Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateChi Onwurah
Main Page: Chi Onwurah (Labour - Newcastle upon Tyne Central and West)Department Debates - View all Chi Onwurah's debates with the Department for Science, Innovation & Technology
(1 month, 2 weeks ago)
Commons ChamberIt is a pleasure to follow the hon. Member for Harpenden and Berkhamsted (Victoria Collins). I would like to start by making two relevant declarations of interest. I worked for the Office of Communications before entering Parliament and I am currently a fellow of the Institution of Engineering and Technology. Madam Deputy Speaker, you might have heard me mention on occasion that I was an engineer before coming into Parliament. As such, in 2010, I was desperate for issues around technology to come up in Parliament, as it was a subject I actually knew something about, but they rarely did. In the intervening 16 years, however, things have changed, and technology issues such as online safety, wi-fi on trains, sovereign technology and infowars are now raised regularly.
I welcome the increasing role of technology in all our constituents’ lives, but this must go hand in hand with rigorous cyber-security to protect against threats from state and non-state actors. As I highlighted in my speech on Second Reading, the UK’s only cross-cutting cyber-security legislation is currently that inherited from the European Union. The previous Conservative Government failed to update these regulations, leaving us working under an outdated framework. I therefore really welcome this Bill, which seeks to expand the scope of existing cyber-security regulations to new sectors, strengthen the role of regulators and grant the Government new powers to respond to the threats posed by cyber-security breaches.
We are only as secure as our weakest link, but I am afraid we still have a number of weak links left. Cyber-attacks are having a real financial impact on the UK and are happening at an increasing rate. According to the Institution of Engineering and Technology, cyber-attacks cost UK businesses an estimated £64 billion annually, with £37 billion in direct costs and £26 billion in indirect costs. Last year we also saw the well-documented cyber-attack that hit Marks & Spencer, leaving shoppers unable to buy online from the company for months. The company’s profits were almost wiped out, down from £390 million to £3 million for the first half of 2025. As a Sparks card holder myself, I was unable to use my card for six months and I fear I may have contributed to those figures.
This brings me to my first amendment, new clause 20, which seeks to designate retail businesses as an essential activity, bringing them within scope of part 3 of the Bill. Retail is the UK’s largest private sector employer. It holds large amounts of consumer data but often relies on dated IT systems. Yet, as I noted on Second Reading, the existing scope of the Bill would not have prevented or even had an impact on the attacks on Marks & Spencer or Jaguar Land Rover, despite the significant disruption they caused to our constituents and our economic activity. Indeed, in November, the Bank of England cited the cyber-attack on JLR as a factor in its decision to hold interest rates.
The Government’s plan to promote the new cyber governance code of practice to improve pre-operative preparedness in sectors such as retail is welcome, but voluntary measures alone will not deliver the consistent adoption of good cyber governance across economically significant sectors such as retail. According to the Government’s figures, only 9,680 Cyber Essentials Plus certificates were issued to small and medium-sized businesses between November 2023 and October 2024. There are an estimated 6 million small and medium-sized enterprises in the UK, so this is not going to address that challenge at the rate at which it needs to be addressed.
I welcome the Opposition amendments that would bring retail businesses within the Bill’s scope, but I am concerned that they might be too extensive in bringing small and medium-sized businesses into its remit and placing a disproportionate burden on them. The revenue threshold of £12 billion in my new clause 20 provides the necessary specificity to ensure that only large retail businesses, including Marks & Spencer and Jaguar Land Rover, would fall under the expanded Network and Information Systems Regulations 2018. This would lead to faster incident-reporting responses and customer notification, alongside stronger powers, including those to deal with non-compliance.
Turning to my new clause 18, we have already heard that the concentration of the UK’s public sector data within a small number of US-owned providers—Amazon Web Services and Microsoft Azure specifically—presents a structural risk to national resilience. Combined, AWS and Microsoft account for 70% to 80% of the public cloud market, according to the Competition and Markets Authority. Part of the issue is that that figure is an estimate. I have put down a series of written parliamentary questions over the last seven years to find out just how dependent the Government are on AWS and Microsoft. This data is not tracked across Government. Can the Minister say how he intends to assess a threat that the Government are not measuring?
