Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Northover Excerpts
Baroness Northover Portrait Baroness Northover (LD)
- View Speech - Hansard - -

My Lords, I too thank the noble Baroness for introducing the Bill. From these Benches we welcome the Bill, but we feel that in a number of ways it does not go far enough. Hostile state actors, organised crime and others are increasingly targeting our systems at every level with potentially catastrophic effects, as previous speakers have said. Attacks on our energy networks, water supplies, transport systems, financial infrastructure and digital services are becoming more frequent. It is clearly vital that organisations that deliver essential services have high standards of cyber security and that they should report serious incidents promptly and transparently. We also recognise that the coverage of those who need to report in this way should be widened. However, is the Bill ambitious enough?

I serve on the House of Lords Select Committee on National Resilience—there is at least one other speaker in the debate who also serves on that Select Committee—and I will draw here from some of the evidence that has been submitted to us. We were, of course, part of the EU arrangements until Brexit, and this is yet another area we needed to address after that. That resulted in the 2018 regulations, which this Bill seeks to update. The post-Brexit arrangements seem to have complicated putting in place clear primary legislation. The Minister in the Commons noted that Brussels is pressing ahead with its own updates “while we lag behind”. He stated that this

“procedural quirk has left essential UK services more exposed, which perhaps tells us something about why the UK has such appalling figures compared with some of our EU counterparts, as hackers and cyber criminals exploit gaps in our dated laws”.—[Official Report, Commons, 6/1/26; col. 179.]

We do indeed have the worst record in Europe for such attacks. I would argue, from submissions we received to our Select Committee, that it makes most sense for us to be aligned with the EU regulations. It has been put to us that this would mean that organisations do not need to answer to two sets of regulations in Europe. It is clear that this would assist us anyway, given that the EU regulations cover a wider range of areas, which it makes little sense to overlook as the Government appear to be doing. As it was put to us by ISC2,

“the government may have missed an opportunity to have the same taxonomy of CNI across jurisdictions. For example, the EU’s NIS2 directive on cybersecurity includes manufacturing, public administration and food production … These sectors are critical for the UK’s national and economic resilience. Under the proposed regime manufacturers operating across the UK and the EU, when victim of a cybersecurity incident in the UK, will be mandated to report”

this to EU authorities but not to the UK.

One of the submissions notes that the Bill is narrow in scope:

“large parts of the economy, including organisations that are economically significant due to their scale, interconnectedness or role in supply chains, will remain outside this regulatory perimeter. The Government’s approach to … these unregulated sectors relies primarily on voluntary governance mechanisms, including its new Cyber Governance Code of Practice”—

although we have seen that yet. The submission argues:

“Without stronger incentives, measurement and accountability, there is a risk that this … will not deliver consistent or meaningful improvements”.


It warns:

“This creates a disconnect between the regulated NIS economy and the wider, unregulated economy, despite risks flowing directly between them”.


We know the wide, deep and prolonged effect of cyber attacks on M&S, JLR and Synnovis, yet JLR and M&S will be out of the scope of the Bill, as the Commons Minister himself noted. Surely, we need to take a whole-of-economy approach. We should surely include the public sector, and economically significant sectors such as retail and manufacturing.

In evidence to our Select Committee, UK Defence First also argued that the potential loss of control of satellite communications is a “severe” national risk and that the Bill should

“explicitly treat space assets as critical national infrastructure”.

Could the Minister comment?

DSIT has estimated that significant cyber attacks on businesses cost the UK almost £15 billion in 2024. The National Cyber Security Centre reported that nationally significant cyber incidents had more than doubled in a year. As ISC2 says:

“It is no longer a question of if an organisation will be attacked, but when”.


ISACA, a global professional association focused on this area, emphasises:

“Digital service providers, particularly cloud infrastructure, also represent a growing concentration of systemic risk. The financial sector is increasingly reliant on a small number of cloud providers, creating potential single points of failure across critical services. For example, evidence presented to the Treasury Committee highlighted that 73% of UK cloud services are provided by just three providers”.


ISACA also warns:

“Cyber risk is inherently systemic, meaning disruption is rarely confined to a single organisation or sector, but is increasingly transmitted through supply chains, shared infrastructure and third-party dependencies”,


which the Minister made reference to. According to the cyber security breaches survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain.

In addition, it is reported that many SMEs may perceive that they are too small to be a target, yet government research has found that 50% of UK SMEs faced some kind of cyber breach or attack in 2025. It is also reported that, for small businesses, a cyber incident can be existential: roughly 60% of SMEs that fall victim to a cyber attack go out of business in six months. It is all very well, as the noble Earl just indicated, being outside regulation here if our SMEs simply go to the wall as a result of inadequate preparation and protection.

Evidence to our Select Committee suggests that skills shortages are a key challenge for companies, especially SMEs and those in the public sector. Is that why the Government have not included them here? That leaves our economy wide open; that is surely not the right answer. Cyber education, training, apprenticeships and investment in skills must accompany regulatory reforms, and the regulators themselves will need to be properly resourced so that they can deal with their new responsibilities. We know that public bodies have often found themselves dependent on ageing digital systems, with the risks from that.

We also need to recognise the need for the highest level of leadership in this area in companies and other organisations. It cannot simply be left to IT departments: cyber security must now be a major consideration at board level. We also need leadership from the Government, working with allies on intelligence sharing, common standards, co-ordinated responses to hostile activity, and co-operation on investigation. We know we face increasing attacks from rogue states: it is spoken of now as being low-level warfare, and we have seen the effect in many other countries as democracies are under attack.

In conclusion, although we welcome the Bill, we are seriously concerned about its limitations. A start would be to align with the EU, which already recognises that a whole-of-economy approach is the right one. I look forward to the Minister’s response.