Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Ben Spencer Portrait Dr Spencer
- Hansard - - - Excerpts

I do not want any part of the UK to be subject to the awful AI Act that has been passed by the European Union. Northern Ireland, and particularly Belfast, is a technological powerhouse of which we should be very proud. We need to ensure that it continues to go from strength to strength as part of our fantastic Union.

We on the Conservative Benches will not back new clause 13, because we understand how markets and global supply chains work. We believe in Britain.

Kanishka Narayan Portrait The Parliamentary Under-Secretary of State for Science, Innovation and Technology (Kanishka Narayan)
- View Speech - Hansard - -

I start by echoing the thoughts of many Members from across the House, particularly my hon. Friends the Members for Leeds Central and Headingley (Alex Sobel) and for Cowdenbeath and Kirkcaldy (Melanie Ward). I did not know Jo Cox, but I admired her deeply. As we talk about our country’s resilience, her central message—that there is no deeper route to resilience than through the unity of our country and community—is top of our minds for all of us in this House.

It is a pleasure to bring this important Bill back to the House this afternoon. The Bill will increase our cyber-defences and resilience, making the UK an even safer place to live and do business. I thank Members on both sides of the Chamber for their valuable contributions to this debate and for the expertise that they have brought throughout the passage of the Bill. I particularly thank them for their recognition of my core belief: that the central question for our national security and resilience is the question of our technological and AI capabilities.

We tested the Bill’s measures carefully before introduction, but we have since listened to feedback. There are a small number of minor, technical drafting improvements, which I will briefly go through. Government amendments 16 and 17 ensure that regulators can ask for the information they need to fulfil their obligations under the NIS regulations. This does not give regulators any new powers; it simply confirms that the current reasons for requesting information under the NIS regulations will still apply under the updated regulations.

Government amendments 7 and 8 make changes to align with two information-gathering Government amendments made in Committee—amendments 16 and 17. Government amendment 11 makes consequential changes following an amendment made in Committee. That amendment enables information sharing between NIS regulators and other public authorities for cyber-matters outside the scope of the NIS regulations.

Government amendments 14 and 15 clarify the safeguards for information sharing gateways, and amendments 9, 10, 12 and 13 make the necessary changes to ensure that the rest of the clause is consistent with the change made by amendment 14. Government amendments 18 to 26, to clause 57, allow regulators and the Secretary of State to issue notices related to the powers of direction to nominated representatives of regulated entities. I have also tabled Government amendment 27, which corrects minor drafting errors to ensure the Bill works as intended.

Members raised a series of questions, and I will address them thematically. First, the question of scope was raised by new clauses 4, 20, 21, 5, 8 and 9. I thank my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), the Chair of the Science, Innovation and Technology Committee, who brings consistent expertise and experience to these questions; the Chair of the Joint Committee on National Security Strategy, my hon. Friend the Member for Warwick and Leamington (Matt Western); and the hon. Members for Harpenden and Berkhamsted (Victoria Collins) and for Brecon, Radnor and Cwm Tawe (David Chadwick), who tabled amendments on the services and scope of the Bill.

All organisations, from high street shops to manufacturing giants, should take steps to increase their cyber-security and resilience. The Government and the National Cyber Security Centre are making sure that the right tools are available for every part of the economy. I am sympathetic to their intent, and in particular with my hon. Friend the Member for Middlesbrough South and East Cleveland (Luke Myer) when he talks about the impact of cyber-security incidents on local communities.

The Government have committed to reviewing whether new activities need to be brought into the scope of the NIS regulations, but it is essential that any such decision is based on a systematic and specific assessment of carefully considering whether the regulation in these particular parts of statute are the most appropriate response. The NIS regime has been put in place to protect the most essential parts of our economy, often those whose disruption would cause an imminent threat to life. It is focused on a specific set of tests where sectors have little or no alternative service provision in the event of disruption and relates the latest systematic evidence of the threats that each sector faces.

