Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Birt
Main Page: Lord Birt (Crossbench - Life peer)Department Debates - View all Lord Birt's debates with the Department for Science, Innovation & Technology
(2Â months, 2Â weeks ago)
Lords ChamberMy Lords, the Government’s own cyber survey reports that 43% of UK businesses experienced a cyber attack last year, costing the UK economy an estimated £15 billion. Here are just a few examples of those many attacks: a deepfake video call cost Arup £20 million; Marks & Spencer was attacked in Easter last year, losing an estimated £300 million, with operations fully restored only three months later; and, most impactful of all so far, Jaguar Land Rover suffered an attack, had to halt production for around five weeks, was unable fully to restore its supply chains for four months and lost around £500 million. Moreover, the Government had to step in and guarantee a loan of £1.5 billion to stabilise JLR’s extensive supply chain. Yet our economy is barely touched by the Bill, as the noble Baroness, Lady Northover, just identified.
I think that a lot of people, untutored, have a mental model of a technology platform as something you might offload off the back of an HGV; in reality, any technology platform, even in a medium-sized business, can be a highly complex network composed of hundreds of providers, any component of which can present a vulnerability. Just two examples among very many are the widespread reliance by providers on free-to-use but vulnerable open-source software maintained by volunteers, and the external software providers bolted on to a technology platform offering a myriad of services —for example, payroll, finance, logistics, e-commerce or customer relationship management.
There is a possible vulnerability in every part of this complex network of providers, with many doors to pry open. Once one door is opened by a bad actor—a fraudster, a foreign power, a hacktivist or a ransom gang—there is the potential to explore and disable much or all of the system. Entry can be through a clever phishing email, perhaps AI-personalised with stolen data, or through application, network and infrastructure vendors failing to close down vulnerabilities immediately they are identified.
Here is a frightening example: a Chinese entity was able to penetrate a large number of services provided by Microsoft to the US Government. As a result, the mailboxes of the Secretary of Commerce and the US ambassador to China, among many, were read. In a coruscating report, the Cyber Safety Review Board, the US government agency that investigated the breach, concluded that
“Microsoft’s security culture was inadequate”
and that the incident resulted from
“the cascade of Microsoft’s avoidable errors”.
We need to act now, to protect our wider economy as well as our public sector institutions.
I am not a technologist, but for three decades I have had to deal constantly with digital technologies and technologists from a position of authority in many large organisations in the public and private sectors, at national, European and global level. I have discussed the Bill extensively with technology and cyber experts who I know and respect, and it has become perfectly clear to me that the Bill as constructed does not begin to match the threats that we in the UK face, which will only grow.
For instance, AI will increasingly empower malign reconnaissance, enabling attacks that probe, diagnose and bypass defences. At some point, quantum computing, with its awesome power, will fatally undermine our current approach to encryption. This is a highly demanding and ever-changing environment, and it is, frankly, preposterous to suppose that the 12 existing sector-specific regulators of our national infrastructure can acquire and constantly update the knowledge effectively to regulate cyber resilience.
I conclude emphatically that we need a single, focused, dedicated and expert regulator, which I suggest we call the office for cyber resilience—OCR—to span both the public and private sectors, including organisations and, vitally, those who supply them with the technologies they use. For clarity, the OCR should also regulate the national infrastructure providers.
First, I propose that the OCR should regulate platform and software providers to ensure that they sell and vouchsafe secure products up front and update them immediately when vulnerabilities become apparent. That does not happen at the moment. The Office for Product Safety and Standards does that in the UK for consumer goods and the Vehicle Certification Agency does it for cars. Why should there not be protection for our vital technology?
Secondly, companies and institutions of a significant size are currently required under statute to face an annual external audit, the purpose of which is to maintain high standards in financial reporting and corporate governance, under a code set by the FRC—Financial Reporting Council. We should extend the remit of that audit, under the auspices of the OCR, to report on the audited organisations’ and their suppliers’ management of cyber security and thus bring company boards clearly into play.