As set out in my Committee’s report entitled “Rewiring the state: Delivering digital government”, our national resilience is put at risk by the strategic lock-in that these companies have in many of our public services and Administrations. Major Departments, including His Majesty’s Revenue and Customs and the NHS, are under multi-year agreements that further entrench these cloud infrastructures within the Whitehall ecosystem. Included in my Committee’s report was evidence we heard from the Open Cloud Coalition, who suggested that the Department for Science, Innovation and Technology should consider a period of over-correction, including the mandatory re-competition of high-risk or large-scale contracts, to break cycles of vendor lock-in.
The Government are rightly seeking to co-ordinate cloud contracting, but I believe that this should be done in a way that would ensure more, not less, competition. We would like to see the detail of how the all-of-Government cloud contract will prevent vendor lock-in, and I would like the Minister to outline his engagement with the CMA on the contract’s development. Not only does our reliance on these two cloud services raise practical issues—as seen with the AWS outage in October—but there are questions around data protection. Under the Clarifying Lawful Overseas Use of Data Act and the Patriot Act, the US Government can compel US companies, including AWS and Microsoft, to hand over data if held overseas—that is, in the UK.
I am aware that the Minister might reference our sovereign hosting capability, Crown Hosting, but it hosts only 4% of Government legacy services. Will he please outline how the Government intend to ensure protection so that the public sector makes better use of the services provided by Crown Hosting? Could he also set out how he will ensure that the Government’s digital transformation ambitions cannot be derailed at any time by decisions based on the narrow interests of a foreign, commercial or state actor? He might choose to argue that this is highly unlikely, but I would point him to the recent decision of the US Government to withdraw foreign nationals’ access to Anthropic’s Fable 5 model.
Finally, my new clause 19 calls on the Secretary of State to conduct a review into the risks posed by foreign state ownership or control of providers of cellular internet-of-things modules. I always like to mention that I was the first Member of Parliament to speak about the internet of things, in my debate back in 2011. Having worked in technology as an engineer, the threat posed by cyber-attacks on the internet of things was very real to me from the start of my parliamentary career. Indeed, in 2017 I wrote an article highlighting the threat of cyber-attacks on sex toys, in a vain attempt to raise the profile of the issue.
The hon. Lady was very prescient then, and it has got worse since. There was lots of talk under the previous Administration about Downing Street cars being searched for IOTs. We know about the huge imports from bad actors, such as China and other countries—that is really what we should be worried about. Many of them contain kill switches, which would devastate some of our industry, such as energy. That would be a disaster. She is right to have raised the issue and to continue to raise it.
The right hon. Member does well to remind us that the impact of hostile action using CIMs, such as by turning on a kill switch, would be devastating across multiple sectors, including potentially the consumer sector, as well as security, automotive, transport and finance. That is why it is so important to consider this.
I particularly draw the Minister’s attention to the list provided by the US Federal Communications Commission—the equivalent of Ofcom—of equipment and services covered by section 2 of the Secure and Trusted Communications Networks Act. The list dictates what technology is legally permitted to be authorised for import and sale in the US, and many companies on the list are owned or controlled by the Chinese state. I thank the Minister in the other place for meeting me and my hon. Friend the Member for Dunfermline and Dollar (Graeme Downie), whose amendment I also support, and hearing our concerns about the supply of IOT devices. It was unfortunate that the Minister did not see the need for action, particularly given that the US has taken action against Chinese-made goods and that, during a trip of the British-American Parliamentary Group to the US just last week, we heard that further action is likely to be taken against cellular IOT modules specifically. That could mean UK products being banned from import into the US if they contain such CIMs.
We have seen a rapid growth of those devices across transport, as we have mentioned, as well as energy and, importantly, water and health. I am concerned about the ability of our domestic British businesses to export into the US given those restrictions, as well as the impact on our security. I would therefore be grateful if the Minister could set out whether he is looking into that concern.