In that context, all Government Departments with sectoral responsibility work with their sectors on broader cyber-resilience. The Department for Environment, Food and Rural Affairs does so with food, and the Department for Business and Trade does so with retail, automotive and so on. The NCSC also has strong relationships across sectors, actively working with them to share best practice and incident insights, and to strengthen overall resilience, such as by engaging with the British Retail Consortium following incidents affecting the sector last year.

The food sector is unique among other critical sectors because of its high levels of diversity. In the analysis underpinning the judgments made in the Bill, there are approximately 20,000 SME food manufacturers in the UK alone, and many more farms, distribution centres, retailers and other types of businesses that form the UK’s food supply chain. Given the lack of a single point of failure, we think there are more proportionate levers to pull, rather than bringing food in scope of the NIS regime. We have made similar judgments about other sectors on the basis of that systematic analysis, as I have shared in Committee and at other stages of the Bill’s consideration.

Matt Western Portrait Matt Western
- Hansard - - - Excerpts

I accept the point about the plethora of businesses in the food supply sector, but my amendment simply seeks commonality with what the European Union has pushed for. Why can it not be the right thing for the UK Government to do as well?

Kanishka Narayan Portrait Kanishka Narayan
- View Speech - Hansard - -

I am happy to the write to the Chair of the Select Committee about comparisons with the EU, but the broad thrust is that we have undertaken a specific analysis of whether the burdens of the Bill should apply in a systematic, proportionate and coherent way to sectors. The analysis suggests that food supply is not in scope for the reasons I mentioned—primarily diversity of supply—but I would be delighted to engage with him on the question of why Europe took a different decision. We have based our decision on our analysis here.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

Will the Minister give way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

I am going to make some progress but will try to come back to the Chair of the Select Committee shortly.

The Government’s cyber action plan is the overarching strategy to raise public sector standards across Government, including local government. The Ministry of Housing, Communities and Local Government has taken action to strengthen local authorities’ cyber-resilience, backed by £29 million of cyber grant funding, technical support and the adoption of the cyber assessment framework for local government. In that spirit, I take particularly seriously the point made by my hon. Friend the Member for Oldham West, Chadderton and Royton (Jim McMahon) on supporting capacity even further with centralised capacity support from the Government Digital Service and other parts of cyber-capability in central Government.

The joint election security and preparedness unit, also raised by Members, works to protect UK elections and referendums, co-ordinating across Government on response to threats, including cyber-risks. JESP works closely with the National Cyber Security Centre, producing guidance for organisations involved in delivering elections and electoral infrastructure, particularly local authorities. JESP and NCSC regularly engage with political-party representatives as well.

The question of a register of foreign powers has been raised in relation to new clauses 14 and 15, tabled by the shadow Minister, the hon. Member for Runnymede and Weybridge (Dr Spencer). New clause 14 would require the creation of a register of foreign states that pose a risk to the UK, based on GCHQ advice, for the purpose of exercising powers under part 4 of the Bill. I assure the shadow Minister, as I did in Committee, that the use of those powers will always be underpinned by robust intelligence. That includes, where relevant, information about state actors involved in cyber-threats. As a result, it is unclear what additional support the register would provide to the Secretary of State.

New clause 15 would require the Government to report annually on risks posed by foreign powers. Drafting a report of vulnerabilities would simply duplicate existing assessments and risk distracting the Government from more effective measures to protect the UK from hostile foreign actors. The shadow Minister also proposes that information that cannot be included in the report for national security reasons is sent to the Intelligence and Security Committee. I have made it clear to him, both in Committee and more broadly, that the Government value the independent and robust oversight that the Intelligence and Security Committee provides on behalf of Parliament. However, we do not consider that the report described in the new clause sits within the ISC’s current oversight remit, as outlined in the Justice and Security Act 2013 and the Committee’s memorandum of understanding with the Prime Minister. The Government are actively reviewing the Committee’s existing memorandum of understanding and will update the House in due course.