Thirdly and finally, we need to professionalise the skills of the cyber and IT community, which are highly variable. Every profession of which I am aware that can have a significantly adverse impact on individuals or society faces a hierarchy of qualification before a professional can operate at different levels—whether physician, lawyer, chartered accountant, architect or airline pilot.
How far across the economy would the OCR’s remit reach? It would extend precisely to the same extent as the obligation to have a statutory audit; that is, to companies with an annual turnover of about £15 million that have in excess of 50 employees. I have a perhaps surprising statistic for the noble Earl, Lord Effingham: that would mean only 2% of UK companies. But those companies represent around 70% to 80% of the UK economy.
To conclude, we simply must be bolder. We must take the opportunity that the Bill presents better to enable every kind of organisation in the UK to withstand the ever-growing and deeply disruptive threat of cyber attack.
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Birt
Main Page: Lord Birt (Crossbench - Life peer)Department Debates - View all Lord Birt's debates with the Department for Digital, Culture, Media & Sport
(3Â weeks, 6Â days ago)
Grand CommitteeMy Lords, I think that this is profoundly unsatisfactory. It is not good parliamentary procedure to table so many amendments radically different from anything that we have seen before, which I, for one, have seen only at the last minute, so to speak—I have read them, but I will not claim to have studied them. I do not altogether know what I think, but I readily accept that the noble Lord, Lord Clement-Jones, has had a chance to scrutinise them in a lot more detail than I have.
I do not have anything substantial to say, but I would like to ask the Minister a question. Manifestly, there is a national security risk, which we would all recognise, and we all recognise that something needs to be done about it. But, if this is a national security issue, perhaps the Minister could explain to us why it cannot be dealt with under existing national security procedures. I have had time to go on to the GCHQ website, where one finds an impressive and considered approach to handling different security issues of this kind called the “equities process”—I did not know about it until the weekend, but it is impressive to read. I just do not understand why you would lodge such a set of issues with DCMS rather than the Cabinet Office. DCMS seems to me completely the wrong home for identifying, weighing and working out what to do about things that have such profound ramifications. Perhaps the Minister could explain to us why existing procedures, which are well tested and, by and large, involve GCHQ with a lot of consent in other areas of government activity, cannot be applied here with the same sensitivity that GCHQ has shown on other occasions. We cannot have a meaningful discussion about this today, but I think that the Minister has to think about how we can have a meaningful discussion before we reach the next stage of the Bill.
My Lords, if I may, I will reiterate points that the noble Lord, Lord Birt, has made. A number of us are struggling to keep up. Much of what the noble Lord, Lord Clement-Jones, said made a lot of sense, but I certainly do not feel sufficiently sighted on the amendments and I would like to request from the Minister a proper briefing as soon as we possibly can. We have multiple days in Committee and I feel that we will keep going round the issue of how AI is being addressed in the Bill. At the core, we are all trying to stand on both sides of the fence: we are very nervous of these powers, which appear to have been snuck in without much scrutiny, but, on the other hand, at Second Reading many of us were clear that we want to see AI captured in the Bill. I am very much in two minds and would welcome a proper briefing from the experts.
Baroness Lloyd of Effra (Lab)
I am very happy to look at the points that noble Lords have raised in the course of this discussion. I believe that elements such as the consultation and the process of scrutiny are well thought out. I believe that in terms of the elements of subsequent parliamentary scrutiny—the reports that will be made both on the application or when the direction is affected—this is very much in keeping with other national security legislation which has been agreed by this and previous Governments. Many of these elements are very akin to processes that are operational in other areas of government. However, I am very happy to look at, and indeed will look at, all the points that noble Lords have raised. We will discuss them in subsequent meetings, and we will revert to them on Report.
Can the Minister explain why GCHQ is not the right home to exercise these powers? I am sure we will all agree that national security is a significant issue, but it is being lodged in departments that have no prior experience of it. What is wrong with existing GCHQ procedures, which are respected and trusted?
Baroness Lloyd of Effra (Lab)
I will need to write to the noble Lord on that specific question of how GCHQ’s powers are executed in respect of operational decisions such as this. I am aware that in other areas they are within Secretary of State responsibility, whether they are exercised by a Secretary of State, advised by GCHQ or whether, as the noble Lord suggests, they are actually undertaken by GCHQ.
