All 1 Debates between Graeme Downie and Chi Onwurah

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Graeme Downie and Chi Onwurah
Graeme Downie Portrait Graeme Downie
- Hansard - -

That proves why we need more awareness of the threat that we face. It is not necessarily a case of banning certain components or technologies, but we must be more aware and ensure that the Government have the powers they need to respond where possible.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

My hon. Friend is right to say in his eloquent speech that raising awareness and having a debate about this issue is important, but the problems may not necessarily be the result of hostile actors. If the providers of the modules were to stop providing software updates, the modules would be more likely to fail and then become the subject of hostile attacks. So not only could the technology be killed by a hostile actor, but an increased dependency on software updates puts us at risk.

Graeme Downie Portrait Graeme Downie
- Hansard - -

As ever, my hon. Friend is correct. How many of us have had some bit of technology break because the firmware is no longer allowed to be updated, meaning that something no longer works, it is no longer supported and it breaks down immediately?

To add to that, by its nature, something that is not regularly updated becomes more vulnerable to attack by hackers. They may not be state sponsored, but they may take advantage of a weaker part of a technology. That was pointed out to me on a recent visit to Taiwan. Its semiconductor industry is incredibly strong, but it builds the more high-tech elements of semiconductors. I was told that it would not bother to commit to manufacturing other types of technology because they were too cheap and simple to make and could be mass produced. On that note, I refer to my entry in the Register of Members’ Financial Interests about the trip to Taiwan. I did not intend to raise it during my speech, but there was an opportunity to do so.

The third element of risk is data extraction, as was mentioned by the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). Under the Chinese national intelligence law, companies and organisations are legally required to assist state intelligence agencies and to hand over data upon request, creating a systemic risk in the UK that any data accessible through a cellular internet-of-things module could ultimately be accessible to the Chinese state.

Modern vehicles, especially electric and autonomous vehicles, are effectively computers on wheels, continuously collecting data on drivers, surroundings and infrastructure. The US Select Committee on China recently warned that Chinese EVs are “rolling data collection devices” and argued that restricting Chinese-made components is a national security imperative. The US Department of Commerce has now moved to limit the deployment of software and communications equipment sourced from adversary Governments in connected vehicles. Those who are worried about China’s reaction to such measures should be aware that it has already taken precisely these steps against the west. Tesla cars have been banned not just from entering Chinese defence, bases but from various Government agencies and authorities.

In the meeting mentioned by my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), I was concerned that there was a suggestion by one of the officials that there was no need to concern ourselves about the threat of Chinese internet-of-things modules because the threat was merely “theoretical”. As I and others have shown today, these examples are not just theoretical. Frankly, most threats are theoretical until they are not theoretical. This is happening now across critical sectors and national infrastructure. Other countries, such as the US, Australia and those in the EU, are all moving to toughen up their legislation specifically on cellular internet-of-things modules, and I believe that the UK must take action as well.

My amendments would ensure that the Bill explicitly covers these risks and gives Ministers the clarity and authority to act when necessary. If this Bill is to truly strengthen the UK’s cyber-resilience, it must not leave one of the most serious threats to our modern and increasingly digital world outside its scope. I ask the Government to work with me to address the threat of cellular IOT modules.