Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Caroline Nokes Portrait Madam Deputy Speaker (Caroline Nokes)
- Hansard - - - Excerpts

I call the shadow Minister.

Ben Spencer Portrait Dr Ben Spencer (Runnymede and Weybridge) (Con)
- View Speech - Hansard - -

Before I begin, I would also like to make some remarks in commemoration of the 10th anniversary of the murder of Jo Cox. I never met Jo Cox. I never knew Jo Cox, and I am very sad that I did not, because having seen the impact she has had on our politics, on this place and on the people who knew her, she was clearly an incredible person. I do not think anyone can disagree with what she stood for, and in particular, that we have more in common in our politics. Our politics is worse off without her.

Yet again, we return to this Government’s vacant vacillation regarding our national security. I urge the Minister again to take this opportunity to strengthen UK cyber-security from the threat posed by foreign state actors. Protecting the UK and its citizens is the primary responsibility of Government, but still, in the face of clear evidence of increasing threats, this Government fail to act. The risk of physical threats and the need to invest in defence are clear to all, yet the Government prioritise increasing welfare spending over the safety and security of armed forces personnel and our country. The situation is so serious that the Defence Secretary had to resign, as he could not defend the inaction of this Government or the risks they are taking.

While the dangers presented to our cyber-security may be less visible, they are no less real. Hostile state actors are working every single hour of every single day to undermine our democracy and our security. These are risks that every Member across this House will be aware of. It is chilling to know that when Iran shut down its internet access, social media accounts purporting to be pro-independence Scottish people stopped tweeting. Expert analysis has estimated that thousands of similar accounts could originate in Iran and that as much as 26% of such accounts could be fake. Social media is now a weapon. We know that hostile state actors have sought to attack and undermine Parliament. Just last week we were told that spyware had been discovered in Government buildings linked to recent high-profile decisions regarding China’s controversial mega-embassy project in London.

Jim McMahon Portrait Jim McMahon
- Hansard - - - Excerpts

I have often said about the device that was found in the Ministry of Housing, Communities and Local Government that unless someone is a member of staff, they cannot get to that side of the building without going through the Home Office. That obviously raises serious questions about the complex on Marsham Street more broadly. Does the shadow Minister accept that there is a pattern of foreign malign forces impacting our institutions, whether that is our Parliament or even the sovereignty of the United Kingdom itself? Unless there is resolve by Government and all parties in this place, we will not face that threat with the scale of response needed.

--- Later in debate ---
Ben Spencer Portrait Dr Spencer
- Hansard - -

I thank the hon. Gentleman for the knowledge and experience he brings to the background of that particular case. I entirely agree that it is incumbent on all parties across the House to strengthen our national security and to be clear-eyed about the threat of hostile state actors. I will continue to develop that point in my wind-up speech.

The evidence is clear that we face an increasing threat from foreign state actors. We need to take action to recognise those risks and to prevent such attacks. Cyber-security should be at the forefront of our defences, and for that reason, His Majesty’s loyal Opposition have focused again on amending the Bill, particularly with new clauses 14 and 15. We table them in the hope that the Government will not squander another opportunity to act in this Bill.

New clause 14 would require the Government to directly identify the threats we face, ending the prevarication we have seen in recent months by obliging the Secretary of State to establish and maintain by regulation a list of foreign powers presenting a significant cyber-security risk to the UK. The amendment would strengthen the link between intelligence agencies and policy enforcement, ensuring that decisions by the Secretary of State to deploy special national security direction powers are based on GCHQ’s verified risk assessments regarding hostile states and state-affiliated groups. It is not about reacting after an attack occurs, but creating a proactive framework to evaluate and mitigate threats, built directly into UK supply chains. That would ensure that the UK is better prepared to deal with cyber-threats and attacks from hostile state actors. With the risks continuing to grow, these decisions cannot remain at the political whim of a Government who are reluctant to act.

Let us talk about the dragon in the room. In 2024, the National Cyber Security Centre confirmed that China state-affiliated actors were responsible for cyber-attacks on the UK’s Electoral Commission and Parliament in 2021 and 2022, yet this Government continue to refuse to recognise China as a threat to the UK. New clause 14 would compel the Government to recognise formally what is readily apparent to those on these Benches, to our security services and to the many Members across both Houses who have expressed urgent concern about the security risks that China and other foreign state actors pose to the United Kingdom. The new clause would force the Government to acknowledge that China is a threat.