My Lords, I will also speak to all the other amendments in my name, which are all supported by the noble Lord, Lord Londesborough, and some by others of your Lordships.
The Bill in its present form, as others have already said, is extraordinarily limited in scope and ambition—well short, for example, of the scope of the EU’s own NIS2 and its Cyber Resilience Act. One likely and highly unwelcome consequence of this shortfall is that, if the Bill passes in its present form, the UK will be even less well defended than our equivalents in Europe and even more of an attractive target for the bad actors than we are now.
Taken together, my amendments would, first, create a single regulator, the “Office for Cyber Resilience”, or OCR; secondly, they would extend the scope of the Bill to all services that have a material impact on the UK’s economy, society or defence and security; thirdly, they would place obligations on technology suppliers, barely discussed so far, to provide safe services; fourthly, they would require relevant bodies to adjust to threats from new and emerging technologies; fifthly, they would ensure that we have sufficient and appropriately qualified cyber professionals; and, sixthly, they would enable new organisations to be brought under the auspices of the Bill as circumstances change.
Why a single regulator? Because the threat we face, as we have heard all afternoon, is enormous, from state actors, from organised criminal gangs and even from obsessive teenagers. Since Second Reading, I have been made personally aware of multiple attempted hacks; some, on the public record, have succeeded, and some have been mentioned already. In July, after Second Reading, Lewis, the self-proclaimed teenage founder of cyber criminal group ExfilSquad, stole 607,000 records from the Department for Education, declaring it “stupid easy”. Such an attack is not at present within the scope of the Bill. In late July, the police national legal database was breached, exposing data on 100,000 police officers and criminal justice professionals. That is also not in scope. In August, as the noble Viscount, Lord Colville, mentioned, customers of Manchester, Stansted and East Midlands airports had their email addresses, phone numbers, vehicle registrations and postcodes stolen in an attack that is also not in scope.
There will have been, since we all last met, many more successful breaches that we simply do not know about, many with a highly adverse impact on the organisations concerned. We need a single regulator because we need a singular focus, not a fragmented one. We need to amass all relevant knowledge in one place about the perpetrators and the vulnerabilities. We need a singular focus on how to respond to minimise attacker success.
We should extend the scope of the Bill because it focuses only narrowly on a very small fraction of the economy, the 12 national infrastructure sectors, each with its own regulator, and because the overwhelming bulk of the high-performing private sector is excluded from the Bill, including M&S and JLR. The damage to our economy can only grow. Moreover, I can see no good reason why the Government themselves, or any part of the public sector—the NHS has just been mentioned—should enjoy a carve-out and should not be brought into scope too. I note that the EU’s NIS2 does just that, with limited exceptions.
My amendment on scope proposes that services that have a material impact on society, the economy or our defence and security should be deemed essential and should have an annual, independently conducted cyber resilience audit alongside the annual, independently conducted financial audit they all have now. For those concerned, rightly, about a possible burden on SMEs, I point out that there are around 6 million private sector businesses in the UK, but that 8,000 with more than 250 employees—less than one-fifth of 1% of the total—produce around half of all private sector turnover, so that only a tiny fraction of businesses would be included within the regulatory orbit of the OCR as I have defined it.
Why place obligations on suppliers? Because while some breaches occur because of poor practice within recipient organisations—falling for scams or failing to introduce multi-factor authentication, for example—at least an equivalent number of breaches result from providers selling insufficiently robust services or not closing down vulnerabilities speedily once they become apparent. In July, the supplier of a service to over 1,000 UK charities and non-profit organisations was breached and personal details and donations paid by multiple donors were stolen—a supplier not in scope.
