Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Luke Myer Portrait Luke Myer (Middlesbrough South and East Cleveland) (Lab)
- View Speech - Hansard - - - Excerpts

My part of the world has already had a hard lesson in what a serious cyber-attack can do, and I thank the Liberal Democrat spokesperson, the hon. Member for Harpenden and Berkhamsted (Victoria Collins), for mentioning it. In 2020, Redcar and Cleveland council was hit by a cyber-attack that has been attributed to the Russian Conti syndicate, and around 135,000 residents were left without online public services. Systems were disrupted, and the cost was put at more than £10 million.

That is a story that has been repeated across our public and private sectors, and we have heard other examples today—my hon. Friend the Member for Leeds Central and Headingley (Alex Sobel) spoke about the NHS, and my hon. Friend the Member for Warwick and Leamington (Matt Western) spoke about manufacturers such as JLR. I echo their calls in the amendments they have tabled today, particularly about the need for last-resort powers in relation to data centres, but also for a national conversation about these issues. I have had discussions with constituents who are sceptical that the Russian state might attack a little council like ours, and it is important to get across the point that it is precisely because ours was low-hanging fruit that it was such a target for Russia.

That is exactly why this Bill is needed. Since the NIS regulations were introduced in 2018, the threat has changed; we are more interconnected and more reliant on cloud services, managed IT providers and data centres than ever before, often across long and complex supply chains. As such, it is very welcome that this Bill gives Ofcom a clearer role and brings significant data centre services into the regulatory framework, as well as relevant managed service providers and critical suppliers. The new reporting regime is a practical improvement as well—a 24-hour initial notification and a fuller report within 72 hours will help regulators and the National Cyber Security Centre to spot patterns, warn others and build a better national picture, which is especially important when we consider hostile states.

Cyber-security is plainly now a frontline part of our national defence—we have seen how Russian military intelligence activity is targeting Government and critical infrastructure, and we need to be equipped to respond. I am sympathetic to new clause 3, which relates to the role of foreign state bodies, but it ought to be broadened beyond critical and essential services. I will give an example that concerns the security of British citizens’ data from foreign Governments. Right now, the largest leveraged buy-out in history is under way—the takeover of global videogames maker Electronic Arts by Saudi Arabia and Jared Kushner’s Affinity Partners. They are buying access to the sensitive personal and behavioural data of 700 million players worldwide, as well as the ability to expand foreign influence in Britain. I urge the Government—both DSIT and the Department for Culture, Media and Sport—and the CMA to look at this deal with their eyes wide open. Ministers should be prepared to stand up for UK data, UK jobs and UK security.

The Chair of the Science, Innovation and Technology Committee, my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), mentioned interconnectedness between data security and national security. I endorse her amendments dealing with internet-of-things modules and the potential threat of hostile states switching off various pieces of infrastructure around our country. I also urge Ministers to keep pushing further on the threat of hostile state disinformation on social media, which has also been referenced in this debate. That is a fundamental security issue. Russia and others do not only try to knock systems offline; they also try to rot public trust, spread falsehoods and undermine democracy, so the technical threat and the information threat are part of the same hostile playbook. I do wonder whether regulators have sufficient resources to act, and I will listen carefully to the Minister’s remarks on new clause 7.

Ultimately, this Bill does not solve every problem, but it is a serious and necessary step forward. It strengthens resilience, widens responsibility, improves reporting, and gives Government clearer powers where national security is at risk. As such, I support the Bill.

Caroline Nokes Portrait Madam Deputy Speaker (Caroline Nokes)
- Hansard - -

I call the shadow Minister.

Ben Spencer Portrait Dr Ben Spencer (Runnymede and Weybridge) (Con)
- View Speech - Hansard - - - Excerpts

Before I begin, I would also like to make some remarks in commemoration of the 10th anniversary of the murder of Jo Cox. I never met Jo Cox. I never knew Jo Cox, and I am very sad that I did not, because having seen the impact she has had on our politics, on this place and on the people who knew her, she was clearly an incredible person. I do not think anyone can disagree with what she stood for, and in particular, that we have more in common in our politics. Our politics is worse off without her.

Yet again, we return to this Government’s vacant vacillation regarding our national security. I urge the Minister again to take this opportunity to strengthen UK cyber-security from the threat posed by foreign state actors. Protecting the UK and its citizens is the primary responsibility of Government, but still, in the face of clear evidence of increasing threats, this Government fail to act. The risk of physical threats and the need to invest in defence are clear to all, yet the Government prioritise increasing welfare spending over the safety and security of armed forces personnel and our country. The situation is so serious that the Defence Secretary had to resign, as he could not defend the inaction of this Government or the risks they are taking.