In view of this established and growing threat, our new clause 15 would compel the Secretary of State to review state-sponsored cyber-threats to the UK’s infrastructure, including the cyber-security risk to surrounding critical networks in the vicinity of the super-embassy site in the City of London. As I said in Committee, there is simply no point in granting the Secretary of State powers to issue directions on the basis of national security if the Government are not willing to be clear-eyed about the most critical national and cyber-security threats to this nation. The new clause also strikes an important balance between ensuring parliamentary scrutiny and recognising and protecting the sensitive nature of some of the material that may be unearthed, by making provision for such information to be sent to the Intelligence and Security Committee of Parliament.

I am pleased that, having resisted calls to address this risk during previous stages of the Bill’s progress, the Government have now taken some action to address risks from foreign state actors. The publication last week of their National Security (State Threats) Bill comes in response to a sharp spike in state-backed intelligence operations, sabotage and proxy violence. Their own explanatory notes to that Bill state:

“Threats to the UK from foreign states are persistent and take many forms, including espionage, foreign interference in the UK’s political system, sabotage, disinformation, cyber operations, and even assassinations. Collectively these are referred to by the Government as state threats.”

However, the Bill itself does not once mention cyber-security, and contains no provision requiring assessment of the risks posed. It does not apply to states themselves, and therefore can only be complemented and strengthened by new clauses 14 and 15, which no responsible Government or Member of the House could vote against.

Amendment 3, which would insert a provision headed “Exemption from disclosure: right to a fair trial”, was tabled by my right hon. Friend the Member for Chingford and Woodford Green (Sir Iain Duncan Smith). As a Member of Parliament whose constituency includes Runnymede, I am proud both to call him a friend and to work with him on, in particular, his fight for the rule of law and fair trials.

The amendment would prevent the sharing of information with overseas authorities for the purpose of prosecuting crimes not committed in the UK, if the Secretary of State determined that the receiving country was one in which the right to a fair trial could not be guaranteed. It would address genuine human rights concerns, and would close a loophole in the Bill that currently fails to anticipate politically motivated requests from authoritarian states. It would help to block hostile state actors such as Russia, China and Iran from probing our systems to detect firmware back doors or vulnerabilities within, for instance, the UK’s utility networks, healthcare systems and data centres. It would also create a statutory duty for the Secretary of State to submit an annual report to Parliament justifying decisions on which foreign jurisdictions are trusted or barred from intelligence sharing. That alone would be invaluable, and would end the many fruitless hours of questions and debate in the Chamber initiated by Conservative Members seeking a clear answer from the Government on whether they see countries such as China as a threat—per my earlier remarks. I am therefore pleased, on behalf of His Majesty’s Opposition, to support my right hon. Friend’s amendment.

Let me also pay tribute to the Chair of the Science, Innovation and Technology Committee, the hon. Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah). I thank her for her comments, which were echoed by others, about the risk from the internet of things and cellular modules. That is an important area, and we need to get it right.

I will conclude by addressing the amendments tabled by our Liberal Democrat colleagues regarding digital sovereignty and the impact that this approach could have on the UK. New clause 13 is the clearest demonstration to date that the Liberal Democrats do not understand the tech sector or global supply chains. Of course it is right to support British business, but it is not feasible or possible to achieve full sovereignty in a global market or supply chain. Rather, we should prioritise capacities and capabilities, and ensure that the UK has an indispensable role in global supply chains.

Victoria Collins Portrait Victoria Collins
- Hansard - - - Excerpts

I do not think that the hon. Member has understood our amendment, which is about having a strategy. It does not say that everything should be sovereign, but we need to look at our tech stack and have a strategy for what is sovereign and what requires the procurement of elements. I ask him to look at our amendment again.

Ben Spencer Portrait Dr Spencer
- Hansard - -

I refer the hon. Member to her new clause 13, particularly subsection 3(c), which makes it very clear that companies would need to deviate from “foreign technologies”, which would be quite a burden.

We need to back Britain in key sectors, from quantum and photonics to chip design and innovation. In so many areas, we lead the world. We should not try to restrict the influence and access of global markets. We must engage not in protectionism, but in leverage, to back Britain and position ourselves so that we are indispensable in the modern global tech sector and supply chains.

Jim Allister Portrait Jim Allister
- Hansard - - - Excerpts

Does the hon. Member agree that if we are to excel, we must excel on a UK-wide basis? Does he agree that it would be a very retrograde step to have part of this United Kingdom subject to another jurisdiction’s AI regulations, rather than those of the UK? Does he agree that it is imperative that the AI regulations that govern our digital sector are those of this Parliament and not those of the European Parliament?