Cars were once sold absent of all safety functionality—seat belts, airbags and the like—but Ralph Nader put an end to all that, thank goodness. The EU has the Cyber Resilience Act. We need an OCR to ensure that the UK’s modern technology suppliers provide safe-to-use and secure services. Why arm the OCR with the power to require relevant bodies to adjust to threats from new and emerging technologies? I think we have just had the answer to that question in spades, from quite a few devastating contributions—for me, the most affecting was from the noble Lord, Lord Tarassenko. New technologies like agentic AI pose an existential threat now. We all appear to agree about that. They are already escaping their minders and practicing trickery. They are in effect unregulated, but they simply must be—I only hear agreement on that question.
The only slight note of caution that I strike is that technology is changing all the time, so we cannot have a Bill which has such an amount of detail in it. I think it was the noble Viscount, Lord Camrose, who suggested it should be more principle-based. We cannot have something with lots of fine detail in it because things will change. Only one person so far has mentioned quantum technology, which will potentially have an even bigger impact down the line than AI. The UK, by the way, has the second highest number of quantum start-ups of any country in the world, second only to the United States.
Why give the OCR a role in the oversight of training and qualifying cyber professionals? Plainly, there are other ways of skinning this particular cat. However, I note how very poor all Governments have been over time in strategic skill planning—viz dentists, for instance. The previous Government’s founding of the Cyber Security Council was a valuable innovation. It is early days but, since its inception, it has qualified 1,761 professionals, 570 in the highest “chartered” category. Purely informal estimates, however, indicate that. across the UK economy as a whole, we will need something like 50,000 to -60,000 qualified cyber professionals, and the sooner we have them, the better.
We have a long road ahead, and with an OCR defined as the “powerhouse” of cyber security and abreast of the scale and nature of offending and vulnerabilities, it would be best placed to vouchsafe that the Cyber Security Council’s qualification standards are bang up to date. I suggest it should report annually on whether the numbers are sufficient and whether we are on track to produce the scale of cyber professionalism that both the public and private sectors will require.
Finally, why enable the OCR to recommend to the Secretary of State the expansion of the definition of an “essential service” to be brought under OCR regulation? Government can be a slow-moving, bureaucratic tangle and an independent, informed and focused regulator with just one job to do is much more likely to act with due urgency and identify vulnerable but critical and essential services that need to be brought under scope.
The noble Lord, Lord Arbuthnot, a gentle and much-respected man in the House who is careful with his words, described this Bill at Second Reading as “a muddle”. I fear that that was understatement. This Bill has been too long in the genesis. It completely fails to deal with the world as it has developed, as the most experienced and acute cyber professionals describe it and as the worst of its victims have experienced it. I implore the Minister to recognise that this is not a partisan matter, as has been very clear from our proceedings this afternoon. There are profound reservations across the Committee about the Bill as presently constructed. As the noble Baroness, Lady Kidron, just did, I urge the Minister to use the period between now and the Bill’s next stage to engage widely, open-mindedly and meaningfully with those who wish to improve it. I beg to move.
My Lords, I shall speak to Amendments 7, 9, 11, 76, 77 and 88 to 91 in the name of my noble friend Lord Birt, each of which I have added my name to, and to Amendment 87 in the name of the noble Lord, Lord Clement-Jones.
Baroness Lloyd of Effra (Lab)
The intent behind the cost recovery model is to provide a fair approach so that regulators, when regulating on cyber, can recover the costs associated with that. Further guidance will be put out on this. I cannot recall the Bill’s exact provisions on fines. I will come back to the noble Baroness on that.
My Lords, I confess to a real disappointment listening to the Minister’s response. We have sat here all afternoon and heard many strong contributions on many matters, but so far, the Government do not appear to have moved an inch on any of them.
I have a few quick points. The Minister just referred to the regulators. There are 12 regulators of 12 sectors, which is a tiny fraction of the economy. We have had this very profound discussion about AI today. Is she really asking us to believe that Ofwat is capable of mastering the complexity and continuing challenge that AI poses? To me, the answer is all too obvious.
Secondly, I say to the noble Baroness, Lady Neville-Jones, in particular, that I have sat on many boards over recent decades at different levels in the UK, in Europe and globally. An awful lot of expertise comes to the table, but it is absolutely out of the question that every board in the land will have a real cyber expert on it—hence the notion. A financial audit is a really powerful thing these days. It gets into the bowels of a company, and if anything is going wrong anywhere then it will find out about it. That is why I propose that we have a cyber resilience audit—not for every company in the land but for those that fall under the heading of essential services.