New clause 3, tabled by the hon. Member for Harpenden and Berkhamsted, would require the Government to assess how many entities regulated by the NIS regime are owned, in part or in full, by foreign states, and the risks that they pose. Publishing a review identifying national security risks caused by foreign state ownership would provide valuable insight for our adversaries. Furthermore, conducting an assessment of the ownership structure of every in-scope entity within six months would be disproportionately resource intensive, and would distract the Government from more effective measures to protect our services.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

Let me take the Minister back to the question of bringing the retail sector into the provisions of the Bill. He seems to be saying that cyber-security and resilience require Government intervention only when there is an immediate threat to life. Will he clarify whether that is what he is saying? My understanding is that we need to keep our economy and citizens secure in all circumstances. On the question of proportionality, my new clause 20 seeks to bring in only very large businesses, so that the requirements of cyber-security on them are proportionate. We know that such businesses are not taking the measures to keep cyber-secure, as we have seen recently with Marks & Spencer, Jaguar Land Rover and others.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

It is rare for me to have a point of divergence with the Chair of the Select Committee, given her experience and expertise. However, on that question I am absolutely not saying that Government support is limited only to the certain number of sectors covered by the Bill. There are a range of other ways in which the Government act to support sectors outside of the scope of the Bill. That is the right thing to do.

The scope of this Bill—the only Bill horizontally applicable to large parts of the economy—is systematically and specifically set to sectors that are significant as essential services, sectors where there is the risk of significant disruption and threat to life, and sectors where alternative supply is limited. For those reasons, we have excluded retail. Consideration of the scale of the business is not currently in that rubric, because there are also businesses that are small in scale but very material in life-threatening impact. I hope that is a satisfactory answer.

I thank my hon. Friends the Members for Dunfermline and Dollar (Graeme Downie) and for Newcastle upon Tyne Central and West for their amendments relating to the risks posed by communications modules made or controlled from outside the UK. Although I am sympathetic to their concerns, the Bill’s approach is intentionally technology and incident-agnostic. Instead of reacting to individual components in isolation, we focus on structural checkpoints and systematic dependencies in this context.

There are a range of other levers—investment screening through the National Security and Investment Act 2021; telecoms and cyber data security requirements to protect data and networks; supply chain measures, such as those in the Procurement Act 2023; diversification requirements to reduce dependency and build resilience—all of which are important to respond to the deeply significant concerns raised.

Graeme Downie Portrait Graeme Downie
- Hansard - - - Excerpts

Will the Minister give way on that point?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

I will make some further progress.

I thank my hon. Friend the Member for Leeds Central and Headingley for his amendment relating to AI emergencies. I recognise his concerns, as well as those of my hon. Friend the Member for Cowdenbeath and Kirkcaldy. Technology is evolving rapidly, and Government must be equipped to respond. That is why the Bill grants the Secretary of State the power to direct regulated entities if the compromise of their network and information system, or the threat of it, gives rise to a national security risk. This could, for instance, require an entity to cease using and isolate an AI model.

These powers are a backstop to an effective cyber-security regime, enabling Government to act swiftly in the face of unexpected national security threats. They are also designed to be proportionate, recognising the need for stability among regulated entities and the importance of proper accountability. While I share my hon. Friends’ concerns, I encourage them to work with the Government on a systematic range of ways in which we can mitigate the risks they have rightly highlighted.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

I will give way to my hon. Friend the Member for Leeds Central and Headingley in the first instance and then to my hon. Friend the Member for Dunfermline and Dollar.

Alex Sobel Portrait Alex Sobel
- Hansard - - - Excerpts

There is obviously a level of complexity here in relation to the data centre, AI development and the network in the UK and more broadly. Will the Minister therefore commit to a meeting with me and my hon. Friend the Member for Cowdenbeath and Kirkcaldy (Melanie Ward) to discuss this matter further?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

I would be delighted to.

Graeme Downie Portrait Graeme Downie
- Hansard - - - Excerpts

I would be more than happy to work with the Government on something that will provide specific protections against cellular internet-of-things modules. What assessment has he made of the specific threat of internet-of-things modules, and what protections are there against that in the legislation?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

Given the specificity of his question, I will suggest that I come back to my hon. Friend. The broad thrust is that through our investment control legislation and procurement legislation, there are a series of responsibilities on Departments to look at it. [Interruption.] Given your encouragement, Madam Deputy Speaker, I shall move on.

