroness Northover Portrait Baroness Northover (LD)
- Hansard - -

I thank the Minister, and I thank noble Lords for their support. This is clearly an area where we agree that there is a problem; we are very vulnerable in the United Kingdom. What we have in place is clearly not working sufficiently well if 60% of SMEs that are hit by cyber attacks go under. That is the context in which we ought to look at proposals that might seek to address that. We clearly need to take SMEs forward in a way that does not overburden them.

I hear the point about extending insurance cover. We can indeed take more than one track, but there is a cost to not supporting SMEs. If they are going to go under, that will be an economic cost to the country and, if we do not support them, they are likely to be hit by cyber attacks, taking them and others under anyway, with that effect upon our economy. Clearly, the Government agree—hence putting in place the measures that the Minister has outlined.

I am suggesting, from the evidence we have received, that this needs to go further and faster. We can discuss exactly how, but it is clear that this is an escalating problem and that we need to do more to tackle it. That is on the basis, in particular, of the concerns expressed to the National Resilience Committee on which I serve and which, as I say, gave me the idea of putting this amendment forward. I think that we will need to return to this, because it is a major problem, but, in the meantime, I beg leave to withdraw the amendment.

Amendment 100 withdrawn.