As was eloquently emphasised in the personal statements made by the recently resigned Secretary of State for Defence, my right hon. Friend the Member for Rawmarsh and Conisbrough (John Healey), and Armed Forces Minister, my hon. Friend the Member for Birmingham Selly Oak (Al Carns), the first duty of Government is the security of their citizens. That is true when it comes to our armed forces and our defence in the real world, and it is also true when it comes to our security in the virtual world. Those two overlap so much more than in the past.
I welcome the Bill, but I have real concerns about the need to bring retail businesses such as M&S within its scope, the concentration of the UK’s public sector data in a small number of US-owned providers, the implications for technology sovereignty that that raises, and the risks posed by foreign state ownership of providers of cellular internet-of-things modules. I hope that the Minister will address those concerns and deliver the cyber-security and resilience that our constituents deserve.
It is always a great honour to follow the hon. Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), who talks common sense most of the time she gets up, which may be one of the reasons why she is still on the Back Benches. If we listened more to those who know something about things, rather than talking as though we know things, and saying things that are invariably wrong, we in Parliament would obviously be better off.
The greatest threat we face is that bad actors out there are using this level of technology to get across to countries such as the UK. This is not a party political point, because both Governments have failed to face up to it to the degree that they should have—that is why this Bill is welcome, but it is not everything, as the hon. Lady says—but we think that we can treat the bad actors as though they were normal actors in a commercial sense. However, China is using slave labour to undercut markets and regularly puts IOTs into cars. It gets away with it because we think that we need China more than it needs us. That is the big problem. The hon. Lady is right to raise it, and I congratulate her for again making an excellent speech.
I will in due course beg to move my amendment on anti-refoulement, because although this is a good Bill, some bits are missing and others have been skated over. This is one area about which we will come, again and again, to regret that we had not done more. The issue is British citizens abroad ending up under the rule of Governments that do not believe in the concept of freedom before the law, in a fair trial as part of that process, or in habeas corpus, which is an English common law right that has gone around the world.
The amendment seeks to prohibit data sharing with jurisdictions that cannot guarantee a fair trial. It maintains the current legal approach, which generally restricts the sharing of sensitive information outside the EU. Currently, information sharing of a type enabled by proposed new regulation 6, which is in clause 18, is prohibited outside the EU. The proposed new regulation is therefore weaker than what is going on in the European Union. Sadly, it paves the way for such sharing, rather than restricting it.
The amendment therefore seeks to prohibit information sharing with places where the Secretary of State believes that a fair trial simply cannot be obtained. It would require the Secretary of State to consult civil society and human rights experts to identify jurisdictions—this would apply universally and not just to China, although China is a big player in this—where the right to a fair trial cannot be guaranteed, with all decisions subject to mandatory annual reports to Parliament. That is important: Parliament should be part of this and make decisions about whether it agrees with the Government.
Beijing is a good example. It has frequently used seemingly legitimate criminal complaints to target dissidents. Proposed new regulation 6, if unamended, therefore raises transnational repression risks rather than solving them. The amendment is necessary to close that loophole in the Bill, which currently fails to anticipate politically motivated requests from such totalitarian states. I often say that we should stop speaking about countries such as China, Russia, Iran and North Korea as authoritarian states. They are not authoritarian states; they are totalitarian states. Why do I say that? Because everything in those countries is owned and run by the state. Authoritarian states are often dictatorships, but they are not the same thing as totalitarian states. They are brutal and nasty, but totalitarianism is a complete system. This is about totalitarian states.
Proposed new regulation 6 is predicated upon helping other Governments obtain justice. The argument of my amendment 3 is that—quite apart from the transnational repression risks—justice as we understand it cannot be served in a country where essentially there is no rule of law, no right to a fair trial, and a judicial system that serves the party. As I often say, it is a matter of pride that perhaps the greatest gift this country has given to the world is the concept of freedom in the face of the law. That is the point I made earlier: habeas corpus came from English common law and dominates so much of the free world’s thinking. It was not until the 1970s that some countries in Europe actually practised habeas corpus, so it was not just the case that it was produced by Britain; it was also owned by many other countries. That is what is at risk here, and we should be the greatest defenders of that right to a fair trial anywhere in the world.