Finally, we are at war, and I completely agree with the noble Lord, Lord Londesborough, that the scale of the damage to our economy is almost certainly vastly underestimated. The framework imposed in this Bill is for fighting a war, but we see around the world at the moment that—guess what—wars change. Different weapons are used and different tactics come up. It is as if we have split the MoD and said that the Army will be with DCMS, the Navy will be with another department and the Air Force with another. The idea that you cannot have effective co-ordination within government and outside government honestly does not carry any weight. I beg leave to withdraw my amendment.
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Birt
Main Page: Lord Birt (Crossbench - Life peer)Department Debates - View all Lord Birt's debates with the Department for Digital, Culture, Media & Sport
(3Â weeks, 4Â days ago)
Grand CommitteeI, too, support the amendment from the noble Baroness, Lady Harding, as I do all the amendments previously discussed. By definition, a near miss means a severe threat narrowly avoided that would have had substantial consequences if it had not been avoided. The interesting thing is that everyone tells me that the near-miss reporting in the aviation industry proved to be massively significant and fundamentally changed the whole approach to air safety, with very beneficial consequences. The case is very sound that it should be applied here.
My Lords, I support this amendment, particularly in terms of its probing nature and what work can potentially be done between Committee and Report in this respect. It is really about the question of mandation. There should not be any question of a voluntary requirement. This is something that is not about the individual organisation, business or entity. It goes broader than that. It is about the community, the greater good and the country. The fact of a near miss says nothing about the severity of intent and the intel that can thus be gleaned to benefit at that point across the sector, the community, the country and beyond. Mandation has to be the standard for this provision.
My Lords, I have added my name to Amendment 167, in the name of the noble Baroness, Lady Ludford, and I also support Amendment 74. I have done that in the knowledge that it is perfectly possible that the Minister will say that she wants to minimise regulation wherever possible—I get that. But I also get that we have been saying for years now that cyber security should be a board responsibility, that it requires knowledge and that that knowledge requires training. That is what Amendment 167 would provide for. We have been saying that, but very little has actually happened. If we are not to legislate about this, what will make people act? If the noble Baroness, Lady Ludford, is right that board ownership of cyber security has declined, we have to do something.
I understand that people who start, say, a wine business or a book business are probably interested in wine or books, rather than cyber security. If they were interested in cyber security, they would probably start a cyber security business, in which they would probably make a great deal more money. But they have to be interested in cyber security in exactly the same way as they have to be interested in money—hence this proposed new clause, which I support.
My Lords, I strongly support the drift of both amendments spoken to by the noble Baronesses, Lady Kidron and Lady Ludford. As I said the other day, I have sat on many boards with many distinguished people that contained a variety of experience in many jurisdictions, but I have not often come across a board that contains anyone with a pronounced understanding of technology, let alone the extremely narrow but deep area of complexity that is cyber security.
I hope noble Lords will forgive me for reminding the Committee of what I said on Tuesday: the way to achieve this objective is to require boards, at an appropriate level—I do not mean every board in the land—to have a cyber resilience audit each year, in the way that all major organisations have a very searching financial audit each year for the whole board, even though it may contain people who are there for different reasons: they may have marketing or sector expertise. But believe me, for every single board, when the team of auditors—who have been in the business for weeks and sometimes months—reports, it is listened to, and anything it advises is acted upon. We need to do exactly the same for cyber resilience.
My Lord, this Bill is largely directed at a given segment of the corporate sector. That reminds us, however, that there is a very large swathe of the corporate sector that we are not focusing on directly.
However, in the corporate sector generally, the board has to be interested in all risks, not just financial risks, or whether the book market or the wine market is in good shape; it must be able to protect the business and its shareholders. The board has a duty to the shareholders to do that. This is a very good opportunity to try to raise the level of performance in this area. The record is demonstrably not very good. This is an opportunity to help raise the level of performance and make it clear that if you take on a responsibility as a board director, you will have to be able to help conduct the business of that organisation at the highest possible level. I very strongly support Amendment 167.
