Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Ramsey of Wall Heath Excerpts
Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- View Speech - Hansard - - - Excerpts

My Lords, I support this Bill. I rather agree with those who have spoken previously that it is not particularly ambitious in its aims, but, if successful, it will be a largely useful piece of legislation. It is modest in its aims but liable to be of service for a period.

What it does not do is look forward very much. The threat landscape is deteriorating. I will not describe it, as that has been done well by others, but the criminals, and indeed other state operators, are leaders in technology adoption. We can be sure that AI is going to be used against us, and so we must be in a position to exploit it ourselves.

One of the conclusions that I draw from the discussion so far is that we will somehow have to learn to both legislate and make policy faster than we are doing at the moment. This Bill has taken a long time to get through the Commons. I hope that it will not take so long to get through this House. I suspect that we are already behind the curve again.

We have to learn to be willing to experiment and to change course if it is not working. We can take many views on the subject of whether we should have sectoral regulation or a single regulator—there are arguments in both directions. At the moment, I am, on the whole, willing to try sectoral regulation, which brings with it potentially more flexibility, as well as more complexity. If it does not work, we will need to be prepared to say that it is not working and that we will do something different. Changes of gear, and willingness to change gear, are things that we will have to come to terms with. When it is the case that we have not got it quite right, we will need to be prepared to say so.

The thrust of the Bill is certainly in the right direction. I will focus on some of the more detailed points in the drafting where I think we need to try to accomplish some improvements. There is quite a lot of looseness in the drafting, which needs tightening up. For example, terms such as “managed service provider” and “critical supplier”, as well as the wide definition of the notion of “incident”, all need greater precision. We need to avoid situations where words such as “incident” become a way in which companies that have no particular involvement get tangled up in regulation. If part of a company provides managed services, we need to know, and the company needs to know, whether the whole company is caught by the Bill or whether it is simply that part that provides managed services.

There is plenty of implementation detail on which we will need to have a closer fix. I am willing to give the Government the power to fill in the detail and update the law through secondary legislation, as it seems to me that we cannot always have primary legislation doing everything. However, we will need a duty to consult written into the Bill for it to be a safe proposition. One thing I would like to ask the Minister is about the timetable for secondary legislation. Will the Government be willing to consult when it comes to putting that through? That will be a very substantial part of the Bill.

I want to make a couple of comments about the effects of the scope of the Bill. First of all, with the exception of service providers, who are classed as “critical suppliers”, and data centres, the Bill, as other people have remarked, is exclusively concerned with the public sector. As the Government Minister and indeed others have pointed out, some of the biggest losses have occurred in the private sector. I do not need to describe these, as they have been described already.

The Government may argue that they properly seek not to regulate the private sector. I certainly have considerable sympathy with that, but it is not satisfactory from the point of view of the taxpayer that the Government had to bail out with public finance Jaguar Land Rover. Under current conditions, I do not think that that breach, which was expensive, is likely to be the last one with sizeable financial effect.

The Government have recognised the problem and are encouraging private sector companies to make a pledge to improve the management of cyber security at board level. I am all in favour of that: improve reporting in the corporate code and increase activity by the audit committee, whose members, if properly equipped with cyber expertise, will make a valuable contribution. That is part of the way that we must move forward. Having said all that, private sector security self-help, while essential, is not sufficient. So what should we do?

The Government correctly tell us that their first duty is the defence and security of the nation. Cyber security strategy—which I know something about, having been involved in it—was founded on the proposition that the protection of the economy involved active partnership between public and private sectors. The NCSC does a vital job in increasing understanding about the threat and giving advice and guidance on countering it, but it could do an even more important and larger job. It was intended at the outset to be more public-facing than is currently the case. It has, to some extent, retreated from its previous public start. I would like to see the NCSC re-emerge from the shadows with more threat analysis, advice and guidance, and its funding increased to do this.

This would be particularly helpful to SMEs. We have all been worried about their access to expertise and considered that the cost to them of security, which is not insignificant, should be somehow alleviated. They are valuable to us. Small companies provide very important parts of larger systems. If the NCSC were to be a much more active security partner to the corporate world, there would be a strong case for financial support from the private sector to it, to make this much more of a joint enterprise.

I urge the Government to put their intelligence capabilities to greater effect in supporting the private sector to raise its level of security. I do not think this is beyond us. We ought to try to do something where there is much closer co-operation between public and private sectors. The banking world, though different, gives us some pointers on the way in which that could be done.