Let us take a few of these countries as examples for why amendment 3 is needed. Let us look at China. Requests were made by authoritarian states—totalitarian states in this case—regarding Interpol notices, as has been the recent pattern, and this happens a lot. The People’s Republic of China and other countries have a troubling recent history of very significant transnational repression, hounding dissidents in the UK and cloaking their political persecution in superficially legitimate criminal charges. The PRC is not alone in requesting information on political opponents in the UK, and it does it a lot. We can confidently speculate that China will make requests of the UK almost immediately should the Bill be passed.
Let me look at the single biggest case that confronts us in China at the moment: that of Jimmy Lai. He is a British citizen. I cannot tell you, Madam Deputy Speaker, how endlessly in debates, even under the previous Administration, we had to fight to get the Government to state that he is a British citizen, not a dual nationality citizen. He is a British citizen, is proud to be British, has been British all his life and has only ever owned a British passport—he has never been a Chinese citizen with a Chinese passport.
The special rapporteur on torture, Alice Jill Edwards, in her 2024 and 2025 reports, specifically flagged concerns that evidence obtained through torture is still widely admitted in Chinese courts. She also expressed concerns in late 2024 regarding the case of Jimmy Lai in Hong Kong, noting that evidence allegedly secured through torture in mainland China was and is being used in the trial. On 15 November 2024, the United Nations working group on arbitrary detention published its opinion that Jimmy Lai is “unlawfully and arbitrarily detained” and called for his immediate release. The proposed new regulation will not go far enough and therefore does not deal with this, and that is what my amendment 3 is all about.
On the risk of extradition to China from safe third countries, currently the UK does not have a bilateral extradition treaty with the People’s Republic of China, and it has suspended its bilateral extradition treaty with Hong Kong—something that many of us were calling out for at the time in 2020. In 2025, proposed changes to the Extradition Act 2003 would allow co-operation between UK and Hong Kong authorities on a
“case-by-case ad hoc basis”.
The trouble with that is that it begins to open the door. The risk of sharing NIS data is not confined to the physical removal of individuals; it also poses a profound threat to national security and the safety of the diaspora within the UK—how often have we heard about that?
These totalitarian states not only seek to extradite dissidents, they seek to silence them through transnational repression and to compromise the UK’s own digital resilience. Sharing NIS data with an adversarial jurisdiction is akin to providing a road map for a state-sponsored cyber-attack. For dissidents and human rights defenders living in the UK, NIS data can be used to demonise and de-anonymise their activity. This information is frequently used to identify and harass family members remaining in their home country, to conduct targeted phishing and surveillance against the individual’s private devices, and to coerce the individual into becoming an informant under the threat of criminal charges based on the shared technical data.
Let me deal with another case: that of Ryan Cornelius in the United Arab Emirates. Ryan Cornelius is a British citizen who has been arbitrarily detained in Dubai for 18 years, despite well-documented evidence of an unfair trial and inhuman treatment. Ryan’s detention has been found to be arbitrary by the UN working group on arbitrary detention. His case arose from a high-profile financial dispute involving loans connected to a major Dubai development project. Although he and his associates had reportedly complied with restructuring agreements with Dubai Islamic Bank, he was arrested without warning, transferred by plain-clothed officers to a police facility, where he was held incommunicado, denied access to a lawyer and subjected to aggressive interrogation. During this time, he was coerced into signing documents in Arabic—a language he does not understand—under the false premise that this would give him his release.
Graeme Downie
That proves why we need more awareness of the threat that we face. It is not necessarily a case of banning certain components or technologies, but we must be more aware and ensure that the Government have the powers they need to respond where possible.