Let me just say, very briefly, that, as I made clear earlier in the week, the scope of the Bill is far too narrow. I suggested and will continue to suggest that we have to extend the definition of essential services. I remind all noble Lords, despite all the things we have been talking about this afternoon, that the organisations in the framing of the Bill, as drafted, are our national infrastructure sectors, not the great width of the economy or the public sector. In my amendments, I have suggested that we should have a definition of essential services that covers the economy—JLA and Marks & Spencer are not covered in the Bill—and society in general. We have just heard an excellent account of why education has to be included, as does defence and security. I do not think that we should be picking and mixing and putting a small number of sectors in the Bill. We need a conceptual approach to what we bring into the orbit of the Bill and we need a process in the Bill to ensure that that happens.
Baroness Lloyd of Effra (Lab)
I am not only committing; I am offering, so I am happy to have the noble Lord confirm that that would be good. I am absolutely offering that as part of the engagement ahead of Report.
I have heard the numerous areas that have been raised for inclusion in the Bill. We should look in a methodical and sensible way at these and at the implications—as we have previously discussed—for the obligations that will placed on any entities that come within the scope of the Bill, such as incident reporting, board accountability and so on, so that we do this in a very sensible manner. That is why this is the right approach to take.
Can I ask the Minister to comment on another point that the noble Lord, Lord Clement-Jones, raised? Why should this not apply to the higher reaches of government? I ask the Minister specifically: what is her view of 607,000 records being stolen, just weeks ago, from the Department for Education?
Baroness Lloyd of Effra (Lab)
I absolutely intend to talk about the public sector. Given the numerous sectors that have been raised, I also want to respond individually on each sector. I absolutely agree that all sectors need to improve their cyber resilience; it is not the case for only those in the regulatory perimeter. It is also not the only way to improve; we should improve things right now. There is funding, and there are activities going on in all of these sectors that we might talk about—sometimes with public funding, sometimes with public advice and sometimes through industry groups.
I have spoken a little already about the cyber resilience pledge, which over 100 companies have now signed. It sets out the absolute best practice and what actions to take, including making cyber a board-level responsibility, following the Cyber Governance Code of Practice, signing up to the early warning service and taking a risk-based approach to requiring cyber essentials across supply chains.
In the retail sector, the DBIST industry-led Retail Sector Council is working with experts and business representatives to consider cyber security.
In respect of the space sector, it is absolutely critical; I could not agree more on the importance of PNT and satcoms, which underpin a huge amount of UK economic activity. The UK Space Agency is already strengthening cyber resilience in practice through the development of a space cyber assurance framework for the space sector, intending to help operators understand and demonstrate cyber resilience in a proportionate and practical way.
The UKSA also supports the provision of threat briefings and is working with industry on the potential development of a space information-sharing analysis centre. This would improve the flow of threat information, warnings and good practice between government and industry, and support links to international networks, such as the US-led global Space ISAC model. That would help operators to understand emerging threats and to act quickly.
My Lords, I echo the words of the noble Baroness, Lady Kidron: in the previous group, we probably would not have had anything like that debate if a clear strategy were indeed in place.
I will speak very briefly and in the context of other countries’ views of the safety and security of doing business with the UK and UK entities. Part of the backdrop is an attempt by His Majesty’s Government to try to do a reset with the EU, not least because of the problems we are having with our erstwhile colonial possessions across the Atlantic. We need to be viewed as a safe haven for the security of our business and data. If we look at what the EU, for all its bureaucratic idiosyncrasies, has been doing with NIS2, in many instances that is an extremely good model for us when looking comprehensively at the different sectors that need to be involved. NIS2 covers energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ISP services, public administration, space, postal services, waste management, chemicals, food, manufacturing, research and other critical parts of the economy. The EU is ahead of us and has done a great deal of groundwork; if we were to talk to the EU, we could benefit hugely without reinventing the wheel.