Finally, I will respond to the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith), who raised a very important point. The most important thing to say is that I share his diagnosis, although for reasons mostly of technical drafting, I disagree with his prescription—I hope he will take that in the spirit in which it is intended. His amendment risks creating undue uncertainty in law for many other areas where we do not have an explicit requirement. While I share his diagnosis and his objective, I hope that we can work together to consider how best to give it effect, including through the Foreign, Commonwealth and Development Office’s overseas security and justice mechanisms for information sharing.

I thank all hon. Members for their consideration.

Jim Allister Portrait Jim Allister
- Hansard - - - Excerpts

I want to draw the Minister back to a point I raised with him at an earlier stage of the Bill, when he gave me what I would call a holding reply. When this legislation goes through, will the whole United Kingdom be subject to it, or will my part of the United Kingdom—Northern Ireland—be subject to the EU’s AI laws as they affect the digital sector? Businesses in that industry in my constituency want to know whether they will be governed by this Bill or by the EU’s AI Act. In other words, will the EU’s AI Act and Cyber Resilience Act be added to annex 2 to the Windsor framework, which would give them superiority and direct application in Northern Ireland? Can we have an answer—are they going to be added or not?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

The hon. and learned Gentleman will be aware from a response I recently gave him that both the complexity of the EU’s AI Act and its interaction with the Windsor framework are under consideration at the moment. The EU has made a proposal and we are working with it on that. I will be happy to engage with him on that particular question in due course.

Iain Duncan Smith Portrait Sir Iain Duncan Smith
- Hansard - - - Excerpts

I am not quite certain that I understand the Minister’s reasons for why he cannot accept my amendment, tweak it or work with it in the other place. The reality is that with this Bill, we are opening the door in a way that we would not have otherwise done to the use of information that may predicate a failure for some British citizen sitting in a country where the rule of law does not protect them in the courts. The Government are taking a risk of making it worse, not better. While the Minister agrees to some degree with the principle of what I am saying, surely this is the time to put it right in the Bill.

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

As I say, I agree with much of the right hon. Gentleman’s diagnosis. Let me state in more detail the reasons for objecting on the mechanism. First, the provisions for information sharing are deeply discretionary for UK regulators. Secondly, the subjects in which they can pursue that information sharing are restricted to significant matters of national security and domestic crime prevention in the UK. Thirdly, the way that the amendment is drafted risks creating undue uncertainty in law. If this is the only regime where there is a specific and explicit reference to fair trial in the legislation, it calls into question how other information-sharing regimes are interpreted, such as under section 114 of the Online Safety Act 2023. In other words, drafted as it is, the amendment could invite legal challenge where a regulator exercises its discretion not to disclose this in other regimes, as there is no explicit exclusion. For those reasons, while I totally agree with the right hon. Gentleman’s diagnosis and his objective, I am afraid that the amendment in question risks undermining the objective.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

Will the Minister give way?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

I will not, because I am testing the patience of Madam Deputy Speaker—[Interruption.] With your permission, Madam Deputy Speaker, I will give way.

Chi Onwurah Portrait Dame Chi Onwurah
- Hansard - - - Excerpts

I thank the Minister for generously giving way again. I have no desire to test the House by pushing my amendments to a vote, and I will be happy if I can receive his assurance. I take his points on not having technology-specific regulation where possible, but can I have an assurance that the Minister will work with me, my Committee and other hon. Members to look at the need to safeguard where there are technology-specific risks?

Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

As ever, I would be delighted to work with the Chair of the Select Committee on a range of technology questions, including this one.

I am delighted with the support that this House has shown for the intention and principles of the Bill, and I am grateful for Members’ consistent, principled scrutiny.

Alex Sobel Portrait Alex Sobel
- Hansard - - - Excerpts

On the amendment from the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith), I think we have made some progress with the Minister, but it is clear that trying to isolate the issues around fair trial from other matters is complex. Repeating my earlier call, will the Minister meet me, the right hon. Member for Chingford and Woodford Green and others who signed his amendment to explore the complexities of this after the debate?