My hon. Friend is right to say in his eloquent speech that raising awareness and having a debate about this issue is important, but the problems may not necessarily be the result of hostile actors. If the providers of the modules were to stop providing software updates, the modules would be more likely to fail and then become the subject of hostile attacks. So not only could the technology be killed by a hostile actor, but an increased dependency on software updates puts us at risk.
Graeme Downie
As ever, my hon. Friend is correct. How many of us have had some bit of technology break because the firmware is no longer allowed to be updated, meaning that something no longer works, it is no longer supported and it breaks down immediately?
To add to that, by its nature, something that is not regularly updated becomes more vulnerable to attack by hackers. They may not be state sponsored, but they may take advantage of a weaker part of a technology. That was pointed out to me on a recent visit to Taiwan. Its semiconductor industry is incredibly strong, but it builds the more high-tech elements of semiconductors. I was told that it would not bother to commit to manufacturing other types of technology because they were too cheap and simple to make and could be mass produced. On that note, I refer to my entry in the Register of Members’ Financial Interests about the trip to Taiwan. I did not intend to raise it during my speech, but there was an opportunity to do so.
The third element of risk is data extraction, as was mentioned by the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). Under the Chinese national intelligence law, companies and organisations are legally required to assist state intelligence agencies and to hand over data upon request, creating a systemic risk in the UK that any data accessible through a cellular internet-of-things module could ultimately be accessible to the Chinese state.
Modern vehicles, especially electric and autonomous vehicles, are effectively computers on wheels, continuously collecting data on drivers, surroundings and infrastructure. The US Select Committee on China recently warned that Chinese EVs are “rolling data collection devices” and argued that restricting Chinese-made components is a national security imperative. The US Department of Commerce has now moved to limit the deployment of software and communications equipment sourced from adversary Governments in connected vehicles. Those who are worried about China’s reaction to such measures should be aware that it has already taken precisely these steps against the west. Tesla cars have been banned not just from entering Chinese defence, bases but from various Government agencies and authorities.
In the meeting mentioned by my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), I was concerned that there was a suggestion by one of the officials that there was no need to concern ourselves about the threat of Chinese internet-of-things modules because the threat was merely “theoretical”. As I and others have shown today, these examples are not just theoretical. Frankly, most threats are theoretical until they are not theoretical. This is happening now across critical sectors and national infrastructure. Other countries, such as the US, Australia and those in the EU, are all moving to toughen up their legislation specifically on cellular internet-of-things modules, and I believe that the UK must take action as well.
My amendments would ensure that the Bill explicitly covers these risks and gives Ministers the clarity and authority to act when necessary. If this Bill is to truly strengthen the UK’s cyber-resilience, it must not leave one of the most serious threats to our modern and increasingly digital world outside its scope. I ask the Government to work with me to address the threat of cellular IOT modules.
Kanishka Narayan
I am happy to the write to the Chair of the Select Committee about comparisons with the EU, but the broad thrust is that we have undertaken a specific analysis of whether the burdens of the Bill should apply in a systematic, proportionate and coherent way to sectors. The analysis suggests that food supply is not in scope for the reasons I mentioned—primarily diversity of supply—but I would be delighted to engage with him on the question of why Europe took a different decision. We have based our decision on our analysis here.
Kanishka Narayan
I am going to make some progress but will try to come back to the Chair of the Select Committee shortly.
The Government’s cyber action plan is the overarching strategy to raise public sector standards across Government, including local government. The Ministry of Housing, Communities and Local Government has taken action to strengthen local authorities’ cyber-resilience, backed by £29 million of cyber grant funding, technical support and the adoption of the cyber assessment framework for local government. In that spirit, I take particularly seriously the point made by my hon. Friend the Member for Oldham West, Chadderton and Royton (Jim McMahon) on supporting capacity even further with centralised capacity support from the Government Digital Service and other parts of cyber-capability in central Government.
The joint election security and preparedness unit, also raised by Members, works to protect UK elections and referendums, co-ordinating across Government on response to threats, including cyber-risks. JESP works closely with the National Cyber Security Centre, producing guidance for organisations involved in delivering elections and electoral infrastructure, particularly local authorities. JESP and NCSC regularly engage with political-party representatives as well.
