Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Julia Lopez Portrait Julia Lopez (Hornchurch and Upminster) (Con)
- View Speech - Hansard - -

I thank Members across the House for their contributions to this Bill over many months and for their relentless scrutiny. I have never known a Minister to be in such a rush, with three hours of protected time left. I am grateful to officials both in the Department for Science, Innovation and Technology and in Parliament for their hard work in getting this legislation to its final stage. I particularly recognise the hard work of my hon. Friend the Member for Runnymede and Weybridge (Dr Spencer) and his team in providing such top-notch scrutiny of the Bill during its passage through the House.

The Opposition have remained at all times supportive of the principles behind the Bill. It was the previous Government who recognised the need to increase cyber-resilience standards for critical digital infrastructure and services, including managed service providers and data centres. It is welcome that those entities—which are so vital to the functioning of the economy, public services and our daily lives—are now covered. However, I said on Second Reading that opportunities to legislate in this area are few and far between, and we need to ask two questions to assess whether this law is fit for purpose: will it work, and is it enough?

There was already an urgent need to strengthen our cyber-defences. However, AI is equipping hostile states, criminal gangs and opportunists alike with tools capable of eroding our national defences at speed and at scale, in ways that will affect businesses, the public sector and our infrastructure. It is right that Parliament legislates to raise the collective security bar, but the nature of the cyber-security risks that necessitated this Bill have developed rapidly as we have been taking it through this House. That demonstrates the difficulties we all face as legislators in dealing with the constantly shifting sands of the digital age. We may need to be ready to return to this subject sooner than we had hoped.

It is right that critical digital infrastructure such as data centres will fall within the scope of regulation, but we need to recognise that no security measures or standards are 100% effective. Government and businesses need to ensure that essential data and workloads are stored and processed in a way that keeps them secure and operational even when they are under attack. Resilience is key—the Islamic Revolutionary Guard Corps’ apparent targeting of Amazon Web Services sites in the United Arab Emirates and Bahrain earlier this year has shown that digital infrastructure is becoming a prime target in times of conflict. It would be irresponsible to assume that these facilities will not also be targets for cyber-warfare, which is why we have to look closely at concentration of risk, our overall resilience, and any leverage we can build in maintaining access to the best technology going forward. From work on the security of our telecoms infrastructure to scrutiny of the platforms on which critical Government services run, we must now be thinking extremely carefully about our procurement of digital technology.

A further significant development since this Bill was introduced is the rapid advance of AI systems capable of identifying cyber-vulnerabilities, particularly in poorly protected legacy IT across Government and public services, including the NHS. It highlights the urgent need to address the Government’s extensive legacy estate, which is especially exposed to exploitation. Nothing in the Bill addresses that need, yet the Government are creating a broader digital architecture for hackers to attack through their plan for Government-issued digital IDs.

If public trust is to be restored, especially after the Government’s abortive attempt to introduce mandatory ID last year—still, I fear, a risk by the back door—such systems must always remain both optional and secure. It is therefore concerning that the Public Accounts Committee felt compelled to write to the permanent secretary at the Department for Science, Innovation and Technology in April to criticise the lack of urgency in reviewing legacy IT equipment, given both the sensitivity of the data involved and the scale of the cyber-risk.

Earlier, my hon. Friend the Member for Runnymede and Weybridge set out one of the most significant threats that this Bill fails to address: the intensifying cyber-security risk posed by the Chinese Communist party and its affiliates. It is regrettable that the Government have, for a second time, voted down amendments that would have compelled the Secretary of State to create a register of hostile state actors threatening the cyber-security of essential networks and information systems. Those concerns are not restricted to Conservative Members, which is why the amendment tabled by my right hon. Friend the Member for Chingford and Woodford Green (Sir Iain Duncan Smith) attracted cross-party support.

The risks posed by cellular IOT modules have been set out expertly in the Chamber today. IOT modules supplied by Chinese manufacturers are now embedded in nearly all internet-connectable products and devices, from smart TVs to electric cars. They can be used to intercept data and track locations, and can even be controlled remotely. The scale of the cyber and physical security threat from IOT modules is the tip of the iceberg, with components that can be used for espionage or cyber-attacks or disabled remotely woven into countless aspects of our critical national infrastructure. This is an issue that is not going away.

In summary, although this Bill is necessary and goes some way towards enhancing our cyber-resilience in critical areas, it will not be enough in isolation. It heaps all the burden on the private sector, yet it would have been insufficient to prevent the Jaguar Land Rover incident. It does not address public sector vulnerabilities, and it falls far short of meeting the moment that the now former Defence Secretary, the right hon. Member for Rawmarsh and Conisbrough (John Healey), lamented that this Government were missing in their approach to our collective defence and security. It speaks to this Government’s continued inability to grapple with and address the red lights that are now flashing on the national dashboard.

The “corrosive complacency” that Lord Robertson called out in the Government’s approach to investment in defence can also be seen here, in the Government’s ongoing refusal to address the urgent threat to our national cyber-security caused by our reliance on technology and components from nations that have demonstrably malign intent. We are living with the uncomfortable reality that the end of history was a dangerous illusion; one that has led to us gradually outsourcing our critical industries to our geopolitical rivals and competitors, only to have their wares sold back to us in the form of latent time bombs.

That is why this legislation, which we support, can only be a discrete tool in addressing a much wider challenge. Cyber-security is no longer a niche compliance exercise; it is about protecting the fundamental economic and defence interests of our nation. That is why I suspect we will be returning to cyber issues in this House before too long, and with greater urgency.

Caroline Nokes Portrait Madam Deputy Speaker (Caroline Nokes)
- Hansard - - - Excerpts

I call the Liberal Democrat spokesperson.