Secondly, within the public sector, the scope of the Bill is puzzlingly selective, as other speakers have touched on. There is palpable anxiety among the general public about the security of One Login and accessing government services safely. This is a moment when the Government could increase confidence. However, not all government services are covered. To take an example, DWP has in its possession detailed personal—not to say intimate—information about its clients and beneficiaries. Surely it should be a candidate for coverage, but it is not. What are the criteria that govern whether a public sector service is covered or not? On the face of it, I do not think selectivity looks wise. The Government have chosen—

Baroness Ramsey of Wall Heath Portrait Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
- Hansard - -

I gently remind the noble Baroness that there is an eight minute advisory Back-Bench speaking time.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

I will conclude. The Bill recognises the need for regulatory co-operation, and it is certainly going to be very important if it is made to work. I also agree with those who think that we should align with things such as NIS2 to reduce the potential conflict between us and other international regulators.

My last thought is that we need to ensure that another definitional issue in the Bill, the level of security

“appropriate to the risk posed”,

is pinned down. There is a great deal in the Bill that we will want to talk about in Committee so that those implicated know exactly where their limits lie.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Ramsey of Wall Heath Excerpts
Baroness Ramsey of Wall Heath Portrait Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
- Hansard - -

I thank noble Lords for their amendments. Obviously, we miss the noble Lord, Lord Alton, who spoke to me this morning to emphasise his regret at not being able to be here. I think many noble Lords know the important reason why he cannot be, which he was keen to stress.

I thank all the noble Lords who spoke on this important amendment, which seeks to restrict overseas information sharing where there could be a risk to an individual’s right to a fair trial. I am sympathetic to noble Lords’ concerns. We must be rigorous in protecting fundamental liberties and the rule of law, both nationally and internationally. I understand that DCMS officials—there is a double D in DCMS; the first D is silent, so I hope that noble Lords been advised accordingly—have been working with teams across government to consider these concerns carefully. From this, I am confident that the risks identified by noble Lords are very low.

The information-sharing powers are discretionary. Regulators are under no obligation to share information overseas under the Bill. We work closely with all regulators and know that they are extremely cautious, sharing information internationally only when it is necessary to do so and after considering whether disclosing that information is in line with their public duties, including those under the Human Rights Act. I have listened carefully to the noble Lord, Lord Markham, my noble friend Lord Hunt and the noble Baroness, Lady Ludford, who all have their particular areas of interest and expertise. I will turn to a couple of those points in a minute.

In addition, the Bill adds further explicit safeguards that information must be disclosed only if it is relevant and proportionate. This requires regulators to exercise judgment and limit information only to that which is necessary for the purposes of the sharing. Requiring the Secretary of State to convene panels of experts in order to judge every instance of information sharing internationally would add a significant layer of bureaucracy. Given the very low risk and the safeguards already in place, that would be disproportionate and would slow or even halt legitimate essential international regulatory co-operation.

International collaboration has long been central to the NIS framework, with information-sharing essential to ensuring that tackling cyber threats is a global effort. The Bill ensures that our regime reflects the UK’s post-Brexit position by enabling effective co-operation with trusted international partners including close allies such as the US and Australia.

On the Hong Kong point raised by the noble Baroness, Lady Ludford, there is no uncertainty regarding UK-Hong Kong extradition. The UK suspended the treaty in 2020 and passed legislation to reflect the suspension in UK domestic law in 2025, completing the severing of ties between the Hong Kong and UK extradition systems. I hope that that addresses that point.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - - - Excerpts

I apologise for interrupting the noble Baroness. My understanding was that, although the treaty had been suspended, there could be consideration on a case-by-case, ad hoc basis. Is that wrong? Is there a complete ban on extradition or, notwithstanding the suspension of the treaty, could there still be a case-by-case, ad hoc extradition?

Baroness Ramsey of Wall Heath Portrait Baroness Ramsey of Wall Heath (Lab)
- Hansard - -

I thank the noble Baroness. I will write to her on the case-by-case point.

Finally, I know that my noble friend the Minister will be very happy to meet noble Lords again to discuss this further, as she has done quite recently with the noble Lord, Lord Alton.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

I thank the Minister for her response and noble Lords for their involvement. As suspected, the Committee is completely united in what we are trying to achieve, and I am pleased to hear that the Minister is sympathetic. I think we all agree that the devil will be in the detail. That is why I am grateful for the offer of a meeting, which I am sure that the noble Lord, Lord Alton, and many of us here will be delighted to take up.

I have a couple of concerns, and we will cover these in the meeting. As the Minister mentioned, there is no obligation for regulators. The question is: why leave it to their discretion? The Minister later said that there was concern about it being overburdensome on the Secretary of State’s officials to have to determine these cases. If it is too much of a burden for a group of experts, surely it is even less likely that regulators in all sorts of different fields are going to try to apply that same knowledge.