While the dangers presented to our cyber-security may be less visible, they are no less real. Hostile state actors are working every single hour of every single day to undermine our democracy and our security. These are risks that every Member across this House will be aware of. It is chilling to know that when Iran shut down its internet access, social media accounts purporting to be pro-independence Scottish people stopped tweeting. Expert analysis has estimated that thousands of similar accounts could originate in Iran and that as much as 26% of such accounts could be fake. Social media is now a weapon. We know that hostile state actors have sought to attack and undermine Parliament. Just last week we were told that spyware had been discovered in Government buildings linked to recent high-profile decisions regarding China’s controversial mega-embassy project in London.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - - - Excerpts

I beg to move, That the Bill be now read the Third time.

It has been a privilege to take this vital piece of legislation through the House. I thank everyone who has played a role in getting the Bill to this stage, including the noble Baroness Lloyd of Effra, who has been instrumental in driving the policy in this Bill and leading its passage in the other place. I also thank my right hon. Friend the Secretary of State for Science, Innovation and Technology; the officials who have worked tirelessly since the Bill’s inception; the Bill team, led by Shona Lester; the policy teams, led by Nick Dodd and Liam Harkin; the legal team, led by Alicia Swannell; and my private secretary, Ben Holloway. I also thank parliamentary counsel, the Clerks and the Chairs of the Public Bill Committee, and every Member of the House who served on the Committee, as well as Members who have provided important input today and during all previous stages.

This country is subject to daily and unrelenting cyber-attacks. This is no longer the stuff of science fiction, but a daily reality that threatens public services, businesses and even our ways of life. As Dr Richard Horne, the CEO of the National Cyber Security Centre, has said:

“The real-world impacts of cyber attacks have never been more evident than in recent months”.

The Bill delivers on the Government’s commitment to drive secure growth and make the UK more resilient to the threats we face. It recognises how things have moved on since 2018, with data centres playing an increasingly important role in our digital lives and supply chains continuing to diversify. It also recognises that things will continue to change, with a deliberate, technology-agnostic approach and proportionate powers to enable the Government to close regulatory gaps and respond to imminent national security threats.

Since the introduction of the Bill, I have tabled a small number of amendments to refine its drafting and ensure that it achieves its intended purposes. They include designating Ofcom as the sole regulator for data centres, to reduce administrative burdens and strengthen accountability in this key sector. They also include enabling the network and information systems regulators to share vital information with other regulators and public bodies overseeing sectors and vice versa, enabling more co-ordinated and strategic oversight without unnecessary business burdens. They also updated the definition of cloud computing to respond to important feedback from the sector and made several minor and technical corrections to ensure that the Bill can be practically implemented.

The version of the Bill before us is an ambitious, practical and proportionate piece of legislation. It is the result of engagement with industry, important regulator feedback, international dialogue and tireless work from officials. I wish Baroness Lloyd the best in moving the Bill forward in the other place, and I commend it to the House.

Caroline Nokes Portrait Madam Deputy Speaker (Caroline Nokes)
- Hansard - -

I call the shadow Secretary of State.

Julia Lopez Portrait Julia Lopez (Hornchurch and Upminster) (Con)
- View Speech - Hansard - - - Excerpts

I thank Members across the House for their contributions to this Bill over many months and for their relentless scrutiny. I have never known a Minister to be in such a rush, with three hours of protected time left. I am grateful to officials both in the Department for Science, Innovation and Technology and in Parliament for their hard work in getting this legislation to its final stage. I particularly recognise the hard work of my hon. Friend the Member for Runnymede and Weybridge (Dr Spencer) and his team in providing such top-notch scrutiny of the Bill during its passage through the House.

The Opposition have remained at all times supportive of the principles behind the Bill. It was the previous Government who recognised the need to increase cyber-resilience standards for critical digital infrastructure and services, including managed service providers and data centres. It is welcome that those entities—which are so vital to the functioning of the economy, public services and our daily lives—are now covered. However, I said on Second Reading that opportunities to legislate in this area are few and far between, and we need to ask two questions to assess whether this law is fit for purpose: will it work, and is it enough?

There was already an urgent need to strengthen our cyber-defences. However, AI is equipping hostile states, criminal gangs and opportunists alike with tools capable of eroding our national defences at speed and at scale, in ways that will affect businesses, the public sector and our infrastructure. It is right that Parliament legislates to raise the collective security bar, but the nature of the cyber-security risks that necessitated this Bill have developed rapidly as we have been taking it through this House. That demonstrates the difficulties we all face as legislators in dealing with the constantly shifting sands of the digital age. We may need to be ready to return to this subject sooner than we had hoped.