Ben Spencer Portrait Dr Spencer
- Hansard - -

I do not want any part of the UK to be subject to the awful AI Act that has been passed by the European Union. Northern Ireland, and particularly Belfast, is a technological powerhouse of which we should be very proud. We need to ensure that it continues to go from strength to strength as part of our fantastic Union.

We on the Conservative Benches will not back new clause 13, because we understand how markets and global supply chains work. We believe in Britain.

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- View Speech - Hansard - - - Excerpts

I start by echoing the thoughts of many Members from across the House, particularly my hon. Friends the Members for Leeds Central and Headingley (Alex Sobel) and for Cowdenbeath and Kirkcaldy (Melanie Ward). I did not know Jo Cox, but I admired her deeply. As we talk about our country’s resilience, her central message—that there is no deeper route to resilience than through the unity of our country and community—is top of our minds for all of us in this House.

It is a pleasure to bring this important Bill back to the House this afternoon. The Bill will increase our cyber-defences and resilience, making the UK an even safer place to live and do business. I thank Members on both sides of the Chamber for their valuable contributions to this debate and for the expertise that they have brought throughout the passage of the Bill. I particularly thank them for their recognition of my core belief: that the central question for our national security and resilience is the question of our technological and AI capabilities.

We tested the Bill’s measures carefully before introduction, but we have since listened to feedback. There are a small number of minor, technical drafting improvements, which I will briefly go through. Government amendments 16 and 17 ensure that regulators can ask for the information they need to fulfil their obligations under the NIS regulations. This does not give regulators any new powers; it simply confirms that the current reasons for requesting information under the NIS regulations will still apply under the updated regulations.

Government amendments 7 and 8 make changes to align with two information-gathering Government amendments made in Committee—amendments 16 and 17. Government amendment 11 makes consequential changes following an amendment made in Committee. That amendment enables information sharing between NIS regulators and other public authorities for cyber-matters outside the scope of the NIS regulations.

Government amendments 14 and 15 clarify the safeguards for information sharing gateways, and amendments 9, 10, 12 and 13 make the necessary changes to ensure that the rest of the clause is consistent with the change made by amendment 14. Government amendments 18 to 26, to clause 57, allow regulators and the Secretary of State to issue notices related to the powers of direction to nominated representatives of regulated entities. I have also tabled Government amendment 27, which corrects minor drafting errors to ensure the Bill works as intended.

Members raised a series of questions, and I will address them thematically. First, the question of scope was raised by new clauses 4, 20, 21, 5, 8 and 9. I thank my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), the Chair of the Science, Innovation and Technology Committee, who brings consistent expertise and experience to these questions; the Chair of the Joint Committee on National Security Strategy, my hon. Friend the Member for Warwick and Leamington (Matt Western); and the hon. Members for Harpenden and Berkhamsted (Victoria Collins) and for Brecon, Radnor and Cwm Tawe (David Chadwick), who tabled amendments on the services and scope of the Bill.

All organisations, from high street shops to manufacturing giants, should take steps to increase their cyber-security and resilience. The Government and the National Cyber Security Centre are making sure that the right tools are available for every part of the economy. I am sympathetic to their intent, and in particular with my hon. Friend the Member for Middlesbrough South and East Cleveland (Luke Myer) when he talks about the impact of cyber-security incidents on local communities.

The Government have committed to reviewing whether new activities need to be brought into the scope of the NIS regulations, but it is essential that any such decision is based on a systematic and specific assessment of carefully considering whether the regulation in these particular parts of statute are the most appropriate response. The NIS regime has been put in place to protect the most essential parts of our economy, often those whose disruption would cause an imminent threat to life. It is focused on a specific set of tests where sectors have little or no alternative service provision in the event of disruption and relates the latest systematic evidence of the threats that each sector faces.

In that context, all Government Departments with sectoral responsibility work with their sectors on broader cyber-resilience. The Department for Environment, Food and Rural Affairs does so with food, and the Department for Business and Trade does so with retail, automotive and so on. The NCSC also has strong relationships across sectors, actively working with them to share best practice and incident insights, and to strengthen overall resilience, such as by engaging with the British Retail Consortium following incidents affecting the sector last year.

The food sector is unique among other critical sectors because of its high levels of diversity. In the analysis underpinning the judgments made in the Bill, there are approximately 20,000 SME food manufacturers in the UK alone, and many more farms, distribution centres, retailers and other types of businesses that form the UK’s food supply chain. Given the lack of a single point of failure, we think there are more proportionate levers to pull, rather than bringing food in scope of the NIS regime. We have made similar judgments about other sectors on the basis of that systematic analysis, as I have shared in Committee and at other stages of the Bill’s consideration.