The concern about all of this is that, while the intentions are good, unless there are firm constraints in the Bill, it will just be something which, through no malcontent or wrong reason, is overlooked. That is why we feel it is very important that we have something in the Bill to add teeth to this. That is something that we would be delighted to explore further in meetings and on Report but at this point, I beg leave to withdraw the amendment.

Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Ramsey of Wall Heath Excerpts
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Clement-Jones, for opening the final day of Committee. For a Bill of such importance, I am surprised at the speed of our progress. However, if quantity has been low, quality has more than compensated.

I agree with the noble Lord that this Committee deserves rather more justification from the Government as to the need for the powers they are granting themselves. The Delegated Powers and Regulatory Reform Committee described the Clause 37(7) power as “unusual” and “novel”, capable of watering down requirements for consultation as it is not constrained by set criteria. The Government’s justification thus far for this power is that it allows them to

“prioritise the content of the code of practice, rather than arbitrary requirements”.

It sounds to me rather as if the Government’s position is that they see any set requirements for consultations and codes of practice as arbitrary. If that is the case—I would appreciate clarification from the Minister—I have to agree with the committee’s description that the position is “quite extraordinary”.

By the way, I noted this morning that the Chancellor of the Duchy of Lancaster has demanded an end to the culture of consultation. I fear that that will be quite a wrench for the former DSIT and its functions, it having launched four new consultations on a single day in July without having responded to the more than 11,000 responses to the AI and copyright consultation. We are already unclear about the machinery of government for that former department. Can the Minister tell us whether its existing and planned consultations will continue or whether today’s announcement represents a fundamental change of approach?

It is not clear why the power conferred by Clause 40(5) has to be sufficiently broad to allow the Government to water down the contents of reports on network and information systems. Could it not be amended, as the committee has recommended, so that the power cannot be used to reduce the requirements to report? It is not unreasonable to question whether the Government really need these extensive powers. Your Lordships’ Committee deserves at least more justification than the Government describing set criteria as arbitrary. I appreciate the need for flexible and adaptive approaches to legislating for fast-moving technologies, but that must come with accountability and I am not sure that we have the balance right at this point. I look forward to the Minister’s response.

Baroness Ramsey of Wall Heath Portrait Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
- Hansard - -

I thank the noble Lord for his Amendments 92C and 95C, and note that these amendments were recommended by the Delegated Powers and Regulatory Reform Committee in its report of 17 July. Some noble Lords may be aware that, until very recently, I was the chair of that committee. I am wondering how best to describe myself: am I gamekeeper turned poacher or poacher turned gamekeeper? I had better let noble Lords decide at the end of my responses.

These delegated powers were included to prevent a scenario where procedure takes priority over the best possible products, whether that be a code of practice or a report on the legislation. The delegated powers will not allow Ministers to bypass Parliament. They are about ensuring that government can respond quickly and effectively to new threats and new technologies that could undermine our national security. The law has always been slower than innovation, and it is unlikely to catch up unless we change our approach. Ministers must provide clear justification and carry out assessments before regulations are laid before Parliament.

On the code of practice, we anticipate that any code will be updated from time to time to remain effective, in line with the latest recommended good practice, evolving threat information and emerging technologies. Any revisions and reissues of a code of practice must first be consulted on with relevant stakeholders before they are effective.

On consultations, it might be above my pay grade to comment so soon after the Chancellor of the Duchy of Lancaster has commented, but I am sure that my noble friend the Minister will have a further response to that at some point, possibly in writing.

I assure noble Lords that the Government are carefully considering the committee’s recommendations and the views of noble Lords today, and will reflect accordingly ahead of Report. My noble friend the Minister will respond formally to the Delegated Powers and Regulatory Reform Committee in the usual manner ahead of Report.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

I thank the Minister for her response, which was the reverse of the usual ministerial response—the sting was not in the tail but at the beginning. The end was much more conciliatory, given that she said the Government will consider taking on board the DPRRC’s recommendations before Report. I very much hope they do. At this stage in Committee, of course, nothing gets decided, but I assure the Minister that, if this continues, and the Government do not respond in some shape or form to both those pretty solid recommendations from the committee, we will bring this back on Report.

When I say that the sting was in the beginning of the response, I mean that it was a bit surprising, given that the Minister has been the chair of the committee and knows the seriousness with which we all take its recommendations. A huge amount of work goes into the detail, and she knows how much store we place on the recommendations. I hope that she will use all her influence to make sure that the Government introduce before Report something along the lines of what I have produced. In the meantime, I beg leave to withdraw Amendment 92C.