The question of a register of foreign powers has been raised in relation to new clauses 14 and 15, tabled by the shadow Minister, the hon. Member for Runnymede and Weybridge (Dr Spencer). New clause 14 would require the creation of a register of foreign states that pose a risk to the UK, based on GCHQ advice, for the purpose of exercising powers under part 4 of the Bill. I assure the shadow Minister, as I did in Committee, that the use of those powers will always be underpinned by robust intelligence. That includes, where relevant, information about state actors involved in cyber-threats. As a result, it is unclear what additional support the register would provide to the Secretary of State.
New clause 15 would require the Government to report annually on risks posed by foreign powers. Drafting a report of vulnerabilities would simply duplicate existing assessments and risk distracting the Government from more effective measures to protect the UK from hostile foreign actors. The shadow Minister also proposes that information that cannot be included in the report for national security reasons is sent to the Intelligence and Security Committee. I have made it clear to him, both in Committee and more broadly, that the Government value the independent and robust oversight that the Intelligence and Security Committee provides on behalf of Parliament. However, we do not consider that the report described in the new clause sits within the ISC’s current oversight remit, as outlined in the Justice and Security Act 2013 and the Committee’s memorandum of understanding with the Prime Minister. The Government are actively reviewing the Committee’s existing memorandum of understanding and will update the House in due course.
New clause 3, tabled by the hon. Member for Harpenden and Berkhamsted, would require the Government to assess how many entities regulated by the NIS regime are owned, in part or in full, by foreign states, and the risks that they pose. Publishing a review identifying national security risks caused by foreign state ownership would provide valuable insight for our adversaries. Furthermore, conducting an assessment of the ownership structure of every in-scope entity within six months would be disproportionately resource intensive, and would distract the Government from more effective measures to protect our services.
Let me take the Minister back to the question of bringing the retail sector into the provisions of the Bill. He seems to be saying that cyber-security and resilience require Government intervention only when there is an immediate threat to life. Will he clarify whether that is what he is saying? My understanding is that we need to keep our economy and citizens secure in all circumstances. On the question of proportionality, my new clause 20 seeks to bring in only very large businesses, so that the requirements of cyber-security on them are proportionate. We know that such businesses are not taking the measures to keep cyber-secure, as we have seen recently with Marks & Spencer, Jaguar Land Rover and others.
Kanishka Narayan
As I say, I agree with much of the right hon. Gentleman’s diagnosis. Let me state in more detail the reasons for objecting on the mechanism. First, the provisions for information sharing are deeply discretionary for UK regulators. Secondly, the subjects in which they can pursue that information sharing are restricted to significant matters of national security and domestic crime prevention in the UK. Thirdly, the way that the amendment is drafted risks creating undue uncertainty in law. If this is the only regime where there is a specific and explicit reference to fair trial in the legislation, it calls into question how other information-sharing regimes are interpreted, such as under section 114 of the Online Safety Act 2023. In other words, drafted as it is, the amendment could invite legal challenge where a regulator exercises its discretion not to disclose this in other regimes, as there is no explicit exclusion. For those reasons, while I totally agree with the right hon. Gentleman’s diagnosis and his objective, I am afraid that the amendment in question risks undermining the objective.
Kanishka Narayan
I will not, because I am testing the patience of Madam Deputy Speaker—[Interruption.] With your permission, Madam Deputy Speaker, I will give way.
I thank the Minister for generously giving way again. I have no desire to test the House by pushing my amendments to a vote, and I will be happy if I can receive his assurance. I take his points on not having technology-specific regulation where possible, but can I have an assurance that the Minister will work with me, my Committee and other hon. Members to look at the need to safeguard where there are technology-specific risks?
Kanishka Narayan
As ever, I would be delighted to work with the Chair of the Select Committee on a range of technology questions, including this one.
I am delighted with the support that this House has shown for the intention and principles of the Bill, and I am grateful for Members’ consistent, principled scrutiny.