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

I can confirm that the Government will be very happy to engage on this question further with my hon. Friend and the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). I commend the Bill to the House.

Victoria Collins Portrait Victoria Collins
- Hansard - - - Excerpts

Before I withdraw new clause 2, I want to draw Members’ attention to my entry in the Register of Members’ Financial Interests in reference to my earlier speech. I beg to ask leave to withdraw the clause.

Clause, by leave, withdrawn.

New Clause 13

Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies

“(1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy (“a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by—

(a) assessing, managing and mitigating risks—

(i) associated with foreign interference,

(ii) arising from reliance on foreign-supplied technologies, and

(b) preventing over-reliance on foreign providers by building domestic capacity.

(2) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to—

(a) an operator of an essential service,

(b) a relevant digital service provider,

(c) a relevant managed service provider, or

(d) a critical supplier, within the meaning of the NIS Regulations.

(3) A Digital Sovereignty Strategy published under this section must—

(a) include risks associated with—

(i) hardware,

(ii) software,

(iii) supply chains, and

(iv) procurement processes;

(b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption;

(c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and

(d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems.”—(Victoria Collins.)

This new clause would require the Government to publish a Digital Sovereignty Strategy setting out how it intends to address risks to relevant network and information systems posed by foreign interference and reliance on foreign technologies, including by supporting the use of domestic technologies.

Brought up, and read the First time.

Question put, That the clause be read a Second time.

--- Later in debate ---
Kanishka Narayan Portrait Kanishka Narayan
- Hansard - -

I beg to move, That the Bill be now read the Third time.

It has been a privilege to take this vital piece of legislation through the House. I thank everyone who has played a role in getting the Bill to this stage, including the noble Baroness Lloyd of Effra, who has been instrumental in driving the policy in this Bill and leading its passage in the other place. I also thank my right hon. Friend the Secretary of State for Science, Innovation and Technology; the officials who have worked tirelessly since the Bill’s inception; the Bill team, led by Shona Lester; the policy teams, led by Nick Dodd and Liam Harkin; the legal team, led by Alicia Swannell; and my private secretary, Ben Holloway. I also thank parliamentary counsel, the Clerks and the Chairs of the Public Bill Committee, and every Member of the House who served on the Committee, as well as Members who have provided important input today and during all previous stages.

This country is subject to daily and unrelenting cyber-attacks. This is no longer the stuff of science fiction, but a daily reality that threatens public services, businesses and even our ways of life. As Dr Richard Horne, the CEO of the National Cyber Security Centre, has said:

“The real-world impacts of cyber attacks have never been more evident than in recent months”.

The Bill delivers on the Government’s commitment to drive secure growth and make the UK more resilient to the threats we face. It recognises how things have moved on since 2018, with data centres playing an increasingly important role in our digital lives and supply chains continuing to diversify. It also recognises that things will continue to change, with a deliberate, technology-agnostic approach and proportionate powers to enable the Government to close regulatory gaps and respond to imminent national security threats.

Since the introduction of the Bill, I have tabled a small number of amendments to refine its drafting and ensure that it achieves its intended purposes. They include designating Ofcom as the sole regulator for data centres, to reduce administrative burdens and strengthen accountability in this key sector. They also include enabling the network and information systems regulators to share vital information with other regulators and public bodies overseeing sectors and vice versa, enabling more co-ordinated and strategic oversight without unnecessary business burdens. They also updated the definition of cloud computing to respond to important feedback from the sector and made several minor and technical corrections to ensure that the Bill can be practically implemented.

The version of the Bill before us is an ambitious, practical and proportionate piece of legislation. It is the result of engagement with industry, important regulator feedback, international dialogue and tireless work from officials. I wish Baroness Lloyd the best in moving the Bill forward in the other place, and I commend it to the House.

Caroline Nokes Portrait Madam Deputy Speaker (Caroline Nokes)
- Hansard - - - Excerpts

I call the shadow Secretary of State.