It is imperative not only that we give noble Lords and parliamentarians a feeling that we know what we are doing and where we are going but that other countries currently doing, or thinking of doing, business or more business with us have faith in the security of our data and cyber security infrastructure. If I were looking to invest in a company, that is an area I would look at very carefully—but, frankly, at the moment, I would not feel very confident.
My Lords, these amendments are highly pertinent. We simply must ensure that non-UK providers of services in this sector are firmly and wholly within the scope of the Bill—they are only partly in scope. For noble Lords who were not at Second Reading, I read out a coruscating report by the American Government that damned Microsoft for its poor cyber security. I am sure that it is not true across the whole of Microsoft, but in that particular instance it manifestly was.
I observe that our previous debate was absolutely excellent; it uniformly focused on organisations in the UK that are providing services. There was a danger that somebody hearing that debate might think that all those organisations are themselves responsible for breaches. The data on whether breaches chiefly occur through failures in organisations mentions the absence of multifactor authentication or that they are caused by failures in the quality and design of the services that those organisations consume. By the way, the organisations consume literally hundreds and hundreds of services, and the reality is that it is a huge challenge for organisations to ensure that all the services that they buy are secure. We might say that it is a near impossibility. Again, it is absolutely vital that we keep providers firmly within the scope of the Bill—I am not saying that they are not there, but they are certainly not there in their totality—and, dare I say, firmly under regulation.
Before the Minister sits down, I ask her to reflect, at the end of our second day in Committee, that the noble Viscount, Lord Camrose, has mentioned more than once that he would like to see a national cyber security strategy, but is not the takeaway from these two days that we are all very clear on the challenges facing the UK? There is a great deal of uniformity across the Room, as well as in the quality of the Minister’s answers, but does the Bill not need to deal with all the issues that have surfaced and been addressed? Frankly, it does not do that at the moment. If the Bill passes in its less ambitious form, how long will it be before we get another Bill to address the strategies? If we have to wait that long, how much more damage is going to be done to our economy and our society in the meantime?
Baroness Lloyd of Effra (Lab)
Going back to the point made by the noble Lord in an earlier intervention, the Bill is a substantive Bill that substantially increases coverage of the digital infrastructure on which much of our economy relies. That is a very important point. As I mentioned at the start of my remarks just now, the question of whether the Bill is the right place to articulate the breadth of many of the issues that have been raised is, indeed, a good one. I am not sure that it is the right place to articulate all the very good questions that have been asked, because some are much more wide-ranging than the scope of the Bill.
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Birt
Main Page: Lord Birt (Crossbench - Life peer)Department Debates - View all Lord Birt's debates with the Department for Digital, Culture, Media & Sport
(3Â weeks ago)
Grand CommitteeMy Lords, I support Amendment 100, in the name of the noble Baroness, Lady Northover. I spoke in support of this type of amendment at Second Reading and I still support its intentions, but I will give it an added twist. The question in my mind is where this resource for SMEs should sit and whether it should have any statutory powers or simply be an information and advisory centre.
There is no doubt that cyber security is needed—and here is another scary statistic—because 96% of all successful cyber attacks in the UK are perpetrated on SMEs, which represent soft targets for hackers. I suggest—here I take noble Lords back to day 1 of Committee— that this resource should sit within the office for cyber resilience proposed by the noble Lord, Lord Clement-Jones, and my noble friend Lord Birt. Indeed, this is yet another example of the need to establish a body like an OCR, given the disturbingly fragmented approach to cyber security in this Bill.
Where can we sensibly draw the line between SMEs across all sectors and the rest of the business world? For instance, advice given to a medium-sized company with, say, 200 staff will overlap hugely with that given to a company with 2,000 staff. In the minds of the hackers and the ransomware merchants there is very little distinction. I argue that our economy needs a coherent, joined-up approach, run by a single competent authority with statutory teeth, for the benefit of SMEs and other companies and sectors.
I am afraid that, as it stands, this Bill is a recipe for chaos. Cooks and broth would be a kind analogy—there is barely any room in the kitchen for the number of departments, teams, councils, centres and agencies involved. The last count I heard was 30 or so, but I believe a few more have cropped up since.