It is right that critical digital infrastructure such as data centres will fall within the scope of regulation, but we need to recognise that no security measures or standards are 100% effective. Government and businesses need to ensure that essential data and workloads are stored and processed in a way that keeps them secure and operational even when they are under attack. Resilience is key—the Islamic Revolutionary Guard Corps’ apparent targeting of Amazon Web Services sites in the United Arab Emirates and Bahrain earlier this year has shown that digital infrastructure is becoming a prime target in times of conflict. It would be irresponsible to assume that these facilities will not also be targets for cyber-warfare, which is why we have to look closely at concentration of risk, our overall resilience, and any leverage we can build in maintaining access to the best technology going forward. From work on the security of our telecoms infrastructure to scrutiny of the platforms on which critical Government services run, we must now be thinking extremely carefully about our procurement of digital technology.

A further significant development since this Bill was introduced is the rapid advance of AI systems capable of identifying cyber-vulnerabilities, particularly in poorly protected legacy IT across Government and public services, including the NHS. It highlights the urgent need to address the Government’s extensive legacy estate, which is especially exposed to exploitation. Nothing in the Bill addresses that need, yet the Government are creating a broader digital architecture for hackers to attack through their plan for Government-issued digital IDs.

If public trust is to be restored, especially after the Government’s abortive attempt to introduce mandatory ID last year—still, I fear, a risk by the back door—such systems must always remain both optional and secure. It is therefore concerning that the Public Accounts Committee felt compelled to write to the permanent secretary at the Department for Science, Innovation and Technology in April to criticise the lack of urgency in reviewing legacy IT equipment, given both the sensitivity of the data involved and the scale of the cyber-risk.

Earlier, my hon. Friend the Member for Runnymede and Weybridge set out one of the most significant threats that this Bill fails to address: the intensifying cyber-security risk posed by the Chinese Communist party and its affiliates. It is regrettable that the Government have, for a second time, voted down amendments that would have compelled the Secretary of State to create a register of hostile state actors threatening the cyber-security of essential networks and information systems. Those concerns are not restricted to Conservative Members, which is why the amendment tabled by my right hon. Friend the Member for Chingford and Woodford Green (Sir Iain Duncan Smith) attracted cross-party support.

The risks posed by cellular IOT modules have been set out expertly in the Chamber today. IOT modules supplied by Chinese manufacturers are now embedded in nearly all internet-connectable products and devices, from smart TVs to electric cars. They can be used to intercept data and track locations, and can even be controlled remotely. The scale of the cyber and physical security threat from IOT modules is the tip of the iceberg, with components that can be used for espionage or cyber-attacks or disabled remotely woven into countless aspects of our critical national infrastructure. This is an issue that is not going away.

In summary, although this Bill is necessary and goes some way towards enhancing our cyber-resilience in critical areas, it will not be enough in isolation. It heaps all the burden on the private sector, yet it would have been insufficient to prevent the Jaguar Land Rover incident. It does not address public sector vulnerabilities, and it falls far short of meeting the moment that the now former Defence Secretary, the right hon. Member for Rawmarsh and Conisbrough (John Healey), lamented that this Government were missing in their approach to our collective defence and security. It speaks to this Government’s continued inability to grapple with and address the red lights that are now flashing on the national dashboard.

The “corrosive complacency” that Lord Robertson called out in the Government’s approach to investment in defence can also be seen here, in the Government’s ongoing refusal to address the urgent threat to our national cyber-security caused by our reliance on technology and components from nations that have demonstrably malign intent. We are living with the uncomfortable reality that the end of history was a dangerous illusion; one that has led to us gradually outsourcing our critical industries to our geopolitical rivals and competitors, only to have their wares sold back to us in the form of latent time bombs.

That is why this legislation, which we support, can only be a discrete tool in addressing a much wider challenge. Cyber-security is no longer a niche compliance exercise; it is about protecting the fundamental economic and defence interests of our nation. That is why I suspect we will be returning to cyber issues in this House before too long, and with greater urgency.

Caroline Nokes Portrait Madam Deputy Speaker (Caroline Nokes)
- Hansard - -

I call the Liberal Democrat spokesperson.

--- Later in debate ---
Calum Miller Portrait Calum Miller (Bicester and Woodstock) (LD)
- Hansard - - - Excerpts

On a point of order, Madam Deputy Speaker. I seek your guidance. There are reports that a Russian warship has today fired warning shots near a UK-registered yacht in the English channel, south of the Isle of Wight. If verified, this action would be of grave concern to the House and would represent a significant escalation in the hostilities shown by Russian actors towards UK interests. Can you guide me on how the House might seek to be urgently updated by a Defence Minister on this development and guided as to the Government’s proposed response?

Caroline Nokes Portrait Madam Deputy Speaker (Caroline Nokes)
- Hansard - -

I thank the hon. Gentleman for his point of order. I have had no notice that the Government intend to bring a statement, but I am sure that those on the Government Front Bench have heard him, and should that change, we will doubtless hear before the Adjournment.