I think we all share the sympathy that the noble Baroness, Lady Northover, has identified SMEs need. There are 5.7 million SMEs in the UK and many of them—indeed, most of them—will purchase what are relatively complex platforms. The noble Lord, Lord Londesborough, is extremely experienced in the SME sector; I have less experience than him, but I do have some. Hardly any of them will be able to employ anybody who is able to understand either the complexity of the platform that they have purchased or the highly dynamic threats to that platform that exist. There are many ways in which we need to raise our game and to help.
I personally think that, at least in the short term, the most important thing, which we have not discussed enough so far, is to require providers to supply safe products and, moreover, when they become vulnerable—which happens all the time, often unexpectedly—to patch those products for their customers immediately. The providers have a level of sophistication that the customers do not, and we have insufficiently focused on that in our discussion so far.
The second thing to mention—this is not really part of the Bill—is that the Government’s Cyber Essentials programme is very sound. The Minister quoted a figure the other day, which I forget, but only a trivial number of businesses have signed up and taken the pledge. This needs much more publicity and much more dynamism from within government to raise the understanding of the level of threat that SMEs face.
My Lords, I too support Amendment 100, in the name of my noble friend Lady Northover, and will add my support to the very useful speeches from the noble Lords, Lord Vaizey, Lord Birt and Lord Londesborough. I entirely agree with the noble Lord, Lord Vaizey, about the need to inject a sense of urgency into this. The noble Lords, Lord Birt and Lord Londesborough, asked some very fair questions, which went back to some of the debate we had on a single regulator and product liability, all of which are relevant to the kinds of duties that SMEs are under.
I welcome what the Minister had to say about the Government’s consciousness of the needs of SMEs, but this amendment would provide a blueprint for a much better form of support for SMEs. They account for 99% of all private sector businesses but, as the NCC Group and industry experts have repeatedly warned, they represent what might be described as the soft underbelly of our national supply chains. They are the prime targets for cyber criminals seeking a backdoor into critical infrastructure.
It is completely unrealistic to expect a 60-person small supplier to bear the same heavy compliance overheads as a multinational utility. A single ransomware attack can permanently destroy a small firm. Hostile state actors and ransomware syndicates are no longer focusing exclusively on attacking the fortified perimeters of FTSE 100 utilities or government departments; instead, they deliberately target smaller, resource-poor suppliers and niche contractors embedded in tier 2 or tier 3 of critical supply chains, using them as an easy, undefended backdoor into our critical national infrastructure.
Under the expanded critical supplier provisions in Clause 12 and the managed services duties in Clause 9, thousands of medium-sized businesses and specialised tech vendors will now be pulled directly into the statutory NIS regime, facing severe regulatory requirements under threat of multi-million pound penalties. However, as the Government’s own impact assessments acknowledge, there is a staggering what might be called resource asymmetry across UK businesses. A 50-person specialised component manufacturer or regional logistics provider does not have a dedicated chief information security officer or possess a 24/7 security operations centre and cannot afford to hire elite forensic incident response teams on £500-an-hour retainers. When a sophisticated ransomware attack hits a small business, it is frequently an existential event that forces insolvency.
During Committee stage in the Commons, when my honourable friend Freddie van Mierlo MP brought forward this proposal, the Minister in the Commons rejected it on the grounds that the Government already provide voluntary advice online. A downloadable PDF checklist on GOV.UK is not an incident response service. When a small critical supplier is locked out of its servers by a Russian ransomware gang at 2 o’clock on a Sunday morning, a generic website checklist is completely useless. It does not need advice to check its passwords; it needs an active, human, technical first responder to help it contain the malware, isolate compromised systems and safely recover its data.
Amendment 100 would bridge this capability gap by mandating a dedicated national support service modelled directly, as my noble friend explained, on the proven and globally respected Australian Cyber Security Centre’s framework. In Australia, the federal Government provide small and medium-sized businesses with free direct phone-in emergency technical support, active breach triage and hands-on recovery assistance. It has achieved extraordinary success in hardening Australia—